Agent skill

Kitaru Dev

by zenml-io in zenml-io/kitaru

Kitaru just recipes, CLI structure and structured-output contract, analytics events, and PR-description conventions.

Apache-2.0Auto-check passedAI & LLM Engineering

Install Kitaru Dev

skills CLI
$ npx skills add zenml-io/kitaru --skill kitaru-dev -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install zenml-io/kitaru kitaru-dev --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/zenml-io/kitaru.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/kitaru-dev .claude/skills/kitaru-dev && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
kitaru-dev
GitHub stars
301
Token cost
~2.6k tokens
SKILL.md length
1,320 words
Files
2 (incl. references)
Skills in repo
7
Repo updated
First seen
Licence
Apache-2.0

At a glance

Kitaru just recipes, CLI structure and structured-output contract, analytics events, and PR-description conventions.

  • Running project commands
  • SKILL.md covers Python Workflows, New Distribution Integration…, Docs Workflows and Native MCP Server, plus 4 more sections
  • Calls just and uv
  • Adding CLI commands

What it does

Kitaru Dev is an agent skill from zenml-io/kitaru. Kitaru just recipes, CLI structure and structured-output contract, analytics events, and PR-description conventions. Use when running project commands, adding CLI commands or analytics events, or writing a PR description.

Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/evaluation-contracts.md`).

It sits in AI & LLM Engineering, covering Pull requests and Structured output and tool calling. It works with Model Context Protocol and Python. The repository describes itself as: Agent traces you can run, not just read. The licence is Apache-2.0.

When your agent uses it

  • Running project commands
  • Adding CLI commands
  • Analytics events
  • Writing a PR description

Example prompts

  • “/kitaru-dev”

Requirements

  • Python 3
  • Docker

What it can do on your machine

Read from SKILL.md and the folder at commit 9d2df59. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • just
    • uv

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use uv, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Kitaru Dev loads about 2.6k tokens when it runs, and up to ~3.1k if it reads all its reference files. Until then it costs about 58 tokens; SKILL.md has 1,320 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~58
When it runs · the whole SKILL.md, loaded when a task matches
~2.6k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from zenml-io/kitaru at commit 9d2df59, republished under its Apache-2.0 licence (© zenml-io). 1,320 words, ~2,634 tokens.

Download SKILL.mdSave it as .claude/skills/kitaru-dev/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
kitaru-dev
description
Kitaru just recipes, CLI structure and structured-output contract, analytics events, and PR-description conventions. Use when running project commands, adding CLI commands or analytics events, or writing a PR description.

Kitaru Development, CLI, and PR Workflow

Use this when you need the command catalog beyond the daily loop in the root AGENTS.md, or when adding CLI commands, analytics events, or PR descriptions.

Python Workflows

  • uv sync: install the base SDK and development dependencies
  • uv sync --extra cli: include the optional CLI
  • uv sync --extra mcp: include the optional native MCP server
  • uv sync --extra server: include server components
  • uv sync --extra worker: include worker components
  • uv sync --extra otel: include OpenTelemetry integrations
  • just check: run formatting, lint, OpenAPI freshness, changelog fragments, typecheck, typos, YAML, actions lint, and links
  • just openapi-check: verify that the committed OpenAPI specification matches the application schema
  • just changelog-check: validate the changelog fragments under changelog.d/
  • just fix: auto-fix formatting, lint issues, and YAML
  • just test: run the full pytest suite
  • just test tests/test_file.py::test_name: run one targeted test
  • just lint: lint only
  • just typecheck: type check only
  • just typos: typo check only
  • just format-check: check formatting without modifying files
  • just yaml-check: check YAML formatting
  • just actions-lint: lint GitHub Actions workflows; requires actionlint
  • just zizmor: audit GitHub Actions workflow security with zizmor
  • just audit: audit Python dependencies with pip-audit and the documented ignore list
  • just links: check Markdown links offline; requires lychee
  • just links-external: check links including external URLs; slow
  • just example-coverage-audit: validate examples/example-coverage.yaml metadata and waivers
  • just build: build wheel and sdist locally
  • just cli-artifact-smoke: verify clean CLI wheel and source installations
  • just plugin-artifact-smoke: build every default-plugin wheel, load its configured entrypoints, and verify default registration
  • just mcp-schema-check: verify public MCP registry budgets and committed snapshots
  • just mcp-wheel-smoke: verify clean base and [mcp] installs from the wheel under dist/
  • just migration-check: compare Alembic migrations with the ORM schema; requires PostgreSQL

There is no v2 kitaru init command or local extra. Do not carry the v1 .kitaru/ project-marker setup into v2 instructions or tests.

