Agent skill

Nix Config Update

by ryan4yin in ryan4yin/nix-config

A skill your agent uses when updating flake inputs, bumping nixpkgs, or rolling an update out to hosts in this repo.

MITAuto-check: notesDevelopment

Install Nix Config Update

skills CLI
$ npx skills add ryan4yin/nix-config --skill nix-config-update -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ryan4yin/nix-config nix-config-update --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ryan4yin/nix-config.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/nix-config-update .claude/skills/nix-config-update && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
nix-config-update
GitHub stars
2.1k
Token cost
~2.3k tokens
SKILL.md length
1,211 words
Files
1
Skills in repo
8
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when updating flake inputs, bumping nixpkgs, or rolling an update out to hosts in this repo.

  • Works in 8 steps: Pre-flight → Run the update → Audit the change → …
  • Updating flake inputs
  • SKILL.md covers Core rules, 1. Pre-flight, 2. Run the update and 3. Audit the change, plus 6 more sections
  • Calls just, git and nix

What it does

Nix Config Update is an agent skill from ryan4yin/nix-config. Use when updating flake inputs, bumping nixpkgs, or rolling an update out to hosts in this repo.

Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development. The repository describes itself as: ❄️ My nix config for both desktops(NixOS+macOS) and homelab servers(NixOS). The licence is MIT.

When your agent uses it

  • Updating flake inputs
  • Bumping nixpkgs
  • Rolling an update out to hosts in this repo

Example prompts

  • “/nix-config-update”

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. Pre-flight
  2. Run the update
  3. Audit the change
  4. Validate before deploying
  5. Deploy in stages
  6. Verify after deploying
  7. Roll back
  8. Clean up only after it is stable

What it can do on your machine

Read from SKILL.md and the folder at commit 63b7183. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • just
    • git
    • nix
    • ssh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git and ssh, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Nix Config Update loads about 2.3k tokens when it runs. Until then it costs about 29 tokens; SKILL.md has 1,211 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~29
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteRuns commands with sudoSKILL.md:107
    are on runs `nixos-rebuild --sudo` (or `sudo -E darwin-rebuild`) and

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ryan4yin/nix-config at commit 63b7183, republished under its MIT licence (© ryan4yin). 1,211 words, ~2,323 tokens.

Download SKILL.mdSave it as .claude/skills/nix-config-update/SKILL.md (or your agent's skills folder).
name
nix-config-update
description
Use when updating flake inputs, bumping nixpkgs, or rolling an update out to hosts in this repo.

Updating this flake safely

Read this before running just up, just upp, just up-nix, or just override-pkgs, and before deploying the result to any host.

Core rules

  1. Update and deploy are two steps. Never fold "bump the lock file" and "switch every host" into one blind action.
  2. Validate before touching a host. An update is only a candidate until just test is green and the affected hosts build locally.
  3. One reviewable commit per update. The convention here is a flake.lock: Update commit for the bump; a config change gets its own commit or PR.
  4. Keep a way back. Anything that reaches a host needs a rollback path: the previous generation, boot mode, just darwin-rollback, or git revert.
  5. Security first. An update re-opens the supply chain. Re-audit every input whose revision moved before you deploy it.
  6. Pin third-party inputs. A third-party input — not one of the user's own ryan4yin/* repositories — MUST name a version tag or a fixed commit, not a branch. Official channel upstreams that publish no release (nixpkgs' nixos-unstable/master) are the exception. When only a branch carries a needed third-party change, keep the resolved revision in the lock, record why next to the declaration, and re-audit each update.

1. Pre-flight

  • git status is clean, and you are on main or a fresh branch for the work. If you are on an unrelated feature branch, stop and ask for the right branch before bumping.
  • just test is green before the update, so you have a baseline to compare against.
  • Enough disk for the new closures: df -h /nix/store. Broad nixpkgs bumps pull a lot.
  • Know what will move and choose the narrowest recipe that does the job.

