Dep Auditor
laolaoshiren/claude-code-skills-zh
审计 Node.js、Python、Go、Rust、JVM、Ruby 项目的依赖漏洞、版本健康度与许可证事实;当用户要求检查 package.json、lockfile、requirements、go.mod、Cargo.toml、pom.xml、Gemfile.lock,或生成不改依赖的中文审计报告时使用
Find any version of any Nix package across nixpkgs git history using the nxv CLI or HTTP API.
$ npx skills add utensils/nxv --skill nxv -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install utensils/nxv nxv --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/utensils/nxv.git skills-src && mkdir -p .claude/skills && cp -r skills-src/src/skill .claude/skills/nxv && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "nxv" agent skill from https://github.com/utensils/nxv/tree/main/src/skill into .claude/skills/nxv/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nxv", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/utensils/nxv/tree/main/src/skillType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add utensils/nxv --skill nxv -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install utensils/nxv nxv --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/utensils/nxv.git skills-src && mkdir -p .agents/skills && cp -r skills-src/src/skill .agents/skills/nxv && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "nxv" agent skill from https://github.com/utensils/nxv/tree/main/src/skill into .agents/skills/nxv/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nxv", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add utensils/nxv --skill nxv -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install utensils/nxv nxv --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/utensils/nxv.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/src/skill .cursor/skills/nxv && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "nxv" agent skill from https://github.com/utensils/nxv/tree/main/src/skill into .cursor/skills/nxv/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nxv", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/utensils/nxv.git --path src/skill--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add utensils/nxv --skill nxv -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install utensils/nxv nxv --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/utensils/nxv.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/src/skill .gemini/skills/nxv && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "nxv" agent skill from https://github.com/utensils/nxv/tree/main/src/skill into .gemini/skills/nxv/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nxv", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install utensils/nxv nxvInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add utensils/nxv --skill nxv -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/utensils/nxv.git skills-src && mkdir -p .github/skills && cp -r skills-src/src/skill .github/skills/nxv && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "nxv" agent skill from https://github.com/utensils/nxv/tree/main/src/skill into .github/skills/nxv/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nxv", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add utensils/nxv --skill nxv -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install utensils/nxv nxv --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/utensils/nxv.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/src/skill .opencode/skills/nxv && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "nxv" agent skill from https://github.com/utensils/nxv/tree/main/src/skill into .opencode/skills/nxv/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nxv", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
nxvFind any version of any Nix package across nixpkgs git history using the nxv CLI or HTTP API.
Nxv is an agent skill from utensils/nxv. Find any version of any Nix package across nixpkgs git history using the nxv CLI or HTTP API. Use when asked which nixpkgs commit shipped a specific package version (e.g. "python 2.7", "nodejs 15", "ruby 2.6"), when looking up package metadata/license/homepage, when generating a nix shell nixpkgs/<commitpkg invocation for an old version, or when querying the public/private nxv server. Triggers include "find python 2.7 in nixpkgs", "which commit had nodejs 15.14", "when was foo added/removed", "give me the nix…
Its SKILL.md is about 7.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file.
It sits in Backend & APIs, covering REST APIs and Git workflow. It works with Python, Ruby, Node.js and SQLite. The repository describes itself as: Find any version of any Nix package, instantly. Fast CLI + HTTP API + web UI over 9+ years of indexed nixpkgs history — get the exact commit for nix shell nixpkgs/<commitpkg. The licence is MIT.
Read from SKILL.md and the folder at commit 82413f0. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
BashReadGlobGrepFrom allowed-tools in the SKILL.md frontmatter.
Ships script files (Rust), which the agent can run.
Shell commands in SKILL.md call:
jqnixcurlpythonrubybrewcargoFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
nxv.urandom.iopython.orggithub.comAlso links to:
agentskills.ioFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
NXV_PUBLIC_KEYNXV_SECRET_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Nxv loads about 7.9k tokens when it runs. Until then it costs about 158 tokens; SKILL.md has 2,429 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
allowed-tools: Bash, Read, Glob, GrepAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from utensils/nxv at commit 82413f0, republished under its MIT licence (© utensils). 2,429 words, ~7,904 tokens.
