gstack Upgrade
garrytan/gstack
Upgrades an installed gstack to the latest version, handling global and vendored installs, optional auto-upgrade and snooze, and showing what is new.
Add or upgrade a curated, immutable managed CLI for Sim Function sandboxes, including client-safe catalog metadata, a pinned server-only installation recipe, checksum and executable verification…
$ npx skills add simstudioai/sim --skill add-managed-cli -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install simstudioai/sim add-managed-cli --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/simstudioai/sim.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/add-managed-cli .claude/skills/add-managed-cli && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "add-managed-cli" agent skill from https://github.com/simstudioai/sim/tree/main/.agents/skills/add-managed-cli into .claude/skills/add-managed-cli/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "add-managed-cli", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/simstudioai/sim/tree/main/.agents/skills/add-managed-cliType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add simstudioai/sim --skill add-managed-cli -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install simstudioai/sim add-managed-cli --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/simstudioai/sim.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/add-managed-cli .agents/skills/add-managed-cli && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "add-managed-cli" agent skill from https://github.com/simstudioai/sim/tree/main/.agents/skills/add-managed-cli into .agents/skills/add-managed-cli/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "add-managed-cli", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add simstudioai/sim --skill add-managed-cli -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install simstudioai/sim add-managed-cli --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/simstudioai/sim.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/add-managed-cli .cursor/skills/add-managed-cli && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "add-managed-cli" agent skill from https://github.com/simstudioai/sim/tree/main/.agents/skills/add-managed-cli into .cursor/skills/add-managed-cli/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "add-managed-cli", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/simstudioai/sim.git --path .agents/skills/add-managed-cli--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add simstudioai/sim --skill add-managed-cli -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install simstudioai/sim add-managed-cli --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/simstudioai/sim.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/add-managed-cli .gemini/skills/add-managed-cli && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "add-managed-cli" agent skill from https://github.com/simstudioai/sim/tree/main/.agents/skills/add-managed-cli into .gemini/skills/add-managed-cli/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "add-managed-cli", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install simstudioai/sim add-managed-cliInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add simstudioai/sim --skill add-managed-cli -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/simstudioai/sim.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/add-managed-cli .github/skills/add-managed-cli && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "add-managed-cli" agent skill from https://github.com/simstudioai/sim/tree/main/.agents/skills/add-managed-cli into .github/skills/add-managed-cli/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "add-managed-cli", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add simstudioai/sim --skill add-managed-cli -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install simstudioai/sim add-managed-cli --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/simstudioai/sim.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/add-managed-cli .opencode/skills/add-managed-cli && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "add-managed-cli" agent skill from https://github.com/simstudioai/sim/tree/main/.agents/skills/add-managed-cli into .opencode/skills/add-managed-cli/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "add-managed-cli", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
add-managed-cliAdd or upgrade a curated, immutable managed CLI for Sim Function sandboxes, including client-safe catalog metadata, a pinned server-only installation recipe, checksum and executable verification…
Add Managed CLI is an agent skill from simstudioai/sim. Add or upgrade a curated, immutable managed CLI for Sim Function sandboxes, including client-safe catalog metadata, a pinned server-only installation recipe, checksum and executable verification, provider compatibility, PATH propagation, content-addressed image identity, and tests. Use when adding a CLI to the Sandbox managed-CLI selector or changing an existing managed CLI version or recipe.
Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).
The repository describes itself as: Sim is the collaborative workspace to build, deploy, and monitor AI agents and workflows. Used by 100,000+ builders. The licence is Apache-2.0.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 546d4e7. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
bunbunxgitnpmpipFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use bunx, git, npm and pip, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Add Managed CLI loads about 2.4k tokens when it runs. Until then it costs about 103 tokens; SKILL.md has 1,148 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from simstudioai/sim at commit 546d4e7, republished under its Apache-2.0 licence (© simstudioai). 1,148 words, ~2,428 tokens.
.claude/skills/add-managed-cli/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Add CLIs through the curated registry. Never turn this surface into arbitrary commands or package names: system packages already cover validated Debian/APT coordinates, while managed CLIs require immutable artifacts and reproducible recipes.
Read these live sources before editing; do not copy their current entries into this skill:
apps/sim/lib/execution/remote-sandbox/cli-tools.ts — persisted IDs and client-safe metadata.apps/sim/lib/execution/remote-sandbox/cli-tools.server.ts — server-only recipes and recipe helpers.apps/sim/lib/execution/remote-sandbox/cli-tools.test.ts — catalog and supply-chain invariants.apps/sim/lib/execution/remote-sandbox/cli-tools-boundary.test.ts — client/server import boundary.apps/sim/lib/execution/remote-sandbox/sandbox-spec.ts — content-addressed hash inputs.Read resolve.ts and e2b.ts only when changing provisioning mechanics. A normal catalog addition should not require UI, API, database, resolver, or provider edits; those paths derive from the registries.
