Agent skill

Blindspot

by vinta in vinta/hal-9000

A skill your agent uses when the user asks for a blindspot pass or to find their unknown unknowns, or signals unfamiliarity with a domain, tool, or codebase area ("never used X", "first time doing…

MITAuto-check passed

Install Blindspot

skills CLI
$ npx skills add vinta/hal-9000 --skill blindspot -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install vinta/hal-9000 blindspot --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/vinta/hal-9000.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/blindspot .claude/skills/blindspot && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
blindspot
GitHub stars
138
Token cost
~1.6k tokens
SKILL.md length
962 words
Files
1
Skills in repo
15
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when the user asks for a blindspot pass or to find their unknown unknowns, or signals unfamiliarity with a domain, tool, or codebase area ("never used X", "first time doing…

  • Works in 5 steps: Recon → Show the territory → Ask which direction → …
  • The user asks for a blindspot pass
  • SKILL.md covers Workflow and Constraints
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Blindspot is an agent skill from vinta/hal-9000. Use when the user asks for a blindspot pass or to find their unknown unknowns, or signals unfamiliarity with a domain, tool, or codebase area ("never used X", "first time doing Y", "no idea where to start", "don't know what I don't know") before working there. Maps the areas their request leaves unnamed, purpose and shape before mechanics, shows how people usually answer each and why, and asks which to explore next, so unknown unknowns become known unknowns they can prompt with. Recommendations on a tool already…

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: Opinionated AI coding agent and dev environment automation for macOS. The licence is MIT.

When your agent uses it

  • The user asks for a blindspot pass
  • Find their unknown unknowns
  • Signals unfamiliarity with a domain
  • Codebase area (never used X

Example prompts

  • “never used X”
  • “first time doing Y”
  • “no idea where to start”
  • “/blindspot”

Requirements

  • Pre-approved tools (allowed-tools): WebSearch

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Recon
  2. Show the territory
  3. Ask which direction
  4. Dig, then repeat
  5. Hand off

What it can do on your machine

Read from SKILL.md and the folder at commit 23243bf. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • WebSearch

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Blindspot loads about 1.6k tokens when it runs. Until then it costs about 140 tokens; SKILL.md has 962 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~140
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from vinta/hal-9000 at commit 23243bf, republished under its MIT licence (© vinta). 962 words, ~1,635 tokens.

Download SKILL.mdSave it as .claude/skills/blindspot/SKILL.md (or your agent's skills folder).
name
blindspot
description
Use when the user asks for a blindspot pass or to find their unknown unknowns, or signals unfamiliarity with a domain, tool, or codebase area ("never used X", "first time doing Y", "no idea where to start", "don't know what I don't know") before working there. Maps the areas their request leaves unnamed, purpose and shape before mechanics, shows how people usually answer each and why, and asks which to explore next, so unknown unknowns become known unknowns they can prompt with. Recommendations on a tool already chosen belong to best-practices
allowed-tools
WebSearch
argument-hint
[unfamiliar topic, tool, or codebase area]

Blindspot

The user is about to work in territory they don't know. Two kinds of blindness live there: unknown unknowns (questions they don't know exist) and unknown knowns (assumptions too obvious to write down, and things they're sure of that are wrong). Convert the first into known unknowns, name the second, then hand back a map they can prompt with.

Boundaries: this skill goes wide over the areas the user's request leaves unnamed, one paragraph each; best-practices goes deep on a topic the user has already named. grilling stress-tests decisions the user can defend; this skill maps territory where they can't decide yet, so it asks which direction to explore, never which option to pick. Neither a tutorial nor a plan.

Workflow

1. Recon

Facts are your job, never the user's. Sweep before writing anything:

  • Goal: the goal the request serves, climbed one level at a time through the request and the repo's records until they run out. The map sits at the highest level still open; the request's own wording is usually the lowest.
  • Premises: what the request and the repo's design records (ADRs, docs, past decisions) take as settled, restated as questions. Premises are the source of idea-level areas; docs and pitfall searches yield mechanics.
  • Repo: the Explore agent in Claude Code or an explorer subagent in Codex, for existing patterns, conventions, and adjacent solutions.
  • Tools and domain: find-docs for current APIs and config; WebSearch in Claude Code or web_search in Codex for pitfalls ("X gotchas", "X common mistakes") — pitfalls live in issue threads and post-mortems, not getting-started docs.

Recon hunts for the areas a practitioner would have on their list that the request never mentions. Done when every area that could reorder the map has its source, recon or a premise, or a note that recon found nothing.

