Skip to content

feat: 8 themed skill packs + /toolkit command + session hook + split roadmap - #3

Merged
Toqsick merged 6 commits into
mainfrom
skill-packs
Aug 5, 2026
Merged

Toqsick merged 6 commits into
mainfrom
skill-packs

Conversation

@Toqsick

@Toqsick Toqsick commented Aug 5, 2026 •

Copy link
Copy Markdown
Owner

Summary

Group the 129 installed skills into 8 themed packs (core, hermes-dev, cybersecurity, methodology, media, docs-web-research, computer-use, dev-essentials) and add a /toolkit browse command + SessionStart status banner — a navigation layer over the single plugin so the wall of 129 skills becomes scannable by domain. Every skill still loads in every session and is invokable as agent-toolkit:<name>; packs just make browsing and routing easier.

Type of change

  • feat — new skill / MCP server / workflow
  • fix — bug fix (two pre-existing src/mcp_server_basti fixes bundled in to unblock CI — see below)
  • docs — documentation only
  • chore — maintenance (deps, config, scripts)
  • refactor — code change without new features

What's in the PR

Skill packs + toolkit (the feature)

  • packs/manifest.json — clean partition of all 129 skills into 8 packs. Validated by scripts/build_packs.py: union == installed skill dirs (129), no duplicates, no missing/extra. Exits non-zero on partition error.
  • packs/<8>/README.md — per-pack "when to use this pack" + the skill roster with one-line descriptions.
  • commands/toolkit.md — /toolkit (overview table of 8 packs), /toolkit <pack> (skill roster), /toolkit doctor (health check: skill/agent/pack counts, GitHub MCP get_me 200/401, INDEX.json freshness). Never prints credentials.
  • hooks/hooks.json + hooks/toolkit-status.sh — SessionStart banner: agent-toolkit: 129 skills · 8 packs · 17 agents · 9 MCP servers — run /toolkit to browse, /toolkit doctor to health-check. Sensor-only, exits 0.
  • scripts/build_packs.py — validates the manifest AND emits routing/bundles/<pack>.yaml (replaces the 12 stale bundles that referenced non-installed library skills). Wired into scripts/build_index.py.
  • routing/bundles/ — 12 stale bundles removed (tailwind, code-review-suite, testing-strategies, react-frontend, …), 8 pack-sourced bundles emitted.
  • .claude-plugin/marketplace.json — +8 themed stub entries (agent-toolkit-core, -hermes-dev, -cybersecurity, -methodology, -media, -docs-web-research, -computer-use, -dev-essentials) as future split targets. All currently point at ./plugins/agent-toolkit (the "split later" decision). Fallback noted in PACKS.md: if /plugin marketplace rejects duplicate sources, keep only the canonical entry — PACKS.md is the durable record either way.
  • PACKS.md (repo root) — the pack index, per-pack counts, and the future "install only what you need" split roadmap (repoint sources, recommended migration order).
  • README.md — new Skill packs section, fixed counts (129 skills, 9 MCP servers incl. basti-tools), updated tree + scripts listing.
  • plugin.json — bump 0.5.0 → 0.6.0; description now reflects packs/command/hook.

Pre-existing CI fixes bundled in (unblock CI on this branch)

These are in src/mcp_server_basti/ — unrelated to skill packs, but main's CI was already red and they blocked this PR's checks. Both are trivial:

  • logging_setup.py:31 — docstring not indented under def setup_json_logging → IndentationError broke pytest collection of 3 unit tests + tripped ruff. Indentation fix.
  • logging_setup.py:17 — timezone.utc → datetime.UTC (ruff UP017; requires-python = ">=3.11" so datetime.UTC is available).

Verification

✅ packs/manifest.json valid: 129 skills across 8 packs
   (core:10, hermes-dev:18, cybersecurity:50, methodology:18, media:6, docs-web-research:15, computer-use:3, dev-essentials:9)
✅ coverage: manifest union == disk skill dirs (129), no dupes, no missing/extra
✅ routing/bundles: 8 YAMLs, every listed skill exists in plugins/agent-toolkit/skills/
✅ build_index.py exits 0; INDEX.json: 129 installed + 1244 library = 1373 skills, 17 agents, 6 workflows, 8 packs
✅ all JSON manifests valid (marketplace, plugin, packs, hooks, .mcp, INDEX)
✅ toolkit-status.sh: syntax ok + exec test prints correct counts
✅ logging_setup.py parses; ruff UP017 + IndentationError resolved

Checklist

  • No secrets or tokens committed (.env is in .gitignore)
  • If adding a skill: SKILL.md has name, description, triggers frontmatter
  • If adding a skill: python3 scripts/build_index.py has been run locally
  • If adding an MCP server: entry added to .mcp.json with ${ENV_VAR} references only
  • If adding an MCP server: env var added to .env.example
  • CI passes (secret-scanning, skill-lint, mcp-health-check)

(No new MCP server in this PR — the 9th, basti-tools, was already present; this PR just documents it in the README table. No skills added either — the 129 were already installed; this PR groups them.)

