Skip to content

Build a skill with your coding agent #2

Description

@thinkingoracle

You do not have to read this repository to add to it. Copy the block below into
Claude Code, Codex, Cursor, or whatever agent you already have open, fill in the
My idea: line near the top, and it does the rest.

It builds both files, checks them, writes the whole submission, and then asks
you before posting anything. It never posts without your yes, and it asks you
the licence and privacy questions in your own words rather than answering them
on your behalf.

I want to add a skill to the public Luke skills catalog at
https://github.com/thinkingoracle/luke-skills

My idea: <one sentence: who needs what public information, from which
public website>

Do this:

1. Clone at the exact release tag below, never main. Use this tag
   literally. Do not pick a different one off the Releases page, which
   currently lists two and marks the older one Latest.

     export LUKE_SKILLS_RELEASE_TAG="luke-skills-v0.1.1"
     git clone --branch "$LUKE_SKILLS_RELEASE_TAG" --depth 1 \
       https://github.com/thinkingoracle/luke-skills.git
     cd luke-skills
     git describe --tags --exact-match HEAD   # must print that tag

2. Read CONTRIBUTING.md there. It is the authority on what a skill may
   do and what the bundle must contain, and it wins over this message on
   both. It is not the authority on how to submit: it describes the
   issue form, and this block files the same issue with gh. Either way
   the result is one public proposal issue and never a pull request.

3. Check my idea first. If it needs a login, a credential, a private
   page, or changes anything in the world, stop and tell me. It is not
   eligible yet, and there is a better place to put it.

4. Build both files with the creator, then run the validator until it
   passes clean. The validator needs --allow-draft-provenance or it
   rejects a draft proposal. Both commands are in CONTRIBUTING.md:

     python3 creator/create-luke-skill/scripts/new_skill.py \
       --output-root /tmp/my-proposal \
       --slug your-skill-slug \
       --description "one line saying what it reads" \
       --host the.public.host.it.reads \
       --data-read "what it reads from that page" \
       --result-lands-in "Luke's response to the requesting user" \
       --positive-example "a request that should use it" \
       --negative-example "a similar request that should not" \
       --failure-example "what unavailable looks like" \
       --redaction-example "sensitive material it must omit"
     python3 creator/create-luke-skill/scripts/validate.py \
       --catalog-root /tmp/my-proposal --allow-draft-provenance

   Replace those values with mine. Do not write them inside angle
   brackets: an unquoted < is a shell redirect, so a command with
   <placeholders> in it fails before python ever runs.

   Keep going until it prints: validated 1 Luke catalog skill(s)
   Every failure has a named CREATOR_ or CATALOG_ code. Read it; it
   says what to fix.

5. Write the whole submission yourself, as markdown, using these
   headings in this order: Proposed skill name and ID; User and need;
   Public hosts; Authentication boundary; Data boundary; Mutation
   boundary; Expected behavior and result; Realistic examples;
   Evaluation evidence; Provenance; License and notices; then both
   complete files in fenced blocks. You already know all of it because
   you wrote it. Do not ask me to retype any of it.

   Two of those take fixed wording, not your own. Authentication
   boundary is exactly "No authentication or credentials are required".
   Mutation boundary is exactly "Read-only, with no external mutation".
   If either is not true of my idea, it is not eligible; go back to
   step 3.

6. Two things you must not answer for me: where the material came from
   and under what licence, and whether it contains anything private.
   Ask me in plain language and use my words.

   Fence both files with a run of backticks LONGER than any run inside
   the file, and directly above each fence state its exact size and
   SHA-256, like this:

     `SKILL.md`, 1684 bytes, sha256 92884a8a...

   Get these from the files themselves:

     wc -c < skills/<slug>/SKILL.md
     shasum -a 256 skills/<slug>/SKILL.md

   This is not decoration. A fence that ends early truncates the file
   silently, and a truncated skill still passes every validator. The
   declared size and hash are what make that impossible to land.

   Then end the submission with this block, and only tick a box after I
   have actually said yes to it. These are legal and safety claims about
   me, not about the skill, and filing without them makes the submission
   incomplete even though the files will still validate:

     ### Contributor attestations

     - [ ] I have the right to submit this material under
           Apache-2.0-compatible terms and included all required notices.
     - [ ] I included no secret, credential, private user data, copied
           browser session, or undisclosed vulnerability detail.
     - [ ] I understand this issue is proposal intake only and cannot
           review, accept, publish, install, or activate the skill.
     - [ ] I understand maintainers control the only source-review
           lifecycle, public status stays on this issue, and each user
           separately trusts the exact content hash.

7. Show me the finished submission and ask whether to post it. If I say
   yes, file it yourself:

     gh issue create --repo thinkingoracle/luke-skills \
       --title "Propose skill: <slug>" --body-file <your-file>.md

   Then give me the link. If gh is not set up, say so and show me the
   block to paste instead.

8. Never post without asking me first. Never open a pull request and
   never push a branch to that repository.

9. Tell me what was unclear or what you had to guess.

Two things worth knowing before you start.

Proposals arrive as issues, never pull requests. You never need write access
to anything here.

Being listed does not make a skill trusted. It arrives on someone's machine
switched off. They read it and approve those exact bytes themselves.

If your agent had to guess at something, tell us. That is the most useful thing
you can report here.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions