Vercel Composition Patterns
supabase/supabase
React composition patterns that scale. An agent skill from supabase/supabase.
A skill your agent uses when adding, changing, renaming, or removing an agenix secret, wiring one into a host, or fixing a decryption or activation failure in this repo.
$ npx skills add ryan4yin/nix-config --skill nix-config-secrets -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install ryan4yin/nix-config nix-config-secrets --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/ryan4yin/nix-config.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/nix-config-secrets .claude/skills/nix-config-secrets && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "nix-config-secrets" agent skill from https://github.com/ryan4yin/nix-config/tree/main/.agents/skills/nix-config-secrets into .claude/skills/nix-config-secrets/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nix-config-secrets", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/ryan4yin/nix-config/tree/main/.agents/skills/nix-config-secretsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add ryan4yin/nix-config --skill nix-config-secrets -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install ryan4yin/nix-config nix-config-secrets --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ryan4yin/nix-config.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/nix-config-secrets .agents/skills/nix-config-secrets && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "nix-config-secrets" agent skill from https://github.com/ryan4yin/nix-config/tree/main/.agents/skills/nix-config-secrets into .agents/skills/nix-config-secrets/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nix-config-secrets", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ryan4yin/nix-config --skill nix-config-secrets -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install ryan4yin/nix-config nix-config-secrets --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ryan4yin/nix-config.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/nix-config-secrets .cursor/skills/nix-config-secrets && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "nix-config-secrets" agent skill from https://github.com/ryan4yin/nix-config/tree/main/.agents/skills/nix-config-secrets into .cursor/skills/nix-config-secrets/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nix-config-secrets", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/ryan4yin/nix-config.git --path .agents/skills/nix-config-secrets--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add ryan4yin/nix-config --skill nix-config-secrets -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install ryan4yin/nix-config nix-config-secrets --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ryan4yin/nix-config.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/nix-config-secrets .gemini/skills/nix-config-secrets && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "nix-config-secrets" agent skill from https://github.com/ryan4yin/nix-config/tree/main/.agents/skills/nix-config-secrets into .gemini/skills/nix-config-secrets/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nix-config-secrets", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install ryan4yin/nix-config nix-config-secretsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add ryan4yin/nix-config --skill nix-config-secrets -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/ryan4yin/nix-config.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/nix-config-secrets .github/skills/nix-config-secrets && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "nix-config-secrets" agent skill from https://github.com/ryan4yin/nix-config/tree/main/.agents/skills/nix-config-secrets into .github/skills/nix-config-secrets/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nix-config-secrets", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ryan4yin/nix-config --skill nix-config-secrets -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install ryan4yin/nix-config nix-config-secrets --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ryan4yin/nix-config.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/nix-config-secrets .opencode/skills/nix-config-secrets && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "nix-config-secrets" agent skill from https://github.com/ryan4yin/nix-config/tree/main/.agents/skills/nix-config-secrets into .opencode/skills/nix-config-secrets/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nix-config-secrets", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
nix-config-secretsA skill your agent uses when adding, changing, renaming, or removing an agenix secret, wiring one into a host, or fixing a decryption or activation failure in this repo.
Nix Config Secrets is an agent skill from ryan4yin/nix-config. Use when adding, changing, renaming, or removing an agenix secret, wiring one into a host, or fixing a decryption or activation failure in this repo.
Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Development. The repository describes itself as: ❄️ My nix config for both desktops(NixOS+macOS) and homelab servers(NixOS). The licence is MIT.
7 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 63b7183. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
justgitnixFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Nix Config Secrets loads about 2.3k tokens when it runs. Until then it costs about 42 tokens; SKILL.md has 1,047 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
not reach it; do not add `sudo -E` or set `EDITOR` yourself.Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from ryan4yin/nix-config at commit 63b7183, republished under its MIT licence (© ryan4yin). 1,047 words, ~2,266 tokens.
.claude/skills/nix-config-secrets/SKILL.md (or your agent's skills folder).Secrets are age-encrypted files in the private repository ~/codes/nix-secrets
(git@github.com:ryan4yin/nix-secrets.git), pulled in as the mysecrets flake input and declared
here in secrets/nixos.nix and secrets/darwin.nix. No secret value or ciphertext is ever stored
in this public repository.