Related

  • Local follow-up (not in this PR): the plugin's github MCP server returns 401 on this workstation — diagnosed as a sourcing issue, not an expired token: the GITHUB_TOKEN in ~/.hermes/.env is valid (GitHub API → HTTP 200), but GITHUB_PERSONAL_ACCESS_TOKEN is unset in the shell because claude wasn't launched via source ~/.claude/load-github-token.sh && claude. Fix = relaunch with the source script. /toolkit doctor surfaces the 401 either way.
  • After merge: git -C ~/.claude/plugins/marketplaces/my-agent-tools pull + claude plugin update agent-toolkit@my-agent-tools → 0.6.0 on this workstation (currently pinned at 0.1.0; clone at 0.4.0, 5 commits behind remote main).

🤖 Generated with Claude Code

…roadmap

Group the 129 installed skills into 8 themed packs (core, hermes-dev, cybersecurity,
methodology, media, docs-web-research, computer-use, dev-essentials) — a navigation layer
over the single plugin so the wall of skills becomes scannable by domain.

- packs/manifest.json: clean partition of all 129 skills (validated, no dupes, full coverage)
- packs/<8>/README.md: per-pack "when to use" + skill roster
- commands/toolkit.md: /toolkit browse + /toolkit <pack> + /toolkit doctor health check
- hooks/: SessionStart banner (skills · packs · agents · MCP counts), sensor-only
- scripts/build_packs.py: validates manifest + emits routing/bundles/*.yaml; wired into build_index
- routing/bundles: replaced 12 stale library-arsenal bundles with 8 pack-sourced bundles
- .claude-plugin/marketplace.json: +8 themed stub entries (future split targets, all → one plugin)
- PACKS.md: pack index + future "install only what you need" split roadmap
- README.md: Packs section, fix counts (129 skills, 9 MCP servers), add basti-tools to MCP table
- plugin.json: bump 0.5.0 → 0.6.0

Regenerated INDEX.json + NAVIGATION.md via scripts/build_index.py.
Coverage verified: manifest union == installed skill dirs (129), no duplicates.

Co-Authored-By: Claude <noreply@anthropic.com>
Copilot AI lite review requested due to automatic review settings August 5, 2026 04:01
Toqsick and others added 2 commits August 5, 2026 06:03
src/mcp_server_basti/logging_setup.py:31 had its docstring at column 0
instead of indented under the function def, causing an IndentationError
that broke pytest collection (3 unit tests) and tripped ruff (2 errors)
on a file unrelated to the skill-packs work. Pre-existing on main; CI
was already red. One-line indentation fix.

Co-Authored-By: Claude <noreply@anthropic.com>
ruff UP017 flags `timezone.utc` in logging_setup.py:17; requires-python
is >=3.11 so `datetime.UTC` (3.11+) is available. Pre-existing on main;
blocked CI ruff job. One-line usage + import fix.

Co-Authored-By: Claude <noreply@anthropic.com>

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR introduces a “skill pack” navigation layer over the existing agent-toolkit plugin by partitioning the installed skills into 8 themed packs, generating pack-based routing bundles, and adding user-facing affordances to browse/health-check the toolkit.

Changes:

  • Added curated pack manifest + per-pack READMEs, plus generated pack-based routing/bundles/*.yaml.
  • Added /toolkit slash command and a SessionStart hook that prints a one-line toolkit status banner.
  • Wired pack validation/bundle emission into scripts/build_index.py, and extended generated navigation/index artifacts to include pack info.

Reviewed changes

Copilot reviewed 42 out of 42 changed files in this pull request and generated 4 comments.

