Agent skill

Gjc SDK Operate

by Yeachan-Heo in Yeachan-Heo/gajae-code

Operate trusted local GJC sessions through a reviewed broker-bound CLI allowlist with single-use human approval.

MITAuto-check passedAgent Workflows

Install Gjc SDK Operate

skills CLI
$ npx skills add Yeachan-Heo/gajae-code --skill gjc-sdk-operate -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Yeachan-Heo/gajae-code gjc-sdk-operate --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Yeachan-Heo/gajae-code.git skills-src && mkdir -p .claude/skills && cp -r skills-src/sdk-skills/gjc-sdk-operate .claude/skills/gjc-sdk-operate && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
gjc-sdk-operate
GitHub stars
2.9k
Token cost
~1.8k tokens
SKILL.md length
907 words
Files
1
Skills in repo
9
Repo updated
First seen
Licence
MIT

At a glance

Operate trusted local GJC sessions through a reviewed broker-bound CLI allowlist with single-use human approval.

  • Works in 8 steps: Select an exact session ID through gjc… → Use only gjc sdk session raw… → Validate the operation against the… → …
  • Agent Workflows work in your project
  • SKILL.md covers Before every operation, Allowed per-session controls, Long-running prompts and Allowed lifecycle operations, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Gjc SDK Operate is an agent skill from Yeachan-Heo/gajae-code. Operate trusted local GJC sessions through a reviewed broker-bound CLI allowlist with single-use human approval.

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Agent Workflows. The licence is MIT.

When your agent uses it

  • Agent Workflows work in your project

Example prompts

  • “/gjc-sdk-operate”

Workflow steps

8 steps, taken from the first numbered list in SKILL.md.

  1. Select an exact session ID through gjc sdk session list --json or a caller-provided stable ID, then fail closed when the Broker cannot…
  2. Use only gjc sdk session raw query|control|global for SDK operations; static help and verified root error-evidence retrieval are…
  3. Validate the operation against the allowlist below. Do not expose arbitrary operation passthrough.
  4. Pass all command data as argv values, never through a shell command string.
  5. For every lifecycle operation, show the exact operation and session target to the human through the external host.
  6. Obtain one explicit approval immediately before the call. Approval is single-use and becomes invalid if the operation, input, or target…
  7. On denial, cancellation, unavailable target, or changed input, send no CLI request.
  8. Add --json explicitly to every machine CLI call. Successful session JSON is unchanged; default ordinary failures are text on stderr…

What it can do on your machine

Read from SKILL.md and the folder at commit 91fe978. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Gjc SDK Operate loads about 1.8k tokens when it runs. Until then it costs about 32 tokens; SKILL.md has 907 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~32
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Yeachan-Heo/gajae-code at commit 91fe978, republished under its MIT licence (© Yeachan-Heo). 907 words, ~1,837 tokens.

Download SKILL.mdSave it as .claude/skills/gjc-sdk-operate/SKILL.md (or your agent's skills folder).
name
gjc-sdk-operate
description
Operate trusted local GJC sessions through a reviewed broker-bound CLI allowlist with single-use human approval.

GJC SDK approved operations

This skill is for trusted local scripts. Its approval challenge is a procedural safety policy, not a security boundary; SDK core retains lifecycle and attachment authority.

Before every operation

  1. Select an exact session ID through gjc sdk session list --json or a caller-provided stable ID, then fail closed when the Broker cannot prove it available.
  2. Use only gjc sdk session raw query|control|global for SDK operations; static help and verified root error-evidence retrieval are discovery-only exceptions. Never scan state roots, read endpoint credentials, or open raw per-session WebSockets.
  3. Validate the operation against the allowlist below. Do not expose arbitrary operation passthrough.
  4. Pass all command data as argv values, never through a shell command string.
  5. For every lifecycle operation, show the exact operation and session target to the human through the external host.
  6. Obtain one explicit approval immediately before the call. Approval is single-use and becomes invalid if the operation, input, or target changes. The templates emit a nonce-bearing, input-bound APPROVE <session> <operation> <digest> <nonce> challenge and read the exact response once from the active process's standard input. Present it verbatim through the external host only after the human accepts that exact action.
  7. On denial, cancellation, unavailable target, or changed input, send no CLI request.
  8. Add --json explicitly to every machine CLI call. Successful session JSON is unchanged; default ordinary failures are text on stderr. Except for session.lookup, consume the single gjc.command-error version 1 stdout envelope on failure, preserve outcome certainty/references, and never publish raw stderr or interpret absent JSON as success. session.lookup deliberately returns a structured reconciliation DTO (ok, operation, status, certainty, error) on stdout and may exit 1 for outcomes such as not_found or conflict; preserve those fields instead of treating the DTO as a malformed failure envelope. Usage exits 2; operation failures exit 1.

