Agent Prompt Engineering
agentailor/fullstack-langgraph-nextjs-agent
Comprehensive guide for designing, refining, and auditing system prompts for autonomous AI agents based on Anthropic's production practices.
Integrate Java business systems with ReachAI SDK registration, SDK instance heartbeat, gateway/embed access, and optional API Management handoff.
$ npx skills add w8123/EnterpriseAgentFramework --skill reachai-onboarding -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install w8123/EnterpriseAgentFramework reachai-onboarding --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/w8123/EnterpriseAgentFramework.git skills-src && mkdir -p .claude/skills && cp -r skills-src/reachai-control-service/src/main/resources/ai-assist/skills/reachai-onboarding .claude/skills/reachai-onboarding && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "reachai-onboarding" agent skill from https://github.com/w8123/EnterpriseAgentFramework/tree/main/reachai-control-service/src/main/resources/ai-assist/skills/reachai-onboarding into .claude/skills/reachai-onboarding/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "reachai-onboarding", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/w8123/EnterpriseAgentFramework/tree/main/reachai-control-service/src/main/resources/ai-assist/skills/reachai-onboardingType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add w8123/EnterpriseAgentFramework --skill reachai-onboarding -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install w8123/EnterpriseAgentFramework reachai-onboarding --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/w8123/EnterpriseAgentFramework.git skills-src && mkdir -p .agents/skills && cp -r skills-src/reachai-control-service/src/main/resources/ai-assist/skills/reachai-onboarding .agents/skills/reachai-onboarding && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "reachai-onboarding" agent skill from https://github.com/w8123/EnterpriseAgentFramework/tree/main/reachai-control-service/src/main/resources/ai-assist/skills/reachai-onboarding into .agents/skills/reachai-onboarding/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "reachai-onboarding", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add w8123/EnterpriseAgentFramework --skill reachai-onboarding -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install w8123/EnterpriseAgentFramework reachai-onboarding --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/w8123/EnterpriseAgentFramework.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/reachai-control-service/src/main/resources/ai-assist/skills/reachai-onboarding .cursor/skills/reachai-onboarding && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "reachai-onboarding" agent skill from https://github.com/w8123/EnterpriseAgentFramework/tree/main/reachai-control-service/src/main/resources/ai-assist/skills/reachai-onboarding into .cursor/skills/reachai-onboarding/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "reachai-onboarding", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/w8123/EnterpriseAgentFramework.git --path reachai-control-service/src/main/resources/ai-assist/skills/reachai-onboarding--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add w8123/EnterpriseAgentFramework --skill reachai-onboarding -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install w8123/EnterpriseAgentFramework reachai-onboarding --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/w8123/EnterpriseAgentFramework.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/reachai-control-service/src/main/resources/ai-assist/skills/reachai-onboarding .gemini/skills/reachai-onboarding && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "reachai-onboarding" agent skill from https://github.com/w8123/EnterpriseAgentFramework/tree/main/reachai-control-service/src/main/resources/ai-assist/skills/reachai-onboarding into .gemini/skills/reachai-onboarding/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "reachai-onboarding", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install w8123/EnterpriseAgentFramework reachai-onboardingInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add w8123/EnterpriseAgentFramework --skill reachai-onboarding -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/w8123/EnterpriseAgentFramework.git skills-src && mkdir -p .github/skills && cp -r skills-src/reachai-control-service/src/main/resources/ai-assist/skills/reachai-onboarding .github/skills/reachai-onboarding && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "reachai-onboarding" agent skill from https://github.com/w8123/EnterpriseAgentFramework/tree/main/reachai-control-service/src/main/resources/ai-assist/skills/reachai-onboarding into .github/skills/reachai-onboarding/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "reachai-onboarding", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add w8123/EnterpriseAgentFramework --skill reachai-onboarding -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install w8123/EnterpriseAgentFramework reachai-onboarding --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/w8123/EnterpriseAgentFramework.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/reachai-control-service/src/main/resources/ai-assist/skills/reachai-onboarding .opencode/skills/reachai-onboarding && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "reachai-onboarding" agent skill from https://github.com/w8123/EnterpriseAgentFramework/tree/main/reachai-control-service/src/main/resources/ai-assist/skills/reachai-onboarding into .opencode/skills/reachai-onboarding/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "reachai-onboarding", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
reachai-onboardingIntegrate Java business systems with ReachAI SDK registration, SDK instance heartbeat, gateway/embed access, and optional API Management handoff.