Show a summary per file
File Description
scripts/build_packs.py Validates packs/manifest.json and emits pack-derived routing bundles.
scripts/build_index.py Calls pack build/validation and includes packs in generated navigation output.
routing/bundles/testing-strategies.yaml Removes legacy/stale bundle in favor of pack-derived bundles.
routing/bundles/tailwind.yaml Removes legacy/stale bundle in favor of pack-derived bundles.
routing/bundles/supabase-platform.yaml Removes legacy/stale bundle in favor of pack-derived bundles.
routing/bundles/react-frontend.yaml Removes legacy/stale bundle in favor of pack-derived bundles.
routing/bundles/obsidian.yaml Removes legacy/stale bundle in favor of pack-derived bundles.
routing/bundles/ml-research.yaml Removes legacy/stale bundle in favor of pack-derived bundles.
routing/bundles/methodology.yaml Adds pack-derived routing bundle for the methodology pack.
routing/bundles/media.yaml Adds pack-derived routing bundle for the media pack.
routing/bundles/llm-operations.yaml Removes legacy/stale bundle in favor of pack-derived bundles.
routing/bundles/hermes-dev.yaml Adds pack-derived routing bundle for the hermes-dev pack.
routing/bundles/find-and-discover.yaml Removes legacy/stale bundle in favor of pack-derived bundles.
routing/bundles/documents-and-web.yaml Removes legacy/stale bundle in favor of pack-derived bundles.
routing/bundles/docs-web-research.yaml Adds pack-derived routing bundle for the docs-web-research pack.
routing/bundles/dev-essentials.yaml Adds pack-derived routing bundle for the dev-essentials pack.
routing/bundles/design-suite.yaml Removes legacy/stale bundle in favor of pack-derived bundles.
routing/bundles/cybersecurity.yaml Adds pack-derived routing bundle for the cybersecurity pack.
routing/bundles/core.yaml Adds pack-derived routing bundle for the core pack.
routing/bundles/computer-use.yaml Adds pack-derived routing bundle for the computer-use pack.
routing/bundles/code-review-suite.yaml Removes legacy/stale bundle in favor of pack-derived bundles.
routing/bundles/backend-frameworks.yaml Removes legacy/stale bundle in favor of pack-derived bundles.
README.md Documents packs, /toolkit, hook banner, and updates counts.
plugins/agent-toolkit/packs/README.md Adds top-level pack index within the plugin.
plugins/agent-toolkit/packs/methodology/README.md Adds pack-specific guidance and roster for methodology.
plugins/agent-toolkit/packs/media/README.md Adds pack-specific guidance and roster for media.
plugins/agent-toolkit/packs/manifest.json Defines the canonical pack partition and skill metadata.
plugins/agent-toolkit/packs/hermes-dev/README.md Adds pack-specific guidance and roster for hermes-dev.
plugins/agent-toolkit/packs/docs-web-research/README.md Adds pack-specific guidance and roster for docs-web-research.
plugins/agent-toolkit/packs/dev-essentials/README.md Adds pack-specific guidance and roster for dev-essentials.
plugins/agent-toolkit/packs/cybersecurity/README.md Adds pack-specific guidance and roster for cybersecurity.
plugins/agent-toolkit/packs/core/README.md Adds pack-specific guidance and roster for core.
plugins/agent-toolkit/packs/computer-use/README.md Adds pack-specific guidance and roster for computer-use.
plugins/agent-toolkit/hooks/toolkit-status.sh Adds SessionStart status banner hook script.
plugins/agent-toolkit/hooks/hooks.json Registers the SessionStart hook to run the status banner.
plugins/agent-toolkit/commands/toolkit.md Adds /toolkit command instructions (browse packs + doctor).
plugins/agent-toolkit/.claude-plugin/plugin.json Bumps plugin version and updates description to include packs/command/hook.
PACKS.md Adds repo-root pack index and future split roadmap.
NAVIGATION.md Updates generated navigation to include pack table.
INDEX.json Updates generated timestamp (and related generated outputs).
.claude-plugin/marketplace.json Adds pack-stub marketplace entries pointing at the current monolithic plugin.
Suppressed comments (20)

plugins/agent-toolkit/packs/manifest.json:148

  • Trailing stray apostrophe in the description string (... Linux. ').
          "description": "Uses the Linux Audit framework (auditd) with ausearch and aureport utilities to detect intrusion attempts, unauthorized access, privilege escalation, and suspicious system activity. Covers audit rule configuration, log querying, timeline reconstruction, and integration with SIEM platforms. Activates for requests involving auditd analysis, Linux audit log investigation, ausearch queries, aureport summaries, or host-based intrusion detection on Linux. '"

