Agent skill

Stack Preview

by vicoa-ai in vicoa-ai/vicoa

Run the whole Vicoa stack (Postgres, backend, realtime server, web dashboard) from the current checkout and publish it at one public tunnel URL, so a branch can be reviewed from another machine or…

AGPL-3.0Auto-check: notesBackend & APIs

Install Stack Preview

skills CLI
$ npx skills add vicoa-ai/vicoa --skill stack-preview -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install vicoa-ai/vicoa stack-preview --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/vicoa-ai/vicoa.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/stack-preview .claude/skills/stack-preview && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
stack-preview
GitHub stars
496
Token cost
~1.8k tokens
SKILL.md length
892 words
Files
5 (incl. scripts)
Skills in repo
3
Repo updated
First seen
Licence
AGPL-3.0

At a glance

Run the whole Vicoa stack (Postgres, backend, realtime server, web dashboard) from the current checkout and publish it at one public tunnel URL, so a branch can be reviewed from another machine or…

  • Works in 4 steps: Start → Seed what the change needs → Check it the way the reviewer will → …
  • Asked for a full-stack
  • SKILL.md covers 1. Start, 2. Seed what the change needs, 3. Check it the way the… and 4. Hand over, plus 2 more sections
  • Runs JavaScript and Shell scripts from its folder; calls git, curl and stripe; needs SUPABASE_ANON_KEY and OWNER_TOKEN

What it does

Stack Preview is an agent skill from vicoa-ai/vicoa. Run the whole Vicoa stack (Postgres, backend, realtime server, web dashboard) from the current checkout and publish it at one public tunnel URL, so a branch can be reviewed from another machine or in the Vicoa app. Use when asked for a full-stack or end-to-end preview link of a Vicoa branch or PR, or when /live-preview is not enough because the dashboard needs a backend.

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts (for example `agents/openai.yaml`, `reference/how-it-works.md` and `scripts/stack-preview.sh`).

It sits in Backend & APIs. It works with PostgreSQL, Flutter, Next.js and Python. The repository describes itself as: Vicoa is the agentic IDE for running a team of coding agents from desktop, mobile, VPS. Open-source, self-hostable. The licence is AGPL-3.0.

When your agent uses it

  • Asked for a full-stack
  • End-to-end preview link of a Vicoa branch
  • /live-preview is not enough because the dashboard needs a backend

Example prompts

  • “/stack-preview”

Requirements

  • Python 3
  • Node.js
  • A Bash shell
  • Docker
  • A credential in SUPABASE_ANON_KEY
  • Pre-approved tools (allowed-tools): Read, Glob, Grep, Bash

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Start
  2. Seed what the change needs
  3. Check it the way the reviewer will
  4. Hand over

What it can do on your machine

Read from SKILL.md and the folder at commit f78cc68. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Glob
    • Grep
    • Bash

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (JavaScript and Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • git
    • curl
    • stripe

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git and curl, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • SUPABASE_ANON_KEY
    • OWNER_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Stack Preview loads about 1.8k tokens when it runs. Until then it costs about 97 tokens; SKILL.md has 892 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~97
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:124
    ackend by hand from `backend/`: `backend/.env` holds real
  • NoteMentions a .env fileSKILL.md:125
    credentials, and the backend reads `.env` from its working directory. The script
  • NoteMentions a .env fileSKILL.md:127
    every key in `apps/web/.env*` for the web server.
  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Glob, Grep, Bash

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from vicoa-ai/vicoa at commit f78cc68, republished under its AGPL-3.0 licence (© vicoa-ai). 892 words, ~1,753 tokens.

