Agent skill

Prismer Role Builder

by Prismer-AI in Prismer-AI/PrismerCloud

Creates or updates Prismer role templates from a persona, SOP or job description, and turns a role into a working agent that runs its first task through a bundled script.

MITAuto-check: notesAgent Workflows

Install Prismer Role Builder

skills CLI
$ npx skills add Prismer-AI/PrismerCloud --skill role-builder -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Prismer-AI/PrismerCloud role-builder --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Prismer-AI/PrismerCloud.git skills-src && mkdir -p .claude/skills && cp -r skills-src/sdk/cloud/catalog/skills/role-builder .claude/skills/role-builder && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
role-builder
GitHub stars
1.6k
Token cost
~2.3k tokens
SKILL.md length
873 words
Files
5 (incl. scripts)
Skills in repo
88
Repo updated
First seen
Licence
MIT

At a glance

Creates or updates Prismer role templates from a persona, SOP or job description, and turns a role into a working agent that runs its first task through a bundled script.

  • Works in 6 steps: Secret-bearing flags, missing/invalid… → Server preflight rejects… → Instance and task writes carry durable… → …
  • Turning a job description or SOP into a role template
  • SKILL.md covers A. Existing role → new working…, B. Material → role template, C. Change an existing agent's… and Configuration ownership, plus 2 more sections
  • Runs JavaScript scripts from its folder; calls node; needs PRISMER_API_KEY

What it does

The agent picks exactly one of two paths and does not explore the CLI first. Path A takes an existing role and runs `node scripts/instantiate-and-run.mjs --json`, which validates locally, does a server preflight, creates or resumes the role-backed agent, waits for its daemon binding, creates one idempotent task and waits for the result. It needs `PRISMER_API_KEY`, `PRISMER_CLOUD_BASE`, `PRISMER_ROLE_SLUG`, `PRISMER_WORKSPACE_ID` and `PRISMER_TASK` injected by the runtime, and credentials are never pasted into chat or passed as flags.

Path B turns source material into a role bundle: a directory with a `role.json` governance manifest and a `SOUL.md` persona file, with no credentials, per-run instructions or `AGENTS.md` inside. Skill slugs must come from the create or import result and are never invented, and missing skills are built first with `skill-creator`. The `--no-wait` and `--preflight-only` flags skip the final wait or any change, and a `ROLE_CONFIG_REQUIRED` result is reported with the exact missing level, target and key names. The excerpt is cut off in the manifest guidance.

When your agent uses it

  • Turning a job description or SOP into a role template
  • Creating a working agent from an existing role
  • Running a first task through a role-backed agent

Example prompts

  • “Create a role template for a legal-expert agent from the job description in docs/legal-brief.md.”
  • “Make the support-lead role into an agent and have it triage today's tickets.”
  • “Run a preflight only for instantiating the finance-analyst role in my workspace.”

Requirements

  • Node.js to run the bundled scripts
  • Prismer variables such as `PRISMER_API_KEY` and `PRISMER_WORKSPACE_ID`, injected by the runtime
  • Compatibility (from SKILL.md): ["prismer-sdk","hermes","claude-code","codex","openclaw"]
  • Pre-approved tools (allowed-tools): Read, Write, Bash, WebFetch

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Secret-bearing flags, missing/invalid local input, and unconfirmed remote
  2. Server preflight rejects inaccessible/non-deployable roles, missing config,
  3. Instance and task writes carry durable idempotency keys. Instance retries
  4. A secret-free ledger is written atomically before mutation. Output contains
  5. Provisioning failure compensates the newly created agent. Incomplete cleanup
  6. ready means the Agent is bound to the exact requested daemon. A

What it can do on your machine

Read from SKILL.md and the folder at commit e5d9444. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Bash
    • WebFetch

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 4 files in scripts/ (JavaScript), which the agent can run.

    Shell commands in SKILL.md call:

    • node

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • PRISMER_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    ["prismer-sdk","hermes","claude-code","codex","openclaw"]

    From compatibility in the SKILL.md frontmatter.

