Repository navigation
feat: 8 themed skill packs + /toolkit command + session hook + split roadmap - #3
Conversation
…roadmap Group the 129 installed skills into 8 themed packs (core, hermes-dev, cybersecurity, methodology, media, docs-web-research, computer-use, dev-essentials) — a navigation layer over the single plugin so the wall of skills becomes scannable by domain. - packs/manifest.json: clean partition of all 129 skills (validated, no dupes, full coverage) - packs/<8>/README.md: per-pack "when to use" + skill roster - commands/toolkit.md: /toolkit browse + /toolkit <pack> + /toolkit doctor health check - hooks/: SessionStart banner (skills · packs · agents · MCP counts), sensor-only - scripts/build_packs.py: validates manifest + emits routing/bundles/*.yaml; wired into build_index - routing/bundles: replaced 12 stale library-arsenal bundles with 8 pack-sourced bundles - .claude-plugin/marketplace.json: +8 themed stub entries (future split targets, all → one plugin) - PACKS.md: pack index + future "install only what you need" split roadmap - README.md: Packs section, fix counts (129 skills, 9 MCP servers), add basti-tools to MCP table - plugin.json: bump 0.5.0 → 0.6.0 Regenerated INDEX.json + NAVIGATION.md via scripts/build_index.py. Coverage verified: manifest union == installed skill dirs (129), no duplicates. Co-Authored-By: Claude <noreply@anthropic.com>
src/mcp_server_basti/logging_setup.py:31 had its docstring at column 0 instead of indented under the function def, causing an IndentationError that broke pytest collection (3 unit tests) and tripped ruff (2 errors) on a file unrelated to the skill-packs work. Pre-existing on main; CI was already red. One-line indentation fix. Co-Authored-By: Claude <noreply@anthropic.com>
ruff UP017 flags `timezone.utc` in logging_setup.py:17; requires-python is >=3.11 so `datetime.UTC` (3.11+) is available. Pre-existing on main; blocked CI ruff job. One-line usage + import fix. Co-Authored-By: Claude <noreply@anthropic.com>
There was a problem hiding this comment.
Pull request overview
This PR introduces a “skill pack” navigation layer over the existing agent-toolkit plugin by partitioning the installed skills into 8 themed packs, generating pack-based routing bundles, and adding user-facing affordances to browse/health-check the toolkit.
Changes:
- Added curated pack manifest + per-pack READMEs, plus generated pack-based
routing/bundles/*.yaml. - Added
/toolkitslash command and aSessionStarthook that prints a one-line toolkit status banner. - Wired pack validation/bundle emission into
scripts/build_index.py, and extended generated navigation/index artifacts to include pack info.
Reviewed changes
Copilot reviewed 42 out of 42 changed files in this pull request and generated 4 comments.
Show a summary per file
| File | Description |
|---|---|
| scripts/build_packs.py | Validates packs/manifest.json and emits pack-derived routing bundles. |
| scripts/build_index.py | Calls pack build/validation and includes packs in generated navigation output. |
| routing/bundles/testing-strategies.yaml | Removes legacy/stale bundle in favor of pack-derived bundles. |
| routing/bundles/tailwind.yaml | Removes legacy/stale bundle in favor of pack-derived bundles. |
| routing/bundles/supabase-platform.yaml | Removes legacy/stale bundle in favor of pack-derived bundles. |
| routing/bundles/react-frontend.yaml | Removes legacy/stale bundle in favor of pack-derived bundles. |
| routing/bundles/obsidian.yaml | Removes legacy/stale bundle in favor of pack-derived bundles. |
| routing/bundles/ml-research.yaml | Removes legacy/stale bundle in favor of pack-derived bundles. |
| routing/bundles/methodology.yaml | Adds pack-derived routing bundle for the methodology pack. |
| routing/bundles/media.yaml | Adds pack-derived routing bundle for the media pack. |
| routing/bundles/llm-operations.yaml | Removes legacy/stale bundle in favor of pack-derived bundles. |
| routing/bundles/hermes-dev.yaml | Adds pack-derived routing bundle for the hermes-dev pack. |
| routing/bundles/find-and-discover.yaml | Removes legacy/stale bundle in favor of pack-derived bundles. |
