Agent skill

Dakota Ujust

by projectbluefin in projectbluefin/dakota

Author safe end-user ujust recipes in files/just-overrides/default.just, including quoting, gum, JSON, and public-post confirmation.

MITAuto-check: notes

Install Dakota Ujust

skills CLI
$ npx skills add projectbluefin/dakota --skill dakota-ujust -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install projectbluefin/dakota dakota-ujust --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/projectbluefin/dakota.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/dakota-ujust .claude/skills/dakota-ujust && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
dakota-ujust
GitHub stars
180
Token cost
~1.1k tokens
SKILL.md length
472 words
Files
1
Skills in repo
10
Repo updated
First seen
Licence
MIT

At a glance

Author safe end-user ujust recipes in files/just-overrides/default.just, including quoting, gum, JSON, and public-post confirmation.

  • Works in 5 steps: Author Recipe: Add or edit the recipe in… → Quote & Validate Arguments: Pass all… → Check Recipe Parsing: Parse the file… → …
  • SKILL.md covers When to Use, When NOT to Use, Core Process and Invariants, plus 4 more sections
  • Calls just and jq

What it does

Dakota Ujust is an agent skill from projectbluefin/dakota. Author safe end-user ujust recipes in files/just-overrides/default.just, including quoting, gum, JSON, and public-post confirmation.

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: The buildstream for making Bluefin. The licence is MIT.

Example prompts

  • “/dakota-ujust”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Author Recipe: Add or edit the recipe in files/just-overrides/default.just.
  2. Quote & Validate Arguments: Pass all arguments through quote() and validate with bash regular expressions
  3. Check Recipe Parsing: Parse the file with the Just version shipped in the target image: just --justfile files/just-overrides/default.just…
  4. Guard Interactive Steps: Ensure commands requiring a TTY fail closed when run in non-interactive environments
  5. Rebuild & Verify

What it can do on your machine

Read from SKILL.md and the folder at commit 909f687. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • just
    • jq

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Dakota Ujust loads about 1.1k tokens when it runs. Until then it costs about 36 tokens; SKILL.md has 472 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~36
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteRuns commands with sudoSKILL.md:52
    - **Non-Interactive Sudo**: Use `sudo -n` for status checks so scripted recipe execution does not hang waiting for a pas

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from projectbluefin/dakota at commit 909f687, republished under its MIT licence (© projectbluefin). 472 words, ~1,108 tokens.

Download SKILL.mdSave it as .claude/skills/dakota-ujust/SKILL.md (or your agent's skills folder).
name
dakota-ujust
description
Author safe end-user ujust recipes in files/just-overrides/default.just, including quoting, gum, JSON, and public-post confirmation.
metadata.context7-sources
/bootc-dev/bootc

Dakota ujust Recipes

just <recipe> is for developers and CI from the root repository Justfile. ujust <recipe> is for end users inside the booted image, authored in files/just-overrides/default.just and built via elements/bluefin/just-overrides.bst.

When to Use

  • Adding, editing, or testing end-user convenience recipes in files/just-overrides/default.just
  • Modifying data donation commands (ujust report, ujust confirm, ujust verify)
  • Handling CLI interaction tools like Charm gum, desktop notifications, or system diagnostics

When NOT to Use

  • Editing repository-level developer commands in the root Justfile → load dakota-buildstream
  • Modifying host Homebrew wrapper recipes → load dakota-workstation
  • Adding BST elements → load dakota-packaging

Core Process

  1. Author Recipe: Add or edit the recipe in files/just-overrides/default.just.
  2. Quote & Validate Arguments: Pass all arguments through quote() and validate with bash regular expressions:
    just
    ISSUE={{ quote(issue_number) }}
    [[ "$ISSUE" =~ ^[1-9][0-9]*$ ]] || exit 2
  3. Check Recipe Parsing: Parse the file with the Just version shipped in the target image: just --justfile files/just-overrides/default.just --list. Heredocs are allowed when their indentation and delimiters parse correctly. Prefer jq -n for constructing JSON.
  4. Guard Interactive Steps: Ensure commands requiring a TTY fail closed when run in non-interactive environments:
    bash
    if [ ! -t 0 ]; then
        echo "Interactive terminal required" >&2
        exit 1
    fi
  5. Rebuild & Verify:
    bash
    just bst build bluefin/just-overrides.bst