Context cost

Prismer Role Builder loads about 2.3k tokens when it runs. Until then it costs about 123 tokens; SKILL.md has 873 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~123
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Write, Bash, WebFetch

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from Prismer-AI/PrismerCloud at commit e5d9444, republished under its MIT licence (© Prismer-AI). 873 words, ~2,296 tokens.

Download SKILL.mdSave it as .claude/skills/role-builder/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
role-builder
description
Create or update a Prismer SS-02 role template from a persona, SOP, job description, or operating brief; instantiate an existing role as a new working agent and run its first task through the bundled one-command harness. Use for "create a role template", "make this role into an agent", "create an agent from this role", or "let this role handle a task". Route standardized instantiate-and-run requests to the script instead of discovering and composing low-level CLI commands.
allowed-tools
Read, Write, Bash, WebFetch
compatibility
["prismer-sdk","hermes","claude-code","codex","openclaw"]
scope
common
category
authoring
license
MIT
metadata.category
authoring

Role Builder

Choose exactly one path from the requested outcome. Do not inspect cloud --help, create probe assets, or compose low-level commands first.

A. Existing role → new working agent → first task

Run the bundled harness directly:

bash
node scripts/instantiate-and-run.mjs --json

Required environment:

  • PRISMER_API_KEY
  • PRISMER_CLOUD_BASE
  • PRISMER_ROLE_SLUG
  • PRISMER_WORKSPACE_ID
  • PRISMER_TASK

Optional environment:

  • PRISMER_AGENT_HANDLE, PRISMER_AGENT_DISPLAY_NAME, PRISMER_AGENT_ADAPTER, PRISMER_TARGET_DAEMON_ID
  • PRISMER_REQUEST_ID, PRISMER_OPERATION_LEDGER
  • PRISMER_WORKFLOW_TIMEOUT_MS, PRISMER_WORKFLOW_POLL_MS
  • PRISMER_ALLOW_REMOTE_WRITE=1 for an explicitly confirmed non-local target

The runtime must inject these variables before the turn. Never ask the user to paste a credential into chat and never pass one as a command-line flag.

The harness validates locally, performs server preflight, creates/resumes the role-backed agent, waits for its exact daemon binding, creates one idempotent task, and waits for the canonical result. --no-wait skips only the final task result wait. --preflight-only performs no mutation.

If it returns ROLE_CONFIG_REQUIRED, report the missing level, target, and key names exactly. Do not guess values:

  • level=skill or level=role, user-owned key: the owner supplies it through Studio or POST /api/im/user-skill-config; values are sealed and never enter the model prompt.
  • role default: edit the role's parameters[] declaration/default.
  • global-only Skill key: inject it into the daemon/deployment environment.
  • workspace/runtime issue: repair the named workspace or daemon; do not create a different workspace as a workaround.

B. Material → role template

Create a directory with exactly the role definition and persona:

text
<role-slug>/
├── role.json
└── SOUL.md

role.json is the SS-02 governance manifest. SOUL.md is persona only; do not put credentials, per-run instructions, or an AGENTS.md in the role bundle.

Minimum useful role.json:

json
{
  "slug": "legal-expert",
  "version": "1.0.0",
  "name": { "en": "Legal Expert", "zh": "法学专家" },
  "description": { "en": "Analyzes legal matters.", "zh": "分析法律事项。" },
  "agentType": "specialist",
  "requiredSkills": [{ "skillSlug": "legal-article-retrieval", "required": true }],
  "taskAuthority": "executor",
  "approvalPolicy": "auto-low-risk",
  "parameters": [],
  "adapters": { "hermes": {} },
  "source": "community",
  "curatedQuality": "review"
}

Use catalog slugs returned by the Skill create/import result. Never derive a slug from a directory name, case-normalize it after creation, or invent one. Build missing skills with skill-creator first.

Declare only role-specific business skills in requiredSkills. The active Admin Built-in Skill baseline is injected automatically at template creation and re-resolved when an Agent is instantiated. Do not copy system skills into the role manifest and do not attempt to remove an injected skill. Readback separates requiredSkills, injectedSkills, and effectiveSkills, plus the baselinePolicyVersion used for the snapshot.