| routing/bundles/documents-and-web.yaml | Removes legacy/stale bundle in favor of pack-derived bundles. |
| routing/bundles/docs-web-research.yaml | Adds pack-derived routing bundle for the docs-web-research pack. |
| routing/bundles/dev-essentials.yaml | Adds pack-derived routing bundle for the dev-essentials pack. |
| routing/bundles/design-suite.yaml | Removes legacy/stale bundle in favor of pack-derived bundles. |
| routing/bundles/cybersecurity.yaml | Adds pack-derived routing bundle for the cybersecurity pack. |
| routing/bundles/core.yaml | Adds pack-derived routing bundle for the core pack. |
| routing/bundles/computer-use.yaml | Adds pack-derived routing bundle for the computer-use pack. |
| routing/bundles/code-review-suite.yaml | Removes legacy/stale bundle in favor of pack-derived bundles. |
| routing/bundles/backend-frameworks.yaml | Removes legacy/stale bundle in favor of pack-derived bundles. |
| README.md | Documents packs, /toolkit, hook banner, and updates counts. |
| plugins/agent-toolkit/packs/README.md | Adds top-level pack index within the plugin. |
| plugins/agent-toolkit/packs/methodology/README.md | Adds pack-specific guidance and roster for methodology. |
| plugins/agent-toolkit/packs/media/README.md | Adds pack-specific guidance and roster for media. |
| plugins/agent-toolkit/packs/manifest.json | Defines the canonical pack partition and skill metadata. |
| plugins/agent-toolkit/packs/hermes-dev/README.md | Adds pack-specific guidance and roster for hermes-dev. |
| plugins/agent-toolkit/packs/docs-web-research/README.md | Adds pack-specific guidance and roster for docs-web-research. |
| plugins/agent-toolkit/packs/dev-essentials/README.md | Adds pack-specific guidance and roster for dev-essentials. |
| plugins/agent-toolkit/packs/cybersecurity/README.md | Adds pack-specific guidance and roster for cybersecurity. |
| plugins/agent-toolkit/packs/core/README.md | Adds pack-specific guidance and roster for core. |
| plugins/agent-toolkit/packs/computer-use/README.md | Adds pack-specific guidance and roster for computer-use. |
| plugins/agent-toolkit/hooks/toolkit-status.sh | Adds SessionStart status banner hook script. |
| plugins/agent-toolkit/hooks/hooks.json | Registers the SessionStart hook to run the status banner. |
| plugins/agent-toolkit/commands/toolkit.md | Adds /toolkit command instructions (browse packs + doctor). |
| plugins/agent-toolkit/.claude-plugin/plugin.json | Bumps plugin version and updates description to include packs/command/hook. |
| PACKS.md | Adds repo-root pack index and future split roadmap. |
| NAVIGATION.md | Updates generated navigation to include pack table. |
| INDEX.json | Updates generated timestamp (and related generated outputs). |
| .claude-plugin/marketplace.json | Adds pack-stub marketplace entries pointing at the current monolithic plugin. |
Suppressed comments (20)
plugins/agent-toolkit/packs/manifest.json:148
- Trailing stray apostrophe in the description string (
... Linux. ').
"description": "Uses the Linux Audit framework (auditd) with ausearch and aureport utilities to detect intrusion attempts, unauthorized access, privilege escalation, and suspicious system activity. Covers audit rule configuration, log querying, timeline reconstruction, and integration with SIEM platforms. Activates for requests involving auditd analysis, Linux audit log investigation, ausearch queries, aureport summaries, or host-based intrusion detection on Linux. '"
plugins/agent-toolkit/packs/manifest.json:160
- Trailing stray apostrophe in the description string (
... analysis. ').
"description": "Detects rootkit presence on compromised systems by identifying hidden processes, hooked system calls, modified kernel structures, hidden files, and covert network connections using memory forensics, cross-view detection, and integrity checking techniques. Activates for requests involving rootkit detection, hidden process discovery, kernel integrity checking, or system call hook analysis. '"
plugins/agent-toolkit/packs/manifest.json:172
- Trailing stray apostrophe in the description string (
... probing. ').
