MCP Server Builder
anthropics/skills
Guides the design and implementation of Model Context Protocol servers in TypeScript or Python, from tool naming and error messages to evaluation.
Guidelines for safe subprocess calls in opencode-swarm. An agent skill from ZaxbyHub/opencode-swarm.
$ npx skills add ZaxbyHub/opencode-swarm --skill subprocess-safety -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install ZaxbyHub/opencode-swarm subprocess-safety --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/ZaxbyHub/opencode-swarm.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/subprocess-safety .claude/skills/subprocess-safety && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "subprocess-safety" agent skill from https://github.com/ZaxbyHub/opencode-swarm/tree/main/.agents/skills/subprocess-safety into .claude/skills/subprocess-safety/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "subprocess-safety", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/ZaxbyHub/opencode-swarm/tree/main/.agents/skills/subprocess-safetyType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add ZaxbyHub/opencode-swarm --skill subprocess-safety -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install ZaxbyHub/opencode-swarm subprocess-safety --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ZaxbyHub/opencode-swarm.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/subprocess-safety .agents/skills/subprocess-safety && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "subprocess-safety" agent skill from https://github.com/ZaxbyHub/opencode-swarm/tree/main/.agents/skills/subprocess-safety into .agents/skills/subprocess-safety/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "subprocess-safety", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ZaxbyHub/opencode-swarm --skill subprocess-safety -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install ZaxbyHub/opencode-swarm subprocess-safety --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ZaxbyHub/opencode-swarm.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/subprocess-safety .cursor/skills/subprocess-safety && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "subprocess-safety" agent skill from https://github.com/ZaxbyHub/opencode-swarm/tree/main/.agents/skills/subprocess-safety into .cursor/skills/subprocess-safety/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "subprocess-safety", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/ZaxbyHub/opencode-swarm.git --path .agents/skills/subprocess-safety--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add ZaxbyHub/opencode-swarm --skill subprocess-safety -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install ZaxbyHub/opencode-swarm subprocess-safety --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ZaxbyHub/opencode-swarm.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/subprocess-safety .gemini/skills/subprocess-safety && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "subprocess-safety" agent skill from https://github.com/ZaxbyHub/opencode-swarm/tree/main/.agents/skills/subprocess-safety into .gemini/skills/subprocess-safety/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "subprocess-safety", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install ZaxbyHub/opencode-swarm subprocess-safetyInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add ZaxbyHub/opencode-swarm --skill subprocess-safety -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/ZaxbyHub/opencode-swarm.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/subprocess-safety .github/skills/subprocess-safety && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "subprocess-safety" agent skill from https://github.com/ZaxbyHub/opencode-swarm/tree/main/.agents/skills/subprocess-safety into .github/skills/subprocess-safety/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "subprocess-safety", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ZaxbyHub/opencode-swarm --skill subprocess-safety -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install ZaxbyHub/opencode-swarm subprocess-safety --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ZaxbyHub/opencode-swarm.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/subprocess-safety .opencode/skills/subprocess-safety && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "subprocess-safety" agent skill from https://github.com/ZaxbyHub/opencode-swarm/tree/main/.agents/skills/subprocess-safety into .opencode/skills/subprocess-safety/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "subprocess-safety", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
subprocess-safetyGuidelines for safe subprocess calls in opencode-swarm. An agent skill from ZaxbyHub/opencode-swarm.
Subprocess Safety is an agent skill from ZaxbyHub/opencode-swarm. Guidelines for safe subprocess calls in opencode-swarm. Load before adding, modifying, or reviewing any file that calls spawn, spawnSync, bunSpawn, or childprocess. Covers the six required properties, Windows portability, internals DI seam pattern, and verification grep.
Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Agent Workflows. The repository describes itself as: Architect-centric agentic swarm plugin for OpenCode. Hub-and-spoke orchestration with SME consultation, code generation, and QA review. The licence is MIT.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit b63a4bd. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
ghgitbunFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use gh and git, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Subprocess Safety loads about 2.4k tokens when it runs. Until then it costs about 73 tokens; SKILL.md has 957 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from ZaxbyHub/opencode-swarm at commit b63a4bd, republished under its MIT licence (© ZaxbyHub). 957 words, ~2,403 tokens.
.claude/skills/subprocess-safety/SKILL.md (or your agent's skills folder).Read, in order:
AGENTS.md (Invariant 3: subprocesses)docs/engineering-invariants.md (subsection 3).agents/skills/writing-tests/SKILL.md if tests are touched.opencode/skills/generated/mock-to-internals-migration/SKILL.md if converting mock.module to _internalsCodex-specific execution notes:
bun run check:invariants (Check 1: subprocess timeout).bunSpawn, spawn,
spawnSync, child_process.execFile, etc.)This skill applies to all files that spawn child processes:
src/utils/git*.tssrc/hooks/*.tssrc/tools/*.tssrc/services/*.tssrc/plugins/*.tssrc/index.ts (init-path subprocesses)tests/**) that stubs or exercises subprocess codeEvery subprocess call MUST follow this pattern:
const PER_CALL_TIMEOUT_MS = 10_000; // module-level constant (choose an appropriate value)
const proc = bunSpawn(['git', '-C', dir, 'rev-parse', '--show-toplevel'], {
stdin: 'ignore',
cwd: dir,
timeout: PER_CALL_TIMEOUT_MS,
// stdout/stderr: piped, bounded, or ignored
});
try {
const result = await proc;
// process result
} finally {
proc.kill(); // best-effort cleanup
}| Property | Required | Rationale |
|---|---|---|
| Array-form args | Yes | No shell-string commands (injection risk, quoting hell) |
cwd or git -C | Yes | Never rely on inherited process.cwd() |
stdin: 'ignore' | Yes | A never-closed stdin pipe under Bun/Windows can block child exit (v7.3.3) |
timeout: <ms> | Yes | No subprocess is "always fast" on every platform |
| stdout/stderr bounded | Yes | Never leave piped stream unattended on long-running child |
proc.kill() in finally | Yes | Outer withTimeout lets awaiter proceed but doesn't abort child |
child_process.execFile (callback form) and child_process.execFileSync have different
default stdio behavior:
| API | Default stdin | Risk |
|---|---|---|
execFileSync | 'inherit' | Child inherits parent stdin — v7.3.3 vector on Windows/Bun if stdin is never closed |
execFile (callback) | 'pipe' | Child gets an internal pipe — lower risk but still not ideal for defense-in-depth |
Key differences from the canonical spawn pattern:
proc.kill() in finally (line 69): Applicable to callback-form execFile.
The function returns a ChildProcess reference (matching the canonical spawn
pattern per Node.js docs). The child reference enables kill() before that
point for timeout safety, and failing to call proc.kill() in finally can
leave orphaned children when combined with an outer withTimeout. The
timeout option triggers internal SIGTERM, but is not a substitute for
explicit kill in finally — always kill the child in finally.
stdin: 'ignore' (line 66): Technically default-safe for callback execFile
(stdin is piped, not inherited). However, always add stdio: ['ignore', 'pipe', 'pipe']
for defense-in-depth and consistency with execFileSync calls. Note: Bun's
TypeScript definitions do not include stdio in ExecFileOptions — use
execOpts as any when passing stdio to callback-form execFile.
execFileSync should always use stdio: ['ignore', 'pipe', 'pipe'] to
prevent the stdin-inheritance hang on Windows/Bun (v7.3.3).
.cmd extensions: npm/bun binaries on Windows are .cmd wrappers. Resolve
the executable path explicitly using which/where or the project's
cross-platform helper. Do NOT enable shell: true or shell-mediated
execution to work around PATH resolution.cmd.exe and PowerShell resolve PATH differently. Test on
Windows, not just macOS/Linux.child_process.spawn('bin', ...) does not behave identically to running
under cmd.exe. Use array-form args and explicit cwd.fs.renameSync cannot overwrite existing directories on Windows. Use a
remove-then-rename pattern or fs.rename with error handling.The gh CLI is a common subprocess in this repo (scripts/release-notes-fragments.mjs, CI workflows). It follows the same six required properties as all subprocesses, plus several gh-specific patterns.
gh api --paginate requires --slurpBug pattern (PR #1762 F-002): gh api --paginate without --slurp produces concatenated JSON arrays on stdout. JSON.parse() can only parse the first array — subsequent arrays cause a parse error or are silently lost.
Correct pattern:
const raw = execFileSync('gh', ['api', '--paginate', '--slurp', 'repos/.../pulls', ...], {
encoding: 'utf8',
timeout: 30_000,
maxBuffer: 16 * 1024 * 1024,
stdio: ['ignore', 'pipe', 'pipe'], // required for execFileSync (AGENTS.md §3)
});
// --slurp wraps paginated results as [[page1], [page2], ...]
const pages = JSON.parse(raw);
const allItems = pages.flat(); // flatten to single arrayWithout --slurp: stdout is [item1, item2][item3, item4] — invalid JSON after the first array. This is a silent data loss bug that only manifests when results span multiple pages (>30 items by default).
stdin: 'ignore' for gh callsgh subprocess calls must include stdin: 'ignore' (or stdio: ['ignore', 'pipe', 'pipe'] for execFileSync). This is the same invariant as all subprocesses (AGENTS.md §3). For example, scripts/release-notes-fragments.mjs defines ghJson() and ghText() helpers using execFileSync — these must include stdio: ['ignore', 'pipe', 'pipe'] per the six required properties. A PR review (pre-merge) identified this gap.
Number.isInteger() for API response validationWhen validating integer IDs from API responses (PR numbers, issue numbers, run IDs), use Number.isInteger(), not Number.isFinite(). Number.isFinite() accepts floats like 1.5, which are never valid IDs.
// Correct
function isValidPrNumber(n) {
return Number.isInteger(n) && n > 0;
}
// Wrong — accepts 1.5, NaN, Infinity
function isValidPrNumber(n) {
return Number.isFinite(n) && n > 0;
}Note: This is a stricter pattern. Some existing code uses
Number.isFinite()afterparseInt()— while technically safe for parsed integers,Number.isInteger()is the correct guard for all ID validation going forward.
maxBuffer for large API responsesgh api can return large payloads. Set maxBuffer: 16 * 1024 * 1024 (16 MiB) to prevent silent truncation. This is especially important for --paginate calls that aggregate multiple pages.
Note:
maxBufferis specific to Node.jschild_process.execFile/execFileSync. For Bun'sbunSpawn, use the equivalent output bounding option.
_internals DI seam, NOT mock.modulemock.module(...) leaks across test files in Bun's shared test-runner process.
Use dependency injection instead:
// --- source file (e.g. src/utils/gitignore-warning.ts) ---
import { bunSpawn } from './bun-compat';
export const _internals: { bunSpawn: typeof bunSpawn } = { bunSpawn };
// In production code, call _internals.bunSpawn(...) instead of bunSpawn(...)
// --- test file ---
import { _internals } from '../../src/utils/gitignore-warning';
const real = _internals.bunSpawn;
beforeEach(() => { _internals.bunSpawn = stub; });
afterEach(() => { _internals.bunSpawn = real; });For the full migration protocol, load the mock-to-internals-migration skill.
After changing any file with subprocess calls, run:
grep -n "bunSpawn\|spawn(\|spawnSync(" src/<changed>/*.tsEvery match MUST have all of:
timeout set to a concrete millisecond valuestdin: 'ignore' (unless intentionally interactive; note: callback-form execFile uses stdio: ['ignore', 'pipe', 'pipe'] instead)cwd or git -C <directory> for explicit working directoryproc.kill() in a finally block or equivalent cleanup path (exception: callback-form execFile manages cleanup internally via timeout option)ensureSwarmGitExcluded
called git without timeout, stdin, or kill. Result: same silent failure on
Windows.Both caused OpenCode to silently drop the plugin manifest. Users saw no agents and no error. Every subprocess call is a potential repeat of these failures unless all six properties are enforced.
© ZaxbyHub, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .agents/skills/subprocess-safety of ZaxbyHub/opencode-swarm.