.claude/skills/nxv/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.nxv is a Rust CLI + HTTP API that indexes nixpkgs channel-release history (2016+) into a local SQLite database with a bloom filter for fast lookups. It answers: "which exact nixpkgs commit shipped version X of package Y?" and produces the nix shell nixpkgs/<commit>#pkg command you need to actually use it.
nxv search python # All python packages (most recent per version)
nxv search python 2.7 # Filter by version (prefix match)
nxv search python --exact # Exact attribute name only
nxv search "json parser" --desc # Full-text search package descriptions
nxv run python 2.7 # Resolve and open a pinned shell
nxv run python 3.11 --with nodejs@20 # Multi-package shell
nxv info python311 # Detailed info for current version
nxv info python311 3.11.4 # Detailed info for specific version
nxv history python311 # Version timeline (first/last seen)
nxv history python311 3.11.4 # When was 3.11.4 available?
nxv stats # Index statistics
nxv update # Update nxv itself to the latest release
nxv sync # Download or refresh the local package index
nxv sync --force # Force a full index re-download
nxv serve --host 0.0.0.0 --port 8080 # Start HTTP API + web UI
nxv completions zsh # Generate shell completions
nxv skill install codex # Install this skill for one explicit agent
nxv skill install --detected # Install for detected AI agents
nxv skill list # Agents, skill paths, install statusParse $ARGUMENTS to determine the action:
search, run, info, history, stats, update, sync, serve, completions, skill, and indexer-only index, dedupe, publish, keygen), run that subcommand.python, nodejs 15, ruby 2.6), default to nxv search.search or history accordingly.nxv stats to give the user a quick health check of their index.For agents: always pass --format json (CLI) or hit the HTTP API and pipe to jq. The table format is human-only; column widths are terminal-dependent. Exception: nxv stats has no --format flag — use GET /api/v1/stats when you need stats as JSON.
Every CLI invocation accepts:
| Flag | Description |
|---|---|
--db-path <PATH> | Path to the index database (default: platform data dir) |
-v, --verbose | -v info, -vv debug (SQL queries, HTTP requests) |
-q, --quiet | Suppress all output except errors |
--no-color | Disable colored output (also honors any non-empty NO_COLOR) |
--api-timeout <SECS> | API request timeout when using remote backend (default: 30) |
nxv transparently runs against either a local SQLite index or a remote nxv serve instance. Set NXV_API_URL to switch:
# Use the public hosted instance — no local index needed
NXV_API_URL=https://nxv.urandom.io nxv search nodejs 15
NXV_API_URL=https://nxv.urandom.io nxv info python311
# Or your own private instance
export NXV_API_URL=http://gpu-host:8080
nxv search rust 1.70If NXV_API_URL is unset, the CLI uses the local index at ~/Library/Application Support/nxv/index.db (macOS) or ~/.local/share/nxv/index.db (Linux). Run nxv sync to download the latest published index on first use.
Find packages and the commits where each version existed:
nxv search python # Recent per (pkg, version)
nxv search python 3.11 # Version prefix filter
nxv search python 2.7.3 --all-depths # Include nested package-set members
nxv search python --exact # Exact attribute name only
nxv search python --license MIT # Filter by license
nxv search python --sort date --reverse # Oldest first
nxv search "web server" --desc # FTS5 description search
nxv search python --show-platforms # Add platforms column
nxv search python --full # All commits (no dedup)
nxv search python --limit 5 # Cap at 5 results
nxv search python --format json # Machine-readable JSON
nxv search python --format plain # TSV for shell scriptsFor version-qualified prefix searches, nxv first resolves the shallowest
attribute-path tier matching the package prefix, then applies the version prefix.
