Agent skill

Vellum Boundary Guard

by vellum-ai in vellum-ai/vellum-assistant

Check Vellum Assistant architecture and package boundaries. An agent skill from vellum-ai/vellum-assistant.

MITAuto-check passed

Install Vellum Boundary Guard

skills CLI
$ npx skills add vellum-ai/vellum-assistant --skill vellum-boundary-guard -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install vellum-ai/vellum-assistant vellum-boundary-guard --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/vellum-ai/vellum-assistant.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.cursor/skills/vellum-boundary-guard .claude/skills/vellum-boundary-guard && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
vellum-boundary-guard
GitHub stars
1.4k
Token cost
~500 tokens
SKILL.md length
238 words
Files
1
Skills in repo
108
Repo updated
First seen
Licence
MIT

At a glance

Check Vellum Assistant architecture and package boundaries. An agent skill from vellum-ai/vellum-assistant.

  • Works in 4 steps: Search changed imports and new route… → Identify any package-crossing dependency. → Decide whether the correct home is a… → …
  • Editing imports
  • SKILL.md covers Package Import Boundaries, HTTP And IPC Boundaries, Security Ownership Boundaries and Skill Boundaries, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Vellum Boundary Guard is an agent skill from vellum-ai/vellum-assistant. Check Vellum Assistant architecture and package boundaries. Use when editing imports, moving code, adding endpoints, touching assistant/gateway/client/skill boundaries, or reviewing architecture-sensitive changes.

Its SKILL.md is about 500 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: An AI Assistant that’s easy to setup, does your work 24/7, knows your preferences and gets better over time. The licence is MIT.

When your agent uses it

  • Editing imports
  • Adding endpoints
  • Touching assistant/gateway/client/skill boundaries
  • Reviewing architecture-sensitive changes

Example prompts

  • “/vellum-boundary-guard”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Search changed imports and new route registrations.
  2. Identify any package-crossing dependency.
  3. Decide whether the correct home is a package-local module, a shared packages/ module, IPC, HTTP through gateway, or a skill contract.
  4. If a violation exists, recommend the smallest boundary-preserving move.

What it can do on your machine

Read from SKILL.md and the folder at commit 33cc983. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Vellum Boundary Guard loads about 500 tokens when it runs. Until then it costs about 59 tokens; SKILL.md has 238 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~59
When it runs · the whole SKILL.md, loaded when a task matches
~500

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from vellum-ai/vellum-assistant at commit 33cc983, republished under its MIT licence (© vellum-ai). 238 words, ~500 tokens.

Download SKILL.mdSave it as .claude/skills/vellum-boundary-guard/SKILL.md (or your agent's skills folder).
name
vellum-boundary-guard
description
Check Vellum Assistant architecture and package boundaries. Use when editing imports, moving code, adding endpoints, touching assistant/gateway/client/skill boundaries, or reviewing architecture-sensitive changes.

Vellum Boundary Guard

Package Import Boundaries

Enforce these boundaries:

  • assistant/ must not import from gateway/ via relative paths.
  • gateway/ must not import from assistant/ via relative paths.
  • assistant/ and skills/ must not import from each other directly.
  • Runtime code must not import from meta/.
  • Shared cross-package logic belongs in packages/.

For tests that need behavior from another package, mock the boundary instead of importing real handlers.

HTTP And IPC Boundaries

  • Public inbound HTTP endpoints belong in gateway/.
  • New CLI-to-assistant interactions should use Unix socket IPC through the existing IPC route pattern.
  • Events from assistant runtime code should use the assistant event hub rather than new HTTP endpoints when possible.

Security Ownership Boundaries

  • Gateway owns trust rules and gateway security files.
  • CES owns credential files.
  • The assistant must not read gateway-owned directories directly.
  • Clients must not read from the user's ~/.vellum directory.
  • Secrets must not be stored in workspace files.

Skill Boundaries

First-party skills run as separate processes and should communicate through supported contracts. Do not bypass skill isolation with direct relative imports.

Review Workflow

  1. Search changed imports and new route registrations.
  2. Identify any package-crossing dependency.
  3. Decide whether the correct home is a package-local module, a shared packages/ module, IPC, HTTP through gateway, or a skill contract.
  4. If a violation exists, recommend the smallest boundary-preserving move.

Verification

Prefer existing guard tests when available, then add focused tests for any new boundary rule or route pattern.

© vellum-ai, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .cursor/skills/vellum-boundary-guard of vellum-ai/vellum-assistant.

Open the folder on GitHubat commit 33cc983

Compare with similar skills

Vellum Boundary Guard next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Vellum Boundary Guard compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Vellum Boundary Guard this skillvellum-ai/vellum-assistant1.4k—~500Automated safety check: PassMIT
Safety Guardaffaan-m/ECC277k2 repos~554Automated safety check: NotesMIT
Guard Modegarrytan/gstack136k—~1kAutomated safety check: NotesMIT
Safety Guardaffaan-m/ECC276k—~323Automated safety check: NotesMIT
Safety Guardaffaan-m/ECC276k—~255Automated safety check: NotesMIT
Generic Assistantmastra-ai/mastra29k—~1.1kAutomated safety check: PassCustom licence

Similar skills

  • Safety Guard

    affaan-m/ECC

    Guard against destructive operations with three modes: Careful intercepts dangerous commands (rm -rf, git push --force, DROP TABLE) for confirmation, Freeze locks writes to one directory, and Guard…

    277k GitHub starsUsed in 2 repos~554 tokens
    DevelopmentAuto-check: notes
  • Guard Mode

    garrytan/gstack

    Switches on full safety by combining warnings before destructive commands with a block on edits outside one directory you choose, for work on production or live systems.