Put the bundle path in PRISMER_ROLE_BUNDLE, then run the fixed authoring closure as one command:

bash
node scripts/author-role.mjs --json

Optional environment: PRISMER_ROLE_PUBLISH=1 for an explicitly requested Marketplace publish, PRISMER_ROLE_AUTHORING_LEDGER, PRISMER_CLOUD_BIN, PRISMER_CLOUD_BASE, and PRISMER_ALLOW_REMOTE_WRITE=1 for a confirmed non-local target. The harness performs local validation, read-only required Skill preflight, private create/owner-update, and owner readback. It resumes a completed same-revision ledger without pushing another role version. Report the returned slug/version; do not use role apply as a test.

The clean lower-level primitives remain available for diagnosis:

bash
cloud role validate ./<role-slug> --json
cloud role test ./<role-slug> --json
cloud role create ./<role-slug> --mine --json
cloud role show <returned-slug-or-id> --json

For the retained legacy entrypoint (requires the current Cloud CLI; no raw HTTP fallback):

bash
node scripts/ingest-role.mjs ./<role-slug> --mine

It reads PRISMER_API_KEY and PRISMER_CLOUD_BASE from the already-injected environment. Do not write literal secrets in the command, bundle, or ledger. The adapter delegates validation and Skill preflight to Cloud before creation. Ledger-based workflows require an injected API key even if Cloud has saved credentials: the target origin and that executing key's hash bind every receipt. Changing either requires a separate ledger. Completed receipts are read back, not blindly trusted. A lock is never stolen on timeout; after a crash, verify the old process has stopped and reconcile remote writes before explicit recovery.

Show full SKILL.md (362 more words)Show less

C. Change an existing agent's role

Only when the user explicitly identifies an existing target:

bash
cloud role apply <role-slug> --agent <imUserId> --workspace-id <workspaceId>

Never apply a role to the currently executing agent as a probe. Template creation is complete after validation, dependency test, ingest, and readback; it does not require mutating a live agent.

Configuration ownership

Declare each value once at the level that owns it:

NeedOwner/declarationDelivery
reusable Skill configSkill frontmatter config:Skill subprocess env
role behavior/defaultrole parameters[], kind:"default"structured roleParams
per-account role secretrole parameters[], kind:"user", type:"secret"environment-only roleParamsEnv
role default for a required Skillrole skillConfig[skillSlug]resolved Skill env
workspace identity/policyworkspace fields and policy APIsserver/runtime bootstrap
workspace runtime secretdaemon/deployment envchild process env only
invocation target/recoveryPRISMER_WORKSPACE_ID, daemon/request/ledger envharness request only

Do not duplicate values across Skill prose, role persona, workspace metadata, and workflow flags. Workspace metadata is not a secret store.

Harness negative-control contract

The bundled mutation harness must keep these guarantees:

  1. Secret-bearing flags, missing/invalid local input, and unconfirmed remote writes fail locally before any fetch.
  2. Server preflight rejects inaccessible/non-deployable roles, missing config, handle collisions, and absent runtime before creating an operation or agent.
  3. Instance and task writes carry durable idempotency keys. Instance retries return the same operation and reject changed instance input with 409; task retries return the first committed task and reject changed task input with 409. Derived task keys are fixed-length hashes, so a 191-character instance request ID cannot overflow the task contract. A new invocation gets a fresh request ID; set PRISMER_REQUEST_ID only to resume that same invocation.
  4. A secret-free ledger is written atomically before mutation. Output contains stage, code, retryability, and recovery path—never credentials. Reusing the ledger path with a different invocation hash is rejected before fetch.
  5. Provisioning failure compensates the newly created agent. Incomplete cleanup remains cleanupStatus=pending with the Agent pointer retained and retryable; it must never be reported as cleaned. Task failure keeps a valid agent for diagnosis/retry.
  6. ready means the Agent is bound to the exact requested daemon. A wrong_daemon binding fails explicitly and cannot advance to task creation.

