Agent skill

Nix Config New Host

by ryan4yin in ryan4yin/nix-config

A skill your agent uses when adding a NixOS, macOS, or MicroVM host in this repo, or wiring an existing machine into outputs/, hostsAddr, secrets recipients, and the eval tests.

MITAuto-check passedDevelopment

Install Nix Config New Host

skills CLI
$ npx skills add ryan4yin/nix-config --skill nix-config-new-host -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ryan4yin/nix-config nix-config-new-host --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ryan4yin/nix-config.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/nix-config-new-host .claude/skills/nix-config-new-host && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
nix-config-new-host
GitHub stars
2.1k
Token cost
~1.6k tokens
SKILL.md length
799 words
Files
1
Skills in repo
9
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when adding a NixOS, macOS, or MicroVM host in this repo, or wiring an existing machine into outputs/, hostsAddr, secrets recipients, and the eval tests.

  • Works in 5 steps: Pick the template → Files to create or edit → Tests that fail until the host is wired → …
  • MicroVM host in this repo
  • SKILL.md covers Core rules, 1. Pick the template, 2. Files to create or edit and 3. Tests that fail until the…, plus 2 more sections
  • Calls just and ssh

What it does

Nix Config New Host is an agent skill from ryan4yin/nix-config. Use when adding a NixOS, macOS, or MicroVM host in this repo, or wiring an existing machine into outputs/, hostsAddr, secrets recipients, and the eval tests.

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development. It works with macOS and Linux. The repository describes itself as: ❄️ My nix config for both desktops(NixOS+macOS) and homelab servers(NixOS). The licence is MIT.

When your agent uses it

  • MicroVM host in this repo
  • Wiring an existing machine into outputs/
  • Secrets recipients

Example prompts

  • “/nix-config-new-host”

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Pick the template
  2. Files to create or edit
  3. Tests that fail until the host is wired
  4. Install and deploy
  5. Verify

What it can do on your machine

Read from SKILL.md and the folder at commit 497fabb. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • just
    • ssh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use ssh, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Nix Config New Host loads about 1.6k tokens when it runs. Until then it costs about 45 tokens; SKILL.md has 799 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~45
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ryan4yin/nix-config at commit 497fabb, republished under its MIT licence (© ryan4yin). 799 words, ~1,618 tokens.

Download SKILL.mdSave it as .claude/skills/nix-config-new-host/SKILL.md (or your agent's skills folder).
name
nix-config-new-host
description
Use when adding a NixOS, macOS, or MicroVM host in this repo, or wiring an existing machine into `outputs/`, `hostsAddr`, secrets recipients, and the eval tests.

Adding a host

Copy the closest existing host and change what differs. The current inventory and naming scheme are in hosts/README.md.

Core rules

  1. Three names, decided up front. The directory (hosts/idols-ai/), the hostname (hostName = "ai"), and the configuration name (ai-niri) differ. Servers use the hostname as the configuration name; Niri desktops append -niri, because just niri deploys $(hostname)-niri. The hostname eval test encodes this.
  2. Secrets come from another repository. The new host decrypts nothing until its host key is a recipient in nix-secrets; see the nix-config-secrets skill. A new desktop also needs its synced dotfiles restored before the first switch, or the shell starts without them.
  3. The shared policy modules are not optional. Several eval tests assert a policy for every configuration, so an under-wired host fails just test instead of failing in production.
  4. Build before you install. just test, just eval-host <name>, and just build-host <name> pass before anything is partitioned or flashed. disko destroys the target disk, and partitioning and installing are user-run actions on a device the user has confirmed.

1. Pick the template

  • Desktop workstation: hosts/idols-ai/ + outputs/x86_64-linux/src/idols-ai.nix
  • Homelab server / VM host: hosts/12kingdoms-shoryu/ + outputs/x86_64-linux/src/12kingdoms-shoryu.nix
  • Apple Silicon Linux: hosts/12kingdoms-shoukei/ + outputs/aarch64-linux/src/12kingdoms-shoukei.nix
  • macOS: hosts/darwin-fern/ + outputs/aarch64-darwin/src/fern.nix (darwinConfigurations, no Colmena)
  • MicroVM guest: hosts/k8s/k3s-test-1-worker-1/ + outputs/x86_64-linux/src/k3s-test-1-worker-1.nix

A MicroVM guest is also registered in its VM host's microvm.nix; deploy it with the procedure in WA-026 of WORKAROUNDS.md, not just microvm-deploy. On a VM host with the br0 bridge it also needs a systemd.network.networks unit that attaches the guest's tap to br0; the tap name comes from the guest IP (192.168.5.116 to vm116). Some guest outputs also expose a Colmena node for evaluation or other workflows; do not assume the physical-host deployment is done through Colmena.