2. Run the update

GoalCommandNotes
Everythingjust upUpdates and commits the lock file automatically; audit before pushing
One inputjust upp <input>Same, for a single input, e.g. just upp catppuccin; audit before pushing
The nixpkgs familyjust up-nixUpdates nixpkgs-stable/-master/-darwin/-patched; not nixpkgs
Pin nixpkgsjust override-pkgs <hash>Pin nixpkgs to a known-good Hydra commit
Update but keep it dirtynix flake update <input>Leaves the change uncommitted so you can inspect it first
Nix itself (macOS)just nix-upgradedeterminate-nixd upgrade; macOS only

After an update, read git diff flake.lock: it lists exactly which inputs moved and by how many commits. Because just up and just upp commit automatically, either use nix flake update <input> while auditing or amend the generated lock commit after the audit so its message records the conclusion.

3. Audit the change

Treat an update as a supply-chain event.

  1. From git diff flake.lock, list every input whose locked.rev changed.

  2. Find the inputs that contribute modules this repo imports:

    bash
    grep -rn "homeModules\.\|nixosModules\.\|darwinModules\." --include='*.nix' .
  3. For each of those inputs, read what changed between the old and new revision in the module files we actually import. Look for:

    • restricted nix.settings (substituters, extra-substituters, trusted-public-keys, trusted-users) — at the Home Manager layer these are ignored for an untrusted user and only warn, but at the system layer they are a root-equivalent trust boundary;
    • environment.etc / home.file entries with a mode or user that widens access;
    • system.activationScripts, systemd.services running as root, sudo/polkit rules;
    • lib.mkForce overrides that silently replace existing settings;
    • eval-time network access or import-from-derivation.
  4. For nixpkgs-class inputs, skim the lock diff and expect broken packages and eval deprecation warnings (see "Lessons from past updates").

  5. Write the audit conclusion into the update commit message. If an automatic recipe already made the commit, amend it only after reviewing the diff; do not push the unaudited commit first.

4. Validate before deploying

Run these before any host is touched:

  • just test — fails (non-zero) unless the suite returns true.
  • just eval-host <host> — fast, evaluation only.
  • just build-host <host> — builds the full system closure and catches broken packages or build failures that eval misses.
  • just build-microvm <guest> — same, for a MicroVM guest.
  • nix flake check — broader checks when the change touches shared code.

Cover every host you are about to deploy, and prefer building the closure over trusting a green eval.

Preview what the machine you are on will change before it is deployed:

bash
nix store diff-closures /run/current-system '.#nixosConfigurations.<host>.config.system.build.toplevel'

It lists every package whose version or size moves; an empty result means nothing changes. Read it for unexpected removals, major-version jumps, and kernel or systemd changes that need a reboot.

Show full SKILL.md (497 more words)Show less

5. Deploy in stages

Modes are switch (take effect now, the default) and boot (only the next boot). Add debug for verbose output. Anything else is rejected.

Activating the machine you are on runs nixos-rebuild --sudo (or sudo -E darwin-rebuild) and blocks on a password prompt. An agent cannot run these; they are for the user to run by hand.

  • Current desktop: just niri [mode] [verbosity]
  • Other local NixOS host: just local [mode] [verbosity]
  • macOS: just local [debug] (build then switch; macOS has no switch/boot split)

The rest authenticate over SSH as root on the target, so they run non-interactively — but they still change remote state. Confirm the target instead of trusting the recipe's default, then state it back to the user and get authorization for that host:

bash
hostname                  # which machine you are on
git branch --show-current
git remote -v
getent hosts <host>       # the address the tag will connect to
ssh root@<host> hostname  # the host that actually answers
  • Remote servers: just shoryu [mode], just shushou, just youko, just ruby, just kana
  • All VM hosts at once: just lab [mode]; any Colmena tag: just col <tag> [mode]
  • k3s test nodes: just k3s-test [mode]
  • MicroVM guest: just microvm-deploy <guest> <host> <guest-ip> — deploy guests serially and check each one before moving on.

Use boot plus a deliberate reboot for anything that can drop networking mid-flight: the VM hosts with the br0 bridge, and broad nixpkgs bumps. See hosts/README.md.

6. Verify after deploying

  • systemctl --failed and just list-failed for failed units.
  • journalctl -b -p err for boot-time errors.
  • The user-visible surface: network, the desktop session, and the specific service you changed.
  • Re-run just test so a dirty tree cannot hide a regression.