Reachai Onboarding is an agent skill from w8123/EnterpriseAgentFramework. Integrate Java business systems with ReachAI SDK registration, SDK instance heartbeat, gateway/embed access, and optional API Management handoff. Use when asked to connect a Spring Boot service to ReachAI, add reachai-capability-sdk or reachai-spring-boot2-starter, configure reachai.registry/reachai.project/reachai.capability, prepare @ReachCapability metadata for later manual SDK sync, or verify SDK onboarding from a ReachAI manifest.
Its SKILL.md is about 6.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 41 other files, including scripts and reference files (for example `agents/openai.yaml`, `artifacts/manifest-artifact.json` and `examples/gateway/README.md`).
It sits in AI & LLM Engineering, covering Backend development and Building AI agents. It works with Java, Spring Boot, Model Context Protocol and LangGraph. The repository describes itself as: ReachAI企业级智能体开发平台:快速、安全完成已有业务系统智能化改造,让 AI 在 OA、ERP、CRM 等原系统中查数据、填表单、办业务。ReachAI: Quickly and securely bring AI to existing enterprise systems, enabling AI to query data, fill out… The licence is MIT.
12 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 7179aab. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Java, from the files we listed), which the agent can run.
Shell commands in SKILL.md call:
npmnodeFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
REACHAI_REGISTRY_APP_SECRETREACHAI_AI_CODING_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Reachai Onboarding loads about 6.1k tokens when it runs, and up to ~27k if it reads all its reference files. Until then it costs about 115 tokens; SKILL.md has 2,892 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from w8123/EnterpriseAgentFramework at commit 7179aab, republished under its MIT licence (© w8123). 2,892 words, ~6,068 tokens.
.claude/skills/reachai-onboarding/SKILL.md (or your agent's skills folder). This skill also uses 33 other files; get the full folder from GitHub.Treat the current business repository as the source of truth. Inspect its Maven modules, Java version, Spring Boot version, configuration files, existing controller/service boundaries, and test commands before editing.
凡是写入 ReachAI 或展示给业务用户的名称、标题、描述、说明、System Prompt、节点名称、审计原因、进度和结果,默认使用清晰的简体中文。不要仅因 API、Schema 或字段名为英文就生成英文业务文案。Token、MCP、AI、Agent、Supervisor、Workflow、Tool、API、SDK 等熟知专业术语,以及 keySlug、toolName、代码、路径、枚举值、协议字段和技术标识可保留英文;必要时使用“中文名称(英文术语)”。不要翻译或改写技术标识。
Never paste, print, or commit the registry app secret. Use the environment variable named by the manifest, normally REACHAI_REGISTRY_APP_SECRET.
ReachAI task handoffs use a one-time activation code. Activate it once, keep the returned short-lived task token only in the current process, and call /api/ai-coding/tasks/{taskId}/** with Authorization: Bearer <taskToken>. Never reuse a project-level aiCodingKey on task protocol routes.
Separate project/Workflow AI Coding APIs under /api/ai-coding/projects/** and /api/workflows/**/ai-coding/** can still use the explicit project aiCodingKey when the user independently supplies one. Send it as X-ReachAI-AiCoding-Key; never put it in a URL, browser bundle, task artifact, or progress event.