"description": "Configures Fail2ban with custom filters and actions to detect port scanning activity, SSH brute force attempts, and network reconnaissance, automatically banning offending IP addresses and alerting security teams to suspicious network probing. '"
plugins/agent-toolkit/packs/manifest.json:228
- Trailing stray apostrophe in the description string (
... segments. ').
"description": "Captures and analyzes network packet data using Wireshark and tshark to identify malicious traffic patterns, diagnose protocol issues, extract artifacts, and support incident response investigations on authorized network segments. '"
plugins/agent-toolkit/packs/manifest.json:236
- Trailing stray apostrophe in the description string (
... monitoring. ').
"description": "Deploys and configures Suricata IDS/IPS with Emerging Threats rulesets, EVE JSON logging, and custom rules for real-time network traffic inspection, threat detection, and integration with SIEM platforms for centralized security monitoring. '"
plugins/agent-toolkit/packs/manifest.json:240
- Trailing stray apostrophe in the description string (
... response. ').
"description": "Deploys and configures Zeek (formerly Bro) network security monitor to passively analyze network traffic, generate structured logs, detect anomalous behavior, and create custom detection scripts for threat hunting and incident response. '"
plugins/agent-toolkit/packs/manifest.json:244
- Trailing stray apostrophe in the description string (
... data. ').
"description": "Performs statistical analysis of Zeek conn.log connection intervals to detect C2 beaconing patterns. Uses the ZAT library to load Zeek logs into Pandas DataFrames, calculates inter-arrival time standard deviation, and flags periodic connections with low jitter. Use when hunting for command-and-control callbacks in network data. '"
plugins/agent-toolkit/packs/manifest.json:252
- Trailing stray apostrophe in the description string (
... querying. ').
"description": "Deploys and configures osquery for real-time endpoint monitoring using SQL-based queries to inspect running processes, open ports, installed software, and system configuration. Use when building visibility into endpoint state, threat hunting across fleet, or implementing compliance monitoring. Activates for requests involving osquery deployment, endpoint visibility, fleet management, or SQL-based endpoint querying. '"
plugins/agent-toolkit/packs/manifest.json:256
- Trailing stray apostrophe in the description string (
... backends. ').
"description": "Builds vendor-agnostic detection rules using the Sigma rule format for threat detection across SIEM platforms including Splunk, Elastic, and Microsoft Sentinel. Use when creating portable detection logic from threat intelligence, mapping rules to MITRE ATT&CK techniques, or converting community Sigma rules into platform-specific queries using sigmac or pySigma backends. '"
plugins/agent-toolkit/packs/manifest.json:260
- Trailing stray apostrophe in the description string (
... detection. ').
"description": "Performs rapid malware triage and classification using YARA rules to match file patterns, strings, byte sequences, and structural characteristics against known malware families and suspicious indicators. Covers rule writing, scanning, and integration with analysis pipelines. Activates for requests involving YARA rule creation, malware classification, pattern matching, sample triage, or signature-based detection. '"
plugins/agent-toolkit/packs/manifest.json:264
- Trailing stray apostrophe in the description string (
... playbooks. ').
"description": "Proactively hunts for Advanced Persistent Threat (APT) activity within enterprise environments using hypothesis-driven searches across endpoint telemetry, network logs, and memory artifacts. Use when conducting scheduled threat hunting cycles, investigating anomalous behavior flagged by UEBA, or validating that known APT TTPs are not present in the environment. Activates for requests involving MITRE ATT&CK, Velociraptor, osquery, Zeek, or threat hunting playbooks. '"
plugins/agent-toolkit/packs/manifest.json:272
- Trailing stray apostrophe in the description string (
... acquisition. ').
"description": "Performs memory forensics analysis using Volatility 3 to extract evidence of malware execution, process injection, network connections, and credential theft from RAM dumps captured during incident response. Covers memory acquisition, process analysis, DLL inspection, and malware detection. Activates for requests involving memory forensics, RAM analysis, Volatility framework, memory dump investigation, volatile evidence analysis, or live memory acquisition. '"
plugins/agent-toolkit/packs/manifest.json:280
- Trailing stray apostrophe in the description string (
... investigation. ').
