Agent skill

Nix Config Debug

by ryan4yin in ryan4yin/nix-config

A skill your agent uses when something in this repo is broken, such as an eval or build error, a failed activation, a crashed service, or an unreachable host or MicroVM guest.

MITAuto-check passedDevelopment

Install Nix Config Debug

skills CLI
$ npx skills add ryan4yin/nix-config --skill nix-config-debug -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ryan4yin/nix-config nix-config-debug --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ryan4yin/nix-config.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/nix-config-debug .claude/skills/nix-config-debug && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
nix-config-debug
GitHub stars
2.1k
Token cost
~1.4k tokens
SKILL.md length
562 words
Files
1
Skills in repo
7
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when something in this repo is broken, such as an eval or build error, a failed activation, a crashed service, or an unreachable host or MicroVM guest.

  • Works in 4 steps: Localize by layer → Read the evaluated value → Your change or the update? → …
  • Something in this repo is broken
  • SKILL.md covers Core rules, 1. Localize by layer, 2. Read the evaluated value and 3. Your change or the update?, plus 2 more sections
  • Calls just, nix and git

What it does

Nix Config Debug is an agent skill from ryan4yin/nix-config. Use when something in this repo is broken, such as an eval or build error, a failed activation, a crashed service, or an unreachable host or MicroVM guest.

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development. The repository describes itself as: ❄️ My nix config for both desktops(NixOS+macOS) and homelab servers(NixOS). The licence is MIT.

When your agent uses it

  • Something in this repo is broken
  • Such as an eval
  • A failed activation
  • A crashed service

Example prompts

  • “/nix-config-debug”

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Localize by layer
  2. Read the evaluated value
  3. Your change or the update?
  4. Prove the fix

What it can do on your machine

Read from SKILL.md and the folder at commit dc211bb. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • just
    • nix
    • git
    • ssh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git and ssh, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Nix Config Debug loads about 1.4k tokens when it runs. Until then it costs about 43 tokens; SKILL.md has 562 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~43
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ryan4yin/nix-config at commit dc211bb, republished under its MIT licence (© ryan4yin). 562 words, ~1,423 tokens.

Download SKILL.mdSave it as .claude/skills/nix-config-debug/SKILL.md (or your agent's skills folder).
name
nix-config-debug
description
Use when something in this repo is broken, such as an eval or build error, a failed activation, a crashed service, or an unreachable host or MicroVM guest.

Debugging this repository

Follow the global systematic-debugging skill for the process (root cause before any fix). This skill is only the map: which layer failed, and where to look. Rolling back, isolating a bad input bump, and the commands that destroy rollback points are in the nix-config-update skill.

Core rules

  1. Restore service first. A down host or a dead session gets the previous generation before any investigation. Rolling back the machine you are on needs sudo, so the user does it.
  2. Name the layer before touching code. Eval, build, activation, and runtime failures have different causes; a green just test says nothing about activation.
  3. Never get to green by weakening a check: no disabled test, dropped assertion, or mkForce over the failing value.
  4. Preserve existing user changes. Do not discard or stash them without authorization. If a clean baseline is needed, record the current diff and ask before isolating it.

1. Localize by layer

LayerSymptomLook with
evaljust test fails, an eval errorjust eval-host <host> (already passes --show-trace)
buildbuild error, hash mismatch, "marked as broken"just build-host <host>, then nix log <drv>
activationthe deploy fails after buildingthe deploy output; journalctl -u home-manager-$USER -b for Home Manager
runtimea unit is failed or restartingjust list-failed, systemctl status <unit>, journalctl -u <unit> -b
proxy/DNSproxied sites time out, node and rules look okdig +short <site> must return a fake-ip (198.18.x.x); a real IP means the system resolver bypasses dns-hijack — mihomo README Gotchas
booterrors at boot, wrong kerneljournalctl -b -p err; just history for what is booted
sessiondesktop or app misbehavesjournalctl --user -b -p err; the nix-config-desktop skill
remote hostanything on a Colmena hostssh root@<host> journalctl -b -p err, same commands over SSH
MicroVM guestguest down or unreachableon the VM host: systemctl status microvm@<guest> and microvm-tap-interfaces@<guest>; then br0
secretsmissing or unreadable /etc/agenix/*the nix-config-secrets skill
Show full SKILL.md (239 more words)Show less

2. Read the evaluated value

When just test fails, re-run the suite directly to get the trace (nix eval exits 0 even when the suite returns false, so read its output):

bash
nix eval .#evalTests --show-trace

The trace names the failing test under outputs/<system>/tests/<name>/. Read its expr.nix and expected.nix, and evaluate the expression to see what actually came out before changing anything.