2. Files to create or edit

  1. hosts/<dir>/default.nix - sets hostName and imports the host's modules. Some hosts (shoryu, shushou, youko, akane) import mylib.scanPaths ./., which pulls in every other .nix file in the directory; keep scratch files out of those.
  2. hosts/<dir>/hardware-configuration.nix - generated on the target machine (nixos-generate-config --show-hardware-config), never copied from another host. Where the layout is declarative, add disko-fs.nix and record the install command in the host's README.md, as hosts/idols-ai/README.md does.
  3. home/hosts/linux/<name>.nix or home/hosts/darwin/<name>.nix - only for a host with Home Manager; otherwise leave home-modules out.
  4. outputs/<system>/src/<name>.nix - add the output types appropriate to the host: nixosConfigurations.<name> for NixOS, darwinConfigurations.<name> for macOS, and a packages.<name> installer image only where the platform provides one. Add colmena.<name> only for a host deployed through Colmena; it then needs tags, ssh-user, and usually targetHost. MicroVM guests also need the VM-host microvm.nix registration. Keep the leading comment about unused args: haumea passes them lazily and they are still required.
  5. vars/networking.nix - hostsAddr.<name> = { iface; ipv4; } for a LAN host. That entry drives the static address, the SSH Host alias used for remote builds, and known_hosts, so a wrong iface takes the host offline at activation. Skip it for a DHCP or mobile host; homeOnly = true only drops the SSH alias and the local exporters, not known_hosts or the scrape targets. If the host enables modules.networking.mihomo and runs systemd-resolved, it needs a DNS takeover tied to mihomo's lifecycle (resolvectl dns/revert in ExecStartPost/ExecStopPost, see hosts/idols-ai/default.nix); a static link DNS would kill DNS when mihomo dies.
  6. hosts/README.md - add the host to the inventory.

Pin service user and group ids (service-user-ids.nix, as on shoryu) before the host has state on disk. A dynamically allocated id that moves on a later rebuild orphans the files it owned (9187e4d9 fix(youko): pin dynamically-allocated service uid/gid (#320)).

Show full SKILL.md (220 more words)Show less

3. Tests that fail until the host is wired

outputs/README.md lists which eval tests check every configuration and which list hosts by name:

  • hostname: a new -niri configuration needs a specialExpected entry, in the test for its platform (ai-niri in x86_64-linux, shoukei-niri in aarch64-linux).
  • security-*, kernel, nix-system-features: apply to every configuration automatically.
  • home-manager, btrbk, and the other host-listing tests: add the host if it should be covered.

just test fails (non-zero) unless the suite returns true.

4. Install and deploy

  • First install: boot the ISO, partition with disko, install, then deploy normally. Partitioning, formatting, and installing destroy the target disk, so they are user-run actions on a device the user confirmed: check lsblk/findmnt first, name the exact device, and get authorization for it before any destroy,format,mount. Follow nixos-installer/README.md and the host's own README.
  • Remote hosts: just col <tag> or the host's own recipe, once its key is a secrets recipient. Deploying is a separate impactful action; use the nix-config-update skill's staged deployment (confirm the target, preview the closure, and get authorization).
  • The machine you are on: the user runs just local or just niri.

5. Verify

  • ssh <name> true, then systemctl --failed and journalctl -b -p err on the host.
  • Secrets decrypted, checked by mode and owner only.
  • The role works: the service, VM, or desktop the host exists for.

© ryan4yin, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/nix-config-new-host of ryan4yin/nix-config.

Open the folder on GitHubat commit 497fabb

Compare with similar skills

Nix Config New Host next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Nix Config New Host compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Nix Config New Host this skillryan4yin/nix-config2.1k—~1.6kAutomated safety check: PassMIT
Native Feel Cross Platform Desktopyetone/native-feel-skill1.9k1 repos~1.5kAutomated safety check: PassMIT
JS Cpp Protocolnotepadqq/notepadqq2.3k—~3.2kAutomated safety check: PassGPL-3.0
RStudio Copilot Language Server Updaterrstudio/rstudio5.1k—~1.1kAutomated safety check: PassCustom licence
OpenLogi Device DiagnosisAprilNEA/OpenLogi23k—~1.6kAutomated safety check: PassApache-2.0
Code Change Verificationopenai/openai-agents-python30k—~1.4kAutomated safety check: PassMIT

Similar skills

  • Native Feel Cross Platform Desktop

    yetone/native-feel-skill

    A skill your agent uses when the user is designing, prototyping, or rewriting a desktop app that must run on multiple OSes (macOS + Windows, optionally Linux) AND feel indistinguishable from a…

    1.9k GitHub starsUsed in 1 repo~1.5k tokens
    DevelopmentAuto-check passed
  • JS Cpp Protocol

    notepadqq/notepadqq

    Reference for the communication protocol between the JavaScript editor (CodeMirror or Monaco) and the C++/Qt UI layer via QWebChannel.

    2.3k GitHub stars~3.2k tokensUpdated 5 days ago
    DevelopmentAuto-check passed
  • Advances RStudio's pinned copilot-language-server dependency to a specified release, then uploads it to S3, verifies the install, and opens a PR.

    5.1k GitHub stars~1.1k tokensUpdated today
    DevelopmentAuto-check passed
  • OpenLogi Device Diagnosis

    AprilNEA/OpenLogi

    Finds the first failing layer when an OpenLogi Logitech device is missing or misbehaving across enumeration, open, probe, IPC and UI.