Open the folder on GitHubat commit b63a4bd
Subprocess Safety next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Subprocess Safety this skillZaxbyHub/opencode-swarm | 494 | — | ~2.4k | Automated safety check: Pass | MIT | |
| MCP Server Builderanthropics/skills | 180k | 63 repos | ~2.3k | Automated safety check: Pass | Apache-2.0 | |
| Hook Development for Claude Code Pluginsanthropics/claude-plugins-official | 38k | 10 repos | ~4.1k | Automated safety check: Notes | Apache-2.0 | |
| Using Superpowersfarm-fe/farm | 5.6k | 35 repos | ~1.4k | Automated safety check: Pass | MIT | |
| Executing Plans Inlineobra/superpowers | 297k | 2 repos | ~5.1k | Automated safety check: Pass | MIT | |
| Skill CreatorAzure/azqr | 796 | 89 repos | ~8.2k | Automated safety check: Pass | Apache-2.0 |
anthropics/skills
Guides the design and implementation of Model Context Protocol servers in TypeScript or Python, from tool naming and error messages to evaluation.
anthropics/claude-plugins-official
Explains how to write Claude Code plugin hooks, both prompt-based checks and bash commands, for events such as PreToolUse, Stop and SessionStart.
farm-fe/farm
A skill your agent uses when starting any conversation - establishes how to find and use skills, requiring Skill tool invocation before ANY response including clarifying questions
obra/superpowers
Has the agent carry out an implementation plan itself, task by task in the current session, keeping a ledger, proving each step with a test and ending with one whole-branch review.
Azure/azqr
Create new skills, modify and improve existing skills, and measure skill performance.
anthropics/claude-plugins-official
Explains how to write agents for Claude Code plugins: the markdown file with YAML frontmatter, trigger descriptions, model and color settings, and system prompt design.
ZaxbyHub/opencode-swarm
Runs an evidence-gated, quote-grounded audit of a codebase for security, QA, accessibility, performance and more, and writes a verified report without changing source files.
ZaxbyHub/opencode-swarm
Drives a bug report from validation and root-cause tracing through a critic-reviewed plan, an approved minimal fix and a PR-ready closure, never merging without recorded human approval.
ZaxbyHub/opencode-swarm
Codex adapter for opencode-swarm that governs commits, pushes, draft PRs, PR body updates and CI closeout, deferring to the repo's canonical commit-pr protocol.
ZaxbyHub/opencode-swarm
Keeps plans, decisions, evidence and reviewer verdicts in small files so long multi-phase tasks survive context compaction and session resumes.
ZaxbyHub/opencode-swarm
Ingests existing pull request feedback such as review comments and CI failures, verifies each claim, fixes confirmed issues and reports closure status for every item.
ZaxbyHub/opencode-swarm
Monitor a pull request after creation and act autonomously on pushed PR activity.
Categories
Guidelines for safe subprocess calls in opencode-swarm. An agent skill from ZaxbyHub/opencode-swarm. Subprocess Safety is an agent skill from ZaxbyHub/opencode-swarm. Guidelines for safe subprocess calls in opencode-swarm.
Subprocess Safety fits situations like: agent Workflows work in your project.
Run `npx skills add ZaxbyHub/opencode-swarm --skill subprocess-safety -a claude-code`. Or copy the skill folder (.agents/skills/subprocess-safety in ZaxbyHub/opencode-swarm) into .claude/skills/subprocess-safety in your project. Claude Code loads it when a task matches its description.
Run `npx skills add ZaxbyHub/opencode-swarm --skill subprocess-safety -a codex`. Or copy the skill folder (.agents/skills/subprocess-safety in ZaxbyHub/opencode-swarm) into .agents/skills/subprocess-safety in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ZaxbyHub/opencode-swarm --skill subprocess-safety -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/subprocess-safety, .gemini/skills/subprocess-safety, .github/skills/subprocess-safety and .opencode/skills/subprocess-safety in your project.
Going by SKILL.md and its folder, Subprocess Safety needs the command-line tools its instructions call (gh, git and bun). Our summary lists: Node.js.
SKILL.md contains no URLs. Its commands use gh and git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Subprocess Safety is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.4k tokens (SKILL.md is roughly 9.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Subprocess Safety: MCP Server Builder (anthropics/skills, 180k stars), Hook Development for Claude Code Plugins (anthropics/claude-plugins-official, 38k stars), Using Superpowers (farm-fe/farm, 5.6k stars) and Executing Plans Inline (obra/superpowers, 297k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
ZaxbyHub (a GitHub organization) maintains it in ZaxbyHub/opencode-swarm, which has 494 GitHub stars. The repository holds 91 skills in this directory. The repository was last updated on October 10, 2026.
Source: ZaxbyHub/opencode-swarm on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.