Sources of truth

  • Role standard: public/docs/Standardization/02-role-template-standard.md
  • Harness standard: public/docs/Standardization/16-automation-harness-standard.md
  • Complete catalog example: sdk/cloud/catalog/roles/team-manager.json
  • Skill authoring/import: sdk/cloud/catalog/skills/skill-creator/SKILL.md

© Prismer-AI, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts) in sdk/cloud/catalog/skills/role-builder of Prismer-AI/PrismerCloud.

  • SKILL.md
  • scripts/author-role.mjs
  • scripts/ingest-role.mjs
  • scripts/instantiate-and-run.mjs
  • scripts/operation-harness.mjs

Open the folder on GitHubat commit e5d9444

Compare with similar skills

Prismer Role Builder next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Prismer Role Builder compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Prismer Role Builder this skillPrismer-AI/PrismerCloud1.6k—~2.3kAutomated safety check: NotesMIT
Agent Creatorjdforsythe/forge151—~4.5kAutomated safety check: PassMIT
Mg CLImodelguide/modelguide108—~3.5kAutomated safety check: PassMIT
Agentsop Idempotent Ingestionagentsope/SkillAlchemy466—~6.8kAutomated safety check: PassMIT
Agentsop Crewaiagentsope/SkillAlchemy466—~4.8kAutomated safety check: PassMIT
Sop PlanStanshy/AgentHub202—~437Automated safety check: NotesMIT

Similar skills

  • Agent Creator

    jdforsythe/forge

    Creates structured agent definitions using the 7-component format grounded in persona science (the alignment-accuracy tradeoff), vocabulary routing, and the MAST failure taxonomy + Forge watchlist.

    151 GitHub stars~4.5k tokensUpdated 3 mo ago
    Agent WorkflowsAuto-check passed
  • Mg CLI

    modelguide/modelguide

    Generate YAML configuration files and run CLI commands to onboard organizations into ModelGuide.

    108 GitHub stars~3.5k tokensUpdated 3 mo ago
    AI & LLM EngineeringAuto-check passed
  • Agentsop Idempotent Ingestion

    agentsope/SkillAlchemy

    Re-ingest-correctness SOP for production RAG. An agent skill from agentsope/SkillAlchemy.

    466 GitHub stars~6.8k tokensUpdated today
    AI & LLM EngineeringAuto-check passed
  • Agentsop Crewai

    agentsope/SkillAlchemy

    SOP for building multi-agent systems with CrewAI — role-based collaboration, sequential/hierarchical processes, Flows, memory, delegation.

    466 GitHub stars~4.8k tokensUpdated today
    AI & LLM EngineeringAuto-check passed
  • Sop Plan

    Stanshy/AgentHub

    L1 計畫模式 SOP — 強制上下文載入 + Plan Mode 評估 + 任務拆解. An agent skill from Stanshy/AgentHub.

    202 GitHub stars~437 tokensUpdated 6 mo ago
    Agent WorkflowsAuto-check: notes
  • Solution Architect

    IBM/ibm-watsonx-orchestrate-adk

    Official

    Expert guidance for creating high-level solution architecture documents from business requirements, use cases, or problem statements.

    178 GitHub stars~8.4k tokensUpdated yesterday
    Agent WorkflowsAuto-check passed

More from Prismer-AI/PrismerCloud

All 88 skills in this repo
  • Prismer Google Workspace

    Prismer-AI/PrismerCloud

    Gives an agent account-scoped access to Gmail, Calendar, Drive, Contacts, Docs and Sheets through the gws CLI or a bundled Python client.

    1.6k GitHub starsUsed in 3 repos~4.2k tokens
    Auto-check passed
  • Prismer Skill Creator

    Prismer-AI/PrismerCloud

    Walks an agent through creating, importing, editing, validating, testing and publishing Prismer Skills with a fixed workflow and bundled scripts.

    1.6k GitHub stars~2.6k tokensUpdated 9 days ago
    Auto-check: notes
  • Himalaya Email CLI

    Prismer-AI/PrismerCloud

    Operates a mailbox from the terminal with the external Himalaya CLI over IMAP, SMTP, Notmuch or Sendmail, separate from any built-in email gateway adapter.