This keeps python 3.11 on interpreter attributes such as python311; a query like
python 2.7.3 reports a precise miss with nearby interpreter versions instead of
returning libraries whose own version is 2.7.3. A package-set query such as
python27Packages 2.7.3 resolves its member depth naturally. Pass --all-depths
to request the legacy broad prefix behavior explicitly. The flag requires a version
and conflicts with --exact and --desc.
Version-miss diagnostics and suggestions are written to stderr. Successful JSON searches return an array of package rows; an empty miss emits no stdout.
JSON shape per row (the same shape is returned by nxv info, nxv history <pkg> <version>, nxv history --full, and the /api/v1 package endpoints):
{
"id": 9630,
"name": "python3",
"version": "3.12.13",
"first_commit_hash": "d78e468770f4ab5e00c5015f4d77c1a499a76dc8",
"first_commit_date": "2026-03-06T20:06:54Z",
"last_commit_hash": "3d2613bc58a1f5b7805467a63a825e1d7bc9b7a9",
"last_commit_date": "2026-07-21T12:39:35Z",
"attribute_path": "python312",
"description": "High-level dynamically-typed programming language",
"license": ["Python-2.0"],
"homepage": "https://www.python.org",
"maintainers": ["mweinelt"],
"platforms": ["x86_64-linux", "aarch64-darwin"],
"source_path": "pkgs/development/interpreters/python/cpython/default.nix",
"known_vulnerabilities": null
}| Field | Type | Notes |
|---|---|---|
id | integer | Index row id. Not stable across index rebuilds — never persist it. |
name | string | Upstream derivation name. Not installable — see below. |
attribute_path | string | The nixpkgs attribute. This is what you install with. |
version | string | Package version. |
first_commit_hash / last_commit_hash | string | Full 40-char nixpkgs commit hashes. |
first_commit_date / last_commit_date | string | RFC 3339 / ISO 8601 UTC. |
description, homepage, source_path | string | null | source_path is null for older packages. |
license, maintainers, platforms | array | null | Arrays of strings. null when the package declares none. |
known_vulnerabilities | array | null | null (or []) means no known advisory; non-empty means the package is insecure. |
name vs attribute_path — these routinely differ and confusing them produces commands that fail. name is the upstream derivation name (pname for top-level attrs, the final attribute segment for nested ones); attribute_path is the address you actually install with. For the row above, nix shell nixpkgs/<hash>#python312 works and #python3 may not. Always use attribute_path.
license, maintainers, platforms, and known_vulnerabilities are real JSON arrays, so jq reaches them directly:
nxv search python312 --exact --format json | jq -r '.[0].license[]' # Python-2.0
nxv search python312 --exact --format json | jq -r '.[0].platforms | join(", ")'
nxv search hello --format json | jq -r '.[] | select(.known_vulnerabilities != null) | .attribute_path'Version note: older nxv releases emitted these four fields as JSON-encoded strings (
"license": "[\"Python-2.0\"]"), requiring a secondfromjson. If you must support both, use(.license | if type == "string" then fromjson else . end).
Detailed metadata for one package version (description, license, homepage, platforms, source path, known vulnerabilities):
nxv info python311 # Latest known version
nxv info python311 3.11.4 # Specific version (positional)
nxv info python311 -V 3.11.4 # Specific version (flag form)
nxv info python311 --format jsoninfo resolves the package name as an exact attribute path first, so it needs no
--exact flag: nxv info python311 3.11.4 returns python311 only, never
python311Full or python311Packages.*. If the package is known but never had the
requested version, info reports not found instead of falling back to unrelated prefix
matches — an empty result means "this package never had that version", not "try harder".
An unknown attribute path is widened to a prefix search, but what gets prefix-matched depends on whether a version was given:
nxv info python311Packages.tk 3.11.4 # widened over ATTRIBUTE PATHS -> resolves
nxv info python311Packages.tk # widened over the NAME field -> usually no matchSo partial attribute paths generally only resolve when you also pass a version. For
open-ended prefix lookups use nxv search (with --exact as needed) instead.