Allowed per-session controls

  • turn.prompt
  • turn.steer
  • turn.follow_up
  • ask.answer
  • workflow.gate_answer
  • todo.replace
  • session.switch
  • session.rename

For workflow.gate_answer, use the durable workflow gate ID and pass expectedSessionId. Never use transient action_needed.id as durable authority.

Long-running prompts

The SDK prompt deadline is progress-aware: sdk.promptDeadlineMs (60 min, 60_000–86_400_000) is an inactivity lease renewed only by attributable tool_execution_start / tool_execution_update / tool_execution_end for the exact accepted commandId/turnId, bounded by sdk.promptMaxRuntimeMs (6 h default, 60_000–86_400_000, caps at 24 h). A running tool's partial-result tool_execution_update counts, so a long-running tool that streams output keeps the lease alive mid-run. Persist session_id / turn_id from turn.prompt acceptance and reconcile with turn.result (Q26) rather than replaying blindly. Distinguish the bounded await_turn poll timeout_ms from the SDK terminal deadline; heartbeats, streaming text/thinking deltas, retries, and other-turn activity do not renew the lease.

Allowed lifecycle operations

  • session.create
  • session.fork
  • session.resume
  • session.close
  • session.lookup

Use gjc sdk session raw global --op <operation> --idempotency-key <key> --json-input <object> --json for lifecycle operations. The Broker derives the canonical lifecycle identity; do not create a second lifecycle route or ledger.

Show full SKILL.md (435 more words)Show less

Local help and uncertain outcomes

Before constructing an invocation, consult inert command-local help such as gjc sdk session raw control --help --json. Select --help-section overview|usage|children|arguments|options|examples|recovery and --help-page <N> as needed (defaults overview/1). Follow next.argv with its --help-revision <sha256> and --json unchanged; do not combine revisions. -h is accepted, --help=json is not. Selectors require actual help, no duplicates and positive decimal safe-integer pages. Help is static, not a target probe.

Help/errors/evidence pages are bounded to 8192 UTF-8 bytes; successful results retain their existing contract. A post-acceptance wait_timeout does not undo work. An uncertain-after-send outcome is unknown, not safe to replay. Retain all complete operation/session/idempotency/claim/command/turn references supplied. No hint authorizes extra probes, automatic retry/restart/kill, or repetition of successful targets after mixed failure. Use an explicit task-appropriate status query to reconcile before considering any new approval or replay.

For verified retained evidence only, follow the actual root-family continuation: gjc sdk --error-ref <id> --error-sha256 <digest> [--error-page <N>] [--error-agent-dir <dir>] --json (or gjc daemon for that original family). Placeholders are not executable. Retrieval is exclusive with help/operations, never reruns them and never scans other roots. Records last exactly 24 hours without sliding reads; limits are 64 committed records, 1 MiB each, 16 MiB total, plus one 1 MiB pending file and a 4096-byte lock. Help/success never initializes the store. Concatenate contiguous base64 fragments, verify total bytes and SHA256, then decode UTF-8/JSON; never execute partial fields or paste escaped text display literals as shell argv.

If publication fails (disk, permissions, quota or verification), the error can be incomplete with evidence.status: "unavailable" and continuation: null. Preserve the original certainty and warn against blind retry; do not invent a locator, alternative store or lossless-retrieval guarantee. Even a published record becomes unavailable after expiry or deletion.