Prefer minimal, reviewable changes:
reachai-spring-boot2-starter in the runnable Spring Boot application module.reachai-capability-sdk in modules that declare @ReachCapability methods or DTO field metadata.@ReachCapability is method-level, @ReachParam is parameter/field-level, and @ReachOutput is field-only on response DTO fields. Do not put @ReachOutput on methods.sdkArtifacts, expand {skillExtractDir} in each installCommandTemplate, and run reachai-capability-sdk before reachai-spring-boot2-starter. The bundled scripts/install-java-sdk.ps1 downloads the declared JAR and standalone consumer POM, verifies both declared SHA-256 values, and installs that exact coordinate into the business system's Maven local repository. Fail if a URL or hash is absent or mismatched; do not guess another URL and do not require access to the ReachAI repository.sdkArtifacts for @reachai/embed-chat, extract this Skill zip anywhere, then run the expanded installCommandTemplate from the business frontend directory that contains package.json. The bundled scripts/install-embed-chat.mjs verifies integritySha256, copies the tgz to the stable repo-local vendor/reachai/ directory, replaces the exact installed package directory, and records .reachai-artifact-sha256. Re-run this installer whenever a SNAPSHOT artifact checksum changes; npm install --force alone does not prove that a same-version file dependency was refreshed. reachai-doctor --mode static reports EMBED_SDK_ARTIFACT_MATCH. Never run npm install directly against a temporary Skill extract path, and never leave %TEMP%, .cursor, .trae or another machine-specific absolute path in package.json / lockfiles. Authenticated downloadUrl needs auth headers that npm cannot send, so prefer this Skill-bundled installer./repository/**, /maven/**, /repository/maven/**, /api/embed/sdk, or /npm/**. Do not use cd ai-admin-front && npm run build:sdk as the business-project install path.gatewayChecklist object list on the onboarding manifest (id, description, required, verificationHint, failureImpact). See references/java-sdk-access.md.PROJECT_ONBOARDING task may explicitly trigger exactly one audited SDK sync with POST <taskRoot>/verifications/SDK_SYNC; the task token scopes that operation to its own project. The equivalent console action remains API Management(API 管理)手动触发的 SDK 同步. Restrict both paths to business-owned packages and never include framework, platform, third-party, starter, or shared infrastructure controllers as business APIs.GET <taskRoot>/context first. Otherwise read the explicitly supplied onboarding manifest URL.application.yml, bootstrap.yml, profile-specific config, or config-center conventions.sdkArtifacts, references/java-sdk-access.md, and templates/pom-dependencies.xml. Platform artifact links are the default when no corporate Maven publication exists.templates/application-reachai.yml. Do not add any capability startup-sync setting. Replace package placeholders only when preparing the explicit SDK sync boundary. Set reachai.project.base-url to an address reachable from the ReachAI server; use localhost, 127.0.0.1, or ::1 only when ReachAI and the business service actually share the same host or network namespace.@ReachCapability / @ReachParam. Use templates/reach-capability-example.java only as a style example.POST /reachai/registry/capabilities/sync to the Starter service through the configured base-url and context-path.X-ReachAI-Invocation-Token, X-ReachAI-Trace-Id, X-ReachAI-Run-Id, and the business identity headers required by the service.reachai.project.base-url points to a gateway or ingress, route /reachai/registry/** to the business service that contains reachai-spring-boot2-starter. Preserve X-ReachAI-App-Key, X-ReachAI-Timestamp, X-ReachAI-Nonce, and X-ReachAI-Signature.POST /reachai/registry/capabilities/sync bypass normal business login/JWT filters and CSRF so the request reaches the Starter controller. Apply the equivalent exclusion for Spring Security, Sa-Token, Shiro, or custom interceptors. Do not remove authentication from the endpoint: the Starter must still validate the ReachAI registry signature and return 401 for invalid requests./api/reachai/embed-token.ReachAiEmbedTokenClient. Business code maps the current authenticated user to ReachAiEmbedPrincipal and forwards the SDK-owned page identity; the client owns project signing, transport, and wrapped data.token parsing./api/reachai/embed-token on the normal business login token path. It reads the current business user and exchanges that identity for a ReachAI embed token./api/reachai/embed/**. This path carries ReachAI embed tokens, so business OAuth/JWT filters must not validate it as a business login token; forward Authorization: Bearer <embedToken> unchanged to ReachAI.permitAll() on /api/reachai/embed/** is not enough by itself: the resource server can still try to authenticate the Bearer <embedToken> before routing and return 401. Add a higher-priority SecurityWebFilterChain with securityMatcher(ServerWebExchangeMatchers.pathMatchers("/api/reachai/embed/**")) that permits all and does