Version timeline — when each version first appeared and when it was last seen:
nxv history python311 # All versions of python311
nxv history python311 3.11.4 # Just one version's window
nxv history ripgrep --full # Add commits, license, homepage, etc.
nxv history python311 --format jsonJSON shape per row — plain nxv history <pkg> returns this compact timeline shape:
{
"version": "3.11.4",
"first_seen": "2023-06-15T00:00:00+00:00",
"last_seen": "2023-12-01T00:00:00+00:00",
"is_insecure": false,
"known_vulnerabilities": null
}is_insecure means nixpkgs reports a known advisory for that software version,
resolved by package name so every attribute packaging the same build agrees
(emacs and emacs28 at 28.2 are both flagged). It does not tell you whether
nix will refuse to build a specific attribute at a specific revision — for that,
name the version (nxv history <pkg> <version>) and read its own
known_vulnerabilities.
Note the field names differ from search (first_seen/last_seen, not first_commit_date/last_commit_date), and there are no commit hashes. Adding --full, or naming a version (nxv history python311 3.11.4), switches the output to the full search row shape documented above — use one of those when you need a commit hash to feed to nix shell. Like the compact timeline, bare --full resolves the package by its exact installable attribute_path.
The quickest interactive path is nxv run, which resolves the same package and
version query as search and opens one pinned shell:
nxv run python 2.7
nxv run python 3.11 --with nodejs@20 --with jqAdditional --with values use PACKAGE@VERSION when a version is needed.
nxv resolves every query before launch, prefers an exact attribute match before
falling back to search's deterministic relevance rules, and uses each result's
latest observed commit. Modern revisions are combined in one nix shell; if
any result predates flakes, nxv uses one compatible nix-shell -p environment
instead. On Apple Silicon, the pre-flake fallback evaluates packages as
x86_64-darwin and requires Rosetta.
For manual command construction, take a first_commit_hash (or
last_commit_hash) from search/history output and feed it to Nix:
# Drop into a shell with that exact version
nix shell nixpkgs/e4a45f9#python
# Run it once
nix run nixpkgs/e4a45f9#python
# Add to a flake input
inputs.nixpkgs-python27.url = "github:NixOS/nixpkgs/<commit>";Pick first_commit_hash for the canonical "introduced in" commit; pick last_commit_hash if you want the most recent commit that still shipped that version.
The direct nix shell nixpkgs/<commit>#<attribute_path> form may fail for old
nixpkgs revisions even when nxv found a valid observation:
edition field in flake files from roughly
2020 and earlier.aarch64-darwin support for
many packages. On Apple Silicon, evaluate the package as x86_64-darwin and
run it through Rosetta when necessary.Use a classic nixpkgs import with the full commit hash and the result's exact
attribute_path:
nix shell --impure --expr '
(import (builtins.fetchTarball
"https://github.com/NixOS/nixpkgs/archive/<full-hash>.tar.gz")
{ system = "x86_64-darwin"; }).ruby
' --command ruby --versionReplace .ruby and the command with the returned attribute and executable.
The platforms field comes from package metadata (meta.platforms); it is not
proof that the historical revision evaluates on that system or that Hydra
produced a cached binary for it.
nxv update # Update the nxv application only
nxv sync # Download or refresh the package index only
nxv sync --force # Force full re-download of the index
nxv sync --skip-verify # Skip minisign signature check (INSECURE)
nxv sync --public-key /path/key.pub # Use a custom public key (self-hosted index)
nxv sync --manifest-url <URL> # Use a custom manifest (self-hosted index)
nxv stats # Index size, commit range, last updatenxv update only checks GitHub for the latest nxv release:
brew upgrade nxv) and exits successfully.nxv sync independently refreshes the SQLite index and bloom filter. It never
checks for or replaces the application. If a published index requires a newer
schema, run nxv update (or the printed package-manager command) and retry
nxv sync.
