Agent skill

Reserved Handle Policy

by swyxio in swyxio/skills

Design, implement, audit, or refresh protected username and handle namespaces for public products.

MITAuto-check passed

Install Reserved Handle Policy

skills CLI
$ npx skills add swyxio/skills --skill reserved-handle-policy -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install swyxio/skills reserved-handle-policy --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/swyxio/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/reserved-handle-policy .claude/skills/reserved-handle-policy && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
reserved-handle-policy
GitHub stars
176
Token cost
~1.1k tokens
SKILL.md length
528 words
Files
10 (incl. scripts, references)
Skills in repo
89
Repo updated
First seen
Licence
MIT

At a glance

Design, implement, audit, or refresh protected username and handle namespaces for public products.

  • Works in 2 steps: hard_reserved: platform routes,… → manual_claim_required: scarce or…
  • A product has open signup
  • SKILL.md covers Start with the policy model, Implementation workflow, Using the bundled registry and Refreshing cohorts, plus 1 more section
  • Runs Python scripts from its folder; calls python3

What it does

Reserved Handle Policy is an agent skill from swyxio/skills. Design, implement, audit, or refresh protected username and handle namespaces for public products. Use whenever a product has open signup, mutable handles, profile URLs, impersonation or squatting risk, reserved route names, short usernames, common-word or common-name claims, developer/AI terminology, notable social identities, or administrator-approved handle assignment—even if the user only asks for a username denylist.

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 13 other files, including scripts and reference files (for example `agents/openai.yaml`, `evals/evals.json` and `references/rationale.md`).

The repository describes itself as: Agent skills for Claude Code and other AI agents. The licence is MIT.

When your agent uses it

  • A product has open signup
  • Mutable handles
  • Reserved route names
  • Short usernames

Example prompts

  • “/reserved-handle-policy”

Requirements

  • Python 3

Workflow steps

2 steps, taken from the first numbered list in SKILL.md.

  1. hard_reserved: platform routes, authority terms, security identities, and service names that users must never claim.
  2. manual_claim_required: scarce or impersonation-prone names that an administrator may assign after identity review.

What it can do on your machine

Read from SKILL.md and the folder at commit a7b8530. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Reserved Handle Policy loads about 1.1k tokens when it runs, and up to ~95k if it reads all its reference files. Until then it costs about 112 tokens; SKILL.md has 528 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~112
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~95k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from swyxio/skills at commit a7b8530, republished under its MIT licence (© swyxio). 528 words, ~1,137 tokens.

Download SKILL.mdSave it as .claude/skills/reserved-handle-policy/SKILL.md (or your agent's skills folder). This skill also uses 9 other files; get the full folder from GitHub.
name
reserved-handle-policy
description
Design, implement, audit, or refresh protected username and handle namespaces for public products. Use whenever a product has open signup, mutable handles, profile URLs, impersonation or squatting risk, reserved route names, short usernames, common-word or common-name claims, developer/AI terminology, notable social identities, or administrator-approved handle assignment—even if the user only asks for a username denylist.

Reserved Handle Policy

Use this skill to protect a public handle namespace without turning a broad list into an unexplained permanent ban.

Start with the policy model

Separate two kinds of restriction:

  1. hard_reserved: platform routes, authority terms, security identities, and service names that users must never claim.
  2. manual_claim_required: scarce or impersonation-prone names that an administrator may assign after identity review.

Do not report both as merely taken. A caller needs to distinguish an existing account, a permanent platform reservation, and a claim that can be reviewed.

Read rationale.md before changing the tiers or source cohorts. Load reserved-handles.toml only when implementing, auditing, or inspecting the concrete list; it is intentionally kept out of the default context because it contains thousands of names.

Implementation workflow

  1. Locate the canonical handle validator, signup command, rename command, availability endpoint, database uniqueness constraints, and administrator mutation boundary.
  2. Preserve the product's existing normalization rules. Compare a normalized lowercase handle and a separator-stripped skeleton where separators are allowed.
  3. Apply the stricter result in this order:
    • hard-reserved exact or confusable match;
    • an already-issued current or historical handle;
    • three-or-fewer-character skeleton;
    • manual-claim exact or confusable match;
    • otherwise available.
  4. Reject protected names in open signup and self-service rename. Do not add a role-based bypass to those public commands.
  5. If manual assignment is in scope, create a distinct administrator command with claimant evidence, reason, actor, timestamp, and audit record. A bootstrap-admin claim may be a narrowly documented exception.
  6. Keep historical handles permanently unavailable if old profile or content URLs redirect through handle history.
  7. Return an explicit machine-readable reason such as manual_claim_required and give the user honest UI copy.
  8. Add focused tests for hard reservations, short handles, separators, one example from every cohort, existing/historical handles, bootstrap behavior, and audited assignment.
Show full SKILL.md (232 more words)Show less