not enable oauth2ResourceServer() for that matcher.IgnoreUrlsRemoveJwtFilter, RemoveJwtFilter, RemoveRequestHeader=Authorization, or security filters that call mutate().header("Authorization", ""). Do not apply that header-clearing behavior to /api/reachai/embed/**; skipping business authentication must still preserve the embed token Authorization header./api/reachai/embed/**, dedupe duplicate CORS response headers when both the gateway and ReachAI write them. A typical route filter is DedupeResponseHeader=Access-Control-Allow-Origin Access-Control-Allow-Credentials, RETAIN_FIRST.domainContext.implementationGuidance.projectCopilotKeySlug as the front-end agentId; ReachAI Control owns idempotent Agent/Supervisor provisioning before handoff. Do not request a project key from the user or call project-key provisioning APIs from the task.manifest.agentProvisioning.provisionAgentUrl remains available to an AI coding tool, local shell, or server-side integration. It is idempotent and creates or reuses the project page copilot Agent, selects an active LLM model, and publishes an ACTIVE AgentScope Supervisor config. It does not create a placeholder Workflow.manifest.agentSupervisor.endpoints.skillPackageUrl and follow the agent-ai-coding Skill. Use only the project-key endpoints in that manifest; never call console /api/agents/** or /api/skills/** with an AI Coding key.manifest.agentSupervisor.endpoints.workflowToolAttachUrlTemplate; the attach operation publishes the next Agent config version containing that Workflow-as-Tool.replaceWorkflowId; ReachAI removes only that entry and preserves every other Workflow. Never infer replacement from pageKey, name, or display order.PAGE_ASSISTANT for page behavior and a read-only GENERAL Workflow for the API chain. Agent risk is declared per attached Workflow, not per branch inside one mixed graph.aiCodingKey to the business front end.appSecret into browser code.manifest.agentProvisioning.provisionAgentUrl from browser runtime code. Use the already provisioned bare JSON agent.keySlug as agentId (not data.agent.keySlug).@reachai/embed-chat for browser embedding when available. Configure apiBase as the ReachAI platform origin by default; if the browser uses a gateway prefix, set embedPathPrefix such as /api/reachai/embed, or set apiBase directly to a recognized embed root such as /api/reachai/embed.projectCode, agentId, and a tokenProvider that calls the business gateway token broker. Use the already provisioned page copilot Agent keySlug for agentId.pageKey, pageInstanceId, route, and origin from the @reachai/embed-chat tokenProvider context and forward them unchanged through the business token broker. The SDK reuses the same Page Bridge identity for Chat Session creation and page actions.createEafPageBridge({ onNavigate }) adapter. Validate the requested target against the business route registry, use the normal router to navigate, then call chat.rebindPage({ bridge, page }) from the target page only after its actions are registered. Do not register or hard-code the reserved navigation action key, session id, or navigation request id; the public SDK owns those details.pageInstanceId in the token provider or business broker. A replacement UUID may make token exchange pass while causing Chat Session or Page Action identity mismatch.@reachai/embed-chat/style.css, mount one visible global launcher, and keep the SDK's visible-first Token state: Token Broker pending/failure must remain visible and retryable instead of being replaced by a business-side hidden failure./api/reachai/embed/**, /api/embed/chat/sessions, and message APIs.POST /api/embed/chat/sessions/{sessionId}/messages or the /messages/stream variant with body { "message": "..." }.{ "content": "..." }, { "text": "..." }, or { "question": "..." }; map any business UI field to message at the ReachAI API boundary.code/message describe transport status only; never render top-level message: "success" as the assistant reply. Render data.answer first, with old-shape fallback only under data.reply, data.message, or data.content.message.completed; there is no done event.references/platform-apis.md for ApiResult vs bare JSON response shapes and apiBase rules.data.metadata.pageActionQueue as the preferred UI/Page Action queue. Treat data.uiRequest and data.uiRequest.extension.pageActionRequest as compatible single-action instructions. Execute them through the page bridge and report each request id back to /api/embed/chat/sessions/{sessionId}/page-actions/{requestId}/result; do not only render data.answer.references/page-action-contract.md. For Angular, reuse references/angular-page-action.md and templates/angular/ rather than inventing a second bridge protocol.powershell -File scripts/reachai-page-actions.ps1 -Mode scaffold-angular -FrontendRoot <frontend> -PageKey <pageKey>.
Adapt the generated registry example to the page's real component methods. Scaffolding is not runtime verification.powershell -File scripts/reachai-page-actions.ps1 -Mode verify-static -FrontendRoot <frontend> -PageKey <pageKey> -ActionKeys <keys>.