nxv serve # 127.0.0.1:8080 (default)
nxv serve --host 0.0.0.0 --port 3000 # Public bind
nxv serve --cors # Enable CORS for all origins
nxv serve --cors-origins https://app.example.com # Restrict CORS
nxv serve --rate-limit 10 --rate-limit-burst 20 # Per-IP rate limitThe server bundles:
/ (Tailwind v4 + vanilla JS, embedded at build time)/docs (Scalar UI)/api/v1/* — see endpoints below/health, /metricsAll paths are under /api/v1. Wrapped responses always look like { "data": ..., "meta": {...} } for paginated lists, { "data": ... } for single items.
| Method | Path | Purpose |
|---|---|---|
GET | /search?q=<name>&limit=&offset=&sort=&exact=&all_depths= | Search packages |
GET | /search/description?q=<text>&limit=&offset= | Full-text search descriptions (FTS5) |
GET | /packages/{attr} | All version records for a package |
GET | /packages/{attr}/history | Version timeline (first/last seen) |
GET | /packages/{attr}/versions/{version} | All records for one version |
GET | /packages/{attr}/versions/{version}/first | First-seen commit |
GET | /packages/{attr}/versions/{version}/last | Last-seen commit |
GET | /stats | Index statistics |
GET | /health | Liveness probe (uncached) |
GET | /metrics | Server metrics (uncached) |
Search query parameters:
| Parameter | Type | Description |
|---|---|---|
q | string | Search query (required) |
version | string | Version filter (prefix match) |
exact | boolean | Exact attribute name match |
all_depths | boolean | Include every attribute depth; requires version |
license | string | License filter |
sort | string | relevance (default), date, version, or name |
reverse | boolean | Reverse sort order |
limit | integer | Max results (default 50) |
offset | integer | Results to skip (default 0) |
Quick examples against the public instance:
curl -s "https://nxv.urandom.io/api/v1/search?q=python&version=3.11&limit=5" | jq
curl -s "https://nxv.urandom.io/api/v1/packages/python311/history" | jq '.data[0:3]'
curl -s "https://nxv.urandom.io/api/v1/packages/nodejs-15_x/versions/15.14.0/first" | jq
curl -s "https://nxv.urandom.io/api/v1/stats" | jq '.data'Version-qualified search responses add an optional meta.resolution object with
scope, resolved_depth, requested_version, version_matched, optional
deeper_matches_available, and up to five {attribute_path, version} suggestions.
This metadata is additive; package rows and the CLI JSON array are unchanged.
nxv can install this very skill for any major AI coding agent — the binary embeds the SKILL.md and writes it where each agent looks, per the Agent Skills standard:
nxv skill install codex # Install user-wide for one agent
nxv skill install --detected # Explicitly install for detected agents
nxv skill install codex --project # Install for Codex in the current project
nxv skill install --detected --project # Map detected agents to project paths
nxv skill install claude codex # Install for specific agents only
nxv skill install --all # Install for every supported agent
nxv skill install copilot --dir ~/repo # Project install into another directory
nxv skill list # Show agents, paths, install status
nxv skill show # Print the SKILL.md to stdout
nxv skill uninstall --project # Remove project-level installsSupported agents and where the skill lands (<dir>/nxv/SKILL.md):
| Agent | User-wide | Project-level |
|---|---|---|
claude | ~/.claude/skills/ | .claude/skills/ |
codex | ~/.codex/skills/ | .agents/skills/ |
pi | ~/.pi/agent/skills/ | .pi/skills/ |
openclaw | ~/.openclaw/skills/ | .agents/skills/ |
copilot | ~/.copilot/skills/ | .github/skills/ |
cursor | ~/.cursor/skills/ | .agents/skills/ |
gemini | ~/.gemini/skills/ | .agents/skills/ |
amp | ~/.config/amp/skills/ | .agents/skills/ |
goose | ~/.config/goose/skills/ | .agents/skills/ |
agents | ~/.agents/skills/ | .agents/skills/ |
The table shows each agent's primary directory — the one nxv skill install <agent> writes to. Several agents read additional locations: Copilot reads .github/skills/, .claude/skills/, or .agents/skills/ in a repository, and Pi reads .agents/skills/ as well as .pi/skills/.