Read secrets/README.md for the concepts and the recipient rule.
cat, copy, or print it. Prove a
change with metadata (mode, owner, timestamps), never with content.flake.lock moves mysecrets to that commit, then the declaration and consumer change here.
file = "${mysecrets}/x.age" resolves against the locked revision, so a declaration that lands
before the lock bump points at a file that does not exist yet.desktop_keys ++ <the hosts that need it>; recovery_key is a member of desktop_keys. The one
exception is restic-password-desktop.age, readable by desktop_keys alone.modules.secrets.desktop only exists on desktops, so only a desktop-gated module may reference
it. Desktops and servers are mutually exclusive: secrets/nixos.nix asserts that a host never
enables desktop together with a server group, so a value both sides need takes a deliberate
choice rather than enabling both groups.| Piece | Location |
|---|---|
Recipient list, encrypted files, agenix CLI | ~/codes/nix-secrets (private; git@github.com:ryan4yin/nix-secrets.git) |
| The pinned revision of that repository | flake.lock, input mysecrets |
Declaration: file, mode/owner, /etc copy | secrets/nixos.nix, secrets/darwin.nix |
| Which host gets which group | modules.secrets.<group>.enable in outputs/<system>/src/<name>.nix or a host module |
| Consumers | modules reading config.age.secrets."<name>".path (default /run/agenix/<name>) |
| Decryption key | age.identityPaths: the host's SSH host key; /persistent/etc/ssh/... on a preservation host |
The private repository groups the .age files: desktop/ (only desktops decrypt them), server/
(any server), certs/, and public/.
Do the mechanical work yourself: edit secrets.nix in ~/codes/nix-secrets, run the
non-interactive steps, bump the lock, and add the declaration and consumer. For a new secret, or a
full replacement, pipe the plaintext into the replace recipe: it removes the target first, so
agenix only encrypts and needs no sudo. Hand back only what needs a human: the partial edit and
the rekey recipes in secrets/Justfile (they decrypt the current
value, so they handle key material, $EDITOR, and sudo) and anything else under sudo. Commits
and pushes follow the global git rules.
~/codes/nix-secrets, add the file under desktop/ or server/ with a matching
secrets.nix entry, keyed by that exact path (e.g. "./desktop/xxx.age"), and the recipient set
from core rule 3. Then encrypt it with the replace recipe (§3); ask the user only when the
plaintext has to come from an interactive session.just upp mysecrets (commits the lock) or nix flake update mysecrets (leaves it for you
to commit). git diff flake.lock should show only mysecrets moving.secrets/nixos.nix or secrets/darwin.nix under the right
modules.secrets.<group> gate, with a mode/owner preset (§4).just test and just build-host <host>, deploy, then verify as in §5.Changing only a secret's value is steps 1, 2, and the deploy: use replace for a full replacement
(the agent can run it) or edit for a partial change (needs the host key).
The agenix operations run against ~/codes/nix-secrets. Their single source is
secrets/Justfile, which pins the identity, option order, and
$EDITOR; run them from this repository's root and keep each path identical to its key in
secrets.nix:
just -f secrets/Justfile replace ./desktop/xxx.age < plaintext # add or fully replace (no sudo)
just -f secrets/Justfile edit ./desktop/xxx.age # partial edit (sudo, $EDITOR)
just -f secrets/Justfile rekey # re-encrypt after a recipient changeedit and rekey decrypt the current value with the host key, so they need sudo; replace only
encrypts to the recipients in secrets.nix, so it needs no sudo. edit passes EDITOR=hx to the
root agenix process, because sudo resets the environment and the invoking user's EDITOR would
not reach it; do not add sudo -E or set EDITOR yourself.
The repository keeps a single amended commit: git commit --amend -a --no-edit,
git reflog expire --expire-unreachable=now --all, git gc --prune=now, then force push. Treat
amend and force push as impactful and get authorization first.
Use one of the presets in secrets/nixos.nix (noaccess, high_security, user_readable); the
table and the environment.etc copy trap are in
secrets/README.md. The rule to remember:
whenever an environment.etc entry sets mode, it also sets user. Never widen a mode to make
a root-owned copy readable.
stat -c '%a %U:%G' /run/agenix/<name> # mode and owner, not content (the default path)
ls -l /run/agenix/ # /etc/agenix/ holds only the environment.etc copies
journalctl -b | grep -5 agenix # NixOS
tail -n 100 /Library/Logs/org.nixos.activate-agenix.stderr.log # macOSA successful activation is silent. Check that the access changed as intended (the mode and owner you set, an old copy gone) instead of assuming activation did it.
Search all references before changing it:
grep -Rni '<secret-name>' --include='*.nix' --include='*.toml' .Check secrets/, home/, modules/, hosts/, outputs, tests, and the private repository.
Delete the age.secrets entry, its environment.etc placement, and every consumer in one change;
a declaration whose file no longer exists breaks activation.
Remove it from secrets.nix and delete the file in the private repository, then bump the lock.
A rename changes the attribute name and every consumer. The .age filename is separate.
/etc/ssh/ssh_host_ed25519_key.pub to secrets.nix, rekey (§3), push, bump the lock, redeploy.mysecrets revision
without it (core rule 2).permission denied in a user service: it reads a root-only secret. Fix that secret's owner;
do not widen the mode.age.identityPaths must use the
/persistent/etc/ssh/... path, which exists before preservation mounts /etc./etc/agenix copies, because they run before
activate-agenix has decrypted anything. Run it again.4909f635 security: scope privileges and stop a world-readable secret copy (#335) - the
environment.etc copy trap in step 3.c8e76cef fix(darwin): agenix - remove non-exist secret - a declaration left behind after its
file was deleted.4211d18a - a shared modules/nixos/base module included nix-access-tokens, which not every
host had; the reference moved to modules/nixos/desktop/nix.nix (core rule 4).260da1ee chore: rename the nushell secret, and forbid reading decrypted secrets - the no-reading
rule.© ryan4yin, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .agents/skills/nix-config-secrets of ryan4yin/nix-config.