Download SKILL.mdSave it as .claude/skills/stack-preview/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
stack-preview
description
Run the whole Vicoa stack (Postgres, backend, realtime server, web dashboard) from the current checkout and publish it at one public tunnel URL, so a branch can be reviewed from another machine or in the Vicoa app. Use when asked for a full-stack or end-to-end preview link of a Vicoa branch or PR, or when /live-preview is not enough because the dashboard needs a backend.
allowed-tools
Read, Glob, Grep, Bash
argument-hint
[up | status | restart | down [--purge]] [--env-file FILE] [--allow-signup]
disable-model-invocation
true

stack-preview

/live-preview tunnels one dev server. The Vicoa dashboard is not one: its browser code calls the REST backend and holds a WebSocket to the agent-facing server, so a tunnel to the web app alone cannot even sign in. This skill runs every piece from the checkout and puts them behind one origin:

browser ──https──▶ tunnel ──▶ proxy :P ─┬─ /ws          → server   (uvicorn, realtime)
                                        ├─ /api/v1/...  → backend  (uvicorn, REST)
                                        └─ everything   → web      (next dev, hot reload)
                   backend + server ──▶ Postgres (throwaway Docker container)

One origin means one link to hand over, no CORS, and realtime works through the tunnel. Everything binds 127.0.0.1; only the tunnel is public.

The script is scripts/stack-preview.sh in this skill's directory. It previews the git checkout of the current directory (a worktree is fine), or --repo DIR.

1. Start

bash
<skill-dir>/scripts/stack-preview.sh up

It creates and migrates the database, opens the tunnel, starts server, backend and web, seeds two accounts, closes sign-up, then checks the page, the API and the WebSocket handshake through the public URL. About 30 s, longer on a first web compile. The result is * key: value lines, the same contract as /live-preview, so the Vicoa app opens the link in Live Preview.

  • status: error means one of those public checks failed. Read the log it names under state:, fix the problem, down, up. Don't hand over a link that failed its own check.
  • "a next dev server already serves apps/web": that server isn't yours. Don't stop it; ask the user.
  • Running up again while the preview is up just prints its status.

Flags:

  • --env-file FILE: KEY=value lines for backend and server, e.g. Stripe test keys, or a PYTHONPATH that adds an overlay package. The preview's own database, URLs and auth settings always win. Never pass a file that holds production credentials.
  • --allow-signup: leave sign-up open (for reviewing the sign-up flow). By default it closes after seeding, because anyone with the link can reach the server.
  • --provider ngrok: by default cloudflared is tried first, then ngrok.
  • --auth supabase: only when the user asks to review the mobile app, which can only sign in with Supabase. Everything else uses the default (builtin), and every up without the flag is builtin again. It signs in with a hosted Supabase project instead of seeded accounts. Export SUPABASE_URL and SUPABASE_ANON_KEY first (apps/mobile/env.json has them). Identity only: the data stays in the preview's database. There are no Ada/Bea accounts, so seeds write rows for the person who signs in (find them in users by email after their first sign-in). Point the app at the preview in the debug branch of apps/mobile/lib/custom_code/actions/vicoa_api_config.dart (https://<public_url> and wss://<public_url>/ws), and never commit that file.

2. Seed what the change needs

A fresh database holds only Ada (ada@example.com, owner) and Bea (bea@example.com, a second person for sharing and permissions). The passwords are in the output. An empty dashboard reviews nothing, so read the diff (git diff origin/main...), list the screens and states it touches, and seed those:

  • Put seed scripts in the state dir (state: in the output), never in the repo.
  • Prefer the API, acting as a real user: curl -H "Authorization: Bearer $OWNER_TOKEN" "$PREVIEW_BACKEND/api/v1/...". This runs the same code the reviewer will use.
  • Write rows directly only for things no endpoint creates (agent sessions and their messages, automation runs). A .py seed can import the models from shared.database. On a branch older than the fix that registers AgentProfile there, flushing an Automation or AgentInstance fails with NoReferencedTableError: agent_profiles; add import shared.database.agent_profile_models.
  • Session status COMPLETED means archived: default lists and share links hide it. For a session that looks finished, use AWAITING_INPUT.
  • Run stack-preview.sh seed FILE. A .py runs in the backend venv with PYTHONPATH set; anything else runs under bash. Seeds get PREVIEW_URL, PREVIEW_BACKEND, DATABASE_URL, OWNER_EMAIL/PASSWORD/TOKEN and the VIEWER_* equivalents. stack-preview.sh env prints the same exports for ad-hoc curl.
  • Use invented data only. The link is public.
Show full SKILL.md (281 more words)Show less

3. Check it the way the reviewer will

Before handing over the link, open it in a headless browser (Playwright) at the public URL: sign in on /sign-in as Ada, open each changed screen, take screenshots, and check the console. Expected noise: 404 /api/v1/billing/* (the open build has no billing) and 401 /api/supabase-user from the sign-in page before login.