Using the bundled registry

Run the classifier against one or more candidates:

bash
python3 reserved-handle-policy/scripts/check_handle.py admin swyx a_i available-name

Validate the registry after editing it:

bash
python3 reserved-handle-policy/scripts/validate.py

The TOML resource is the source of truth. It uses one compact inline table per handle while retaining ranks, karma, source spelling, cohort metadata, and policy rules. The CSV is a flattened convenience export containing one row per exact handle and all matching cohorts. The bundled readers require Python 3.11 or newer for the standard-library tomllib parser and install no dependencies.

Refreshing cohorts

Read refresh.md for the source-specific retrieval notes and the exact Hacker News query.

  • Treat rankings as dated evidence, not timeless identity truth.
  • Preserve source order and rank metadata when available.
  • Filter candidates through the product's syntactic handle rules, but record how many source rows were excluded.
  • Do not import a raw Reddit karma leaderboard as authoritative. There is no official global ranking, and third-party lists are noisy with bots, repost accounts, deleted users, and unsafe identities. Keep Reddit curated unless a better defensible dataset appears.
  • Adding a newly protected name cannot reclaim a handle already issued. Produce a collision report before changing a live policy.
  • Keep source URLs, capture date, cohort rationale, and policy version beside the data.

Handoff

Report:

  • counts by tier and cohort;
  • normalization and confusable rules;
  • collisions with existing or historical accounts;
  • which user-facing and administrator flows changed;
  • tests run;
  • source capture dates and any cohorts deliberately excluded.

© swyxio, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 9 other files (scripts, references) in reserved-handle-policy of swyxio/skills.

  • SKILL.md
  • LICENSE
  • agents/openai.yaml
  • evals/evals.json
  • references/rationale.md
  • references/refresh.md
  • references/reserved-handles.csv
  • references/reserved-handles.toml
  • scripts/check_handle.py
  • scripts/validate.py

Open the folder on GitHubat commit a7b8530

Compare with similar skills

Reserved Handle Policy next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Reserved Handle Policy compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Reserved Handle Policy this skillswyxio/skills176—~1.1kAutomated safety check: PassMIT
Implementing Policy As Code With Open Policy Agentmukul975/Anthropic-Cybersecurity-Skills34k—~2.6kAutomated safety check: NotesApache-2.0
Implementing API Threat Protection With Apigeemukul975/Anthropic-Cybersecurity-Skills34k—~2.8kAutomated safety check: PassApache-2.0
Implementing Cloud Dlp For Data Protectionmukul975/Anthropic-Cybersecurity-Skills34k—~4.2kAutomated safety check: PassApache-2.0
Implementing Cloud Workload Protectionmukul975/Anthropic-Cybersecurity-Skills34k—~578Automated safety check: PassApache-2.0
Implementing Mimecast Targeted Attack Protectionmukul975/Anthropic-Cybersecurity-Skills34k—~1.8kAutomated safety check: PassApache-2.0

Similar skills

  • Implementing Policy As Code With Open Policy Agent

    mukul975/Anthropic-Cybersecurity-Skills

    Implements policy-as-code enforcement with Open Policy Agent (OPA) and Gatekeeper for Kubernetes and CI/CD pipelines, covering writing Rego policies, deploying OPA Gatekeeper as a Kubernetes…

    34k GitHub stars~2.6k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check: notes
  • Implementing API Threat Protection With Apigee

    mukul975/Anthropic-Cybersecurity-Skills

    Implements API threat protection using Google Apigee reverse-proxy policies, including JSON/XML threat protection, OAuth 2.0 enforcement, SpikeArrest rate limiting, regex-based threat detection, and…

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Implementing Cloud Dlp For Data Protection

    mukul975/Anthropic-Cybersecurity-Skills

    Implement cloud DLP using Amazon Macie, Google Cloud DLP API, Microsoft Purview, Azure Information Protection, and Nightfall AI to discover, classify, label, de-identify, and protect sensitive data…

    34k GitHub stars~4.2k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Implementing Cloud Workload Protection

    mukul975/Anthropic-Cybersecurity-Skills

    Implements cloud workload protection using boto3 and google-cloud APIs for runtime security monitoring, process anomaly detection, and file integrity checking on EC2/GCE instances.