A static PASS proves only source alignment; use an authenticated browser and a fresh Embed session before reporting runtime PASS. Use only an existing authorized business-system test session or account supplied outside ReachAI. If none is available, keep browserVerification null and report browser acceptance as NOT RUN; never fabricate evidence or place login credentials in task artifacts.expiresIn boundary. If a session or message request returns embed token is expired, clear the cached embed token, call the broker again, and retry once.sdkAccessCheckUrl only after local compile/config succeeds, or explain why a live check cannot run.CODE_READY requires observed Starter registration, RUNTIME_READY requires a fresh instance heartbeat, and SDK_CALLBACK_READY requires a successful signed callback plus a received capability snapshot.CODE_READY and RUNTIME_READY are observed, explicitly call POST <taskRoot>/verifications/SDK_SYNC with the task Bearer token. No body is required. This operation is project-scoped, succeeds only for a RUNNING onboarding task, and writes a verification event back to the task.E2E_READY remains pending until ReachAI observes an authorized Embed session, user message and assistant reply created after the current task started. The session may come from the real browser SDK or from reachai-doctor --mode e2e using a business-supplied test Authorization/Cookie; doctor never mints or mocks the business identity. This proves only the authorized conversation protocol: declared Workflow capability nodes and Page Actions need their own exact-Trace / real-browser evidence in the Page Workbench. Final launcher visibility and interaction quality remain user acceptance items.protocolGuide.eventStateRules and write real STARTED / PROGRESS events to the current task. While the task is WAITING_USER, you may report work that does not depend on the answer with PROGRESS; it preserves WAITING_USER and every open question. Submit blocking ambiguities through /questions, poll for the user's answer, then write RESUMED only after all answers have been read. Before submission, run the Bootstrap-provided Test-ReachAiArtifact -Content <artifact-content> local schema check; Send-ReachAiArtifact runs the same check again before posting. Finish by submitting exactly one artifact matching the JSON Schema in task context; never invent success evidence.references/java-sdk-api-reference.md;
then use references/java-sdk-access.md for placement, configuration and
runtime boundaries.references/platform-apis.md.references/embed-chat-quick-reference.md.references/gateway-examples.md and reuse the copy-ready files under examples/gateway/.references/security.md.references/page-action-contract.md.references/angular-page-action.md.templates/.scripts/verify-reachai-access.py.node scripts/reachai-doctor.mjs --mode static --business-root <repo> and then node scripts/reachai-doctor.mjs --mode runtime --manifest-url <onboardingManifestUrl> after services are available. For /api/ai-coding/projects/**, put the project AI Coding key in the current process environment variable REACHAI_AI_CODING_KEY; never pass the key as a command-line argument. Use --ai-coding-key-env <name> only when the repository already uses another secret environment variable name.REACHAI_E2E_AUTHORIZATION or the business Cookie header in REACHAI_E2E_COOKIE, then run node scripts/reachai-doctor.mjs --mode e2e --broker-url <business-origin>/api/reachai/embed-token --embed-api-base <business-origin>/api/reachai/embed --agent-id <provisioned-key-slug> --page-key <page-key> --route <route>. Never put authorization values on the command line or into task events/artifacts. EMBED_CONVERSATION_E2E=PASS proves only the authorized broker/proxy/session/message protocol; doctor deliberately leaves WORKFLOW_CAPABILITY_E2E and PAGE_ACTION_BROWSER_E2E as PENDING until real intent and real browser evidence are available. It does not prove launcher visibility.scripts/set-reachai-registry-secret.ps1. It stores the value in the current Windows user environment and never prints it; start a new terminal/process before launching the business service.scripts/reachai-page-actions.ps1.End with:
REACHAI_REGISTRY_APP_SECRET still needs to be configured outside the repository.© w8123, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 33 other files (scripts, references) in reachai-control-service/src/main/resources/ai-assist/skills/reachai-onboarding of w8123/EnterpriseAgentFramework.
