Agent skill

Agentctl Setup

by sd0xdev in sd0xdev/sd0x-harness

Install and set up the optional agentctl mod (task scope, refusal before execution, evidence that goes stale, model-free hand-over) — checks the environment, installs after approval, builds the…

MITAuto-check passedDevelopment

Install Agentctl Setup

skills CLI
$ npx skills add sd0xdev/sd0x-harness --skill agentctl-setup -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install sd0xdev/sd0x-harness agentctl-setup --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/sd0xdev/sd0x-harness.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/agentctl-setup .claude/skills/agentctl-setup && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
agentctl-setup
GitHub stars
192
Token cost
~2.2k tokens
SKILL.md length
1,193 words
Files
3 (incl. scripts, references)
Skills in repo
91
Repo updated
First seen
Licence
MIT

At a glance

Install and set up the optional agentctl mod (task scope, refusal before execution, evidence that goes stale, model-free hand-over) — checks the environment, installs after approval, builds the…

  • Works in 6 steps: Explain and ask → Check → Install (after approval) → …
  • Development work in your project
  • SKILL.md covers Trigger, When NOT to Use, What the mod is — say this… and Modes, plus 4 more sections
  • Runs JavaScript scripts from its folder; calls claude, git and kubectl

What it does

Agentctl Setup is an agent skill from sd0xdev/sd0x-harness. Install and set up the optional agentctl mod (task scope, refusal before execution, evidence that goes stale, model-free hand-over) — checks the environment, installs after approval, builds the first task line, optional deny rules, uninstall

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including scripts and reference files (for example `references/workflow-integration.md` and `scripts/agentctl-setup.js`).

It sits in Development. It works with Git. The repository describes itself as: The harness layer for Claude Code — a reference implementation of harness engineering with hook-enforced dual review, state-machine gates that survive context compaction, and… The licence is MIT.

When your agent uses it

  • Development work in your project

Example prompts

  • “/agentctl-setup”

Requirements

  • Node.js
  • Pre-approved tools (allowed-tools): Read, Write, AskUserQuestion, Bash(node:*), Bash(claude:*)

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Explain and ask
  2. Check
  3. Install (after approval)
  4. First task
  5. Second layer (optional)
  6. Uninstall (--uninstall)

What it can do on your machine

Read from SKILL.md and the folder at commit c9a2036. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • AskUserQuestion
    • Bash(node:*)
    • Bash(claude:*)

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (JavaScript), which the agent can run.

    Shell commands in SKILL.md call:

    • claude
    • git
    • kubectl
    • gh
    • node
    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, kubectl, gh and npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Agentctl Setup loads about 2.2k tokens when it runs, and up to ~3.2k if it reads all its reference files. Until then it costs about 64 tokens; SKILL.md has 1,193 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~64
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from sd0xdev/sd0x-harness at commit c9a2036, republished under its MIT licence (© sd0xdev). 1,193 words, ~2,225 tokens.

Download SKILL.mdSave it as .claude/skills/agentctl-setup/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
agentctl-setup
description
Install and set up the optional agentctl mod (task scope, refusal before execution, evidence that goes stale, model-free hand-over) — checks the environment, installs after approval, builds the first task line, optional deny rules, uninstall
allowed-tools
Read, Write, AskUserQuestion, Bash(node:*), Bash(claude:*)
model
sonnet

agentctl Setup

Trigger

  • Keywords: agentctl, agent control plane, install the mod, set up agentctl, agentctl task, uninstall agentctl

When NOT to Use

  • Reviewing or gating a change (use /codex-review-fast, /precommit) — the mod is a control and a display, never a gate
  • Installing sd0x-dev-flow's own rules, hooks or scripts (use /install-rules, /install-hooks, /install-scripts)

What the mod is — say this first, in the user's language

Hand a task to Claude and leave; when you come back, three questions:

QuestionWhat the mod does
Did it stay in scope?You declare the task once (what may be edited, which test command may run). A call outside it — git push, kubectl rollout, an edit outside the allowed directories — is refused before it runs, with the rule named. Only a line you type changes the scope
Did Claude ask for more than it needs?Claude drafts the scope from the ticket; the mod previews it and binds it only when you type /agentctl accept. Recognized direct git push, gh pr merge and production writes are refused even with no task; anything the mod cannot classify goes to Claude Code's own permission prompt or auto mode
Is "tests pass" true?A test run is recorded with a Git-derived fingerprint of the tree; a later change to a tracked or untracked file reads stale within 30 s, not "passed" (ignored files, submodule contents and the environment are outside it)
Where is it, do I need to step in?A one-line band above the prompt; /agentctl for detail; /agentctl handoff writes a hand-over from records with no model call

It is not a security boundary: production stays protected by credentials. It ships in this repository under mods/agentctl/ and is never installed by installing sd0x-dev-flow — this skill is the opt-in.

