Vercel Composition Patterns
supabase/supabase
React composition patterns that scale. An agent skill from supabase/supabase.
A skill your agent uses when updating flake inputs, bumping nixpkgs, or rolling an update out to hosts in this repo.
$ npx skills add ryan4yin/nix-config --skill nix-config-update -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install ryan4yin/nix-config nix-config-update --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/ryan4yin/nix-config.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/nix-config-update .claude/skills/nix-config-update && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "nix-config-update" agent skill from https://github.com/ryan4yin/nix-config/tree/main/.agents/skills/nix-config-update into .claude/skills/nix-config-update/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nix-config-update", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/ryan4yin/nix-config/tree/main/.agents/skills/nix-config-updateType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add ryan4yin/nix-config --skill nix-config-update -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install ryan4yin/nix-config nix-config-update --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ryan4yin/nix-config.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/nix-config-update .agents/skills/nix-config-update && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "nix-config-update" agent skill from https://github.com/ryan4yin/nix-config/tree/main/.agents/skills/nix-config-update into .agents/skills/nix-config-update/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nix-config-update", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ryan4yin/nix-config --skill nix-config-update -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install ryan4yin/nix-config nix-config-update --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ryan4yin/nix-config.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/nix-config-update .cursor/skills/nix-config-update && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "nix-config-update" agent skill from https://github.com/ryan4yin/nix-config/tree/main/.agents/skills/nix-config-update into .cursor/skills/nix-config-update/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nix-config-update", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/ryan4yin/nix-config.git --path .agents/skills/nix-config-update--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add ryan4yin/nix-config --skill nix-config-update -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install ryan4yin/nix-config nix-config-update --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ryan4yin/nix-config.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/nix-config-update .gemini/skills/nix-config-update && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "nix-config-update" agent skill from https://github.com/ryan4yin/nix-config/tree/main/.agents/skills/nix-config-update into .gemini/skills/nix-config-update/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nix-config-update", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install ryan4yin/nix-config nix-config-updateInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add ryan4yin/nix-config --skill nix-config-update -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/ryan4yin/nix-config.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/nix-config-update .github/skills/nix-config-update && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "nix-config-update" agent skill from https://github.com/ryan4yin/nix-config/tree/main/.agents/skills/nix-config-update into .github/skills/nix-config-update/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nix-config-update", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ryan4yin/nix-config --skill nix-config-update -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install ryan4yin/nix-config nix-config-update --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ryan4yin/nix-config.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/nix-config-update .opencode/skills/nix-config-update && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "nix-config-update" agent skill from https://github.com/ryan4yin/nix-config/tree/main/.agents/skills/nix-config-update into .opencode/skills/nix-config-update/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nix-config-update", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
nix-config-updateA skill your agent uses when updating flake inputs, bumping nixpkgs, or rolling an update out to hosts in this repo.
Nix Config Update is an agent skill from ryan4yin/nix-config. Use when updating flake inputs, bumping nixpkgs, or rolling an update out to hosts in this repo.
Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Development. The repository describes itself as: ❄️ My nix config for both desktops(NixOS+macOS) and homelab servers(NixOS). The licence is MIT.
8 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 63b7183. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
justgitnixsshFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git and ssh, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Nix Config Update loads about 2.3k tokens when it runs. Until then it costs about 29 tokens; SKILL.md has 1,211 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
are on runs `nixos-rebuild --sudo` (or `sudo -E darwin-rebuild`) andAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from ryan4yin/nix-config at commit 63b7183, republished under its MIT licence (© ryan4yin). 1,211 words, ~2,323 tokens.
.claude/skills/nix-config-update/SKILL.md (or your agent's skills folder).Read this before running just up, just upp, just up-nix, or just override-pkgs, and before
deploying the result to any host.
just test is green and
the affected hosts build locally.flake.lock: Update commit for
the bump; a config change gets its own commit or PR.boot mode, just darwin-rollback, or git revert.ryan4yin/*
repositories — MUST name a version tag or a fixed commit, not a branch. Official channel
upstreams that publish no release (nixpkgs' nixos-unstable/master) are the exception. When
only a branch carries a needed third-party change, keep the resolved revision in the lock, record
why next to the declaration, and re-audit each update.git status is clean, and you are on main or a fresh branch for the work. If you are on an
unrelated feature branch, stop and ask for the right branch before bumping.just test is green before the update, so you have a baseline to compare against.df -h /nix/store. Broad nixpkgs bumps pull a lot.| Goal | Command | Notes |
|---|---|---|
| Everything | just up | Updates and commits the lock file automatically; audit before pushing |
| One input | just upp <input> | Same, for a single input, e.g. just upp catppuccin; audit before pushing |
| The nixpkgs family | just up-nix | Updates nixpkgs-stable/-master/-darwin/-patched; not nixpkgs |
Pin nixpkgs | just override-pkgs <hash> | Pin nixpkgs to a known-good Hydra commit |
| Update but keep it dirty | nix flake update <input> | Leaves the change uncommitted so you can inspect it first |
| Nix itself (macOS) | just nix-upgrade | determinate-nixd upgrade; macOS only |
After an update, read git diff flake.lock: it lists exactly which inputs moved and by how many
commits. Because just up and just upp commit automatically, either use
nix flake update <input> while auditing or amend the generated lock commit after the audit so its
message records the conclusion.