    136k GitHub stars~1k tokensUpdated today
    Agent WorkflowsAuto-check: notes
  • Safety Guard

    affaan-m/ECC

    本番システムでの作業時や、エージェントを自律的に実行する際に破壊的な操作を防ぐためにこのスキルを使用してください. An agent skill from affaan-m/ECC.

    276k GitHub stars~323 tokensUpdated yesterday
    Auto-check: notes
  • Safety Guard

    affaan-m/ECC

    使用此技能可防止在生产系统上工作或自主运行代理时进行破坏性操作。

    276k GitHub stars~255 tokensUpdated yesterday
    Auto-check: notes
  • Generic Assistant

    mastra-ai/mastra

    Fallback authoring playbook for building general-purpose personal assistant agents that do not fit a more specific archetype.

    29k GitHub stars~1.1k tokensUpdated today
    Sales & SupportAuto-check passed
  • Official

    Answers n8n product, setup, credential, node, hosting, API, and usage questions from current n8n docs.

    207k GitHub stars~550 tokensUpdated today
    Productivity & AutomationAuto-check passed

More from vellum-ai/vellum-assistant

All 108 skills in this repo
  • Vellum GitHub App Setup

    vellum-ai/vellum-assistant

    Create and configure a GitHub App so the assistant can push commits, open PRs, and comment under its own bot identity.

    1.4k GitHub stars~3.1k tokensUpdated 2 days ago
    Auto-check passed
  • Discord App Setup

    vellum-ai/vellum-assistant

    Connect a Discord bot to the assistant via the Discord Gateway with guided application creation and intent configuration

    1.4k GitHub stars~4.2k tokensUpdated 2 days ago
    Auto-check passed
  • Sentry App Setup

    vellum-ai/vellum-assistant

    Create and configure a Sentry internal integration so the assistant can manage issues, alerts, and releases under its own identity

    1.4k GitHub stars~1.3k tokensUpdated 2 days ago
    Auto-check passed
  • Memory Corpus Ingest

    vellum-ai/vellum-assistant

    Ingest a large dataset into memory as a skimmed map. An agent skill from vellum-ai/vellum-assistant.

    1.4k GitHub stars~3k tokensUpdated 2 days ago
    Auto-check: notes
  • Plugin Builder

    vellum-ai/vellum-assistant

    A skill your agent uses when the user wants to build, scaffold, ship, or edit a Vellum plugin that bundles multiple surfaces (hooks, tools, skills, and more) into one installable package.

    1.4k GitHub stars~3.1k tokensUpdated 2 days ago
    Auto-check passed
  • Slack App Setup

    vellum-ai/vellum-assistant

    Connect a Slack app to the Vellum Assistant via Socket Mode.

    1.4k GitHub stars~2.5k tokensUpdated 2 days ago
    Auto-check: warnings

Questions about Vellum Boundary Guard

What does Vellum Boundary Guard do?

Check Vellum Assistant architecture and package boundaries. An agent skill from vellum-ai/vellum-assistant. Vellum Boundary Guard is an agent skill from vellum-ai/vellum-assistant. Check Vellum Assistant architecture and package boundaries.

When should I use Vellum Boundary Guard?

Vellum Boundary Guard fits situations like: editing imports; adding endpoints; touching assistant/gateway/client/skill boundaries; reviewing architecture-sensitive changes.

How do I install Vellum Boundary Guard in Claude Code?

Run `npx skills add vellum-ai/vellum-assistant --skill vellum-boundary-guard -a claude-code`. Or copy the skill folder (.cursor/skills/vellum-boundary-guard in vellum-ai/vellum-assistant) into .claude/skills/vellum-boundary-guard in your project. Claude Code loads it when a task matches its description.

How do I install Vellum Boundary Guard in Codex?

Run `npx skills add vellum-ai/vellum-assistant --skill vellum-boundary-guard -a codex`. Or copy the skill folder (.cursor/skills/vellum-boundary-guard in vellum-ai/vellum-assistant) into .agents/skills/vellum-boundary-guard in your project. Codex loads it when a task matches its description.

Can I use Vellum Boundary Guard in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add vellum-ai/vellum-assistant --skill vellum-boundary-guard -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/vellum-boundary-guard, .gemini/skills/vellum-boundary-guard, .github/skills/vellum-boundary-guard and .opencode/skills/vellum-boundary-guard in your project.

What does Vellum Boundary Guard need to run?

SKILL.md names no scripts, command-line tools or credentials: Vellum Boundary Guard is instructions for the agent only.

Does Vellum Boundary Guard access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Vellum Boundary Guard safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Vellum Boundary Guard use?

Vellum Boundary Guard is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Vellum Boundary Guard use?

About 500 tokens (SKILL.md is roughly 2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Vellum Boundary Guard?

Skills that share tags, products or a category with Vellum Boundary Guard: Safety Guard (affaan-m/ECC, 277k stars), Guard Mode (garrytan/gstack, 136k stars), Safety Guard (affaan-m/ECC, 276k stars) and Safety Guard (affaan-m/ECC, 276k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Vellum Boundary Guard?

vellum-ai (a GitHub organization) maintains it in vellum-ai/vellum-assistant, which has 1,408 GitHub stars. The repository holds 108 skills in this directory. The repository was last updated on October 9, 2026.

Source: vellum-ai/vellum-assistant on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.