Agent skill

Best Practices

by vinta in vinta/hal-9000

A skill your agent uses when about to choose, configure, or refine a tool, library, config format, API pattern, or project setup, or before proposing a design of your own — research current…

MITAuto-check passedLegal & Compliance

Install Best Practices

skills CLI
$ npx skills add vinta/hal-9000 --skill best-practices -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install vinta/hal-9000 best-practices --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/vinta/hal-9000.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/best-practices .claude/skills/best-practices && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
best-practices
GitHub stars
138
Token cost
~553 tokens
SKILL.md length
244 words
Files
1
Skills in repo
15
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when about to choose, configure, or refine a tool, library, config format, API pattern, or project setup, or before proposing a design of your own — research current…

  • Works in 3 steps: Break the topic into 2-4 specific… → Dispatch one subagent per query in a… → Present the recommended approach, key…
  • About to choose
  • SKILL.md covers Two-Phase Rule and Workflow
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Best Practices is an agent skill from vinta/hal-9000. Use when about to choose, configure, or refine a tool, library, config format, API pattern, or project setup, or before proposing a design of your own — research current guidance, pitfalls, and prior art first; already knowing an approach, or assuming no prior art exists, is not an exemption. Also use when the user asks about best practices, gotchas, or recommended patterns

Its SKILL.md is about 550 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Legal & Compliance, covering Intellectual property. The repository describes itself as: Opinionated AI coding agent and dev environment automation for macOS. The licence is MIT.

When your agent uses it

  • About to choose
  • Before proposing a design of your own — research current guidance
  • Prior art first
  • Already knowing an approach

Example prompts

  • “/best-practices”

Requirements

  • Node.js
  • Pre-approved tools (allowed-tools): WebSearch, WebFetch, Bash(ctx7:*), Bash(npx ctx7:*), Bash(npx ctx7@latest:*)

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Break the topic into 2-4 specific queries. Dedicate at least one query to pitfalls ("common mistakes with X", "X gotchas in production")…
  2. Dispatch one subagent per query in a single message, passing model: sonnet on each Agent call. Tell each subagent to use find-docs and web…
  3. Present the recommended approach, key patterns, and gotchas covering every recommendation (not just the primary one), each claim keeping…

What it can do on your machine

Read from SKILL.md and the folder at commit 23243bf. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • WebSearch
    • WebFetch
    • Bash(ctx7:*)
    • Bash(npx ctx7:*)
    • Bash(npx ctx7@latest:*)

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Best Practices loads about 553 tokens when it runs. Until then it costs about 98 tokens; SKILL.md has 244 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~98
When it runs · the whole SKILL.md, loaded when a task matches
~553

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from vinta/hal-9000 at commit 23243bf, republished under its MIT licence (© vinta). 244 words, ~553 tokens.

Download SKILL.mdSave it as .claude/skills/best-practices/SKILL.md (or your agent's skills folder).
name
best-practices
description
Use when about to choose, configure, or refine a tool, library, config format, API pattern, or project setup, or before proposing a design of your own — research current guidance, pitfalls, and prior art first; already knowing an approach, or assuming no prior art exists, is not an exemption. Also use when the user asks about best practices, gotchas, or recommended patterns
allowed-tools
WebSearch, WebFetch, Bash(ctx7:*), Bash(npx ctx7:*), Bash(npx ctx7@latest:*)
argument-hint
[tool, library, pattern, or design to research]

Best Practices

Answer two questions from current sources: what's the recommended way, and what bites people (the gotchas and pitfalls around it). A how-to without its pitfalls is half an answer.

Two-Phase Rule

  • Phase 1: Research. Dispatch find-docs and/or web search queries (WebSearch in Claude Code, web_search in Codex).
  • Phase 2: Synthesize and act. Starts only after Phase 1 results arrive.

The user's argument may be a question or an imperative. Imperatives ("refine X", "set up Y") determine what Phase 2 does, not whether Phase 1 happens. Phase 1 always runs.

Workflow

  1. Break the topic into 2-4 specific queries. Dedicate at least one query to pitfalls ("common mistakes with X", "X gotchas in production"): pitfalls live in issue threads, migration guides, and post-mortems, not in getting-started docs. For design prior-art, dedicate queries to how existing open source projects implement it. For single-library lookups, call find-docs or web search directly without subagents.
  2. Dispatch one subagent per query in a single message, passing model: sonnet on each Agent call. Tell each subagent to use find-docs and web search, and to report in under 400 words: the recommended approach, concrete code/config examples, and every pitfall it found with its consequence, including minor or uncertain ones (its job is coverage; you rank and filter), with each claim citing its source and publication date.
  3. Present the recommended approach, key patterns, and gotchas covering every recommendation (not just the primary one), each claim keeping its source citation.

© vinta, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/best-practices of vinta/hal-9000.

Open the folder on GitHubat commit 23243bf

Compare with similar skills

Best Practices next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Best Practices compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Best Practices this skillvinta/hal-9000138—~553Automated safety check: PassMIT
Paper to Chinese Patent DrafterYuan1z0825/nature-skills46k1 repos~1.1kAutomated safety check: PassApache-2.0
Paper To Cn Patentsnipp-zha/Paper-to-patent-Skill1051 repos~959Automated safety check: PassNone
Patent Examinegfodor/legal-skills393—~4.8kAutomated safety check: PassGPL-3.0
Patent Auditgfodor/legal-skills393—~2.9kAutomated safety check: PassGPL-3.0
Patent Workaroundgfodor/legal-skills393—~5.7kAutomated safety check: PassGPL-3.0

Similar skills

  • Paper to Chinese Patent Drafter

    Yuan1z0825/nature-skills

    Drafts Chinese invention patent applications and technical disclosures from research papers or inventor materials, tying each claim feature to source evidence.