Semantics:
--detected, or --all. With no target, nxv exits without writing anything.--detected checks user configuration directories. With --project / --dir,
those detected agents are mapped to their corresponding project paths. No
detected agents is an error; use the explicit agents target for the generic
Agent Skills directory.skills/nxv/SKILL.md unconditionally and never touches other files; uninstall removes only that file (and the nxv/ directory if it is then empty).These require nxv built with --features indexer (cargo build --features indexer or nix build .#nxv-indexer). The indexer ingests channel-release snapshots from releases.nixos.org — no nixpkgs checkout and no Nix evaluation needed for the main path:
# Ingest new channel releases (default channels: nixpkgs-unstable + nixos-unstable-small)
nxv index # Incremental: only new releases
nxv index --channel nixpkgs-unstable # Restrict to one channel
nxv index --since 2024-01-01 --until 2024-06-30 # Bound by release date
nxv index --strict --report report.json # CI mode: gates fatal, JSON report
nxv index --backfill-evals # One-time 2016-2020 era (needs `nix`, ~2-3h)
nxv index --head-eval # Evaluate master HEAD when channels stall (needs `nix`)
nxv index --retry-failed # Re-attempt failed/parked releases
nxv index --max-releases 5 # Bound a run (testing)
# Repair duplicate rows in pre-v4 databases (also runs during v3->v4 migration)
nxv dedupe --dry-run # Preview
nxv dedupe # Run
# Publish distribution-ready compressed artifacts + manifest
nxv publish --output ./publish --url-prefix https://your-server/nxv
nxv publish --output ./publish --url-prefix https://... --sign --secret-key nxv.key
nxv publish --output ./publish --url-prefix https://... --artifact-name-prefix run-123-
# Generate a minisign keypair for signing manifests
nxv keygen --secret-key ./nxv.key --public-key ./nxv.pubEvery recorded commit is a real, Hydra-built channel commit — nix shell commands produced from the index hit the binary cache instead of compiling from source. Version ranges mean "observed at both endpoints"; a version that lived shorter than one channel advance (~a day) may be missed.
Retired commands: nxv backfill and nxv reset are gone — snapshots carry complete metadata (source_path, homepage, known_vulnerabilities), and there is no checkout to reset.
Most users never need these — they consume a pre-built published index via nxv sync. Only run these when self-hosting an index. Use --artifact-name-prefix for mutable stores such as GitHub Releases so payload assets can be uploaded under immutable names before replacing manifest.json.
| Variable | Purpose |
|---|---|
NXV_API_URL | Point CLI at a remote nxv serve instead of the local DB |
NXV_DB_PATH | Override local SQLite path |
NXV_API_TIMEOUT | HTTP client timeout in seconds (default 30) |
NXV_MANIFEST_URL | Override the manifest URL used by nxv sync |
NXV_PUBLIC_KEY | Public key for manifest verification (path or raw key) |
NXV_SECRET_KEY | Secret key for nxv publish --sign (path or raw content) |
NXV_SKIP_VERIFY | 1/true/yes/on skip; 0/false/no/off do not (INSECURE) |
NXV_VERSION | Pin the version installed by install.sh (self-update targets latest) |
NXV_HOST | nxv serve bind host |
NXV_PORT | nxv serve listen port |
NXV_RATE_LIMIT | nxv serve per-IP rate limit (req/sec) |
NXV_RATE_LIMIT_BURST | nxv serve per-IP rate-limit burst size (default: 2x rate_limit) |
NXV_FRONTEND_DIR | nxv serve reads frontend assets from disk on every request (dev mode) |
NO_COLOR | Disable ANSI colors when set to any non-empty value |
The local index lives in platform data directories:
~/Library/Application Support/nxv/~/.local/share/nxv/Files:
index.db — SQLite database with package versionsbloom.bin — Bloom filter sibling for fast negative lookups (loaded at search time)Safe to delete; nxv sync will rebuild from the published manifest.