Invariants

  • Mandatory Quoting: Just interpolates recipe arguments textually before bash parses them. Every parameter MUST pass through {{ quote(...) }} to prevent shell injection.
  • No Global Positional Arguments: Never add set positional-arguments to files/just-overrides/default.just; this file merges into the global system recipe set.
  • Fail Closed Without TTY: Any recipe posting data publicly (e.g. creating GitHub issues or gists) must fail closed when stdin is not a terminal. Never treat a failed gum confirm as affirmative consent.
  • Non-Interactive Sudo: Use sudo -n for status checks so scripted recipe execution does not hang waiting for a password prompt.
  • Version-Specific Parsing: Older Just versions (including previously reported 1.47.1 cases) had heredoc parsing problems; that is not a blanket prohibition. Existing recipes parse with 1.58.0. Check the target image's version and test both Just parsing and the rendered shell syntax before changing valid heredocs.
Show full SKILL.md (160 more words)Show less

Common Rationalizations

RationalizationReality
"The argument is just a number, so quoting isn't strictly necessary."Unquoted arguments allow arbitrary shell token expansion if malformed input is passed.
"A heredoc parsed on my host, so it works everywhere."Validate with the target image's Just version and preserve literal shell/JSON quoting.
"Users only run ujust in terminal windows."Scripts and background services invoke ujust; non-TTY safety must always be guarded.

Red Flags

  • Unquoted recipe arguments: {{ arg }} instead of {{ quote(arg) }}
  • Heredoc delimiters or indentation that fail parsing with the target image's Just version
  • Missing non-interactive guards on destructive or public-posting commands
  • Modifying the root Justfile when a user-facing command was requested

Verification

  • Every interpolated argument is wrapped in {{ quote(...) }}
  • Argument syntax validation is enforced in shell
  • Recipe exits with code != 0 when run non-interactively without required flags
  • The recipe file parses with the target image's Just version; rendered shell syntax is valid
  • just bst build bluefin/just-overrides.bst builds without errors

References

© projectbluefin, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/dakota-ujust of projectbluefin/dakota.

Open the folder on GitHubat commit 909f687

Compare with similar skills

Dakota Ujust next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Dakota Ujust compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Dakota Ujust this skillprojectbluefin/dakota180—~1.1kAutomated safety check: NotesMIT
Hermes Agent Skill AuthoringNousResearch/hermes-agent252k—~3.6kAutomated safety check: PassMIT
Configuring Oauth2 Authorization Flowmukul975/Anthropic-Cybersecurity-Skills34k—~1.7kAutomated safety check: PassApache-2.0
Cloud API Recipe AuthoringTencentCloudBase/CloudBase-AI-Toolkit1.1k—~3.7kAutomated safety check: PassMIT
Authoring Skillsvercel/next.js143k—~1kAutomated safety check: PassMIT
Ecc Recipesaffaan-m/ECC276k1 repos~1.6kAutomated safety check: PassMIT

Similar skills

  • Hermes Agent Skill Authoring

    NousResearch/hermes-agent

    Author in-repo SKILL.md files: frontmatter and structure. An agent skill from NousResearch/hermes-agent.

    252k GitHub stars~3.6k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Configuring Oauth2 Authorization Flow

    mukul975/Anthropic-Cybersecurity-Skills

    Configures secure OAuth 2.0 authorization flows, including Authorization Code with PKCE, Client Credentials, and Device Authorization Grant, covering flow selection, PKCE implementation, token…

    34k GitHub stars~1.7k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Cloud API Recipe Authoring

    TencentCloudBase/CloudBase-AI-Toolkit

    Author or revise a cloud-api-operations recipe (config/source/skills/cloud-api-operations/references/recipes/).

    1.1k GitHub stars~3.7k tokensUpdated today
    Writing & ContentAuto-check passed
  • Authoring Skills

    vercel/next.js

    Official

    How to create and maintain agent skills in .agents/skills/. An agent skill from vercel/next.js.

    143k GitHub stars~1k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Ecc Recipes

    affaan-m/ECC

    Map a described workflow to the right ECC command group with run-order and stop condition, or browse all command-group recipe families read live from the commands directory.

    276k GitHub starsUsed in 1 repo~1.6k tokens
    AI & LLM EngineeringAuto-check passed
  • Abp Authorization

    abpframework/abp

    ABP permission system - PermissionDefinitionProvider, [Authorize] attribute, CheckPolicyAsync, IsGrantedAsync, ICurrentUser, IPermissionManager, multi-tenancy side.

    14k GitHub stars~1.3k tokensUpdated today
    Backend & APIsAuto-check passed

More from projectbluefin/dakota

All 10 skills in this repo
  • Dakota Buildstream

    projectbluefin/dakota

    BuildStream elements, junctions, patches, dependency graphs, and build failures in Dakota.

    180 GitHub stars~1k tokensUpdated today
    Auto-check passed
  • Dakota Extensions

    projectbluefin/dakota

    Package, update, and configure GNOME Shell extensions, Quick Settings panels, and schemas in Dakota.

    180 GitHub stars~1.6k tokensUpdated today
    Auto-check passed
  • Dakota Factory

    projectbluefin/dakota

    Maintain task-relevant Dakota guidance: documentation accuracy, official-source verification, and skill auditing.

    180 GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Dakota Packaging

    projectbluefin/dakota

    Add, remove, or update native software built from source in Dakota, including Go, Rust, Zig, C/Meson, and binary releases.

    180 GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Dakota Image

    projectbluefin/dakota

    OCI layer assembly, boot testing, installer boundaries, VM work, and local OTA verification for Dakota images.

    180 GitHub stars~929 tokensUpdated today
    Auto-check passed
  • Dakota Workstation

    projectbluefin/dakota

    Dakota host Homebrew integration and workstation-specific services.

    180 GitHub stars~937 tokensUpdated today
    Auto-check passed

Questions about Dakota Ujust

What does Dakota Ujust do?

Author safe end-user ujust recipes in files/just-overrides/default.just, including quoting, gum, JSON, and public-post confirmation. Dakota Ujust is an agent skill from projectbluefin/dakota.just, including quoting, gum, JSON, and public-post confirmation.

How do I install Dakota Ujust in Claude Code?

Run `npx skills add projectbluefin/dakota --skill dakota-ujust -a claude-code`. Or copy the skill folder (.agents/skills/dakota-ujust in projectbluefin/dakota) into .claude/skills/dakota-ujust in your project. Claude Code loads it when a task matches its description.

How do I install Dakota Ujust in Codex?

Run `npx skills add projectbluefin/dakota --skill dakota-ujust -a codex`. Or copy the skill folder (.agents/skills/dakota-ujust in projectbluefin/dakota) into .agents/skills/dakota-ujust in your project. Codex loads it when a task matches its description.

Can I use Dakota Ujust in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add projectbluefin/dakota --skill dakota-ujust -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dakota-ujust, .gemini/skills/dakota-ujust, .github/skills/dakota-ujust and .opencode/skills/dakota-ujust in your project.

What does Dakota Ujust need to run?

Going by SKILL.md and its folder, Dakota Ujust needs the command-line tools its instructions call (just and jq).

Does Dakota Ujust access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Dakota Ujust safe to install?

Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Dakota Ujust use?

Dakota Ujust is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Dakota Ujust use?

About 1.1k tokens (SKILL.md is roughly 4.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Dakota Ujust?

Skills that share tags, products or a category with Dakota Ujust: Hermes Agent Skill Authoring (NousResearch/hermes-agent, 252k stars), Configuring Oauth2 Authorization Flow (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Cloud API Recipe Authoring (TencentCloudBase/CloudBase-AI-Toolkit, 1.1k stars) and Authoring Skills (vercel/next.js, 143k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Dakota Ujust?

projectbluefin (a GitHub organization) maintains it in projectbluefin/dakota, which has 180 GitHub stars. The repository holds 10 skills in this directory. The repository was last updated on October 10, 2026.

Source: projectbluefin/dakota on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.