Do not modify the dedicated Function base image or the separate Mothership Shell template for a normal managed CLI addition. Managed recipes layer on the Function base image. Do not change MAX_SANDBOX_CLI_TOOLS from ten unless the user separately requests a product-limit change.
Use primary upstream release documentation and official artifacts. Establish all of the following before writing code:
latest, mutable redirects, or an unversioned installer./opt/sim-cli.When the user does not name a version, select the current stable upstream release from primary sources and state the exact version chosen. Do not silently choose a prerelease or infer a version from an unverified secondary source.
Reject curl-to-shell installers, npm install, pip install, distro package repositories, arbitrary user commands, and artifacts from unofficial mirrors. Never place credentials, tokens, login commands, or account configuration in an image recipe or build log; authentication is runtime-only.
Use <tool>@<upstream-version>-r<recipe-revision>.
-r1.-r2, -r3, and so on.SandboxCliToolMetadata has no retirement field yet, so the first upgrade adds one generically (type, selector, and contract validation) per the next paragraph.Before shipping the first upgrade for a tool family, verify that editing a sandbox cannot leave both the retired and replacement IDs selected. If the generic selector and API validation do not already replace or reject colliding versions, address that once at the generic registry boundary with focused UI and contract tests; never special-case the individual CLI or silently install two versions that expose the same executable.
Recipe identity includes the ID, revision, and SHA-256 in the sandbox image hash. Keeping old entries is what makes that identity reproducible rather than merely cache-busting.
In cli-tools.ts:
SANDBOX_CLI_TOOL_IDS in the same order used by the metadata and recipe registries.SANDBOX_CLI_TOOLS entry whose key and id exactly match.label, concise description, existing category, and useful executable/vendor aliases in searchTerms.Keep this file safe for client bundles. It must not contain artifact URLs, checksums, install commands, verification commands, PATH recipes, provider SDKs, or imports from cli-tools.server.ts.
The API enum and searchable grouped selector derive from this registry. Do not add parallel option arrays or route-local wire types.
In cli-tools.server.ts, use the narrowest existing helper:
defineBinaryRecipe for one downloaded binary.defineTarGzipRecipe or defineZipRecipe for archives containing binaries.defineVerifiedRecipe for a vendor archive or installer layout that needs explicit commands.Provide every field the recipe contract requires:
version, artifactUrl, artifactName, and lowercase 64-character sha256.executable and a corresponding verificationCommands entry./opt/sim-cli; quote fixed paths and clean temporary artifacts.pathEntries when the executable is not installed into the helper's default bin directory.supportedProviders only when it differs from the E2B-and-Daytona default.revision when it differs from 1; it must agree with the ID suffix.Verification must prove the command is discoverable through sandboxCliEnvironment, not authenticate or contact a user account. Recipe commands run as root during both prebuilt image creation and runtime provisioning.
If the artifact host is new, add only the exact official hostname to the officialHosts allowlist in cli-tools.test.ts. Treat that as a supply-chain review, not a way to silence the test.
Confirm the existing generic paths remain sufficient:
sandboxCliToolRecipes canonicalizes and resolves the recipe.sandboxCliEnvironment propagates PATH to Python subprocesses, JavaScript subprocesses, and Shell.hashSandboxSpec includes recipe ID, revision, and checksum while preserving the legacy hash for an empty CLI list.Do not special-case a CLI in those layers unless the registry contract cannot express a genuine provider requirement. Extend the registry contract generically when multiple CLIs need the same new behavior.
Extend tests only when the new entry introduces behavior not already covered and the test passes the test-audit authoring gate:
Never commit downloaded artifacts or credentials.
bun run --cwd apps/sim test \
lib/execution/remote-sandbox/cli-tools.test.ts \
lib/execution/remote-sandbox/cli-tools-boundary.test.ts \
lib/execution/remote-sandbox/sandbox-spec.test.ts \
lib/execution/remote-sandbox/resolve.test.ts \
'app/workspace/[workspaceId]/settings/components/sandboxes/utils.test.ts'From the repository root:
bun run type-check
bun run check:api-validation:strict
bunx biome check \
apps/sim/lib/execution/remote-sandbox/cli-tools.ts \
apps/sim/lib/execution/remote-sandbox/cli-tools.server.ts \
apps/sim/lib/execution/remote-sandbox/cli-tools.test.ts
git diff --checkFor a new recipe, also exercise its install and every verification command in an actual E2B or Daytona sandbox when credentials and network access are available. Report clearly when only registry/unit validation ran.
© simstudioai, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in .agents/skills/add-managed-cli of simstudioai/sim.
