Agent skill

Deep Links

by stacklok in stacklok/toolhive-studio

Deep links in ToolHive Studio. An agent skill from stacklok/toolhive-studio.

Apache-2.0Auto-check: notesMobile

Install Deep Links

skills CLI
$ npx skills add stacklok/toolhive-studio --skill deep-links -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install stacklok/toolhive-studio deep-links --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/stacklok/toolhive-studio.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.codex/skills/deep-links .claude/skills/deep-links && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
deep-links
GitHub stars
170
Token cost
~1.6k tokens
SKILL.md length
546 words
Files
4 (incl. references)
Skills in repo
9
Repo updated
First seen
Licence
Apache-2.0

At a glance

Deep links in ToolHive Studio. An agent skill from stacklok/toolhive-studio.

  • Works in 6 steps: Protocol registration: On app start,… → URL extraction: On Windows/Linux, the… → Parse + validate: parseDeepLinkUrl()… → …
  • Asking about deep link features (toolhive-gui:// protocol)
  • SKILL.md covers URL Schema, Current Implementation, How to Add a New Deep Link and Reference Documents
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Deep Links is an agent skill from stacklok/toolhive-studio. Deep links in ToolHive Studio. Use when implementing, debugging, or asking about deep link features (toolhive-gui:// protocol), adding new deep link intents, understanding the deep link architecture, IPC model, or platform/packaging support.

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/design.md`, `references/os-and-packaging.md` and `references/patterns.md`).

It sits in Mobile, covering MCP servers. It works with Model Context Protocol. The repository describes itself as: ToolHive is an application that allows you to install, manage and run MCP servers and connect them to AI agents. The licence is Apache-2.0.

When your agent uses it

  • Asking about deep link features (toolhive-gui:// protocol)
  • Adding new deep link intents
  • Understanding the deep link architecture
  • Platform/packaging support

Example prompts

  • “/deep-links”

Requirements

  • Pre-approved tools (allowed-tools): Read, Grep, Glob, Bash

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Protocol registration: On app start, app.setAsDefaultProtocolClient('toolhive-gui') registers the protocol. On Windows with Squirrel…
  2. URL extraction: On Windows/Linux, the URL arrives in process.argv. extractDeepLinkFromArgs() scans for the first toolhive-gui:// argument…
  3. Parse + validate: parseDeepLinkUrl() parses the URL and runs it through the Zod discriminated union schema defined in…
  4. Window ready: waitForMainWindowReady() polls until the window is visible and not loading before dispatching.
  5. Dispatch: resolveDeepLinkTarget() converts the validated intent to a NavigateTarget, which is sent to the renderer via the…
  6. Renderer: The renderer listens for deep-link-navigation and calls navigate(target).

What it can do on your machine

Read from SKILL.md and the folder at commit 87f7a55. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Grep
    • Glob
    • Bash

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are typescript and bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Deep Links loads about 1.6k tokens when it runs, and up to ~8.8k if it reads all its reference files. Until then it costs about 63 tokens; SKILL.md has 546 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~63
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~8.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Grep, Glob, Bash

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from stacklok/toolhive-studio at commit 87f7a55, republished under its Apache-2.0 licence (© stacklok). 546 words, ~1,613 tokens.

Download SKILL.mdSave it as .claude/skills/deep-links/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
deep-links
description
Deep links in ToolHive Studio. Use when implementing, debugging, or asking about deep link features (toolhive-gui:// protocol), adding new deep link intents, understanding the deep link architecture, IPC model, or platform/packaging support.
allowed-tools
Read, Grep, Glob, Bash

Deep links allow external systems (browsers, terminals, other apps) to trigger navigation inside ToolHive Desktop via the toolhive-gui:// custom protocol.

About this document: Much of the content in the reference docs is the result of research into how other Electron apps implement deep links. Some design decisions are implemented; others describe the intended direction but are not yet in the codebase. The base skill reflects the current implementation. The reference docs reflect the research and design intent — read them with that in mind, and update them when relevant implementation decisions change.


URL Schema

toolhive-gui://v1/<intent>[?<query>]

Examples:

  • toolhive-gui://v1/open-registry-server-detail?serverName=fetch — open a registry server detail page
  • toolhive-gui://v1/open-registry-server-install?serverName=fetch — open the registry server detail page and auto-open the install dialog
  • toolhive-gui://v1/open-registry-skill-detail?namespace=io.github.stacklok&skillName=skill-creator — open a registry skill detail page
  • toolhive-gui://v1/open-registry-skill-install?namespace=io.github.stacklok&skillName=skill-creator&version=v1.0.0 — open the skill detail page and auto-open the install dialog with the reference (and optional ?version tag) prefilled. Tag-only — OCI digests (sha256:…) are intentionally not supported because safeIdentifier rejects colons; users wanting digest pinning can paste it into the dialog directly.

The v1 segment is the version. The intent is a kebab-case action name. Query params carry intent-specific data.