7. Roll back

  • NixOS: just history lists system generations; pick the previous one in the bootloader menu, or re-deploy a reverted tree.
  • macOS: just darwin-rollback (darwin-rebuild --rollback).
  • Remote (Colmena): git revert <sha> and re-apply, or apply with boot and reboot.
  • Update failed but never deployed: drop the bump's own uncommitted lock change with git checkout -- flake.lock, then reproduce. If the tree holds other uncommitted work, ask before discarding anything.
  • Isolate a bad bump by moving one input at a time with nix flake update <input>, and pin a known-good nixpkgs with just override-pkgs <hash> while the breakage is fixed upstream.

8. Clean up only after it is stable

just gc (older than 7 days) and just clean (wipes profile history) delete the generations you would roll back to, so run them last, once the update has proven stable. just gcroot only lists GC roots. The full list of hazardous recipes is in the Command Hazards section of AGENTS.md.

Why these rules exist

  • 0fe12bef fix(nix): preserve default sandbox shell - a nix.settings change used sandbox-paths, which replaced Nix's compiled defaults (including the sandbox shell used for legacy shebangs). Use extra-sandbox-paths, and verify with nix config show | grep sandbox-paths.
  • 125bce3b fix: cuda12.8-cuda_cudart-12.8.90 is marked as broken and 78fc64e1 fix(neovim): disable nixvim manpage on broken nixpkgs pin - broken packages after a nixpkgs bump are normal; just build-host finds them before a deploy does.
  • 4bd463a7 chore(eval): resolve catppuccin and rust-overlay deprecation warnings - input bumps surface deprecation warnings that become errors in a later bump.

© ryan4yin, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/nix-config-update of ryan4yin/nix-config.

Open the folder on GitHubat commit 63b7183

Compare with similar skills

Nix Config Update next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Nix Config Update compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Nix Config Update this skillryan4yin/nix-config2.1k—~2.3kAutomated safety check: NotesMIT
Vercel Composition Patternssupabase/supabase111k58 repos~726Automated safety check: PassMIT
Finishing a Development Branchobra/superpowers297k5 repos~1.9kAutomated safety check: PassMIT
Typescript Advanced Typesrolling-scopes/rsschool-app10k25 repos~4.2kAutomated safety check: PassMPL-2.0
PR Babysitteropeninterpreter/openinterpreter69k3 repos~4.2kAutomated safety check: PassApache-2.0
Code Review ChecklistshareAI-lab/learn-claude-code78k5 repos~1.1kAutomated safety check: PassMIT

Similar skills

  • Official

    React composition patterns that scale. An agent skill from supabase/supabase.

    111k GitHub starsUsed in 58 repos~726 tokens
    DevelopmentAuto-check passed
  • Walks the last step of a branch: confirm tests pass, detect the git environment, ask how to integrate, carry out your choice and clean up the worktree.

    297k GitHub starsUsed in 5 repos~1.9k tokens
    DevelopmentAuto-check passed
  • Typescript Advanced Types

    rolling-scopes/rsschool-app

    Master TypeScript's advanced type system including generics, conditional types, mapped types, template literals, and utility types for building type-safe applications.

    10k GitHub starsUsed in 25 repos~4.2k tokens
    DevelopmentAuto-check passed
  • PR Babysitter

    openinterpreter/openinterpreter

    Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.

    69k GitHub starsUsed in 3 repos~4.2k tokens
    DevelopmentAuto-check passed
  • Code Review Checklist

    shareAI-lab/learn-claude-code

    Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.

    78k GitHub starsUsed in 5 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Greploop

    onyx-dot-app/onyx

    Iteratively improves a PR (GitHub), MR (GitLab), or shelved changelist (Perforce) until Greptile gives it a 5/5 confidence score with zero unresolved comments.