Open the folder on GitHubat commit 63b7183
Nix Config Secrets next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Nix Config Secrets this skillryan4yin/nix-config | 2.1k | — | ~2.3k | Automated safety check: Notes | MIT | |
| Vercel Composition Patternssupabase/supabase | 111k | 58 repos | ~726 | Automated safety check: Pass | MIT | |
| Finishing a Development Branchobra/superpowers | 297k | 5 repos | ~1.9k | Automated safety check: Pass | MIT | |
| Typescript Advanced Typesrolling-scopes/rsschool-app | 10k | 25 repos | ~4.2k | Automated safety check: Pass | MPL-2.0 | |
| PR Babysitteropeninterpreter/openinterpreter | 69k | 3 repos | ~4.2k | Automated safety check: Pass | Apache-2.0 | |
| Code Review ChecklistshareAI-lab/learn-claude-code | 78k | 5 repos | ~1.1k | Automated safety check: Pass | MIT |
supabase/supabase
React composition patterns that scale. An agent skill from supabase/supabase.
obra/superpowers
Walks the last step of a branch: confirm tests pass, detect the git environment, ask how to integrate, carry out your choice and clean up the worktree.
rolling-scopes/rsschool-app
Master TypeScript's advanced type system including generics, conditional types, mapped types, template literals, and utility types for building type-safe applications.
openinterpreter/openinterpreter
Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.
shareAI-lab/learn-claude-code
Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.
onyx-dot-app/onyx
Iteratively improves a PR (GitHub), MR (GitLab), or shelved changelist (Perforce) until Greptile gives it a 5/5 confidence score with zero unresolved comments.
ryan4yin/nix-config
A skill your agent uses when installing a Windows game launcher (二次元 / gacha or any non-Steam game) on a NixOS desktop via umu-launcher, given an installer URL or an .exe, or when such a launcher…
ryan4yin/nix-config
A skill your agent uses when something in this repo is broken, such as an eval or build error, a failed activation, a crashed service, or an unreachable host or MicroVM guest.
ryan4yin/nix-config
A skill your agent uses when changing the Niri/Noctalia desktop, the Wayland session, input method (fcitx5), theming, fonts, or desktop autostart in this repo.
ryan4yin/nix-config
A skill your agent uses when updating flake inputs, bumping nixpkgs, or rolling an update out to hosts in this repo.
ryan4yin/nix-config
A skill your agent uses when temporarily carrying an unmerged nixpkgs pull request or commit in the personal ryan4yin/nixpkgs fork, updating the nixos-unstable-patched branch, or consuming that…
ryan4yin/nix-config
A skill your agent uses when reviewing an upstream NixOS/nixpkgs pull request before it is merged, including its package changes, passthru tests, dependencies, or CI results.
Categories
A skill your agent uses when adding, changing, renaming, or removing an agenix secret, wiring one into a host, or fixing a decryption or activation failure in this repo. Nix Config Secrets is an agent skill from ryan4yin/nix-config. Use when adding, changing, renaming, or removing an agenix secret, wiring one into a host, or fixing a decryption or activation failure in this repo.
Nix Config Secrets fits situations like: removing an agenix secret; wiring one into a host; fixing a decryption; activation failure in this repo.
Run `npx skills add ryan4yin/nix-config --skill nix-config-secrets -a claude-code`. Or copy the skill folder (.agents/skills/nix-config-secrets in ryan4yin/nix-config) into .claude/skills/nix-config-secrets in your project. Claude Code loads it when a task matches its description.
Run `npx skills add ryan4yin/nix-config --skill nix-config-secrets -a codex`. Or copy the skill folder (.agents/skills/nix-config-secrets in ryan4yin/nix-config) into .agents/skills/nix-config-secrets in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ryan4yin/nix-config --skill nix-config-secrets -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/nix-config-secrets, .gemini/skills/nix-config-secrets, .github/skills/nix-config-secrets and .opencode/skills/nix-config-secrets in your project.
Going by SKILL.md and its folder, Nix Config Secrets needs the command-line tools its instructions call (just, git and nix).
SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Nix Config Secrets is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.3k tokens (SKILL.md is roughly 9.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Nix Config Secrets: Vercel Composition Patterns (supabase/supabase, 111k stars), Finishing a Development Branch (obra/superpowers, 297k stars), Typescript Advanced Types (rolling-scopes/rsschool-app, 10k stars) and PR Babysitter (openinterpreter/openinterpreter, 69k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
ryan4yin (a GitHub user) maintains it in ryan4yin/nix-config, which has 2,090 GitHub stars. The repository holds 8 skills in this directory. The repository was last updated on October 9, 2026.
Source: ryan4yin/nix-config on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.