Current Implementation

Key Files
FileRole
common/deep-links.tsSingle source of truth. All deep link definitions: intent name, Zod param schema, navigation target.
main/src/deep-links/parse.tsParses and validates a raw URL string using the schemas from common/deep-links.ts.
main/src/deep-links/index.tsEntry point: extracts URL from argv (Windows/Linux), waits for window ready, dispatches via IPC.
main/src/deep-links/squirrel.tsSquirrel.Windows-specific protocol registration.
IPC Channel

deep-link-navigation — sent main → renderer as a NavigateTarget ({ to: string; params?: Record<string, string> }).

The renderer receives this and calls the TanStack Router navigate() directly.

How It Works (Current)
  1. Protocol registration: On app start, app.setAsDefaultProtocolClient('toolhive-gui') registers the protocol. On Windows with Squirrel, registerProtocolWithSquirrel() is called instead (see squirrel.ts).
  2. URL extraction: On Windows/Linux, the URL arrives in process.argv. extractDeepLinkFromArgs() scans for the first toolhive-gui:// argument (safe against argv injection — see patterns doc).
  3. Parse + validate: parseDeepLinkUrl() parses the URL and runs it through the Zod discriminated union schema defined in common/deep-links.ts. Invalid links resolve to showNotFound.
  4. Window ready: waitForMainWindowReady() polls until the window is visible and not loading before dispatching.
  5. Dispatch: resolveDeepLinkTarget() converts the validated intent to a NavigateTarget, which is sent to the renderer via the deep-link-navigation IPC channel.
  6. Renderer: The renderer listens for deep-link-navigation and calls navigate(target).
Show full SKILL.md (164 more words)Show less
Current Limitations vs. Design Intent

The current implementation only supports read (navigate) operations. The design doc proposes a confirmation flow for write/destructive operations (C/U/D), but this is not yet implemented. The IPC sends a pre-resolved NavigateTarget rather than a raw parsed intent — this simplified the initial implementation. See design doc for the full intended model.


All changes happen in common/deep-links.ts:

ts
// 1. Define the new intent using v1DeepLink()
export const myNewIntent = v1DeepLink({
  intent: 'my-new-intent', // kebab-case, matches URL path segment
  params: z.object({
    someParam: safeIdentifier, // use safeIdentifier for user-supplied strings
  }),
  navigate: (params) => ({
    to: '/some-route/$id', // TanStack Router route
    params: { id: params.someParam },
  }),
})

// 2. Add to allDeepLinks array
const allDeepLinks = [
  openRegistryServerDetail,
  showNotFound,
  myNewIntent,
] as const

// 3. Add to deepLinkSchema discriminated union
export const deepLinkSchema = z.discriminatedUnion('intent', [
  openRegistryServerDetail.schema,
  showNotFound.schema,
  myNewIntent.schema, // ← add here
])

Test manually:

bash
./node_modules/.bin/electron . "toolhive-gui://v1/my-new-intent?someParam=value"

safeIdentifier is defined as z.string().regex(/^[a-zA-Z0-9_.-]+$/) — use it for any param that could be user-supplied to prevent injection.


Reference Documents

For deeper background, see:

  • OS & Packaging Support — Platform-specific registration requirements (Windows, Linux, macOS) and packaging format considerations (Squirrel, Flatpak, .deb, .rpm, .dmg, AppImage, MSIX, etc.). Largely research/prior art.
  • Observed Patterns — Patterns from VS Code, GitHub Desktop, Mattermost, Element, and others: URL sanitization, argv injection, security confirmations, waiting-for-readiness patterns, telemetry.
  • Design & Decisions — Full design rationale, IPC model, error handling strategy, queue management, testing approach, and the decisions log. Some sections describe planned future behaviour not yet implemented.

© stacklok, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (references) in .codex/skills/deep-links of stacklok/toolhive-studio.

  • SKILL.md
  • references/design.md
  • references/os-and-packaging.md
  • references/patterns.md

Open the folder on GitHubat commit 87f7a55

Compare with similar skills

Deep Links next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Deep Links compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Deep Links this skillstacklok/toolhive-studio170—~1.6kAutomated safety check: NotesApache-2.0
Appllama UsageAppllama/appllama-skills2.4k1 repos~1.6kAutomated safety check: PassMIT
Scrcpy GotchasJuanCF/scrcpy-mcp112—~5.8kAutomated safety check: PassMIT
MCP SDK Tier Auditmodelcontextprotocol/conformance129—~4.4kAutomated safety check: PassCustom licence
iOS Simulator Workflowsconorluddy/xclaude-plugin183—~3.3kAutomated safety check: PassMIT
Healthmd CLI QACodyBontecou/health-md230—~4kAutomated safety check: PassAGPL-3.0

Similar skills

  • Appllama Usage

    Appllama/appllama-skills

    Use the Appllama MCP (mcp.appllama.io) well — research real top-grossing mobile apps, their screens, flows, and UI elements, then build from what you learn.

    2.4k GitHub starsUsed in 1 repo~1.6k tokens
    MobileAuto-check passed
  • Scrcpy Gotchas

    JuanCF/scrcpy-mcp

    A skill your agent uses when interacting with Android devices via scrcpy-mcp tools (tap, swipe, inputtext, keyevent, uidump, uifindelement, appstart, etc.).