Open the folder on GitHubat commit 7179aab
Reachai Onboarding next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Reachai Onboarding this skillw8123/EnterpriseAgentFramework | 865 | — | ~6.1k | Automated safety check: Pass | MIT | |
| Agent Prompt Engineeringagentailor/fullstack-langgraph-nextjs-agent | 132 | — | ~3.6k | Automated safety check: Pass | MIT | |
| Agent Inspectrajudandigam/agent-inspect | 165 | — | ~424 | Automated safety check: Pass | MIT | |
| Tool Designagentailor/fullstack-langgraph-nextjs-agent | 132 | — | ~3.2k | Automated safety check: Pass | MIT | |
| Agent Eval Casesagentailor/fullstack-langgraph-nextjs-agent | 132 | — | ~5.3k | Automated safety check: Pass | MIT | |
| Bootui Java Developmentjdubois/boot-ui | 315 | — | ~1.3k | Automated safety check: Pass | Apache-2.0 |
agentailor/fullstack-langgraph-nextjs-agent
Comprehensive guide for designing, refining, and auditing system prompts for autonomous AI agents based on Anthropic's production practices.
rajudandigam/agent-inspect
Local evidence debugger and trajectory-test toolkit for TypeScript AI agents.
agentailor/fullstack-langgraph-nextjs-agent
Design and verify tools that AI agents can actually use — for any framework or language (MCP servers, LangChain/LangGraph, function-calling, raw JSON schema; TypeScript, Python, or otherwise).
agentailor/fullstack-langgraph-nextjs-agent
Decide which AI agent behaviors are worth an eval case, then write those cases — harness-, framework-, and language-agnostic.
jdubois/boot-ui
A skill your agent uses when implementing, debugging, refactoring, or testing existing BootUI Java code, including framework-neutral engine logic, Spring MVC and WebFlux adapters, Quarkus runtime…
ruanrongman/IntelliConnect
Create or update IntelliConnect Spring Boot service/serviceimpl code in this repository style.
w8123/EnterpriseAgentFramework
Edit, validate, debug, publish, and inspect ReachAI Workflow drafts through the Workflow AI Coding REST API.
w8123/EnterpriseAgentFramework
Create, inspect, and safely update project-scoped ReachAI Agents; edit and publish Supervisor config drafts; discover published bindable Skills; and attach or detach exact Skill versions through the…
Categories
Integrate Java business systems with ReachAI SDK registration, SDK instance heartbeat, gateway/embed access, and optional API Management handoff. Reachai Onboarding is an agent skill from w8123/EnterpriseAgentFramework. Integrate Java business systems with ReachAI SDK registration, SDK instance heartbeat, gateway/embed access, and optional API Management handoff.
Reachai Onboarding fits situations like: asked to connect a Spring Boot service to ReachAI; add reachai-capability-sdk; reachai-spring-boot2-starter; configure reachai.registry/reachai.project/reachai.capability.
Run `npx skills add w8123/EnterpriseAgentFramework --skill reachai-onboarding -a claude-code`. Or copy the skill folder (reachai-control-service/src/main/resources/ai-assist/skills/reachai-onboarding in w8123/EnterpriseAgentFramework) into .claude/skills/reachai-onboarding in your project. Claude Code loads it when a task matches its description.
Run `npx skills add w8123/EnterpriseAgentFramework --skill reachai-onboarding -a codex`. Or copy the skill folder (reachai-control-service/src/main/resources/ai-assist/skills/reachai-onboarding in w8123/EnterpriseAgentFramework) into .agents/skills/reachai-onboarding in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add w8123/EnterpriseAgentFramework --skill reachai-onboarding -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/reachai-onboarding, .gemini/skills/reachai-onboarding, .github/skills/reachai-onboarding and .opencode/skills/reachai-onboarding in your project.
Going by SKILL.md and its folder, Reachai Onboarding needs Java for the scripts in its folder, the command-line tools its instructions call (npm and node) and credentials named REACHAI_REGISTRY_APP_SECRET and REACHAI_AI_CODING_KEY. Our summary lists: Node.js; A credential in REACHAI_REGISTRY_APP_SECRET.
SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Reachai Onboarding is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 6.1k tokens (SKILL.md is roughly 24k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 21k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Reachai Onboarding: Agent Prompt Engineering (agentailor/fullstack-langgraph-nextjs-agent, 132 stars), Agent Inspect (rajudandigam/agent-inspect, 165 stars), Tool Design (agentailor/fullstack-langgraph-nextjs-agent, 132 stars) and Agent Eval Cases (agentailor/fullstack-langgraph-nextjs-agent, 132 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
w8123 (a GitHub user) maintains it in w8123/EnterpriseAgentFramework, which has 865 GitHub stars. The repository holds 3 skills in this directory. The repository was last updated on October 7, 2026.
Source: w8123/EnterpriseAgentFramework on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.