Most eval-layer questions are "what did this option actually end up as?". Ask the configuration directly instead of reading modules:

bash
nix eval .#nixosConfigurations.<host>.config.<option.path>
nix eval .#nixosConfigurations.<host>.config.systemd.services \
  --apply 's: builtins.filter (n: builtins.match "microvm.*" n != null) (builtins.attrNames s)'
nix repl   # then `:lf .` and inspect nixosConfigurations.<host>.config

Renamed or removed options are the most common eval break after an update; the error or warning names the replacement. Treat deprecation warnings as failures waiting to happen.

3. Your change or the update?

git status, git log --oneline -5 -- flake.lock, and git diff flake.lock tell you which. If the lock moved, isolate the input as described in the nix-config-update skill before reading code. Preserve unrelated working-tree changes; do not use git checkout, git stash, or cleanup commands to manufacture a clean tree without authorization.

4. Prove the fix

Re-run the exact command that failed, then just test, then just build-host <host> for every affected host before anyone deploys. Report the evidence ("the unit is active, just test is true"), not the intent.

Why these rules exist

  • 5ee8b728 fix(restic): use the correct systemd timer option names (#319) - an option-name error that only reading the evaluated value catches quickly.
  • 9315055b fix(darwin): unblock home-manager activation - an activation failure that eval and build both passed.

© ryan4yin, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/nix-config-debug of ryan4yin/nix-config.

Open the folder on GitHubat commit dc211bb

Compare with similar skills

Nix Config Debug next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Nix Config Debug compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Nix Config Debug this skillryan4yin/nix-config2.1k—~1.4kAutomated safety check: PassMIT
Vercel Composition Patternssupabase/supabase111k59 repos~726Automated safety check: PassMIT
Finishing a Development Branchobra/superpowers296k5 repos~1.9kAutomated safety check: PassMIT
Typescript Advanced Typesrolling-scopes/rsschool-app10k25 repos~4.2kAutomated safety check: PassMPL-2.0
PR Babysitteropeninterpreter/openinterpreter69k3 repos~4.2kAutomated safety check: PassApache-2.0
Code Review ChecklistshareAI-lab/learn-claude-code78k5 repos~1.1kAutomated safety check: PassMIT

Similar skills

  • Official

    React composition patterns that scale. An agent skill from supabase/supabase.

    111k GitHub starsUsed in 59 repos~726 tokens
    DevelopmentAuto-check passed
  • Walks the last step of a branch: confirm tests pass, detect the git environment, ask how to integrate, carry out your choice and clean up the worktree.

    296k GitHub starsUsed in 5 repos~1.9k tokens
    DevelopmentAuto-check passed
  • Typescript Advanced Types

    rolling-scopes/rsschool-app

    Master TypeScript's advanced type system including generics, conditional types, mapped types, template literals, and utility types for building type-safe applications.

    10k GitHub starsUsed in 25 repos~4.2k tokens
    DevelopmentAuto-check passed
  • PR Babysitter

    openinterpreter/openinterpreter

    Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.

    69k GitHub starsUsed in 3 repos~4.2k tokens
    DevelopmentAuto-check passed
  • Code Review Checklist

    shareAI-lab/learn-claude-code

    Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.

    78k GitHub starsUsed in 5 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Greploop

    onyx-dot-app/onyx

    Iteratively improves a PR (GitHub), MR (GitLab), or shelved changelist (Perforce) until Greptile gives it a 5/5 confidence score with zero unresolved comments.