    1.6k GitHub starsUsed in 2 repos~2.3k tokens
    Auto-check passed
  • Prismer Image Generation

    Prismer-AI/PrismerCloud

    Generates one image from a text prompt with a bundled Node.js helper and delivers it once as the attachment to the current Prismer reply.

    1.6k GitHub stars~1.4k tokensUpdated 9 days ago
    Auto-check passed
  • Manim Explainer Videos

    Prismer-AI/PrismerCloud

    Produces 3Blue1Brown-style explainer animations with Manim Community Edition for math, algorithms, equations and architecture diagrams, with planning and rendering references.

    1.6k GitHub starsUsed in 2 repos~3.1k tokens
    Auto-check passed
  • YouTube Transcript Reformatter

    Prismer-AI/PrismerCloud

    Fetches a YouTube transcript with a helper script and reshapes it into chapters, summaries, X threads, blog posts or timestamped quotes.

    1.6k GitHub starsUsed in 2 repos~905 tokens
    Auto-check passed

Questions about Prismer Role Builder

What does Prismer Role Builder do?

Creates or updates Prismer role templates from a persona, SOP or job description, and turns a role into a working agent that runs its first task through a bundled script. The agent picks exactly one of two paths and does not explore the CLI first.mjs --json`, which validates locally, does a server preflight, creates or resumes the role-backed agent, waits for its daemon binding, creates one idempotent task and waits for the result.

When should I use Prismer Role Builder?

Prismer Role Builder fits situations like: turning a job description or SOP into a role template; creating a working agent from an existing role; running a first task through a role-backed agent.

How do I install Prismer Role Builder in Claude Code?

Run `npx skills add Prismer-AI/PrismerCloud --skill role-builder -a claude-code`. Or copy the skill folder (sdk/cloud/catalog/skills/role-builder in Prismer-AI/PrismerCloud) into .claude/skills/role-builder in your project. Claude Code loads it when a task matches its description.

How do I install Prismer Role Builder in Codex?

Run `npx skills add Prismer-AI/PrismerCloud --skill role-builder -a codex`. Or copy the skill folder (sdk/cloud/catalog/skills/role-builder in Prismer-AI/PrismerCloud) into .agents/skills/role-builder in your project. Codex loads it when a task matches its description.

Can I use Prismer Role Builder in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Prismer-AI/PrismerCloud --skill role-builder -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/role-builder, .gemini/skills/role-builder, .github/skills/role-builder and .opencode/skills/role-builder in your project.

What does Prismer Role Builder need to run?

Going by SKILL.md and its folder, Prismer Role Builder needs JavaScript for the scripts in its folder, the command-line tools its instructions call (node) and credentials named PRISMER_API_KEY. Our summary lists: Node.js to run the bundled scripts; Prismer variables such as `PRISMER_API_KEY` and `PRISMER_WORKSPACE_ID`, injected by the runtime. Its frontmatter pre-approves these tools: Read, Write, Bash, WebFetch. Compatibility (from SKILL.md): ["prismer-sdk","hermes","claude-code","codex","openclaw"].

Does Prismer Role Builder access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Prismer Role Builder safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Prismer Role Builder use?

Prismer Role Builder is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Prismer Role Builder use?

About 2.3k tokens (SKILL.md is roughly 9.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Prismer Role Builder?

Skills that share tags, products or a category with Prismer Role Builder: Agent Creator (jdforsythe/forge, 151 stars), Mg CLI (modelguide/modelguide, 108 stars), Agentsop Idempotent Ingestion (agentsope/SkillAlchemy, 466 stars) and Agentsop Crewai (agentsope/SkillAlchemy, 466 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Prismer Role Builder?

Prismer-AI (a GitHub organization) maintains it in Prismer-AI/PrismerCloud, which has 1,555 GitHub stars. The repository holds 88 skills in this directory. The repository was last updated on September 30, 2026.

Source: Prismer-AI/PrismerCloud on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.