Catalogskills.sh · nomadamas

k-skill-setup

Install the k-skill bundle, use the unified CLI, resolve credentials, verify the runtime, and optionally configure update checks and GitHub starring.

Review advisedVerified hub6.5k installs

Savant verdict: Review advised

SkillSpector or the source hub flagged patterns to review before use.

Live evaluation

Not evaluated yet. Workspaces can request a live evaluation.

Safety (NVIDIA SkillSpector)

Scan pending.

Structure

  • 1 referenced file isn't in the packagescripts/generate-skill-stubs.js. They may be binary, too large to catalog, or missing upstream.
  • Ships 1 executable scriptscripts/check-setup.sh. Review what they do before enabling the skill for agents with tool access.
  • The source hub's security checks flagged this skillGen Agent Trust Hub: warn (The skill performs system setup tasks including downloading tools from the author's registry and configuring automated update checks. It uses a dynamic instruction model where the agent is told to follow instructions fetched at runtime from a CLI tool, and it establishes persistence on the host machine through cron jobs or scheduled tasks.); Socket: warn (1 alert: gptAnomaly); Snyk: warn (Risk: MEDIUM · 1 issue)

SKILL.md

---
name: k-skill-setup
description: Install the k-skill bundle, use the unified CLI, resolve credentials, verify the runtime, and optionally configure update checks and GitHub starring.
license: MIT
metadata:
  category: setup
  locale: ko-KR
  phase: v1
---

# k-skill-setup

<!-- k-skill:cli-stub — generated by scripts/generate-skill-stubs.js; edit skill.json / instruction.md instead -->

## Get the full instructions (required first step)

Run this and follow its output as the primary instructions for this skill:

```bash
npx -y @nomadamas/k-skill@0 instruct k-skill-setup
```

The CLI detects the current runtime (Dolshoi vault/CloakBrowser vs generic) and prints only the applicable instructions, always up to date. Helper files bundled with the CLI are listed by:

```bash
npx -y @nomadamas/k-skill@0 files k-skill-setup
```

Keep the CLI and every coding-agent skill install current (including Vercel Agent Skills) with:

```bash
npx -y @nomadamas/k-skill@0 update
```

If `npx` is unavailable, install Node.js 18+ or follow https://github.com/NomaDamas/k-skill#readme, or read the source instructions at https://github.com/NomaDamas/k-skill/blob/main/k-skill-setup/instruction.md.

## Hard rules even without the CLI

- Never execute payment, message/email delivery, final submission, cancellation, or public posting without the user's explicit approval immediately beforehand.
- Never ask for, print, or store plaintext credentials in chat, files, or shell arguments.
- Never bypass legal, physical-presence, CAPTCHA, identity-proofing, or electronic-signature boundaries.