    112 GitHub stars~5.8k tokensUpdated 14 days ago
    MobileAuto-check passed
  • MCP SDK Tier Audit

    modelcontextprotocol/conformance

    Official

    Comprehensive tier assessment for an MCP SDK repository against SEP-1730.

    129 GitHub stars~4.4k tokensUpdated 2 days ago
    MobileAuto-check passed
  • iOS Simulator Workflows

    conorluddy/xclaude-plugin

    Manages iOS Simulator devices and apps through the execute_simulator_command MCP tool instead of raw simctl: boot, create and delete devices, install and launch apps, screenshots and diagnostics.

    183 GitHub stars~3.3k tokensUpdated 25 days ago
    MobileAuto-check passed
  • Healthmd CLI QA

    CodyBontecou/health-md

    Test the standalone Health.md CLI, portable healthmd-mcp server, and direct mobile paths.

    230 GitHub stars~4k tokensUpdated today
    MobileAuto-check passed
  • Xcode Build Workflows

    conorluddy/xclaude-plugin

    Directs iOS build, test and clean operations through the execute_xcode_command MCP tool instead of raw xcodebuild in the shell, with parameter-level retries on failure.

    183 GitHub stars~3k tokensUpdated 25 days ago
    MobileAuto-check passed

More from stacklok/toolhive-studio

All 9 skills in this repo
  • Bug Fix TDD

    stacklok/toolhive-studio

    Reproduce and fix bugs using TDD. An agent skill from stacklok/toolhive-studio.

    170 GitHub stars~1.7k tokensUpdated today
    Auto-check: notes
  • Devcontainer Dev

    stacklok/toolhive-studio

    Spin up and interact with ToolHive Studio's containerized dev environment (Xvfb + noVNC + DinD).

    170 GitHub stars~3.8k tokensUpdated today
    Auto-check: notes
  • Security Vuln Remediation

    stacklok/toolhive-studio

    Remediate security vulnerabilities found by Grype or pnpm audit.

    170 GitHub stars~2.3k tokensUpdated today
    Auto-check: notes
  • Skill Creator

    stacklok/toolhive-studio

    Create new AI agent skills for Claude Code, Codex, and Cursor.

    170 GitHub stars~677 tokensUpdated today
    Auto-check passed
  • Testing API Assertions

    stacklok/toolhive-studio

    Verify API requests in tests. An agent skill from stacklok/toolhive-studio.

    170 GitHub stars~993 tokensUpdated today
    Auto-check passed
  • Testing API Overrides

    stacklok/toolhive-studio

    Test that components send correct query parameters or request arguments.

    170 GitHub stars~1.6k tokensUpdated today
    Auto-check passed

Categories

Questions about Deep Links

What does Deep Links do?

Deep links in ToolHive Studio. An agent skill from stacklok/toolhive-studio. Deep Links is an agent skill from stacklok/toolhive-studio. Deep links in ToolHive Studio.

When should I use Deep Links?

Deep Links fits situations like: asking about deep link features (toolhive-gui:// protocol); adding new deep link intents; understanding the deep link architecture; platform/packaging support.

How do I install Deep Links in Claude Code?

Run `npx skills add stacklok/toolhive-studio --skill deep-links -a claude-code`. Or copy the skill folder (.codex/skills/deep-links in stacklok/toolhive-studio) into .claude/skills/deep-links in your project. Claude Code loads it when a task matches its description.

How do I install Deep Links in Codex?

Run `npx skills add stacklok/toolhive-studio --skill deep-links -a codex`. Or copy the skill folder (.codex/skills/deep-links in stacklok/toolhive-studio) into .agents/skills/deep-links in your project. Codex loads it when a task matches its description.

Can I use Deep Links in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add stacklok/toolhive-studio --skill deep-links -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/deep-links, .gemini/skills/deep-links, .github/skills/deep-links and .opencode/skills/deep-links in your project.

What does Deep Links need to run?

SKILL.md names no scripts, command-line tools or credentials: Deep Links is instructions for the agent only. Its frontmatter pre-approves these tools: Read, Grep, Glob, Bash.

Does Deep Links access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Deep Links safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Deep Links use?

Deep Links is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Deep Links use?

About 1.6k tokens (SKILL.md is roughly 6.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 7.1k tokens, read only when the agent opens those files.

What are the alternatives to Deep Links?

Skills that share tags, products or a category with Deep Links: Appllama Usage (Appllama/appllama-skills, 2.4k stars), Scrcpy Gotchas (JuanCF/scrcpy-mcp, 112 stars), MCP SDK Tier Audit (modelcontextprotocol/conformance, 129 stars) and iOS Simulator Workflows (conorluddy/xclaude-plugin, 183 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Deep Links?

stacklok (a GitHub organization) maintains it in stacklok/toolhive-studio, which has 170 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on October 7, 2026.

Source: stacklok/toolhive-studio on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.