plugins/agent-toolkit/packs/manifest.json:160

  • Trailing stray apostrophe in the description string (... analysis. ').
          "description": "Detects rootkit presence on compromised systems by identifying hidden processes, hooked system calls, modified kernel structures, hidden files, and covert network connections using memory forensics, cross-view detection, and integrity checking techniques. Activates for requests involving rootkit detection, hidden process discovery, kernel integrity checking, or system call hook analysis. '"

plugins/agent-toolkit/packs/manifest.json:172

  • Trailing stray apostrophe in the description string (... probing. ').
          "description": "Configures Fail2ban with custom filters and actions to detect port scanning activity, SSH brute force attempts, and network reconnaissance, automatically banning offending IP addresses and alerting security teams to suspicious network probing. '"

plugins/agent-toolkit/packs/manifest.json:228

  • Trailing stray apostrophe in the description string (... segments. ').
          "description": "Captures and analyzes network packet data using Wireshark and tshark to identify malicious traffic patterns, diagnose protocol issues, extract artifacts, and support incident response investigations on authorized network segments. '"

plugins/agent-toolkit/packs/manifest.json:236

  • Trailing stray apostrophe in the description string (... monitoring. ').
          "description": "Deploys and configures Suricata IDS/IPS with Emerging Threats rulesets, EVE JSON logging, and custom rules for real-time network traffic inspection, threat detection, and integration with SIEM platforms for centralized security monitoring. '"

plugins/agent-toolkit/packs/manifest.json:240

  • Trailing stray apostrophe in the description string (... response. ').
          "description": "Deploys and configures Zeek (formerly Bro) network security monitor to passively analyze network traffic, generate structured logs, detect anomalous behavior, and create custom detection scripts for threat hunting and incident response. '"

plugins/agent-toolkit/packs/manifest.json:244

  • Trailing stray apostrophe in the description string (... data. ').
          "description": "Performs statistical analysis of Zeek conn.log connection intervals to detect C2 beaconing patterns. Uses the ZAT library to load Zeek logs into Pandas DataFrames, calculates inter-arrival time standard deviation, and flags periodic connections with low jitter. Use when hunting for command-and-control callbacks in network data. '"

plugins/agent-toolkit/packs/manifest.json:252

  • Trailing stray apostrophe in the description string (... querying. ').
          "description": "Deploys and configures osquery for real-time endpoint monitoring using SQL-based queries to inspect running processes, open ports, installed software, and system configuration. Use when building visibility into endpoint state, threat hunting across fleet, or implementing compliance monitoring. Activates for requests involving osquery deployment, endpoint visibility, fleet management, or SQL-based endpoint querying. '"

plugins/agent-toolkit/packs/manifest.json:256

  • Trailing stray apostrophe in the description string (... backends. ').
          "description": "Builds vendor-agnostic detection rules using the Sigma rule format for threat detection across SIEM platforms including Splunk, Elastic, and Microsoft Sentinel. Use when creating portable detection logic from threat intelligence, mapping rules to MITRE ATT&CK techniques, or converting community Sigma rules into platform-specific queries using sigmac or pySigma backends. '"

plugins/agent-toolkit/packs/manifest.json:260

  • Trailing stray apostrophe in the description string (... detection. ').
          "description": "Performs rapid malware triage and classification using YARA rules to match file patterns, strings, byte sequences, and structural characteristics against known malware families and suspicious indicators. Covers rule writing, scanning, and integration with analysis pipelines. Activates for requests involving YARA rule creation, malware classification, pattern matching, sample triage, or signature-based detection. '"

plugins/agent-toolkit/packs/manifest.json:264

  • Trailing stray apostrophe in the description string (... playbooks. ').
          "description": "Proactively hunts for Advanced Persistent Threat (APT) activity within enterprise environments using hypothesis-driven searches across endpoint telemetry, network logs, and memory artifacts. Use when conducting scheduled threat hunting cycles, investigating anomalous behavior flagged by UEBA, or validating that known APT TTPs are not present in the environment. Activates for requests involving MITRE ATT&CK, Velociraptor, osquery, Zeek, or threat hunting playbooks. '"

plugins/agent-toolkit/packs/manifest.json:272

  • Trailing stray apostrophe in the description string (... acquisition. ').
          "description": "Performs memory forensics analysis using Volatility 3 to extract evidence of malware execution, process injection, network connections, and credential theft from RAM dumps captured during incident response. Covers memory acquisition, process analysis, DLL inspection, and malware detection. Activates for requests involving memory forensics, RAM analysis, Volatility framework, memory dump investigation, volatile evidence analysis, or live memory acquisition. '"