4. Hand over

Give the user the public URL, both logins, what you seeded and where to click, and the stop command. Leave the preview running until they say they're done.

While it runs: web edits hot-reload by themselves. After backend changes, run stack-preview.sh restart (default: server and backend; or restart backend|server|web). restart keeps the tunnel, so the link stays valid. down then up keeps the data but gives a new URL.

Stop

stack-preview.sh down stops every process the script started (checked by recorded PID and start time) and the database container; the data survives. down --purge also deletes the container and the state dir. Side processes started with stack-preview.sh run NAME -- CMD... (e.g. a stripe listen forwarding to 127.0.0.1:$PREVIEW_BACKEND_PORT) stop with it.

Rules

  • The script's own Postgres container is the only database. Never point a preview at the shared dev database or at production.
  • Don't start the backend by hand from backend/: backend/.env holds real credentials, and the backend reads .env from its working directory. The script runs Python with an empty environment from an empty directory, and blanks every key in apps/web/.env* for the web server.
  • Stop things only with down or restart. Never pattern-kill: every Next dev server on the machine is titled next-server.

Ports, state files, every variable the script sets, and the traps it works around: reference/how-it-works.md.

© vicoa-ai, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts) in .agents/skills/stack-preview of vicoa-ai/vicoa.

  • SKILL.md
  • agents/openai.yaml
  • reference/how-it-works.md
  • scripts/proxy.mjs
  • scripts/stack-preview.sh

Open the folder on GitHubat commit f78cc68

Compare with similar skills

Stack Preview next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Stack Preview compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Stack Preview this skillvicoa-ai/vicoa496—~1.8kAutomated safety check: NotesAGPL-3.0
Senior Architect Toolkitmaslennikov-ig/claude-code-orchestrator-kit2608 repos~1.2kAutomated safety check: NotesCustom licence
Spec To Repoalirezarezvani/claude-skills28k—~2.7kAutomated safety check: NotesMIT
App BuilderxenitV1/Antigravity-Workflows1309 repos~767Automated safety check: NotesMIT
Tech Stack Recommenderalirezarezvani/claude-cto-team117—~4.3kAutomated safety check: PassMIT
jscpd Code Migration Trackerkucherenko/jscpd6.4k—~5kAutomated safety check: PassMIT

Similar skills

  • Senior Architect Toolkit

    maslennikov-ig/claude-code-orchestrator-kit

    Comprehensive software architecture skill for designing scalable, maintainable systems using ReactJS, NextJS, NodeJS, Express, React Native, Swift, Kotlin…

    260 GitHub starsUsed in 8 repos~1.2k tokens
    DevelopmentAuto-check: notes
  • Spec To Repo

    alirezarezvani/claude-skills

    A skill your agent uses when the user says 'build me an app', 'create a project from this spec', 'scaffold a new repo', 'generate a starter', 'turn this idea into code', 'bootstrap a project', 'I…

    28k GitHub stars~2.7k tokensUpdated 1 mo ago
    Backend & APIsAuto-check: notes
  • App Builder

    xenitV1/Antigravity-Workflows

    Main application building orchestrator. An agent skill from xenitV1/Antigravity-Workflows.

    130 GitHub starsUsed in 9 repos~767 tokens
    DevelopmentAuto-check: notes
  • Tech Stack Recommender

    alirezarezvani/claude-cto-team

    Recommend technology stacks based on project requirements, team expertise, and constraints.