Treat an update as a supply-chain event.
From git diff flake.lock, list every input whose locked.rev changed.
Find the inputs that contribute modules this repo imports:
grep -rn "homeModules\.\|nixosModules\.\|darwinModules\." --include='*.nix' .For each of those inputs, read what changed between the old and new revision in the module files we actually import. Look for:
nix.settings (substituters, extra-substituters, trusted-public-keys,
trusted-users) — at the Home Manager layer these are ignored for an untrusted user and only
warn, but at the system layer they are a root-equivalent trust boundary;environment.etc / home.file entries with a mode or user that widens access;system.activationScripts, systemd.services running as root, sudo/polkit rules;lib.mkForce overrides that silently replace existing settings;For nixpkgs-class inputs, skim the lock diff and expect broken packages and eval deprecation warnings (see "Lessons from past updates").
Write the audit conclusion into the update commit message. If an automatic recipe already made the commit, amend it only after reviewing the diff; do not push the unaudited commit first.
Run these before any host is touched:
just test — fails (non-zero) unless the suite returns true.just eval-host <host> — fast, evaluation only.just build-host <host> — builds the full system closure and catches broken packages or build
failures that eval misses.just build-microvm <guest> — same, for a MicroVM guest.nix flake check — broader checks when the change touches shared code.Cover every host you are about to deploy, and prefer building the closure over trusting a green eval.
Preview what the machine you are on will change before it is deployed:
nix store diff-closures /run/current-system '.#nixosConfigurations.<host>.config.system.build.toplevel'It lists every package whose version or size moves; an empty result means nothing changes. Read it for unexpected removals, major-version jumps, and kernel or systemd changes that need a reboot.
Modes are switch (take effect now, the default) and boot (only the next boot). Add debug for
verbose output. Anything else is rejected.
Activating the machine you are on runs nixos-rebuild --sudo (or sudo -E darwin-rebuild) and
blocks on a password prompt. An agent cannot run these; they are for the user to run by hand.
just niri [mode] [verbosity]just local [mode] [verbosity]just local [debug] (build then switch; macOS has no switch/boot split)The rest authenticate over SSH as root on the target, so they run non-interactively — but they still change remote state. Confirm the target instead of trusting the recipe's default, then state it back to the user and get authorization for that host:
hostname # which machine you are on
git branch --show-current
git remote -v
getent hosts <host> # the address the tag will connect to
ssh root@<host> hostname # the host that actually answersjust shoryu [mode], just shushou, just youko, just ruby, just kanajust lab [mode]; any Colmena tag: just col <tag> [mode]just k3s-test [mode]just microvm-deploy <guest> <host> <guest-ip> — deploy guests serially and check
each one before moving on.Use boot plus a deliberate reboot for anything that can drop networking mid-flight: the VM hosts
with the br0 bridge, and broad nixpkgs bumps. See
hosts/README.md.
systemctl --failed and just list-failed for failed units.journalctl -b -p err for boot-time errors.just test so a dirty tree cannot hide a regression.just history lists system generations; pick the previous one in the bootloader menu, or
re-deploy a reverted tree.just darwin-rollback (darwin-rebuild --rollback).git revert <sha> and re-apply, or apply with boot and reboot.git checkout -- flake.lock, then reproduce. If the tree holds other uncommitted work, ask before
discarding anything.nix flake update <input>, and pin a
known-good nixpkgs with just override-pkgs <hash> while the breakage is fixed upstream.just gc (older than 7 days) and just clean (wipes profile history) delete the generations you
would roll back to, so run them last, once the update has proven stable. just gcroot only lists GC
roots. The full list of hazardous recipes is in the Command Hazards section of
AGENTS.md.
0fe12bef fix(nix): preserve default sandbox shell - a nix.settings change used
sandbox-paths, which replaced Nix's compiled defaults (including the sandbox shell used for
legacy shebangs). Use extra-sandbox-paths, and verify with
nix config show | grep sandbox-paths.125bce3b fix: cuda12.8-cuda_cudart-12.8.90 is marked as broken and
78fc64e1 fix(neovim): disable nixvim manpage on broken nixpkgs pin - broken packages after a
nixpkgs bump are normal; just build-host finds them before a deploy does.4bd463a7 chore(eval): resolve catppuccin and rust-overlay deprecation warnings - input bumps
surface deprecation warnings that become errors in a later bump.© ryan4yin, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .agents/skills/nix-config-update of ryan4yin/nix-config.