"description": "Conducts disk forensics investigations using forensic imaging, file system analysis, artifact recovery, and timeline reconstruction to support incident response cases. Utilizes tools such as FTK Imager, Autopsy, and The Sleuth Kit for evidence acquisition, deleted file recovery, and artifact examination. Activates for requests involving disk forensics, hard drive analysis, forensic imaging, file recovery, evidence acquisition, or digital forensic investigation. '"
plugins/agent-toolkit/packs/manifest.json:284
- Trailing stray apostrophe in the description string (
... investigation. ').
"description": "Performs digital forensics investigation on compromised endpoints including memory acquisition, disk imaging, artifact analysis, and timeline reconstruction. Use when investigating security incidents, collecting evidence for legal proceedings, or analyzing endpoint compromise scope. Activates for requests involving endpoint forensics, memory analysis, disk forensics, or incident investigation. '"
plugins/agent-toolkit/packs/manifest.json:292
- Trailing stray apostrophe in the description string (
... design. ').
"description": "Designs and documents structured incident response playbooks that define step-by-step procedures for specific incident types aligned with NIST SP 800-61r3 and SANS PICERL frameworks. Covers playbook structure, decision trees, escalation criteria, RACI matrices, and integration with SOAR platforms. Activates for requests involving IR playbook creation, incident response procedure documentation, response runbook development, or SOAR playbook design. '"
plugins/agent-toolkit/packs/manifest.json:312
- Trailing stray apostrophe in the description string (
... assessments. ').
"description": "Implements external attack surface management (EASM) using Shodan, Censys, and ProjectDiscovery tools (subfinder, httpx, nuclei) for asset discovery, subdomain enumeration, service fingerprinting, and exposure scoring. Includes a weighted risk scoring algorithm based on OWASP attack surface analysis methodology and the Relative Attack Surface Quotient (RSQ). Use when building continuous ASM programs or performing external reconnaissance for security assessments. '"
plugins/agent-toolkit/packs/manifest.json:316
- Trailing stray apostrophe in the description string (
... GCP. ').
"description": "This skill details how to conduct cloud security audits using Center for Internet Security benchmarks for AWS, Azure, and GCP. It covers interpreting CIS Foundations Benchmark controls, running automated assessments with tools like Prowler and ScoutSuite, remediating failed controls, and maintaining continuous compliance monitoring against CIS v5 for AWS, v4 for Azure, and v4 for GCP. '"
plugins/agent-toolkit/packs/manifest.json:320
- Trailing stray apostrophe in the description string (
... credentials. ').
"description": "This skill covers implementing Gitleaks for detecting and preventing hardcoded secrets in git repositories. It addresses configuring pre-commit hooks, CI/CD pipeline integration, custom rule authoring for organization-specific secrets, baseline management for existing repositories, and remediation workflows for exposed credentials. '"
plugins/agent-toolkit/packs/manifest.json:324
- Trailing stray apostrophe in the description string (
... access. ').
"description": "Detecting exposed AWS credentials in source code repositories, CI/CD pipelines, and configuration files using TruffleHog, git-secrets, and AWS-native detection mechanisms to prevent credential theft and unauthorized account access. '"
plugins/agent-toolkit/packs/manifest.json:332
- Trailing stray apostrophe in the description string (
... correlation. ').