    32k GitHub starsUsed in 4 repos~3.3k tokens
    DevelopmentAuto-check passed

More from ryan4yin/nix-config

  • Nix Config Desktop

    ryan4yin/nix-config

    A skill your agent uses when changing the Niri/Noctalia desktop, the Wayland session, input method (fcitx5), theming, fonts, or desktop autostart in this repo.

    2.1k GitHub stars~2k tokensUpdated yesterday
    Auto-check passed
  • Nix Config Secrets

    ryan4yin/nix-config

    A skill your agent uses when adding, changing, renaming, or removing an agenix secret, wiring one into a host, or fixing a decryption or activation failure in this repo.

    2.1k GitHub stars~2.3k tokensUpdated yesterday
    Auto-check: notes
  • Nix Config Update

    ryan4yin/nix-config

    A skill your agent uses when updating flake inputs, bumping nixpkgs, or rolling an update out to hosts in this repo.

    2.1k GitHub stars~2.2k tokensUpdated yesterday
    Auto-check: notes
  • Nixpkgs Patched

    ryan4yin/nix-config

    A skill your agent uses when temporarily carrying an unmerged nixpkgs pull request or commit in the personal ryan4yin/nixpkgs fork, updating the nixos-unstable-patched branch, or consuming that…

    2.1k GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Nixpkgs Review

    ryan4yin/nix-config

    A skill your agent uses when reviewing an upstream NixOS/nixpkgs pull request before it is merged, including its package changes, passthru tests, dependencies, or CI results.

    2.1k GitHub stars~2.8k tokensUpdated yesterday
    Auto-check passed
  • Nix Config New Host

    ryan4yin/nix-config

    A skill your agent uses when adding a NixOS, macOS, or MicroVM host in this repo, including its outputs, networking, secrets, and eval-test wiring.

    2.1k GitHub stars~1.6k tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Nix Config Debug

What does Nix Config Debug do?

A skill your agent uses when something in this repo is broken, such as an eval or build error, a failed activation, a crashed service, or an unreachable host or MicroVM guest. Nix Config Debug is an agent skill from ryan4yin/nix-config. Use when something in this repo is broken, such as an eval or build error, a failed activation, a crashed service, or an unreachable host or MicroVM guest.

When should I use Nix Config Debug?

Nix Config Debug fits situations like: something in this repo is broken; such as an eval; A failed activation; A crashed service.

How do I install Nix Config Debug in Claude Code?

Run `npx skills add ryan4yin/nix-config --skill nix-config-debug -a claude-code`. Or copy the skill folder (.agents/skills/nix-config-debug in ryan4yin/nix-config) into .claude/skills/nix-config-debug in your project. Claude Code loads it when a task matches its description.

How do I install Nix Config Debug in Codex?

Run `npx skills add ryan4yin/nix-config --skill nix-config-debug -a codex`. Or copy the skill folder (.agents/skills/nix-config-debug in ryan4yin/nix-config) into .agents/skills/nix-config-debug in your project. Codex loads it when a task matches its description.

Can I use Nix Config Debug in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ryan4yin/nix-config --skill nix-config-debug -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/nix-config-debug, .gemini/skills/nix-config-debug, .github/skills/nix-config-debug and .opencode/skills/nix-config-debug in your project.

What does Nix Config Debug need to run?

Going by SKILL.md and its folder, Nix Config Debug needs the command-line tools its instructions call (just, nix, git and ssh).

Does Nix Config Debug access the network?

SKILL.md contains no URLs. Its commands use git and ssh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Nix Config Debug safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Nix Config Debug use?

Nix Config Debug is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Nix Config Debug use?

About 1.4k tokens (SKILL.md is roughly 5.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Nix Config Debug?

Skills that share tags, products or a category with Nix Config Debug: Vercel Composition Patterns (supabase/supabase, 111k stars), Finishing a Development Branch (obra/superpowers, 296k stars), Typescript Advanced Types (rolling-scopes/rsschool-app, 10k stars) and PR Babysitter (openinterpreter/openinterpreter, 69k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Nix Config Debug?

ryan4yin (a GitHub user) maintains it in ryan4yin/nix-config, which has 2,089 GitHub stars. The repository holds 7 skills in this directory. The repository was last updated on October 8, 2026.

Source: ryan4yin/nix-config on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.