Find the commit that introduced a specific version (CLI):
nxv search python 3.11.4 --exact --format json | \
jq '.[0] | {pkg: .attribute_path, version, commit: .first_commit_hash, date: .first_commit_date}'Generate the nix shell invocation directly (CLI):
nxv search nodejs-15_x 15 --exact --format json | \
jq -r '.[0] | "nix shell nixpkgs/\(.first_commit_hash | .[0:7])#\(.attribute_path)"'Find a package version on the public API:
curl -s "https://nxv.urandom.io/api/v1/packages/python/versions/2.7.18/first" | \
jq -r '.data | "nix shell nixpkgs/\(.first_commit_hash | .[0:7])#\(.attribute_path)"'Check whether a version of a package was ever in nixpkgs (HTTP):
curl -s "https://nxv.urandom.io/api/v1/packages/ruby/history" | \
jq '.data[] | select(.version | startswith("2.6"))'Get the index freshness (newest ingested channel commit):
curl -s "https://nxv.urandom.io/api/v1/stats" | \
jq '.data | {commit: .last_indexed_commit, date: .last_indexed_date, packages: .unique_names}'(attribute_path, version) pair is returned. Pass --full (CLI) or use the /packages/{attr} HTTP endpoint to see every commit.nxv search python 3.11 matches 3.11.0, 3.11.4, 3.11.10, etc. Use --exact for whole-attribute matches, not for whole-version matches.meta.resolution or CLI stderr for suggestions, query the package-set prefix directly, or opt into --all-depths / all_depths=true.--public-key or set NXV_PUBLIC_KEY when consuming a manifest you signed yourself, otherwise nxv sync rejects the signature.--format json shape is stable: safe to pipe to jq. Breaking shape changes would be a semver bump — license/maintainers/platforms/known_vulnerabilities changed from stringified JSON to real arrays in a recent release.attribute_path, never name: they differ often ("name": "python3" vs "attribute_path": "python312"). name is the upstream derivation name and is not a valid flake attribute on its own./api/v1 data responses always wrap in {data, meta} (or {data} for single items): do jq '.data' first. Exceptions: the operational /health and /metrics endpoints are unwrapped.nxv run python 2.7; nxv resolves the best match and handles old pre-flake revisions automatically.--exact when one exact attribute is required. Default version searches stay within the shallowest matching tier; use --all-depths only when nested variants are intentional.--desc for fuzzy intent ("a package that does X") instead of exact name searches.NXV_API_URL=https://nxv.urandom.io to skip the ~220MB index download entirely if you only need occasional lookups.publish-index.yml); nxv sync pulls the latest.nxv sync; it never checks for or replaces the application.This skill is generated by the nxv binary itself. To refresh it after upgrading nxv:
nxv update # Get the latest nxv application
nxv skill install codex # Rewrite one user-wide install
nxv skill install --detected # ...or explicitly refresh detected agents
nxv skill install codex --project # Refresh one project-level installWithout an nxv binary on hand, fetch the canonical copy from the repository:
curl -sL https://raw.githubusercontent.com/utensils/nxv/main/.claude/skills/nxv/SKILL.md \
-o ~/.claude/skills/nxv/SKILL.md© utensils, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in src/skill of utensils/nxv.