Modes

InvocationDoes
/agentctl-setupSteps 1 → 5, in order
/agentctl-setup --taskStep 4b (a proposal) only, then stop
/agentctl-setup --statusStep 2's doctor report only — no install, enable or task question — then stop
/agentctl-setup --uninstallStep 6 only, then stop

Dispatch on the flag before step 1: each flagged mode runs only its row and returns.

SETUP below is node "${CLAUDE_PLUGIN_ROOT}/skills/agentctl-setup/scripts/agentctl-setup.js". Every subcommand prints one JSON document; read ok, problems / errors from it, never guess.

Workflow

1. Explain and ask

Show the table above in a few lines, then one AskUserQuestion: Install · Not now. On Not now, stop.

2. Check

Run SETUP doctor. Report claudeVersion, installed, and every entry of problems in plain words:

FieldMeaningResponse
problems non-emptyMods cannot run hereSay why (old Claude Code, no git, disableAllHooks), how to fix it, and stop
installed.enabled is trueInstalled and onSkip to step 4
installed.enabled is falseInstalled but disabled — /agentctl does not exist until it is enabledSay so; one AskUserQuestion naming claude plugin enable <installed.id>; run it after approval, then step 4. It takes effect in the next session
installed: falseNot installedStep 3
installed: nullclaude plugin list could not be readSay so; step 3 is still safe — installing an installed plugin changes nothing
3. Install (after approval)

One AskUserQuestion naming the exact command, then run it:

bash
claude plugin install agentctl@sd0xdev-marketplace

On failure (for example sd0x-dev-flow was loaded with --plugin-dir and the marketplace was never added), report the error and offer the per-session alternative, which changes no setting: claude --plugin-dir "${CLAUDE_PLUGIN_ROOT}/mods/agentctl". The mod loads in the next Claude Code session; say so.

4. First task

Ask with AskUserQuestion (free text through "Other" where noted):

QuestionBecomes
What is the task? (free text)--goal
Which directories may be edited? src,tests · none (read-only) · other--edit
Which test or check command may run? npm test · none · other--check
Anything else to forbid? none · other--forbid

The answers are free text, so they never go on a command line — a shell would expand $(…), backticks or $VAR inside them before the helper could refuse them. Instead:

  1. SETUP alloc → prints input, a fresh file in a private temporary directory
  2. Write the answers to that path with the Write tool, as one JSON object of strings: {"goal": "…", "edit": "src,tests", "check": "npm test", "forbid": "terraform apply"} (omit a key the user answered "none")
  3. SETUP task-line --input <that path> — it reads the file once and deletes it

On ok: false, show errors and ask again for that answer — task-line runs each command through the mod's own classifier, so a form the mod would refuse (an inline VAR=value, a wildcard, shell operators) is caught here, not after the user has left. On ok: true, show line in a fenced block and say:

Send this line yourself in the session where the mod runs. The mod accepts a task only from a line you type — a command run by Claude is refused, so nothing Claude reads can widen the scope.

Do not send the line yourself, and do not paraphrase it: the user copies it as printed.

Show full SKILL.md (389 more words)Show less
4b. Proposal instead of a typed line (--task, and the workflow skills)

When the mod is installed, Claude drafts the scope and the user only accepts it. Follow references/workflow-integration.md § Drafting a proposal: the same alloc + Write answers file, then SETUP propose --input <path>, which validates with the mod's own rules and writes one private file under ~/.claude/agentctl/proposals/. While a task is bound, the Write to the answers file is refused by agentctl; use the reference's --stdin form. Show preview, then say the mod shows its own preview, with the digest, at the end of this turn and that they type /agentctl accept <first 8 of that digest> (or /agentctl discard); digest is null unless a base was given. Accept binds exactly the previewed scope; a later change to the file needs a new preview.