"description": "Parses Software Bill of Materials (SBOM) in CycloneDX and SPDX JSON formats to identify supply chain vulnerabilities by correlating components against the NVD CVE database via the NVD 2.0 API. Builds dependency graphs, calculates risk scores, identifies transitive vulnerability paths, and generates compliance reports. Activates for requests involving SBOM analysis, software composition analysis, supply chain security assessment, dependency vulnerability scanning, CycloneDX/SPDX parsing, or CVE correlation. '"
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
| lines = [ | ||
| f"name: {pname}", | ||
| f"description: {desc}", | ||
| "skills:", | ||
| ] | ||
| for s in skills: | ||
| lines.append(f" - {s}") |
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Summary
Group the 129 installed skills into 8 themed packs (core, hermes-dev, cybersecurity, methodology, media, docs-web-research, computer-use, dev-essentials) and add a
/toolkitbrowse command +SessionStartstatus banner — a navigation layer over the single plugin so the wall of 129 skills becomes scannable by domain. Every skill still loads in every session and is invokable asagent-toolkit:<name>; packs just make browsing and routing easier.Type of change
feat— new skill / MCP server / workflowfix— bug fix (two pre-existingsrc/mcp_server_bastifixes bundled in to unblock CI — see below)docs— documentation onlychore— maintenance (deps, config, scripts)refactor— code change without new featuresWhat's in the PR
Skill packs + toolkit (the feature)
packs/manifest.json— clean partition of all 129 skills into 8 packs. Validated byscripts/build_packs.py: union == installed skill dirs (129), no duplicates, no missing/extra. Exits non-zero on partition error.packs/<8>/README.md— per-pack "when to use this pack" + the skill roster with one-line descriptions.commands/toolkit.md—/toolkit(overview table of 8 packs),/toolkit <pack>(skill roster),/toolkit doctor(health check: skill/agent/pack counts, GitHub MCPget_me200/401, INDEX.json freshness). Never prints credentials.hooks/hooks.json+hooks/toolkit-status.sh—SessionStartbanner:agent-toolkit: 129 skills · 8 packs · 17 agents · 9 MCP servers — run /toolkit to browse, /toolkit doctor to health-check.Sensor-only, exits 0.scripts/build_packs.py— validates the manifest AND emitsrouting/bundles/<pack>.yaml(replaces the 12 stale bundles that referenced non-installed library skills). Wired intoscripts/build_index.py.routing/bundles/— 12 stale bundles removed (tailwind, code-review-suite, testing-strategies, react-frontend, …), 8 pack-sourced bundles emitted..claude-plugin/marketplace.json— +8 themed stub entries (agent-toolkit-core,-hermes-dev,-cybersecurity,-methodology,-media,-docs-web-research,-computer-use,-dev-essentials) as future split targets. All currently point at./plugins/agent-toolkit(the "split later" decision). Fallback noted in PACKS.md: if/plugin marketplacerejects duplicate sources, keep only the canonical entry — PACKS.md is the durable record either way.PACKS.md(repo root) — the pack index, per-pack counts, and the future "install only what you need" split roadmap (repoint sources, recommended migration order).README.md— new Skill packs section, fixed counts (129 skills, 9 MCP servers incl.basti-tools), updated tree + scripts listing.plugin.json— bump0.5.0 → 0.6.0; description now reflects packs/command/hook.Pre-existing CI fixes bundled in (unblock CI on this branch)
These are in
src/mcp_server_basti/— unrelated to skill packs, but main's CI was already red and they blocked this PR's checks. Both are trivial:logging_setup.py:31— docstring not indented underdef setup_json_logging→IndentationErrorbroke pytest collection of 3 unit tests + tripped ruff. Indentation fix.logging_setup.py:17—timezone.utc→datetime.UTC(ruff UP017;requires-python = ">=3.11"sodatetime.UTCis available).Verification
Checklist
.envis in.gitignore)SKILL.mdhasname,description,triggersfrontmatterpython3 scripts/build_index.pyhas been run locally.mcp.jsonwith${ENV_VAR}references only.env.example(No new MCP server in this PR — the 9th,
basti-tools, was already present; this PR just documents it in the README table. No skills added either — the 129 were already installed; this PR groups them.)Related
githubMCP server returns 401 on this workstation — diagnosed as a sourcing issue, not an expired token: theGITHUB_TOKENin~/.hermes/.envis valid (GitHub API → HTTP 200), butGITHUB_PERSONAL_ACCESS_TOKENis unset in the shell becauseclaudewasn't launched viasource ~/.claude/load-github-token.sh && claude. Fix = relaunch with the source script./toolkit doctorsurfaces the 401 either way.git -C ~/.claude/plugins/marketplaces/my-agent-tools pull+claude plugin update agent-toolkit@my-agent-tools→ 0.6.0 on this workstation (currently pinned at 0.1.0; clone at 0.4.0, 5 commits behind remote main).🤖 Generated with Claude Code