When resolving pyproject.toml or uv.lock conflicts, do not regenerate the whole lockfile: that silently reverts intentional dependency-security bumps. Upgrade only the packages involved and run just audit before pushing.

New Distribution Integration Review

Before opening a PR that creates an independently published package, trace how it will be built, installed, discovered, and released. This applies to a new adapter, importer, evaluator, or other Python distribution; adding an evaluator inside the existing kitaru-evaluator wheel does not create a new distribution. For substantial packages, ask a bounded independent subagent to review the integration points and omissions, then verify its findings against the code. Record the applicable paths and any deliberate exclusions in Reviewer Notes or Release context so a reviewer can check the complete package path.

  • Add the package manifest, source, tests, README, changelog, plugin workspace lock entry, and a row in plugins/README.md. Add artifact import metadata for a non-default package, and check whether plugins/pyproject.toml needs an update.
  • Add every new Python distribution to release/release-units.toml and the expected inventory in tests/scripts/test_release_units.py. Check that the release workflow and CI matrix discover it; edit fixed selections only when they actually exclude the new package.
  • Add every new PyPI kitaru-* distribution to src/kitaru/worker/process.py::_FIRST_PARTY_KITARU_PACKAGES, including packages outside the default server catalog. Run the inventory-based test in tests/worker/test_process.py; the server catalog is not the worker's package list.
  • Decide separately whether the server should offer the package by default. Set default-catalog in the release inventory accordingly, and change DEFAULT_PLUGIN_DEFINITIONS and its tests only for an approved default. Do not add adapters to the server catalog.
  • Inspect package-specific selections and exclusions, including candidate-wheel builds, example dependencies, and the quickstart's --no-install-package list in .github/workflows/ci.yml. There is no global plugin ignore list; those exclusions apply to their particular example or build. Update them only when the new package enters that path.
  • Check the required core version, release order, documentation, and runnable examples. For worker-installed exact pins, test candidate-wheel resolution with a cutoff predating the package, verify that supported uv accepts the package exception, and verify that older uv retains the prior command and warns. Only a postpublication registry install proves the published wheel resolves under that cutoff. Run the focused package tests, release-inventory test, and just plugin-artifact-smoke before handoff.

Use plugins/DEVELOPMENT.md for package and candidate-server commands, and the kitaru-release skill for version selection and publication. Do not treat registration metadata or a local wheel as proof that the published package can be installed by a worker.

Docs Workflows

These require Node 22+ and pnpm.

  • just docs: preview docs locally at localhost:3000
  • just docs-build: build the static docs export
  • just docs-validate: validate the export as served under /docs
  • just generate-docs: regenerate the SDK and CLI reference content

scripts/generate_sdk_docs.py extracts the v2 SDK reference through a PUBLIC_API allowlist. Edit that allowlist and tests/scripts/test_generate_sdk_docs.py together; the test compares each published module against its __all__. The generator needs the fumapy bridge after installing the docs dependencies. scripts/generate_cli_docs.py generates CLI reference content from the offline kitaru schema contract rather than a hardcoded command list.

Show full SKILL.md (517 more words)Show less

Native MCP Server

The native v2 server is installed with kitaru[mcp] and started with kitaru-mcp. It defaults to read-only; standard and destructive expose progressively broader capabilities.

Treat tests/mcp/snapshots/metrics.json and src/kitaru/mcp/registry.py as the inventory authorities. Do not copy tool counts into prose. Run just mcp-schema-check after changing MCP models, registry declarations, descriptions, annotations, or SDK versions. Build the wheel and run just mcp-wheel-smoke after entrypoint, packaging, lifecycle, or optional-import changes.

CLI Structure

The kitaru console script is defined in pyproject.toml under [project.scripts]. src/kitaru/cli/__init__.py is the lazy entry point, src/kitaru/cli/app.py registers the shared Cyclopts applications, and command implementations live under src/kitaru/cli/.

Register new leaf commands through the _spec(...) and _register(...) metadata in src/kitaru/cli/app.py. Tests should call main([...]) with an explicit argument list and assert the returned integer exit code.

When changing evaluation, replay, or experiment commands or contracts, read Evaluation contracts.