2. Show the territory

Before any question, one reply the user reads, under a page:

  • Framing: the assumptions the request takes for granted, and the missing information that would change the approach, as bullets. These are the unknown knowns; naming them is the point. A premise the user can settle with a word or a fact stays here; one that takes a dig to answer is an area.
  • Areas: numbered, ranked by altitude, then by how much the answer would reorder the rest of the map. Altitudes, top down: what the thing is for and what "better" means; which shape it could take and who owns what; mechanics (APIs, limits, schemas, code seams, tool picks). Mechanics become areas only when nothing above them is open; until then a mechanic recon turned up is one line inside the area it would answer. Idea-level: "is the model a classifier that settles what rules can't, or an author that rewrites the text?"; mechanic: "does the provider accept a string-enum root schema?". Each area is one paragraph: the question an expert would ask here, how people usually answer it and why, and what in this repo or situation makes it bite, with its source: recon or the premise it restates. Where the request already matches usual practice, one line saying so. "No significant unknowns here" is a valid result; a manufactured concern erodes trust faster than a short map.
Show full SKILL.md (426 more words)Show less
3. Ask which direction

Use AskUserQuestion in Claude Code or request_user_input in Codex when available.

One single-select question: the top 3 unexplored areas by number, plus "Enough, hand off". Each option is an area and its description that area's why in one line; every option names an area the reply above explained. The user is choosing where to look, so labels stay unranked: no "(Recommended)". A free-text answer reaches any numbered area.

Round 1 adds one premortem question phrased in past tense — "it's three months later and this failed: what broke?" — past tense recruits prospective hindsight; "what could go wrong" is measurably weaker. Its answer often names the real goal, so re-rank the areas by it. If the user's goal or familiarity is still unclear after recon, round 1 also carries one calibration question.

"You pick" means take the top-ranked area and record the pick as a named assumption.

4. Dig, then repeat

Explore the picked area one altitude down, never two: a goal-level area opens into the shapes it could take; a shape-level area opens into what each costs to build. Only at mechanics does a tool or setup choice go to the best-practices skill; anything else gets the same recon one level down. Show what turned up in the shape of step 2 (sub-areas join the numbered map, unpicked areas stay on it, re-ranked), then ask again. Stop when the user picks "Enough", when a round surfaces nothing new, or when what's left is cheaper to learn while building — say which.

5. Hand off

End with:

  1. Territory map: explored areas with what each dig settled; unexplored areas, each with the usual practice as its default; named assumptions — every open point this skill resolved by guessing gets its own bullet; recon sources cited so the user can dig deeper.
  2. Sharpened prompt draft the user could send: explored areas resolved inline, unexplored ones listed as open questions with their defaults.
  3. Offers, not auto-runs: stress-test the now-visible decisions with the grilling skill, get recommendations via best-practices, or enter plan mode.

Every explored area lands in the map or the prompt draft — a dig that shapes nothing was a wasted round.

Constraints

  • Ask only what recon can't answer: a question the codebase or docs already answer wastes a round and erodes trust.
  • Teach to prompt, not to master. If a findings reply or the hand-off exceeds roughly one page, cut.
  • Ground every fact in recon, not training data: a stale fact plants a false known-known. A question needs no source beyond the premise it restates.

© vinta, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/blindspot of vinta/hal-9000.

Open the folder on GitHubat commit 23243bf

Compare with similar skills

Blindspot next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Blindspot compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Blindspot this skillvinta/hal-9000138—~1.6kAutomated safety check: PassMIT
Blindspot PassNeeeophytee/finding-unknowns-skills343—~482Automated safety check: PassMIT
Blindspot Passjellydn/my-ai-tools123—~1.7kAutomated safety check: NotesMIT
Babysit PR To Pass CIsgl-project/sglang37k2 repos~3kAutomated safety check: PassApache-2.0
Detecting Pass The Hash Attacksmukul975/Anthropic-Cybersecurity-Skills34k—~904Automated safety check: PassApache-2.0
Detecting Pass The Ticket Attacksmukul975/Anthropic-Cybersecurity-Skills34k—~717Automated safety check: PassApache-2.0

Similar skills

  • Blindspot Pass

    Neeeophytee/finding-unknowns-skills

    Surface the user's unknown unknowns before work starts. An agent skill from Neeeophytee/finding-unknowns-skills.

    343 GitHub stars~482 tokensUpdated 10 days ago
    Auto-check passed
  • Blindspot Pass

    jellydn/my-ai-tools

    Inspect history and architecture for hidden constraints before risky cross-cutting changes.

    123 GitHub stars~1.7k tokensUpdated today
    Auto-check: notes
  • Babysit PR To Pass CI

    sgl-project/sglang

    Start and persistently pursue a goal to babysit an SGLang pull request until selected GitHub Actions workflows pass on the latest PR head.