Daemon targets are telegram/discord/slack, never SDK: do not suggest gjc daemon restart sdk. Stop/restart can interrupt work and --force permits SIGKILL. session retire is a proof-bound mutation, not a status query, and is outside this skill's allowlist; uncertainty alone does not authorize retirement.

For a lost session.create response, use the read-only lookup with the same request key and create target retained before dispatch:

sh
gjc sdk session raw global --op session.lookup \
  --idempotency-key <create-request-key> \
  --json-input '{"cwd":"/absolute/path/to/repo"}' \
  --json

Lookup never replays creation. Treat not_found as an unknown outcome, not as proof that the create did not execute; found, pending, conflict, uncertain, and terminal remain distinct structured statuses.

Explicitly excluded

  • session.delete
  • managed bash operations
  • configuration mutation
  • authentication mutation
  • permission-mode mutation
  • tool activation mutation
  • extension mutation
  • session cwd mutation
  • endpoint credential display
  • arbitrary SDK operation names

The templates demonstrate one inspection flow and one allowlisted per-session control flow. Keep broader lifecycle orchestration in reviewed scripts that use the documented lifecycle facade and stable idempotency keys.

© Yeachan-Heo, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in sdk-skills/gjc-sdk-operate of Yeachan-Heo/gajae-code.

Open the folder on GitHubat commit 91fe978

Compare with similar skills

Gjc SDK Operate next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Gjc SDK Operate compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Gjc SDK Operate this skillYeachan-Heo/gajae-code2.9k—~1.8kAutomated safety check: PassMIT
MCP Server Builderanthropics/skills180k63 repos~2.3kAutomated safety check: PassApache-2.0
Hook Development for Claude Code Pluginsanthropics/claude-plugins-official38k10 repos~4.1kAutomated safety check: NotesApache-2.0
Using Superpowersfarm-fe/farm5.6k36 repos~1.4kAutomated safety check: PassMIT
Executing Plans Inlineobra/superpowers297k2 repos~5.1kAutomated safety check: PassMIT
Skill CreatorAzure/azqr79689 repos~8.2kAutomated safety check: PassApache-2.0

Similar skills

  • MCP Server Builder

    anthropics/skills

    Official

    Guides the design and implementation of Model Context Protocol servers in TypeScript or Python, from tool naming and error messages to evaluation.

    180k GitHub starsUsed in 63 repos~2.3k tokens
    Agent WorkflowsAuto-check passed
  • Hook Development for Claude Code Plugins

    anthropics/claude-plugins-official

    Official

    Explains how to write Claude Code plugin hooks, both prompt-based checks and bash commands, for events such as PreToolUse, Stop and SessionStart.

    38k GitHub starsUsed in 10 repos~4.1k tokens
    Agent WorkflowsAuto-check: notes
  • Using Superpowers

    farm-fe/farm

    A skill your agent uses when starting any conversation - establishes how to find and use skills, requiring Skill tool invocation before ANY response including clarifying questions

    5.6k GitHub starsUsed in 36 repos~1.4k tokens
    Agent WorkflowsAuto-check passed
  • Executing Plans Inline

    obra/superpowers

    Has the agent carry out an implementation plan itself, task by task in the current session, keeping a ledger, proving each step with a test and ending with one whole-branch review.

    297k GitHub starsUsed in 2 repos~5.1k tokens
    Agent WorkflowsAuto-check passed
  • Skill Creator

    Azure/azqr

    Official

    Create new skills, modify and improve existing skills, and measure skill performance.

    796 GitHub starsUsed in 89 repos~8.2k tokens
    Agent WorkflowsAuto-check passed
  • Claude Code Agent Development

    anthropics/claude-plugins-official

    Official

    Explains how to write agents for Claude Code plugins: the markdown file with YAML frontmatter, trigger descriptions, model and color settings, and system prompt design.

    38k GitHub starsUsed in 7 repos~2.8k tokens
    Agent WorkflowsAuto-check passed

More from Yeachan-Heo/gajae-code

All 9 skills in this repo
  • Autoresearch Improvement Loop

    Yeachan-Heo/gajae-code

    Runs one improvement mission as a bounded loop: each round makes a change, runs a strict JSON evaluator, logs the decision in markdown and continues until a max runtime is hit.

    2.9k GitHub stars~3.6k tokensUpdated yesterday
    Auto-check passed
  • Ralplan Consensus Planning

    Yeachan-Heo/gajae-code

    Shorthand for oh-my-claudecode's consensus planning, where Planner, Architect and Critic agents iterate on a plan before any execution begins.

    2.9k GitHub stars~8.5k tokensUpdated yesterday
    Auto-check passed
  • Ultragoal Multi-Goal Ledger

    Yeachan-Heo/gajae-code

    Breaks a brief into ordered goals, keeps a durable ledger under .omc/ultragoal and prints handoff text so a Claude /goal run survives session restarts.

    2.9k GitHub stars~8.4k tokensUpdated yesterday
    Auto-check passed
  • Gjc Delegation

    Yeachan-Heo/gajae-code

    Delegate planning and execution workflows to gajae-code via the coordinator MCP server.

    2.9k GitHub stars~439 tokensUpdated yesterday
    Auto-check passed
  • Gjc SDK Discover

    Yeachan-Heo/gajae-code

    Discover and inspect trusted local GJC sessions through the broker-bound session CLI.

    2.9k GitHub stars~1k tokensUpdated yesterday
    Auto-check passed
  • Gjc SDK Session

    Yeachan-Heo/gajae-code

    Operate GJC SDK sessions from the CLI (gjc sdk session list|inspect|send|status|tail|close|raw plus the explicit raw control|query|global hatch).

    2.9k GitHub stars~1.2k tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Gjc SDK Operate

What does Gjc SDK Operate do?

Operate trusted local GJC sessions through a reviewed broker-bound CLI allowlist with single-use human approval. Gjc SDK Operate is an agent skill from Yeachan-Heo/gajae-code. Operate trusted local GJC sessions through a reviewed broker-bound CLI allowlist with single-use human approval.

When should I use Gjc SDK Operate?

Gjc SDK Operate fits situations like: agent Workflows work in your project.

How do I install Gjc SDK Operate in Claude Code?

Run `npx skills add Yeachan-Heo/gajae-code --skill gjc-sdk-operate -a claude-code`. Or copy the skill folder (sdk-skills/gjc-sdk-operate in Yeachan-Heo/gajae-code) into .claude/skills/gjc-sdk-operate in your project. Claude Code loads it when a task matches its description.

How do I install Gjc SDK Operate in Codex?

Run `npx skills add Yeachan-Heo/gajae-code --skill gjc-sdk-operate -a codex`. Or copy the skill folder (sdk-skills/gjc-sdk-operate in Yeachan-Heo/gajae-code) into .agents/skills/gjc-sdk-operate in your project. Codex loads it when a task matches its description.

Can I use Gjc SDK Operate in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Yeachan-Heo/gajae-code --skill gjc-sdk-operate -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/gjc-sdk-operate, .gemini/skills/gjc-sdk-operate, .github/skills/gjc-sdk-operate and .opencode/skills/gjc-sdk-operate in your project.

What does Gjc SDK Operate need to run?

SKILL.md names no scripts, command-line tools or credentials: Gjc SDK Operate is instructions for the agent only.

Does Gjc SDK Operate access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Gjc SDK Operate safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Gjc SDK Operate use?

Gjc SDK Operate is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Gjc SDK Operate use?

About 1.8k tokens (SKILL.md is roughly 7.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Gjc SDK Operate?

Skills that share tags, products or a category with Gjc SDK Operate: MCP Server Builder (anthropics/skills, 180k stars), Hook Development for Claude Code Plugins (anthropics/claude-plugins-official, 38k stars), Using Superpowers (farm-fe/farm, 5.6k stars) and Executing Plans Inline (obra/superpowers, 297k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Gjc SDK Operate?

Yeachan-Heo (a GitHub user) maintains it in Yeachan-Heo/gajae-code, which has 2,937 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on October 10, 2026.

Source: Yeachan-Heo/gajae-code on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.