Open the folder on GitHubat commit 82413f0
Nxv next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Nxv this skillutensils/nxv | 136 | — | ~7.9k | Automated safety check: Notes | MIT | |
| Dep Auditorlaolaoshiren/claude-code-skills-zh | 879 | — | ~895 | Automated safety check: Pass | MIT | |
| Dependency Scanjwynia/agent-skills | 169 | — | ~1.7k | Automated safety check: Pass | MIT | |
| Temporal Developertemporalio/skill-temporal-developer | 230 | — | ~2.5k | Automated safety check: Pass | MIT | |
| Cloudflare Email Servicehodgef/apiker | 127 | 2 repos | ~2k | Automated safety check: Pass | MIT | |
| Sasjs Serversasjs/core | 132 | — | ~2.4k | Automated safety check: Notes | MIT |
laolaoshiren/claude-code-skills-zh
审计 Node.js、Python、Go、Rust、JVM、Ruby 项目的依赖漏洞、版本健康度与许可证事实;当用户要求检查 package.json、lockfile、requirements、go.mod、Cargo.toml、pom.xml、Gemfile.lock,或生成不改依赖的中文审计报告时使用
jwynia/agent-skills
Detect CVEs and security issues in project dependencies. An agent skill from jwynia/agent-skills.
temporalio/skill-temporal-developer
Develop, debug, and manage Temporal applications across Python, TypeScript, Go, Java, .NET, Ruby, and Rust.
hodgef/apiker
Send and receive transactional emails with Cloudflare Email Service (Email Sending + Email Routing).
sasjs/core
Installing, configuring, and running @sasjs/server - the open-source NodeJS wrapper around the SAS binary that provides a REST API, filesystem (SASjs Drive), Stored Program execution, and web app…
davila7/claude-code-templates
Comprehensive backend development skill for building scalable backend systems using NodeJS, Express, Go, Python, Postgres, GraphQL, REST APIs.
utensils/nxv
Review and merge the release-plz release PR with explicit user confirmation
utensils/nxv
A skill your agent uses to generate well-branded interfaces and assets for nxv (Nix Version Index) — either for production or throwaway prototypes/mocks.
Categories
Find any version of any Nix package across nixpkgs git history using the nxv CLI or HTTP API. Nxv is an agent skill from utensils/nxv. Find any version of any Nix package across nixpkgs git history using the nxv CLI or HTTP API.
Nxv fits situations like: asked which nixpkgs commit shipped a specific package version (e.g; include find python 2.7 in nixpkgs; which commit had nodejs 15.14; was foo added/removed.
Run `npx skills add utensils/nxv --skill nxv -a claude-code`. Or copy the skill folder (src/skill in utensils/nxv) into .claude/skills/nxv in your project. Claude Code loads it when a task matches its description.
Run `npx skills add utensils/nxv --skill nxv -a codex`. Or copy the skill folder (src/skill in utensils/nxv) into .agents/skills/nxv in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add utensils/nxv --skill nxv -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/nxv, .gemini/skills/nxv, .github/skills/nxv and .opencode/skills/nxv in your project.
Going by SKILL.md and its folder, Nxv needs Rust for the scripts in its folder, the command-line tools its instructions call (jq, nix, curl, python, ruby and brew) and credentials named NXV_PUBLIC_KEY and NXV_SECRET_KEY. Our summary lists: Python 3; Node.js. Its frontmatter pre-approves these tools: Bash, Read, Glob, Grep.
SKILL.md names 4 domains. In commands or code: nxv.urandom.io, python.org and github.com; the agent is likely to contact these when it follows the instructions. As links in the text: agentskills.io. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Nxv is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 7.9k tokens (SKILL.md is roughly 32k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Nxv: Dep Auditor (laolaoshiren/claude-code-skills-zh, 879 stars), Dependency Scan (jwynia/agent-skills, 169 stars), Temporal Developer (temporalio/skill-temporal-developer, 230 stars) and Cloudflare Email Service (hodgef/apiker, 127 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
utensils (a GitHub organization) maintains it in utensils/nxv, which has 136 GitHub stars. The repository holds 3 skills in this directory. The repository was last updated on August 12, 2026.
Source: utensils/nxv on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.