    34k GitHub stars~578 tokensUpdated 1 mo ago
    Data & AnalyticsAuto-check passed
  • Implementing Mimecast Targeted Attack Protection

    mukul975/Anthropic-Cybersecurity-Skills

    Deploys and configures Mimecast Targeted Threat Protection (TTP) modules -- URL Protect (click-time URL rewriting/analysis), Attachment Protect (sandbox detonation), Impersonation Protect…

    34k GitHub stars~1.8k tokensUpdated 1 mo ago
    Documents & OfficeAuto-check passed
  • Implementing Usb Device Control Policy

    mukul975/Anthropic-Cybersecurity-Skills

    Implements USB device control policies to restrict unauthorized removable media access on endpoints, preventing data exfiltration and malware introduction via USB devices.

    34k GitHub stars~1.4k tokensUpdated 1 mo ago
    SecurityAuto-check passed

More from swyxio/skills

All 89 skills in this repo
  • Programmatic Agents

    swyxio/skills

    Run a selected coding-agent CLI programmatically, with latency, error, usage, cost, and trace logging.

    176 GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • New Mac Setup

    swyxio/skills

    Fully automated new Mac setup for fullstack web developers and AI engineers.

    176 GitHub stars~4.3k tokensUpdated today
    Auto-check passed
  • Youtube API

    swyxio/skills

    Manage YouTube videos programmatically via the YouTube Data API v3 — upload video files, upload custom thumbnails, update video metadata (titles, descriptions, tags), and query video/channel info…

    176 GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • Batch YouTube Studio upload workflow for videos sourced from Airtable, Google Drive, Loom, YouTube, or local files.

    176 GitHub stars~1.5k tokensUpdated today
    Auto-check: warnings
  • Reconstruct and visually analyze paired agent, game, or policy trajectories to determine whether changed actions produced their intended effects.

    176 GitHub stars~1.8k tokensUpdated today
    Auto-check passed
  • Forge

    swyxio/skills

    Operate or diagnose SmolForge repositories and Forge Deploy/Sites when the task requires Forge-specific CLI, authentication, manifest, or release behavior on forge.smol.ai or .sites.smol.ai.

    176 GitHub stars~1.3k tokensUpdated today
    Auto-check passed

Questions about Reserved Handle Policy

What does Reserved Handle Policy do?

Design, implement, audit, or refresh protected username and handle namespaces for public products. Reserved Handle Policy is an agent skill from swyxio/skills. Design, implement, audit, or refresh protected username and handle namespaces for public products.

When should I use Reserved Handle Policy?

Reserved Handle Policy fits situations like: A product has open signup; mutable handles; reserved route names; short usernames.

How do I install Reserved Handle Policy in Claude Code?

Run `npx skills add swyxio/skills --skill reserved-handle-policy -a claude-code`. Or copy the skill folder (reserved-handle-policy in swyxio/skills) into .claude/skills/reserved-handle-policy in your project. Claude Code loads it when a task matches its description.

How do I install Reserved Handle Policy in Codex?

Run `npx skills add swyxio/skills --skill reserved-handle-policy -a codex`. Or copy the skill folder (reserved-handle-policy in swyxio/skills) into .agents/skills/reserved-handle-policy in your project. Codex loads it when a task matches its description.

Can I use Reserved Handle Policy in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add swyxio/skills --skill reserved-handle-policy -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/reserved-handle-policy, .gemini/skills/reserved-handle-policy, .github/skills/reserved-handle-policy and .opencode/skills/reserved-handle-policy in your project.

What does Reserved Handle Policy need to run?

Going by SKILL.md and its folder, Reserved Handle Policy needs Python for the scripts in its folder and the command-line tools its instructions call (python3). Our summary lists: Python 3.

Does Reserved Handle Policy access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Reserved Handle Policy safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Reserved Handle Policy use?

Reserved Handle Policy is published under the MIT licence (from the LICENSE file in the skill folder). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Reserved Handle Policy use?

About 1.1k tokens (SKILL.md is roughly 4.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 94k tokens, read only when the agent opens those files.

What are the alternatives to Reserved Handle Policy?

Skills that share tags, products or a category with Reserved Handle Policy: Implementing Policy As Code With Open Policy Agent (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Implementing API Threat Protection With Apigee (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Implementing Cloud Dlp For Data Protection (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Implementing Cloud Workload Protection (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Reserved Handle Policy?

swyxio (a GitHub user) maintains it in swyxio/skills, which has 176 GitHub stars. The repository holds 89 skills in this directory. The repository was last updated on October 11, 2026.

Source: swyxio/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.