plugins/agent-toolkit/packs/manifest.json:280

  • Trailing stray apostrophe in the description string (... investigation. ').
          "description": "Conducts disk forensics investigations using forensic imaging, file system analysis, artifact recovery, and timeline reconstruction to support incident response cases. Utilizes tools such as FTK Imager, Autopsy, and The Sleuth Kit for evidence acquisition, deleted file recovery, and artifact examination. Activates for requests involving disk forensics, hard drive analysis, forensic imaging, file recovery, evidence acquisition, or digital forensic investigation. '"

plugins/agent-toolkit/packs/manifest.json:284

  • Trailing stray apostrophe in the description string (... investigation. ').
          "description": "Performs digital forensics investigation on compromised endpoints including memory acquisition, disk imaging, artifact analysis, and timeline reconstruction. Use when investigating security incidents, collecting evidence for legal proceedings, or analyzing endpoint compromise scope. Activates for requests involving endpoint forensics, memory analysis, disk forensics, or incident investigation. '"

plugins/agent-toolkit/packs/manifest.json:292

  • Trailing stray apostrophe in the description string (... design. ').
          "description": "Designs and documents structured incident response playbooks that define step-by-step procedures for specific incident types aligned with NIST SP 800-61r3 and SANS PICERL frameworks. Covers playbook structure, decision trees, escalation criteria, RACI matrices, and integration with SOAR platforms. Activates for requests involving IR playbook creation, incident response procedure documentation, response runbook development, or SOAR playbook design. '"

plugins/agent-toolkit/packs/manifest.json:312

  • Trailing stray apostrophe in the description string (... assessments. ').
          "description": "Implements external attack surface management (EASM) using Shodan, Censys, and ProjectDiscovery tools (subfinder, httpx, nuclei) for asset discovery, subdomain enumeration, service fingerprinting, and exposure scoring. Includes a weighted risk scoring algorithm based on OWASP attack surface analysis methodology and the Relative Attack Surface Quotient (RSQ). Use when building continuous ASM programs or performing external reconnaissance for security assessments. '"

plugins/agent-toolkit/packs/manifest.json:316

  • Trailing stray apostrophe in the description string (... GCP. ').
          "description": "This skill details how to conduct cloud security audits using Center for Internet Security benchmarks for AWS, Azure, and GCP. It covers interpreting CIS Foundations Benchmark controls, running automated assessments with tools like Prowler and ScoutSuite, remediating failed controls, and maintaining continuous compliance monitoring against CIS v5 for AWS, v4 for Azure, and v4 for GCP. '"

plugins/agent-toolkit/packs/manifest.json:320

  • Trailing stray apostrophe in the description string (... credentials. ').
          "description": "This skill covers implementing Gitleaks for detecting and preventing hardcoded secrets in git repositories. It addresses configuring pre-commit hooks, CI/CD pipeline integration, custom rule authoring for organization-specific secrets, baseline management for existing repositories, and remediation workflows for exposed credentials. '"

plugins/agent-toolkit/packs/manifest.json:324

  • Trailing stray apostrophe in the description string (... access. ').
          "description": "Detecting exposed AWS credentials in source code repositories, CI/CD pipelines, and configuration files using TruffleHog, git-secrets, and AWS-native detection mechanisms to prevent credential theft and unauthorized account access. '"

plugins/agent-toolkit/packs/manifest.json:332

  • Trailing stray apostrophe in the description string (... correlation. ').
          "description": "Parses Software Bill of Materials (SBOM) in CycloneDX and SPDX JSON formats to identify supply chain vulnerabilities by correlating components against the NVD CVE database via the NVD 2.0 API. Builds dependency graphs, calculates risk scores, identifies transitive vulnerability paths, and generates compliance reports. Activates for requests involving SBOM analysis, software composition analysis, supply chain security assessment, dependency vulnerability scanning, CycloneDX/SPDX parsing, or CVE correlation. '"

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread scripts/build_index.py Outdated
Comment thread scripts/build_packs.py
Comment on lines +102 to +108
lines = [
f"name: {pname}",
f"description: {desc}",
"skills:",
]
for s in skills:
lines.append(f" - {s}")

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@copilot try to fix it

Comment thread plugins/agent-toolkit/commands/toolkit.md Outdated
Comment thread plugins/agent-toolkit/packs/manifest.json Outdated
Toqsick and others added 3 commits August 5, 2026 06:07
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants