Agent skill

Onboarding

by projectbluefin in projectbluefin/finpilot

Bootstrap a new image from this template: rename the project, enable Actions and Renovate, protect the branch, and reach a first green build.

Apache-2.0Auto-check passed

Install Onboarding

skills CLI
$ npx skills add projectbluefin/finpilot --skill onboarding -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install projectbluefin/finpilot onboarding --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/projectbluefin/finpilot.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/onboarding .claude/skills/onboarding && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
onboarding
GitHub stars
126
Token cost
~2.9k tokens
SKILL.md length
1,395 words
Files
1
Skills in repo
5
Repo updated
First seen
Licence
Apache-2.0

At a glance

Bootstrap a new image from this template: rename the project, enable Actions and Renovate, protect the branch, and reach a first green build.

  • Works in 11 steps: Rename the project → Enable Actions → Allow auto-merge → …
  • Forking the template
  • SKILL.md covers Before you start, 1. Rename the project, 2. Enable Actions and 3. Allow auto-merge, plus 10 more sections
  • Calls gh, just and git; needs RENOVATE_TOKEN

What it does

Onboarding is an agent skill from projectbluefin/finpilot. Bootstrap a new image from this template: rename the project, enable Actions and Renovate, protect the branch, and reach a first green build. Use when forking the template or when setup has stalled.

Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: Build your own custom Bluefin. The licence is Apache-2.0.

When your agent uses it

  • Forking the template
  • Setup has stalled

Example prompts

  • “/onboarding”

Requirements

  • A credential in RENOVATE_TOKEN

Workflow steps

11 steps, taken from the step headings in SKILL.md.

  1. Rename the project
  2. Enable Actions
  3. Allow auto-merge
  4. Workflow permissions
  5. Create the Renovate token
  6. Create stable
  7. Protect main
  8. Protect stable
  9. Restrict stable to squash merges
  10. Create the labels
  11. Enable issues

What it can do on your machine

Read from SKILL.md and the folder at commit 8e0eb5d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh
    • just
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gh and git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • RENOVATE_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Onboarding loads about 2.9k tokens when it runs. Until then it costs about 52 tokens; SKILL.md has 1,395 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~52
When it runs · the whole SKILL.md, loaded when a task matches
~2.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from projectbluefin/finpilot at commit 8e0eb5d, republished under its Apache-2.0 licence (© projectbluefin). 1,395 words, ~2,894 tokens.

Download SKILL.mdSave it as .claude/skills/onboarding/SKILL.md (or your agent's skills folder).
name
onboarding
description
Bootstrap a new image from this template: rename the project, enable Actions and Renovate, protect the branch, and reach a first green build. Use when forking the template or when setup has stalled.

Onboarding

Take a fresh fork from "Use this template" to a green build on main.

Every step has two routes: a gh command and a by-hand walkthrough through the GitHub website (or git). They do the same thing, so use whichever suits you — the by-hand route is written for someone who has never opened these settings before. Substitute your own {owner}/{repo} throughout.

Before you start

  • You need admin on the repository for every step below.
  • For the gh route, run gh auth login and authenticate as that admin.
  • Two different Settings pages are involved. Most steps are in the repository's settings — open your repository and click Settings in the top bar. The token in step 5 is in your account's settings — click your profile picture, top right. They look similar; check the sidebar heading.
  • Only step 5 has no shortcut, because only you can mint a personal access token.

1. Rename the project

See the Quick start in README.md. Three identity sites, and just test-contract fails when they disagree.

2. Enable Actions

Without this no workflow runs at all, including the first build.

  • gh — gh api -X PUT repos/{owner}/{repo}/actions/permissions -F enabled=true -f allowed_actions=all
  • By hand:
    1. Open your repository and click the Actions tab.
    2. GitHub shows "Workflows aren't being run on this repository" with a green button. Click I understand my workflows, go ahead and enable them.
    3. To set the broader permission, go to Settings → Actions → General. Under Actions permissions, select Allow all actions and reusable workflows, then click Save.

3. Allow auto-merge

Renovate merges low-risk updates on its own, and it cannot without this.

  • gh — gh api -X PATCH repos/{owner}/{repo} -F allow_auto_merge=true
  • By hand:
    1. In your repository, click Settings.
    2. In the left sidebar, click General.
    3. Scroll down to Pull Requests.
    4. Tick Allow auto-merge. This section has no Save button; it applies immediately.
    5. Automatically delete head branches is optional. The template does not depend on it.

4. Workflow permissions

Two settings on one screen. The first lets workflows write — push images, open pull requests. The second is what lets the promotion workflow approve the check runs GitHub holds for its own pull request.

  • gh — gh api -X PUT repos/{owner}/{repo}/actions/permissions/workflow -f default_workflow_permissions=write -f can_approve_pull_request_reviews=true
  • By hand:
    1. Settings → Actions → General.
    2. Scroll down to Workflow permissions.
    3. Select Read and write permissions.
    4. Tick Allow GitHub Actions to create and approve pull requests.
    5. Click Save.

5. Create the Renovate token

The one step with no shortcut. Renovate uses this token to push branches and open pull requests, so it needs to act as you.

Skip this step if you do not want Renovate. Without the secret the workflow logs a skip and the run stays green; nothing else in the image depends on it.

Create the token
  1. On any GitHub page, click your profile picture in the top right, then Settings.

  2. In the left sidebar, click Developer settings.

  3. Under Personal access tokens, click Tokens (classic).

  4. Click Generate new token, then Generate new token (classic).

  5. Give it a Note, for example renovate-your-repo.

  6. Set an Expiration. The default is 30 days. When it lapses, Renovate stops opening pull requests until you replace the secret, so pick a date you will notice.

  7. Under Select scopes, tick:

    • repo — read and write the repository
    • workflow — update the files under .github/workflows/
  8. Click Generate token.

  9. Copy the token now. GitHub shows it once. If you lose it, generate another and replace the secret.

A classic token carries every permission you have, on every repository you can reach. If you would rather not, create a fine-grained token instead, scoped to this repository, with Contents: Read and write and Workflows: Write.

Store it as a secret
  • gh — gh secret set RENOVATE_TOKEN --repo {owner}/{repo}, then paste the token when prompted.
  • By hand:
    1. Back in your repository, go to Settings → Secrets and variables → Actions.
    2. Click New repository secret.
    3. Name it exactly RENOVATE_TOKEN.
    4. Paste the token into Secret, then click Add secret.

6. Create stable

Promotion opens a pull request into stable, so the branch has to exist before the first promotion can run. Create it from main.

  • git — from a clone: git push origin main:stable
  • gh — gh api -X POST repos/{owner}/{repo}/git/refs -f ref=refs/heads/stable -f sha="$(gh api repos/{owner}/{repo}/git/ref/heads/main --jq .object.sha)"
  • By hand:
    1. In your repository, click the branch dropdown in the file list — it reads main.
    2. Click View all branches, then New branch.
    3. Name it stable and set the source to main.
    4. Click Create new branch.

Never commit to stable directly. It only ever receives the promotion.

7. Protect main

Require the validate check, so nothing lands without passing shellcheck and hadolint.

  • gh:

    bash
    gh api -X PUT repos/{owner}/{repo}/branches/main/protection --input - <<'JSON'
    {
      "required_status_checks": {"strict": false, "contexts": ["validate"]},
      "enforce_admins": false,
      "required_pull_request_reviews": null,
      "restrictions": null
    }
    JSON
  • By hand:

    1. Settings → Branches (newer repositories keep this under Rules).
    2. Click Add branch protection rule, or Add classic branch protection rule.
    3. Branch name pattern: main.
    4. Tick Require status checks to pass before merging.
    5. In the search box, type validate and select the validate check. It must be exactly validate. A check that has never run does not appear in the list — push something first if it is missing.
    6. Require a pull request before merging is optional. The template's convention is that main takes no direct pushes, but the setting is what enforces it.
    7. Click Create, or Save changes.
Show full SKILL.md (547 more words)Show less

8. Protect stable

The same check, and zero required approvals so promotion merges the moment checks pass.

  • gh — the same call against stable, with:

    json
    "required_pull_request_reviews": {"required_approving_review_count": 0}
  • By hand:

    1. Settings → Branches → Add branch protection rule.
    2. Pattern: stable.
    3. Tick Require status checks to pass before merging and select validate.
    4. Tick Require a pull request before merging, then set Required approvals to 0. Zero is deliberate — with one or more, every promotion waits for a human.
    5. Click Create.

9. Restrict stable to squash merges

Promotion is a squash PR, so the branch should accept nothing else.

  • gh:

    bash
    gh api -X POST repos/{owner}/{repo}/rulesets --input - <<'JSON'
    {
      "name": "stable — squash-only promotion",
      "target": "branch",
      "enforcement": "active",
      "conditions": {"ref_name": {"include": ["refs/heads/stable"], "exclude": []}},
      "rules": [{"type": "pull_request", "parameters": {
        "allowed_merge_methods": ["squash"],
        "required_approving_review_count": 0,
        "dismiss_stale_reviews_on_push": false,
        "require_code_owner_review": false,
        "require_last_push_approval": false,
        "required_review_thread_resolution": false
      }}]
    }
    JSON
  • By hand:

    1. Settings → Rules → Rulesets, then New branch ruleset.
    2. Ruleset name: stable — squash-only promotion.
    3. Enforcement status: Active.
    4. Under Target branches, click Add target, choose Include by pattern, and enter stable.
    5. Tick Require a pull request before merging.
    6. Under Allowed merge methods, tick Squash and untick the rest.
    7. Leave Required approvals at 0.
    8. Click Create.

10. Create the labels

The release gate applies release/ready and release/blocked, and the shared label workflow uses the lifecycle set. When a label is missing, the step that applies it fails, and the failure is easy to miss.

  • gh — one call per label: gh label create <name> --repo {owner}/{repo} --color <hex> --force (--force updates a label that already exists, so the block is safe to re-run.)
  • By hand — Issues → Labels → New label, then name, colour, and description, one at a time. Twelve labels is tedious; the gh route is worth it here even if you did everything else by hand.

Required:

LabelColour
release/ready0e8a16
release/blockedb60205
1-triageFBCA04
2-discussingD876E3
3-human-queue1D76DB
3-clanker-queue0E8A16
4-review0052CC
blockedB60205
hold6E7781

Optional: area/ci, kind/bug, priority/p1 (all ededed), and GitHub's defaults.

11. Enable issues

The issue templates in .github/ISSUE_TEMPLATE/ only appear when issues are on.

  • gh — gh api -X PATCH repos/{owner}/{repo} -F has_issues=true
  • By hand:
    1. Settings → General.
    2. Scroll to Features.
    3. Tick Issues.
    4. Click Save.

Verify

Run every check and compare against the values in this skill:

bash
gh api repos/{owner}/{repo} --jq '{auto_merge: .allow_auto_merge, issues: .has_issues}'
gh api repos/{owner}/{repo}/actions/permissions
gh api repos/{owner}/{repo}/actions/permissions/workflow
gh api repos/{owner}/{repo}/branches --jq '.[].name'
gh api repos/{owner}/{repo}/branches/main/protection --jq '.required_status_checks.contexts'
gh api repos/{owner}/{repo}/branches/stable/protection --jq '.required_status_checks.contexts'
gh api repos/{owner}/{repo}/rulesets --jq '.[].name'
gh secret list --repo {owner}/{repo}

Done when main and stable both exist and both require validate, the squash ruleset is active, RENOVATE_TOKEN is set, and a push to main that changes more than documentation produces a green Build and Push Image run and a :stable-testing image. Documentation-only pushes are skipped by paths-ignore.

Failure modes

  • The first build never starts — Actions were never enabled (step 2).
  • validate is not offered as a check — it has never run. Push something that is not documentation-only and try again.
  • Renovate opens no pull requests — the token is missing, expired, or lacks the workflow scope (step 5).
  • The promotion PR never opens — stable does not exist (step 6).
  • The promotion PR cannot merge — stable requires an approval, or the check name is not exactly validate (steps 7–8).
  • The promotion PR is merged by hand — expected on a personal repository. A merge queue needs an organization, so enrollment is off.
  • The release gate reports release/blocked — the labels in step 10 are missing, or the candidate image is unsigned.

© projectbluefin, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/onboarding of projectbluefin/finpilot.

Open the folder on GitHubat commit 8e0eb5d

Compare with similar skills

Onboarding next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Onboarding compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Onboarding this skillprojectbluefin/finpilot126—~2.9kAutomated safety check: PassApache-2.0
Onboardalirezarezvani/claude-skills28k—~1.3kAutomated safety check: PassMIT
Codebase Onboardingaffaan-m/ECC275k3 repos~2kAutomated safety check: PassMIT
Onboardingsickn33/agentic-awesome-skills47k1 repos~1.8kAutomated safety check: PassMIT
Contributor Onboarding DocDonchitos/Claude-Code-Game-Studios26k—~1.4kAutomated safety check: PassMIT
RuView Onboarding Path Pickerruvnet/RuView97k—~333Automated safety check: PassMIT

Similar skills

  • Onboard

    alirezarezvani/claude-skills

    /cs:onboard — Founder interview that populates ~/.claude/company-context.md using the canonical 7-dimension cs-onboard schema.

    28k GitHub stars~1.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Analyze an unfamiliar codebase and generate a structured onboarding guide with architecture map, key entry points, conventions, and a starter CLAUDE.md.

    275k GitHub starsUsed in 3 repos~2k tokens
    DevelopmentAuto-check passed
  • Onboarding

    sickn33/agentic-awesome-skills

    When the user wants to optimize post-signup onboarding, user activation, first-run experience, or time-to-value.

    47k GitHub starsUsed in 1 repo~1.8k tokens
    Auto-check passed
  • Contributor Onboarding Doc

    Donchitos/Claude-Code-Game-Studios

    Writes an onboarding document for a new contributor or agent, covering project state, conventions and priorities relevant to a chosen role.

    26k GitHub stars~1.4k tokensUpdated 9 days ago
    DevelopmentAuto-check passed
  • Zero-to-sensing path picker for RuView (WiFi-DensePose) — pick docker-demo, repo-build, or live-esp32 and run the next concrete step.

    97k GitHub stars~333 tokensUpdated today
    DevelopmentAuto-check passed
  • 分析一个陌生的代码库,并生成一个结构化的入门指南,包括架构图、关键入口点、规范和一个起始的CLAUDE.md文件。适用于加入新项目或首次在代码仓库中设置Claude Code时。

    275k GitHub starsUsed in 1 repo~1.1k tokens
    DevelopmentAuto-check passed

More from projectbluefin/finpilot

  • Customize

    projectbluefin/finpilot

    Decide where a package, app, or command belongs — dnf5 at build time, Homebrew, Flatpak, or ujust — and how each is validated.

    126 GitHub stars~625 tokensUpdated today
    Auto-check passed
  • CI

    projectbluefin/finpilot

    GitHub Actions, Renovate, the two-branch release model, signing, and promotion.

    126 GitHub stars~1.5k tokensUpdated today
    Auto-check passed
  • Overview

    projectbluefin/finpilot

    Architecture, repository layout, and file map for this template.

    126 GitHub stars~740 tokensUpdated today
    Auto-check passed
  • Troubleshooting

    projectbluefin/finpilot

    Symptom to cause to fix for build, CI, and runtime failures, plus the pre-commit checklist.

    126 GitHub stars~605 tokensUpdated today
    Auto-check passed

Questions about Onboarding

What does Onboarding do?

Bootstrap a new image from this template: rename the project, enable Actions and Renovate, protect the branch, and reach a first green build. Onboarding is an agent skill from projectbluefin/finpilot. Bootstrap a new image from this template: rename the project, enable Actions and Renovate, protect the branch, and reach a first green build.

When should I use Onboarding?

Onboarding fits situations like: forking the template; setup has stalled.

How do I install Onboarding in Claude Code?

Run `npx skills add projectbluefin/finpilot --skill onboarding -a claude-code`. Or copy the skill folder (.agents/skills/onboarding in projectbluefin/finpilot) into .claude/skills/onboarding in your project. Claude Code loads it when a task matches its description.

How do I install Onboarding in Codex?

Run `npx skills add projectbluefin/finpilot --skill onboarding -a codex`. Or copy the skill folder (.agents/skills/onboarding in projectbluefin/finpilot) into .agents/skills/onboarding in your project. Codex loads it when a task matches its description.

Can I use Onboarding in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add projectbluefin/finpilot --skill onboarding -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/onboarding, .gemini/skills/onboarding, .github/skills/onboarding and .opencode/skills/onboarding in your project.

What does Onboarding need to run?

Going by SKILL.md and its folder, Onboarding needs the command-line tools its instructions call (gh, just and git) and credentials named RENOVATE_TOKEN. Our summary lists: A credential in RENOVATE_TOKEN.

Does Onboarding access the network?

SKILL.md contains no URLs. Its commands use gh and git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Onboarding safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Onboarding use?

Onboarding is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Onboarding use?

About 2.9k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Onboarding?

Skills that share tags, products or a category with Onboarding: Onboard (alirezarezvani/claude-skills, 28k stars), Codebase Onboarding (affaan-m/ECC, 275k stars), Onboarding (sickn33/agentic-awesome-skills, 47k stars) and Contributor Onboarding Doc (Donchitos/Claude-Code-Game-Studios, 26k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Onboarding?

projectbluefin (a GitHub organization) maintains it in projectbluefin/finpilot, which has 126 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on October 8, 2026.

Source: projectbluefin/finpilot on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.