    32k GitHub starsUsed in 4 repos~3.3k tokens
    DevelopmentAuto-check passed

More from ryan4yin/nix-config

All 8 skills in this repo
  • Nix Config Umu Game

    ryan4yin/nix-config

    A skill your agent uses when installing a Windows game launcher (二次元 / gacha or any non-Steam game) on a NixOS desktop via umu-launcher, given an installer URL or an .exe, or when such a launcher…

    2.1k GitHub stars~3.5k tokensUpdated today
    Auto-check passed
  • Nix Config Debug

    ryan4yin/nix-config

    A skill your agent uses when something in this repo is broken, such as an eval or build error, a failed activation, a crashed service, or an unreachable host or MicroVM guest.

    2.1k GitHub stars~1.4k tokensUpdated today
    Auto-check passed
  • Nix Config Desktop

    ryan4yin/nix-config

    A skill your agent uses when changing the Niri/Noctalia desktop, the Wayland session, input method (fcitx5), theming, fonts, or desktop autostart in this repo.

    2.1k GitHub stars~2k tokensUpdated today
    Auto-check passed
  • Nix Config Secrets

    ryan4yin/nix-config

    A skill your agent uses when adding, changing, renaming, or removing an agenix secret, wiring one into a host, or fixing a decryption or activation failure in this repo.

    2.1k GitHub stars~2.3k tokensUpdated today
    Auto-check: notes
  • Nixpkgs Patched

    ryan4yin/nix-config

    A skill your agent uses when temporarily carrying an unmerged nixpkgs pull request or commit in the personal ryan4yin/nixpkgs fork, updating the nixos-unstable-patched branch, or consuming that…

    2.1k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Nixpkgs Review

    ryan4yin/nix-config

    A skill your agent uses when reviewing an upstream NixOS/nixpkgs pull request before it is merged, including its package changes, passthru tests, dependencies, or CI results.

    2.1k GitHub stars~2.8k tokensUpdated today
    Auto-check passed

Categories

Questions about Nix Config Update

What does Nix Config Update do?

A skill your agent uses when updating flake inputs, bumping nixpkgs, or rolling an update out to hosts in this repo. Nix Config Update is an agent skill from ryan4yin/nix-config. Use when updating flake inputs, bumping nixpkgs, or rolling an update out to hosts in this repo.

When should I use Nix Config Update?

Nix Config Update fits situations like: updating flake inputs; bumping nixpkgs; rolling an update out to hosts in this repo.

How do I install Nix Config Update in Claude Code?

Run `npx skills add ryan4yin/nix-config --skill nix-config-update -a claude-code`. Or copy the skill folder (.agents/skills/nix-config-update in ryan4yin/nix-config) into .claude/skills/nix-config-update in your project. Claude Code loads it when a task matches its description.

How do I install Nix Config Update in Codex?

Run `npx skills add ryan4yin/nix-config --skill nix-config-update -a codex`. Or copy the skill folder (.agents/skills/nix-config-update in ryan4yin/nix-config) into .agents/skills/nix-config-update in your project. Codex loads it when a task matches its description.

Can I use Nix Config Update in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ryan4yin/nix-config --skill nix-config-update -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/nix-config-update, .gemini/skills/nix-config-update, .github/skills/nix-config-update and .opencode/skills/nix-config-update in your project.

What does Nix Config Update need to run?

Going by SKILL.md and its folder, Nix Config Update needs the command-line tools its instructions call (just, git, nix and ssh).

Does Nix Config Update access the network?

SKILL.md contains no URLs. Its commands use git and ssh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Nix Config Update safe to install?

Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Nix Config Update use?

Nix Config Update is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Nix Config Update use?

About 2.3k tokens (SKILL.md is roughly 9.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Nix Config Update?

Skills that share tags, products or a category with Nix Config Update: Vercel Composition Patterns (supabase/supabase, 111k stars), Finishing a Development Branch (obra/superpowers, 297k stars), Typescript Advanced Types (rolling-scopes/rsschool-app, 10k stars) and PR Babysitter (openinterpreter/openinterpreter, 69k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Nix Config Update?

ryan4yin (a GitHub user) maintains it in ryan4yin/nix-config, which has 2,090 GitHub stars. The repository holds 8 skills in this directory. The repository was last updated on October 9, 2026.

Source: ryan4yin/nix-config on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.