    117 GitHub stars~4.3k tokensUpdated 9 mo ago
    Backend & APIsAuto-check passed
  • Measures a code port between languages or frameworks with jscpd's function-level comparison, porting tests before code and tracking what is left unmatched.

    6.4k GitHub stars~5k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Glasses App

    brilliantlabsAR/brilliant_sdk

    Build an app for Brilliant Labs smart glasses (Halo or Frame) with this SDK, in Python, Flutter or WebBluetooth/TypeScript.

    114 GitHub stars~1.2k tokensUpdated 2 days ago
    MobileAuto-check passed

More from vicoa-ai/vicoa

  • Vicoa CLI

    vicoa-ai/vicoa

    Operate Vicoa from the terminal with the vicoa CLI — list and inspect agent sessions (and their transcripts) across machines, start/resume/stop sessions, manage the task backlog with projects and…

    496 GitHub stars~5.7k tokensUpdated yesterday
    Auto-check passed
  • Live Preview

    vicoa-ai/vicoa

    Start a local app in the current user project, expose it through a tunnel, and return preview details in structured Markdown.

    496 GitHub stars~755 tokensUpdated yesterday
    Auto-check: notes

Questions about Stack Preview

What does Stack Preview do?

Run the whole Vicoa stack (Postgres, backend, realtime server, web dashboard) from the current checkout and publish it at one public tunnel URL, so a branch can be reviewed from another machine or…. Stack Preview is an agent skill from vicoa-ai/vicoa. Run the whole Vicoa stack (Postgres, backend, realtime server, web dashboard) from the current checkout and publish it at one public tunnel URL, so a branch can be reviewed from another machine or in the Vicoa app.

When should I use Stack Preview?

Stack Preview fits situations like: asked for a full-stack; end-to-end preview link of a Vicoa branch; /live-preview is not enough because the dashboard needs a backend.

How do I install Stack Preview in Claude Code?

Run `npx skills add vicoa-ai/vicoa --skill stack-preview -a claude-code`. Or copy the skill folder (.agents/skills/stack-preview in vicoa-ai/vicoa) into .claude/skills/stack-preview in your project. Claude Code loads it when a task matches its description.

How do I install Stack Preview in Codex?

Run `npx skills add vicoa-ai/vicoa --skill stack-preview -a codex`. Or copy the skill folder (.agents/skills/stack-preview in vicoa-ai/vicoa) into .agents/skills/stack-preview in your project. Codex loads it when a task matches its description.

Can I use Stack Preview in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add vicoa-ai/vicoa --skill stack-preview -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/stack-preview, .gemini/skills/stack-preview, .github/skills/stack-preview and .opencode/skills/stack-preview in your project.

What does Stack Preview need to run?

Going by SKILL.md and its folder, Stack Preview needs JavaScript and a shell for the scripts in its folder, the command-line tools its instructions call (git, curl and stripe) and credentials named SUPABASE_ANON_KEY and OWNER_TOKEN. Our summary lists: Python 3; Node.js; A Bash shell; Docker; A credential in SUPABASE_ANON_KEY. Its frontmatter pre-approves these tools: Read, Glob, Grep, Bash.

Does Stack Preview access the network?

SKILL.md contains no URLs. Its commands use git and curl, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Stack Preview safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file; pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Stack Preview use?

Stack Preview is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Stack Preview use?

About 1.8k tokens (SKILL.md is roughly 7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Stack Preview?

Skills that share tags, products or a category with Stack Preview: Senior Architect Toolkit (maslennikov-ig/claude-code-orchestrator-kit, 260 stars), Spec To Repo (alirezarezvani/claude-skills, 28k stars), App Builder (xenitV1/Antigravity-Workflows, 130 stars) and Tech Stack Recommender (alirezarezvani/claude-cto-team, 117 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Stack Preview?

vicoa-ai (a GitHub organization) maintains it in vicoa-ai/vicoa, which has 496 GitHub stars. The repository holds 3 skills in this directory. The repository was last updated on October 8, 2026.

Source: vicoa-ai/vicoa on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.