Open the folder on GitHubat commit 546d4e7
Add Managed CLI next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Add Managed CLI this skillsimstudioai/sim | 30k | — | ~2.4k | Automated safety check: Pass | Apache-2.0 | |
| gstack Upgradegarrytan/gstack | 136k | — | ~5.5k | Automated safety check: Notes | MIT | |
| Secrets Managementdavila7/claude-code-templates | 32k | 11 repos | ~2k | Automated safety check: Pass | MIT | |
| Project ManagerRightNow-AI/openfang | 18k | — | ~960 | Automated safety check: Pass | Apache-2.0 | |
| Content Management Systemsgithub/awesome-copilot | 40k | 1 repos | ~1.3k | Automated safety check: Pass | MIT | |
| Secrets Vault Manageralirezarezvani/claude-skills | 28k | 1 repos | ~3.6k | Automated safety check: Notes | MIT |
garrytan/gstack
Upgrades an installed gstack to the latest version, handling global and vendored installs, optional auto-upgrade and snooze, and showing what is new.
davila7/claude-code-templates
Secure secrets management practices for CI/CD pipelines using Vault, AWS Secrets Manager, and other tools.
RightNow-AI/openfang
Project management expert for Agile, estimation, risk management, and stakeholder communication
github/awesome-copilot
Workflow for building and modifying content management systems across WordPress, Shopify, Wix, Squarespace, Drupal, WooCommerce, Joomla, HubSpot CMS Hub, Webflow, Adobe Experience Manager, and…
alirezarezvani/claude-skills
A skill your agent uses when the user asks to set up secret management infrastructure, integrate HashiCorp Vault, configure cloud secret stores (AWS Secrets Manager, Azure Key Vault, GCP Secret…
sickn33/agentic-awesome-skills
CRITICAL: Use for Robius state management patterns. An agent skill from sickn33/agentic-awesome-skills.
simstudioai/sim
Install, upgrade, and operate the Sim Helm chart on Kubernetes.
simstudioai/sim
Add a new table column type to Sim — registry entry, icon, storage shape, coercion, and the behavioral hooks the grid and API read.
simstudioai/sim
Add a code-defined table enrichment (registry entry) under apps/sim/enrichments/ backed by an ordered provider cascade, ensuring every provider tool it calls has hosted-key support.
simstudioai/sim
Add hosted API key support to a tool so Sim provides the key (metered and billed to the workspace) when a user has not brought their own.
simstudioai/sim
Add or update a Sim dynamic selector using the shared manifest, server attachment, and selectors.execute path.
simstudioai/sim
Drive a PR to a clean review (Greptile 5/5, zero open threads) — ships if needed, keeps it mergeable against staging, re-triggers both Greptile and cubic, fixes real findings, replies to and…
Add or upgrade a curated, immutable managed CLI for Sim Function sandboxes, including client-safe catalog metadata, a pinned server-only installation recipe, checksum and executable verification…. Add Managed CLI is an agent skill from simstudioai/sim. Add or upgrade a curated, immutable managed CLI for Sim Function sandboxes, including client-safe catalog metadata, a pinned server-only installation recipe, checksum and executable verification, provider compatibility, PATH propagation, content-addressed image identity, and tests.
Add Managed CLI fits situations like: adding a CLI to the Sandbox managed-CLI selector; changing an existing managed CLI version.
Run `npx skills add simstudioai/sim --skill add-managed-cli -a claude-code`. Or copy the skill folder (.agents/skills/add-managed-cli in simstudioai/sim) into .claude/skills/add-managed-cli in your project. Claude Code loads it when a task matches its description.
Run `npx skills add simstudioai/sim --skill add-managed-cli -a codex`. Or copy the skill folder (.agents/skills/add-managed-cli in simstudioai/sim) into .agents/skills/add-managed-cli in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add simstudioai/sim --skill add-managed-cli -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/add-managed-cli, .gemini/skills/add-managed-cli, .github/skills/add-managed-cli and .opencode/skills/add-managed-cli in your project.
Going by SKILL.md and its folder, Add Managed CLI needs the command-line tools its instructions call (bun, bunx, git, npm and pip). Our summary lists: Python 3; Node.js.
SKILL.md contains no URLs. Its commands use git, npm and pip, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Add Managed CLI is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.4k tokens (SKILL.md is roughly 9.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Add Managed CLI: gstack Upgrade (garrytan/gstack, 136k stars), Secrets Management (davila7/claude-code-templates, 32k stars), Project Manager (RightNow-AI/openfang, 18k stars) and Content Management Systems (github/awesome-copilot, 40k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
simstudioai (a GitHub organization) maintains it in simstudioai/sim, which has 29,785 GitHub stars. The repository holds 40 skills in this directory. The repository was last updated on October 7, 2026.
Source: simstudioai/sim on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.