5. Second layer (optional)

The mod refuses only while it runs. Offer native permissions.deny rules as a second layer: AskUserQuestion, multiSelect, over the rules SETUP deny-rules --settings <path> lists as missing, plus where to write: this project, personal (.claude/settings.local.json) · every project (~/.claude/settings.json) · Skip. After the choice, run SETUP deny-rules --settings <path> --rules "<chosen,comma-separated>" --write and report written. git push is not offered: /push-ci runs it, and a native deny would block that workflow.

6. Uninstall (--uninstall)

AskUserQuestion naming claude plugin uninstall agentctl@sd0xdev-marketplace; run it after approval. Then say the mod's own data stays in ~/.claude/plugins/store/agentctl_*.json, and drafted proposals in ~/.claude/agentctl/proposals/, until deleted, and that deny rules added in step 5 stay in the settings file they were written to.

Prohibited

  • Putting any free-text answer on a command line — answers go through alloc + Write + --input

  • Installing, uninstalling or writing settings without that step's AskUserQuestion approval

  • Sending /agentctl task set or /agentctl accept on the user's behalf, or editing the printed line

  • Describing the mod as a security boundary, a gate, or an approval

  • Offering Bash(git push:*) as a deny rule

Verification

  • The flag chose the steps: a flagged mode ran only its own row
  • Default mode: the user saw what the mod does before any install question
  • doctor ran (default and --status), and every problems entry was reported
  • Install, deny-rule writes and uninstall each had their own approval
  • The task line came from task-line --input (or the proposal from propose --input) with ok: true, and the user was told to send or accept it themselves

Examples

Input: /agentctl-setup
Action: explain → doctor (ok, not installed) → approve → claude plugin install → four questions →
        task-line → "send this line yourself" → deny rules for this project → written
Input: /agentctl-setup --task
Action: draft from the ticket → propose → preview shown → "type /agentctl accept <digest>" yourself

© sd0xdev, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (scripts, references) in skills/agentctl-setup of sd0xdev/sd0x-harness.

  • SKILL.md
  • references/workflow-integration.md
  • scripts/agentctl-setup.js

Open the folder on GitHubat commit c9a2036

Compare with similar skills

Agentctl Setup next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Agentctl Setup compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Agentctl Setup this skillsd0xdev/sd0x-harness192—~2.2kAutomated safety check: PassMIT
Finishing a Development Branchobra/superpowers296k5 repos~1.9kAutomated safety check: PassMIT
Code Review ChecklistshareAI-lab/learn-claude-code78k5 repos~1.1kAutomated safety check: PassMIT
Codebase Knowledge Graph Q&AEgonex-AI/Understand-Anything85k1 repos~1.2kAutomated safety check: PassMIT
Code Design Rationale Investigatorcursor/plugins10k9 repos~2.6kAutomated safety check: PassNone
Understand Diff AnalysisEgonex-AI/Understand-Anything85k1 repos~1.4kAutomated safety check: PassMIT

Similar skills

  • Walks the last step of a branch: confirm tests pass, detect the git environment, ask how to integrate, carry out your choice and clean up the worktree.

    296k GitHub starsUsed in 5 repos~1.9k tokens
    DevelopmentAuto-check passed
  • Code Review Checklist

    shareAI-lab/learn-claude-code

    Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.

    78k GitHub starsUsed in 5 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Codebase Knowledge Graph Q&A

    Egonex-AI/Understand-Anything

    Answers questions about a codebase by searching a prebuilt knowledge graph of its files, functions, classes and dependencies, not by rereading every source file.

    85k GitHub starsUsed in 1 repo~1.2k tokens
    DevelopmentAuto-check passed
  • Official

    Digs into why code is shaped the way it is by checking git history, pull requests and connected tools in parallel, then reporting a cited read on the tradeoffs.

    10k GitHub starsUsed in 9 repos~2.6k tokens
    DevelopmentAuto-check passed
  • Understand Diff Analysis

    Egonex-AI/Understand-Anything

    Reads your git changes or a pull request against a prebuilt knowledge graph of the project to explain what changed, which components are affected and what is risky.

    85k GitHub starsUsed in 1 repo~1.4k tokens
    DevelopmentAuto-check passed
  • Understand Explain

    Egonex-AI/Understand-Anything

    Gives an in-depth explanation of one file, function or module by reading the project's knowledge graph and checking that the graph is still fresh.