    37k GitHub starsUsed in 2 repos~3k tokens
    DevelopmentAuto-check passed
  • Detecting Pass The Hash Attacks

    mukul975/Anthropic-Cybersecurity-Skills

    Detect Pass-the-Hash (T1550.002) attacks by analyzing NTLM authentication patterns, flagging Type 3 logons using NTLM where Kerberos would be expected, and correlating with credential-dumping…

    34k GitHub stars~904 tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Detecting Pass The Ticket Attacks

    mukul975/Anthropic-Cybersecurity-Skills

    Detect Kerberos Pass-the-Ticket (PtT) attacks by analyzing Windows Event IDs 4768, 4769, and 4771 for anomalous ticket usage patterns, with detection queries for Splunk and Elastic SIEM.

    34k GitHub stars~717 tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Blindspot

    scunning1975/MixtapeTools

    Peripheral vision audit for empirical output. An agent skill from scunning1975/MixtapeTools.

    470 GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed

More from vinta/hal-9000

All 15 skills in this repo
  • Finds which plugins in the repository changed, bumps only the ones not already bumped since origin/main, and checks that each plugin's two manifests stay in sync.

    138 GitHub starsUsed in 1 repo~1k tokens
    Auto-check passed
  • Audits your Claude Code settings and environment variables against the current official docs and returns a ranked list of changes tied to how you actually work.

    138 GitHub stars~1.4k tokensUpdated today
    Auto-check passed
  • Logical Git Commits

    vinta/hal-9000

    Commits everything in the working tree as one logical change per commit, splitting files by hunk, with bodies that say what was wrong before and never an invented reason.

    138 GitHub stars~3.1k tokensUpdated today
    Auto-check passed
  • PR

    vinta/hal-9000

    A skill your agent uses when the user explicitly asks to push the current branch and open a PR, rewrite an open PR's body from its commits, or wait for CI and merge it

    138 GitHub stars~1.4k tokensUpdated today
    Auto-check passed
  • Keeps Ansible install tasks in line with upstream docs by fixing version, install-method and link drift one tool at a time, with a commit for each.

    138 GitHub stars~1.4k tokensUpdated today
    Auto-check passed
  • Rewrites docs, READMEs, issues, comments or UI text in plain Global English that translates well and still sounds native, keeping every fact intact.

    138 GitHub stars~1.1k tokensUpdated today
    Auto-check passed

Questions about Blindspot

What does Blindspot do?

A skill your agent uses when the user asks for a blindspot pass or to find their unknown unknowns, or signals unfamiliarity with a domain, tool, or codebase area ("never used X", "first time doing…. Blindspot is an agent skill from vinta/hal-9000. Use when the user asks for a blindspot pass or to find their unknown unknowns, or signals unfamiliarity with a domain, tool, or codebase area ("never used X", "first time doing Y", "no idea where to start", "don't know what I don't know") before working there.

When should I use Blindspot?

Blindspot fits situations like: the user asks for a blindspot pass; find their unknown unknowns; signals unfamiliarity with a domain; codebase area (never used X.

How do I install Blindspot in Claude Code?

Run `npx skills add vinta/hal-9000 --skill blindspot -a claude-code`. Or copy the skill folder (skills/blindspot in vinta/hal-9000) into .claude/skills/blindspot in your project. Claude Code loads it when a task matches its description.

How do I install Blindspot in Codex?

Run `npx skills add vinta/hal-9000 --skill blindspot -a codex`. Or copy the skill folder (skills/blindspot in vinta/hal-9000) into .agents/skills/blindspot in your project. Codex loads it when a task matches its description.

Can I use Blindspot in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add vinta/hal-9000 --skill blindspot -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/blindspot, .gemini/skills/blindspot, .github/skills/blindspot and .opencode/skills/blindspot in your project.

What does Blindspot need to run?

SKILL.md names no scripts, command-line tools or credentials: Blindspot is instructions for the agent only. Its frontmatter pre-approves these tools: WebSearch.

Does Blindspot access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Blindspot safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Blindspot use?

Blindspot is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Blindspot use?

About 1.6k tokens (SKILL.md is roughly 6.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Blindspot?

Skills that share tags, products or a category with Blindspot: Blindspot Pass (Neeeophytee/finding-unknowns-skills, 343 stars), Blindspot Pass (jellydn/my-ai-tools, 123 stars), Babysit PR To Pass CI (sgl-project/sglang, 37k stars) and Detecting Pass The Hash Attacks (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Blindspot?

vinta (a GitHub user) maintains it in vinta/hal-9000, which has 138 GitHub stars. The repository holds 15 skills in this directory. The repository was last updated on October 7, 2026.

Source: vinta/hal-9000 on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.