Open the folder on GitHubat commit 63b7183
Nix Config Update next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Nix Config Update this skillryan4yin/nix-config | 2.1k | — | ~2.3k | Automated safety check: Notes | MIT | |
| Vercel Composition Patternssupabase/supabase | 111k | 58 repos | ~726 | Automated safety check: Pass | MIT | |
| Finishing a Development Branchobra/superpowers | 297k | 5 repos | ~1.9k | Automated safety check: Pass | MIT | |
| Typescript Advanced Typesrolling-scopes/rsschool-app | 10k | 25 repos | ~4.2k | Automated safety check: Pass | MPL-2.0 | |
| PR Babysitteropeninterpreter/openinterpreter | 69k | 3 repos | ~4.2k | Automated safety check: Pass | Apache-2.0 | |
| Code Review ChecklistshareAI-lab/learn-claude-code | 78k | 5 repos | ~1.1k | Automated safety check: Pass | MIT |
supabase/supabase
React composition patterns that scale. An agent skill from supabase/supabase.
obra/superpowers
Walks the last step of a branch: confirm tests pass, detect the git environment, ask how to integrate, carry out your choice and clean up the worktree.
rolling-scopes/rsschool-app
Master TypeScript's advanced type system including generics, conditional types, mapped types, template literals, and utility types for building type-safe applications.
openinterpreter/openinterpreter
Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.
shareAI-lab/learn-claude-code
Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.
onyx-dot-app/onyx
Iteratively improves a PR (GitHub), MR (GitLab), or shelved changelist (Perforce) until Greptile gives it a 5/5 confidence score with zero unresolved comments.
ryan4yin/nix-config
A skill your agent uses when installing a Windows game launcher (二次元 / gacha or any non-Steam game) on a NixOS desktop via umu-launcher, given an installer URL or an .exe, or when such a launcher…
ryan4yin/nix-config
A skill your agent uses when something in this repo is broken, such as an eval or build error, a failed activation, a crashed service, or an unreachable host or MicroVM guest.
ryan4yin/nix-config
A skill your agent uses when changing the Niri/Noctalia desktop, the Wayland session, input method (fcitx5), theming, fonts, or desktop autostart in this repo.
ryan4yin/nix-config
A skill your agent uses when adding, changing, renaming, or removing an agenix secret, wiring one into a host, or fixing a decryption or activation failure in this repo.
ryan4yin/nix-config
A skill your agent uses when temporarily carrying an unmerged nixpkgs pull request or commit in the personal ryan4yin/nixpkgs fork, updating the nixos-unstable-patched branch, or consuming that…
ryan4yin/nix-config
A skill your agent uses when reviewing an upstream NixOS/nixpkgs pull request before it is merged, including its package changes, passthru tests, dependencies, or CI results.
Categories
A skill your agent uses when updating flake inputs, bumping nixpkgs, or rolling an update out to hosts in this repo. Nix Config Update is an agent skill from ryan4yin/nix-config. Use when updating flake inputs, bumping nixpkgs, or rolling an update out to hosts in this repo.
Nix Config Update fits situations like: updating flake inputs; bumping nixpkgs; rolling an update out to hosts in this repo.
Run `npx skills add ryan4yin/nix-config --skill nix-config-update -a claude-code`. Or copy the skill folder (.agents/skills/nix-config-update in ryan4yin/nix-config) into .claude/skills/nix-config-update in your project. Claude Code loads it when a task matches its description.
Run `npx skills add ryan4yin/nix-config --skill nix-config-update -a codex`. Or copy the skill folder (.agents/skills/nix-config-update in ryan4yin/nix-config) into .agents/skills/nix-config-update in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ryan4yin/nix-config --skill nix-config-update -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/nix-config-update, .gemini/skills/nix-config-update, .github/skills/nix-config-update and .opencode/skills/nix-config-update in your project.
Going by SKILL.md and its folder, Nix Config Update needs the command-line tools its instructions call (just, git, nix and ssh).
SKILL.md contains no URLs. Its commands use git and ssh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Nix Config Update is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.3k tokens (SKILL.md is roughly 9.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Nix Config Update: Vercel Composition Patterns (supabase/supabase, 111k stars), Finishing a Development Branch (obra/superpowers, 297k stars), Typescript Advanced Types (rolling-scopes/rsschool-app, 10k stars) and PR Babysitter (openinterpreter/openinterpreter, 69k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
ryan4yin (a GitHub user) maintains it in ryan4yin/nix-config, which has 2,090 GitHub stars. The repository holds 8 skills in this directory. The repository was last updated on October 9, 2026.
Source: ryan4yin/nix-config on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.