    85k GitHub starsUsed in 1 repo~1.3k tokens
    DevelopmentAuto-check passed

More from sd0xdev/sd0x-harness

All 91 skills in this repo
  • Adr

    sd0xdev/sd0x-harness

    Write an Architecture Decision Record (ADR) for a feature — Context / Decision / Status / Consequences / Alternatives, filed as docs/features/<feature/adr-<NNN-<title.md with a 3-digit zero-padded…

    192 GitHub stars~4.8k tokensUpdated yesterday
    Auto-check passed
  • Load PR Review

    sd0xdev/sd0x-harness

    Load GitHub PR review comments into AI session — analyze, triage, plan.

    192 GitHub stars~4.4k tokensUpdated yesterday
    Auto-check passed
  • Next Step

    sd0xdev/sd0x-harness

    Change-aware next step advisor. An agent skill from sd0xdev/sd0x-harness.

    192 GitHub stars~1.6k tokensUpdated yesterday
    Auto-check passed
  • Obsidian CLI

    sd0xdev/sd0x-harness

    Obsidian vault integration via official CLI. An agent skill from sd0xdev/sd0x-harness.

    192 GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Orchestrate

    sd0xdev/sd0x-harness

    Agent-driven workflow orchestration (v1 report-only). An agent skill from sd0xdev/sd0x-harness.

    192 GitHub stars~2.5k tokensUpdated yesterday
    Auto-check passed
  • PR Comment

    sd0xdev/sd0x-harness

    Post friendly review comments to a GitHub PR — prepare locally, preview, then submit as atomic review.

    192 GitHub stars~1.5k tokensUpdated yesterday
    Auto-check passed

Works with

Categories

Questions about Agentctl Setup

What does Agentctl Setup do?

Install and set up the optional agentctl mod (task scope, refusal before execution, evidence that goes stale, model-free hand-over) — checks the environment, installs after approval, builds the…. Agentctl Setup is an agent skill from sd0xdev/sd0x-harness.

When should I use Agentctl Setup?

Agentctl Setup fits situations like: development work in your project.

How do I install Agentctl Setup in Claude Code?

Run `npx skills add sd0xdev/sd0x-harness --skill agentctl-setup -a claude-code`. Or copy the skill folder (skills/agentctl-setup in sd0xdev/sd0x-harness) into .claude/skills/agentctl-setup in your project. Claude Code loads it when a task matches its description.

How do I install Agentctl Setup in Codex?

Run `npx skills add sd0xdev/sd0x-harness --skill agentctl-setup -a codex`. Or copy the skill folder (skills/agentctl-setup in sd0xdev/sd0x-harness) into .agents/skills/agentctl-setup in your project. Codex loads it when a task matches its description.

Can I use Agentctl Setup in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sd0xdev/sd0x-harness --skill agentctl-setup -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/agentctl-setup, .gemini/skills/agentctl-setup, .github/skills/agentctl-setup and .opencode/skills/agentctl-setup in your project.

What does Agentctl Setup need to run?

Going by SKILL.md and its folder, Agentctl Setup needs JavaScript for the scripts in its folder and the command-line tools its instructions call (claude, git, kubectl, gh, node and npm). Our summary lists: Node.js. Its frontmatter pre-approves these tools: Read, Write, AskUserQuestion, Bash(node:*), Bash(claude:*).

Does Agentctl Setup access the network?

SKILL.md contains no URLs. Its commands use git, gh and npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Agentctl Setup safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Agentctl Setup use?

Agentctl Setup is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Agentctl Setup use?

About 2.2k tokens (SKILL.md is roughly 8.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1k tokens, read only when the agent opens those files.

What are the alternatives to Agentctl Setup?

Skills that share tags, products or a category with Agentctl Setup: Finishing a Development Branch (obra/superpowers, 296k stars), Code Review Checklist (shareAI-lab/learn-claude-code, 78k stars), Codebase Knowledge Graph Q&A (Egonex-AI/Understand-Anything, 85k stars) and Code Design Rationale Investigator (cursor/plugins, 10k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Agentctl Setup?

sd0xdev (a GitHub user) maintains it in sd0xdev/sd0x-harness, which has 192 GitHub stars. The repository holds 91 skills in this directory. The repository was last updated on October 6, 2026.

Source: sd0xdev/sd0x-harness on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.