Structured Output Contract

Agent-facing commands use the version-1 structured contract. Success documents include schema_version, command, ok, warnings, links, and next_actions, plus item for one result or items, count, and page for a list. Streaming commands emit JSONL events. Structured errors are one JSON object on stderr with a stable error kind and exit code.

For agent-facing use, prefer --output json --machine --non-interactive --no-browser. A deliberate dashboard or device-login handoff is the exception.

Document login consistently: kitaru login starts the interactive managed-cloud device flow and connects to the Kitaru workspace selected or created in the browser. kitaru login SERVER targets the full managed or self-hosted instance URL, while kitaru login --local provisions or reuses the CLI-owned Docker or Podman Compose deployment. The local deployment defaults to http://localhost:8000; --port takes precedence over KITARU_LOCAL_PORT, and the selected port persists with the deployment. kitaru logout stops that deployment when it is selected, and kitaru logout --volumes also deletes its PostgreSQL data.

kitaru status shows the selected server, provenance, credential state, compatibility, and live-worker count. kitaru info adds local package, Python, platform, and server details. kitaru doctor runs independent local, server, authentication, and tooling checks without stopping after the first failure. These commands never print secret values.

Analytics

Analytics events live in src/kitaru/analytics/events.py; source attribution lives in src/kitaru/analytics/source.py. Server-side feature events are emitted through the application analytics service. MCP attribution is set once for the MCP lifecycle through AnalyticsSource.MCP.

  • Add event names to AnalyticsEvent in src/kitaru/analytics/events.py.
  • Track only reviewed, non-sensitive metadata such as event names, boolean flags, enum values, and counts.
  • Never include user content, file paths, prompts, credentials, or secret values.
  • Keep analytics failures non-fatal.

Pull Requests

Use a clear human-readable title without a [Codex] prefix. Include what changed, why it was needed, important implementation decisions, and reviewer focus areas. Link related issues when applicable.

Add a changelog.d/<pr-number>.<section>.md fragment for user-facing changes instead of editing CHANGELOG.md. Any slug works in place of the number while the PR does not exist yet. See changelog.d/README.md for the format.

Every PR description should include a Reviewer Notes H2 or H3 section that explains the story and risks of the change, plus a concrete Reproduction subsection. Keep local hygiene commands as a short note after reproduction rather than using them as a substitute for reviewer guidance.

© zenml-io, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in .agents/skills/kitaru-dev of zenml-io/kitaru.

  • SKILL.md
  • references/evaluation-contracts.md

Open the folder on GitHubat commit 9d2df59

Compare with similar skills

Kitaru Dev next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Kitaru Dev compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Kitaru Dev this skillzenml-io/kitaru301—~2.6kAutomated safety check: PassApache-2.0
Perfupraullenchai/Rapid-MLX3.9k—~1.6kAutomated safety check: NotesCustom licence
Gemini API DevAyuilos/Miffan1921 repos~1.4kAutomated safety check: PassAGPL-3.0
Tool Designagentailor/fullstack-langgraph-nextjs-agent132—~3.2kAutomated safety check: PassMIT
Agent Framework Azure AI Pymicrosoft/skills3.1k1 repos~3.1kAutomated safety check: PassMIT
Gemini API Devaiskillstore/marketplace4303 repos~1.6kAutomated safety check: PassApache-2.0

Similar skills

  • Perfup

    raullenchai/Rapid-MLX

    Autonomous performance optimization: research, PoC, benchmark, implement, review, PR

    3.9k GitHub stars~1.6k tokensUpdated today
    AI & LLM EngineeringAuto-check: notes
  • Gemini API Dev

    Ayuilos/Miffan

    A skill your agent uses when building applications with Gemini API hosted models, including Gemini and Gemma 4, working with multimodal content (text, images, audio, video), implementing function…

    192 GitHub starsUsed in 1 repo~1.4k tokens
    AI & LLM EngineeringAuto-check passed
  • Tool Design

    agentailor/fullstack-langgraph-nextjs-agent

    Design and verify tools that AI agents can actually use — for any framework or language (MCP servers, LangChain/LangGraph, function-calling, raw JSON schema; TypeScript, Python, or otherwise).

    132 GitHub stars~3.2k tokensUpdated 1 mo ago
    AI & LLM EngineeringAuto-check passed
  • Official

    Build Azure AI Foundry agents using the Microsoft Agent Framework Python SDK (agent-framework-azure-ai).

    3.1k GitHub starsUsed in 1 repo~3.1k tokens
    AI & LLM EngineeringAuto-check passed
  • Gemini API Dev

    aiskillstore/marketplace

    A skill your agent uses when building applications with Gemini API hosted models, including Gemini and Gemma 4, working with multimodal content (text, images, audio, video), implementing function…

    430 GitHub starsUsed in 3 repos~1.6k tokens
    AI & LLM EngineeringAuto-check passed
  • Retentioneering Contributing

    retentioneering/retentioneering-tools

    Help the user turn their Retentioneering ideas, friction reports, bug findings, or feature needs into high-quality upstream contributions: from capturing and validating the idea, through minimal…

    920 GitHub stars~1.8k tokensUpdated today
    Data & AnalyticsAuto-check passed

More from zenml-io/kitaru

  • Kitaru Docs

    zenml-io/kitaru

    Kitaru documentation surfaces, link rules, and accuracy rules.

    301 GitHub stars~936 tokensUpdated today
    Auto-check passed
  • Kitaru Release

    zenml-io/kitaru

    Discover dependencies and prepare or execute Kitaru core and plugin releases, including version proposals, Kitaru UI selection, release PRs, ordered tag commands, artifact verification, and recovery.

    301 GitHub stars~7k tokensUpdated today
    Auto-check passed
  • Add, reuse, or change a frontend-specific Kitaru REST response under /api/v1/ui and its OpenAPI contract in zenml-frontend-monorepo.

    301 GitHub stars~1.6k tokensUpdated today
    Auto-check passed
  • Add or change a Kitaru framework adapter that records native agent runs or supports bounded replay.

    301 GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Add or change a separately packaged Kitaru trace importer that normalizes provider exports into imported sessions.

    301 GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • Kitaru Tests Release

    zenml-io/kitaru

    Kitaru test layout, CI workflows, and release-workflow behavior.

    301 GitHub stars~2.8k tokensUpdated today
    Auto-check passed

Questions about Kitaru Dev

What does Kitaru Dev do?

Kitaru just recipes, CLI structure and structured-output contract, analytics events, and PR-description conventions. Kitaru Dev is an agent skill from zenml-io/kitaru. Kitaru just recipes, CLI structure and structured-output contract, analytics events, and PR-description conventions.

When should I use Kitaru Dev?

Kitaru Dev fits situations like: running project commands; adding CLI commands; analytics events; writing a PR description.

How do I install Kitaru Dev in Claude Code?

Run `npx skills add zenml-io/kitaru --skill kitaru-dev -a claude-code`. Or copy the skill folder (.agents/skills/kitaru-dev in zenml-io/kitaru) into .claude/skills/kitaru-dev in your project. Claude Code loads it when a task matches its description.

How do I install Kitaru Dev in Codex?

Run `npx skills add zenml-io/kitaru --skill kitaru-dev -a codex`. Or copy the skill folder (.agents/skills/kitaru-dev in zenml-io/kitaru) into .agents/skills/kitaru-dev in your project. Codex loads it when a task matches its description.

Can I use Kitaru Dev in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add zenml-io/kitaru --skill kitaru-dev -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/kitaru-dev, .gemini/skills/kitaru-dev, .github/skills/kitaru-dev and .opencode/skills/kitaru-dev in your project.

What does Kitaru Dev need to run?

Going by SKILL.md and its folder, Kitaru Dev needs the command-line tools its instructions call (just and uv). Our summary lists: Python 3; Docker.

Does Kitaru Dev access the network?

SKILL.md contains no URLs. Its commands use uv, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Kitaru Dev safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Kitaru Dev use?

Kitaru Dev is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Kitaru Dev use?

About 2.6k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 509 tokens, read only when the agent opens those files.

What are the alternatives to Kitaru Dev?

Skills that share tags, products or a category with Kitaru Dev: Perfup (raullenchai/Rapid-MLX, 3.9k stars), Gemini API Dev (Ayuilos/Miffan, 192 stars), Tool Design (agentailor/fullstack-langgraph-nextjs-agent, 132 stars) and Agent Framework Azure AI Py (microsoft/skills, 3.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Kitaru Dev?

zenml-io (a GitHub organization) maintains it in zenml-io/kitaru, which has 301 GitHub stars. The repository holds 7 skills in this directory. The repository was last updated on October 7, 2026.

Source: zenml-io/kitaru on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.