    23k GitHub stars~1.6k tokensUpdated today
    DevelopmentAuto-check passed
  • Code Change Verification

    openai/openai-agents-python

    Official

    Run the required final formatting, lint, type, and test checks after eligible SDK changes pass review.

    30k GitHub stars~1.4k tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Tk Impact Analysis

    tonkeeper/tonkeeper-web

    Analyze QA regression impact for Tonkeeper Web by comparing the current branch with the relevant release tag, reviewing sources/Web/regress.txt, and recommending test blocks, missing coverage, extra…

    444 GitHub stars~3.7k tokensUpdated 8 days ago
    DevelopmentAuto-check passed

More from ryan4yin/nix-config

All 10 skills in this repo
  • Nix Config Umu Game

    ryan4yin/nix-config

    A skill your agent uses when installing a Windows game launcher (二次元 / gacha or any non-Steam game) on a NixOS desktop via umu-launcher, given an installer URL or an .exe, when such a launcher opens…

    2.1k GitHub stars~3.3k tokensUpdated today
    Auto-check passed
  • Find Docs

    ryan4yin/nix-config

    Look up current documentation and code examples for a library, framework, SDK, CLI tool, or cloud service with the Context7 CLI.

    2.1k GitHub stars~650 tokensUpdated today
    Auto-check passed
  • Nix Config Debug

    ryan4yin/nix-config

    A skill your agent uses when something here is broken or stops working: an eval or build error, a failed activation, a dead or restarting unit, a mihomo or DNS outage, an unreachable host or MicroVM…

    2.1k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Nix Config Desktop

    ryan4yin/nix-config

    A skill your agent uses when changing what the desktop shows or runs: Niri/Noctalia config, a window that is the wrong size, garbled, or missing after a reboot, autostart, fcitx5 or vinput input…

    2.1k GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Nix Config Secrets

    ryan4yin/nix-config

    A skill your agent uses when adding, changing, renaming, or removing an agenix secret, deciding whether a secret belongs to agenix or to the encrypted dotfiles sync, wiring a secret into a host, or…

    2.1k GitHub stars~2.7k tokensUpdated today
    Auto-check: notes
  • Nix Config Update

    ryan4yin/nix-config

    A skill your agent uses when a version changes here: upgrading or updating a package or nixpkgs, bumping or pinning a flake input (a tag or commit, not a branch), or deploying the result to hosts…

    2.1k GitHub stars~2.2k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Nix Config New Host

What does Nix Config New Host do?

A skill your agent uses when adding a NixOS, macOS, or MicroVM host in this repo, or wiring an existing machine into outputs/, hostsAddr, secrets recipients, and the eval tests. Nix Config New Host is an agent skill from ryan4yin/nix-config. Use when adding a NixOS, macOS, or MicroVM host in this repo, or wiring an existing machine into outputs/, hostsAddr, secrets recipients, and the eval tests.

When should I use Nix Config New Host?

Nix Config New Host fits situations like: microVM host in this repo; wiring an existing machine into outputs/; secrets recipients.

How do I install Nix Config New Host in Claude Code?

Run `npx skills add ryan4yin/nix-config --skill nix-config-new-host -a claude-code`. Or copy the skill folder (.agents/skills/nix-config-new-host in ryan4yin/nix-config) into .claude/skills/nix-config-new-host in your project. Claude Code loads it when a task matches its description.

How do I install Nix Config New Host in Codex?

Run `npx skills add ryan4yin/nix-config --skill nix-config-new-host -a codex`. Or copy the skill folder (.agents/skills/nix-config-new-host in ryan4yin/nix-config) into .agents/skills/nix-config-new-host in your project. Codex loads it when a task matches its description.

Can I use Nix Config New Host in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ryan4yin/nix-config --skill nix-config-new-host -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/nix-config-new-host, .gemini/skills/nix-config-new-host, .github/skills/nix-config-new-host and .opencode/skills/nix-config-new-host in your project.

What does Nix Config New Host need to run?

Going by SKILL.md and its folder, Nix Config New Host needs the command-line tools its instructions call (just and ssh).

Does Nix Config New Host access the network?

SKILL.md contains no URLs. Its commands use ssh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Nix Config New Host safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Nix Config New Host use?

Nix Config New Host is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Nix Config New Host use?

About 1.6k tokens (SKILL.md is roughly 6.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Nix Config New Host?

Skills that share tags, products or a category with Nix Config New Host: Native Feel Cross Platform Desktop (yetone/native-feel-skill, 1.9k stars), JS Cpp Protocol (notepadqq/notepadqq, 2.3k stars), RStudio Copilot Language Server Updater (rstudio/rstudio, 5.1k stars) and OpenLogi Device Diagnosis (AprilNEA/OpenLogi, 23k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Nix Config New Host?

ryan4yin (a GitHub user) maintains it in ryan4yin/nix-config, which has 2,094 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on October 11, 2026.

Source: ryan4yin/nix-config on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.