    46k GitHub starsUsed in 1 repo~1.1k tokens
    Legal & ComplianceAuto-check passed
  • Paper To Cn Patent

    snipp-zha/Paper-to-patent-Skill

    Convert scientific papers, theses, technical reports, source code, figures, or research manuscripts into evidence-grounded Chinese invention patent drafts.

    105 GitHub starsUsed in 1 repo~959 tokens
    Legal & ComplianceAuto-check passed
  • Patent Examine

    gfodor/legal-skills

    Iteratively examine and revise a draft U.S. An agent skill from gfodor/legal-skills.

    393 GitHub stars~4.8k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Patent Audit

    gfodor/legal-skills

    Audit a draft U.S. An agent skill from gfodor/legal-skills.

    393 GitHub stars~2.9k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Patent Workaround

    gfodor/legal-skills

    Adversarially pressure-test a draft or pending U.S. An agent skill from gfodor/legal-skills.

    393 GitHub stars~5.7k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Replica Brand

    Jakeschincariol/replica-skill

    Names and rebrands an app clone so it is the user's own: name candidates with the trademark, domain, store and handle checks to run, a new palette checked for contrast, a logo brief, a voice guide…

    908 GitHub stars~1.1k tokensUpdated 5 days ago
    Legal & ComplianceAuto-check passed

More from vinta/hal-9000

All 15 skills in this repo
  • Finds which plugins in the repository changed, bumps only the ones not already bumped since origin/main, and checks that each plugin's two manifests stay in sync.

    138 GitHub starsUsed in 1 repo~1k tokens
    Auto-check passed
  • Audits your Claude Code settings and environment variables against the current official docs and returns a ranked list of changes tied to how you actually work.

    138 GitHub stars~1.4k tokensUpdated today
    Auto-check passed
  • Logical Git Commits

    vinta/hal-9000

    Commits everything in the working tree as one logical change per commit, splitting files by hunk, with bodies that say what was wrong before and never an invented reason.

    138 GitHub stars~3.1k tokensUpdated today
    Auto-check passed
  • PR

    vinta/hal-9000

    A skill your agent uses when the user explicitly asks to push the current branch and open a PR, rewrite an open PR's body from its commits, or wait for CI and merge it

    138 GitHub stars~1.4k tokensUpdated today
    Auto-check passed
  • Keeps Ansible install tasks in line with upstream docs by fixing version, install-method and link drift one tool at a time, with a commit for each.

    138 GitHub stars~1.4k tokensUpdated today
    Auto-check passed
  • Rewrites docs, READMEs, issues, comments or UI text in plain Global English that translates well and still sounds native, keeping every fact intact.

    138 GitHub stars~1.1k tokensUpdated today
    Auto-check passed

Questions about Best Practices

What does Best Practices do?

A skill your agent uses when about to choose, configure, or refine a tool, library, config format, API pattern, or project setup, or before proposing a design of your own — research current…. Best Practices is an agent skill from vinta/hal-9000. Use when about to choose, configure, or refine a tool, library, config format, API pattern, or project setup, or before proposing a design of your own — research current guidance, pitfalls, and prior art first; already knowing an approach, or assuming no prior art exists, is not an exemption.

When should I use Best Practices?

Best Practices fits situations like: about to choose; before proposing a design of your own — research current guidance; prior art first; already knowing an approach.

How do I install Best Practices in Claude Code?

Run `npx skills add vinta/hal-9000 --skill best-practices -a claude-code`. Or copy the skill folder (skills/best-practices in vinta/hal-9000) into .claude/skills/best-practices in your project. Claude Code loads it when a task matches its description.

How do I install Best Practices in Codex?

Run `npx skills add vinta/hal-9000 --skill best-practices -a codex`. Or copy the skill folder (skills/best-practices in vinta/hal-9000) into .agents/skills/best-practices in your project. Codex loads it when a task matches its description.

Can I use Best Practices in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add vinta/hal-9000 --skill best-practices -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/best-practices, .gemini/skills/best-practices, .github/skills/best-practices and .opencode/skills/best-practices in your project.

What does Best Practices need to run?

SKILL.md names no scripts, command-line tools or credentials: Best Practices is instructions for the agent only. Our summary lists: Node.js. Its frontmatter pre-approves these tools: WebSearch, WebFetch, Bash(ctx7:*), Bash(npx ctx7:*), Bash(npx ctx7@latest:*).

Does Best Practices access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Best Practices safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Best Practices use?

Best Practices is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Best Practices use?

About 553 tokens (SKILL.md is roughly 2.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Best Practices?

Skills that share tags, products or a category with Best Practices: Paper to Chinese Patent Drafter (Yuan1z0825/nature-skills, 46k stars), Paper To Cn Patent (snipp-zha/Paper-to-patent-Skill, 105 stars), Patent Examine (gfodor/legal-skills, 393 stars) and Patent Audit (gfodor/legal-skills, 393 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Best Practices?

vinta (a GitHub user) maintains it in vinta/hal-9000, which has 138 GitHub stars. The repository holds 15 skills in this directory. The repository was last updated on October 7, 2026.

Source: vinta/hal-9000 on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.