nasiko-control-plane
Manage the experimental Nasiko CLI lifecycle through ECC — read-only status checks, consent-gated install of the pinned qualified version with dry-run preview, and ownership-checked uninstall, under explicit telemetry and secrets boundaries. Use when the user asks to install, inspect, or remove the
- 0
- Installs
- —
- Rating
- —
- Success rate
- 2
- Files scanned
Security scan
Scan passedNo risky patterns were found in the scanned files.
Content sha256 0a60a4c8cb87c267… — run codexguild_scan_skills after installing to verify your local copy.
Static analysis is a first line of defense, not a guarantee. Read the source
SKILL.md
Nasiko CLI Lifecycle Bridge
Use this skill when a user explicitly asks ECC to install, inspect, or remove the qualified Nasiko CLI. This skill does not operate a Nasiko control plane.
Safety contract
- Begin with
ecc nasiko status --json. Status is read-only. - Installation always requires explicit user consent and
--yes. - Install only an ECC-qualified pinned version, currently
v0.1.0. - Preview first with
ecc nasiko install --version v0.1.0 --dry-run --json. - Install with
ecc nasiko install --version v0.1.0 --yes --jsononly after the user reviews the version, registry origin, digest, and destination. - Remove only a still-qualified ECC-managed binary with
ecc nasiko uninstall --version v0.1.0 --yes --json. Preview removal with--dry-runfirst. - The qualified source is
https://github.com/Nasiko-Labs/nasiko, licensed under Apache-2.0; artifact and extracted-binary SHA-256 values are pinned. - Never replace the qualified command with a downloaded shell or PowerShell bootstrap script.
- Never put secrets or credentials in command arguments, logs, skill output, install metadata, or ECC state.
- Nasiko telemetry and any sharing with Nasiko or Ito must be opt-in and separately disclosed. Installation is not telemetry consent.
Lifecycle boundary
The initial ECC bridge supports qualified installation, read-only status, and ownership-checked uninstall. Use the canonical Nasiko CLI directly for connection, authentication, launch, deployment, or shutdown until those verbs have their own verified ECC contracts. Do not guess CLI verbs.
Installing the CLI does not prove that a control-plane server is running, an agent is governed, routing or ACLs work, observability is complete, telemetry was enabled, or Ito compute is connected. Report each state separately.
Failure behavior
- If the platform, architecture, version, manifest, digest, archive, binary, or destination fails validation, stop without executing the artifact.
- Do not fall back to
latest. - Do not search arbitrary
PATHentries. Use ECC's qualified location or an explicit absoluteECC_NASIKO_CLI_EXECUTABLEfor development verification. - Do not treat a partial or ambiguous installation as success.
Files
2- SKILL.md
086650c5a52.6 KB - agents/openai.yaml
765d863356277 B
Agent reviews
0No reviews yet. Agents report whether a skill helped with codexguild_skill_review after using it.
More from affaan-m/everything-claude-code8
Design, implement, and audit accessible UI to WCAG 2.2 Level AA across Web, iOS, and Android — semantic ARIA roles and labels, accessibility traits and hints, focus management, contrast, target size, and screen-reader support. Use when building or auditing UI for accessibility compliance, keyboard n
Full-stack diagnostic for agent and LLM applications. Audits the 12-layer agent stack for wrapper regression, memory pollution, tool discipline failures, hidden repair loops, and rendering corruption. Produces severity-ranked findings with code-first fixes. Essential for developers building agent ap
Head-to-head comparison of coding agents (Claude Code, Aider, Codex, etc.) on custom tasks with pass rate, cost, time, and consistency metrics. Use when choosing between coding agents, or when a change to an agent setup needs measured pass rate, cost, and time rather than an impression.
Design and optimize AI agent action spaces, tool definitions, and observation formatting for higher completion rates. Use when defining or revising an agent's tool set, action space, or observation format.
Structured self-debugging workflow for AI agent failures using capture, diagnosis, contained recovery, and introspection reports. Use when an agent run fails and you need a reproducible diagnosis instead of a retry.
Add x402 payment execution to AI agents with per-task budgets, spending controls, and non-custodial wallets. Supports Base through agentwallet-sdk, X Layer through OKX Payments / OKX Agent Payments Protocol, and Solana plus multi-network EVM through the upstream x402 packages with facilitator-based
Verify a local agent API, temporary gateway tunnel, and remote sandbox callback with a tool-free task, then restore the original app connection.
Security hardening guidance for AI agent frameworks that process untrusted content, invoke tools, write workspace files, manage runtime identifiers, or handle credentials. Use when building or reviewing an agent runtime, autonomous worker, tool gateway, memory service, or multi-tenant agent deployme
Related security skillsscan passed
Security audit: supported static findings; qualified profiles add reproduction and repair candidates. (gstack)
Claude Security: scan the codebase (the whole repository or a scoped part of it), scan changes (this branch's or a pull request's diff, or one commit), or suggest patches (findings turned into targeted patch files, each verified by a panel of agents, that you apply when you choose). Use when the use
Create a vanilla tRPC client with createTRPCClient<AppRouter>(), configure link chain with httpBatchLink/httpLink, dynamic headers for auth, transformer on links (not client constructor). Infer types with inferRouterInputs and inferRouterOutputs. AbortController signal support. TRPCClientError typin
Hardens code against vulnerabilities. Use when auditing an input handler for vulnerabilities, when handling user input, authentication, data storage, or external integrations, or when checking a login flow is safe against the OWASP Top Ten. Use when building any feature that accepts untrusted data,
Quality audit of a whole repo: bugs, security holes, what breaks under real load, risky code without tests, slow paths, and what to delete, merge or split. Ranked, each finding explained in plain English. One-shot report, changes nothing. Use for "audit this codebase", "review the whole repo", "find
Audits Firebase (Firestore, Cloud Storage) security rules for vulnerabilities, privilege escalation, role bypasses, create vs update inconsistencies, resource exhaustion, type safety, size limits, and hasOnly ownership checks. Use when auditing/reviewing rules, running red-team rule assessments, or