Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions docs/README.skills.md
Original file line number Diff line number Diff line change
Expand Up @@ -37,6 +37,7 @@ See [CONTRIBUTING.md](../CONTRIBUTING.md#adding-skills) for guidelines on how to
| [agent-governance](../skills/agent-governance/SKILL.md)<br />`gh skills install github/awesome-copilot agent-governance` | Patterns and techniques for adding governance, safety, and trust controls to AI agent systems. Use this skill when:<br />- Building AI agents that call external tools (APIs, databases, file systems)<br />- Implementing policy-based access controls for agent tool usage<br />- Adding semantic intent classification to detect dangerous prompts<br />- Creating trust scoring systems for multi-agent workflows<br />- Building audit trails for agent actions and decisions<br />- Enforcing rate limits, content filters, or tool restrictions on agents<br />- Working with any agent framework (PydanticAI, CrewAI, OpenAI Agents, LangChain, AutoGen) | None |
| [agent-owasp-compliance](../skills/agent-owasp-compliance/SKILL.md)<br />`gh skills install github/awesome-copilot agent-owasp-compliance` | Check any AI agent codebase against the OWASP Agentic Security Initiative (ASI) Top 10 risks.<br />Use this skill when:<br />- Evaluating an agent system's security posture before production deployment<br />- Running a compliance check against OWASP ASI 2026 standards<br />- Mapping existing security controls to the 10 agentic risks<br />- Generating a compliance report for security review or audit<br />- Comparing agent framework security features against the standard<br />- Any request like "is my agent OWASP compliant?", "check ASI compliance", or "agentic security audit" | None |
| [agent-skill-stack](../skills/agent-skill-stack/SKILL.md)<br />`gh skills install github/awesome-copilot agent-skill-stack` | Find, evaluate, and assemble the smallest compatible set of AI Agent Skills for an end-to-end natural-language goal. Use when a user wants Skills for a multi-step workflow, asks which Skills fit a project, needs an installed-Skill audit or conflict check, has low Skill recall, wants indirect helpers such as humanizers or compliance checks, or wants a project-specific Skill Stack with controlled installation. Search local Skills, registries, GitHub, and OpenCLI; compare adoption, verified fit, safety, and overlap. Do not use for locating one known or common Skill; use the generic find-skills workflow. | `agents/openai.yaml`<br />`references/discovery-ranking.md`<br />`references/local-index-and-profiles.md`<br />`references/security-installation.md`<br />`references/workflow-model.md`<br />`scripts/inventory_skills.py`<br />`scripts/project_profile.py`<br />`scripts/render_stack_card.py`<br />`scripts/skill_index.py`<br />`scripts/stage_install.py` |
| [agent-skills-setup](../skills/agent-skills-setup/SKILL.md)<br />`gh skills install github/awesome-copilot agent-skills-setup` | Use when a user wants to migrate, back up, restore, compare, or move AI-coding-agent context across Cursor, Claude Code, Codex, Cline, Copilot, Windsurf, Gemini CLI, or another supported profile, including switching computers. Handles reviewed Skills, instructions/rules, and MCP with secret redaction, plan preview, verification, and rollback. | `assets/LICENSE.clawhub`<br />`assets/demo.gif`<br />`evals/evals.json`<br />`evals/files/cursor-project-mcp.json`<br />`evals/files/instruction-cline-source.md`<br />`evals/files/instruction-ir-cursor.golden.mdc`<br />`evals/files/instruction-ir-source.mdc`<br />`evals/profile-contracts.json`<br />`evals/trigger-evals.json`<br />`references/doc-freshness-checks.json`<br />`references/ide-paths.json`<br />`references/ide-registry.md`<br />`references/ides/aider.md`<br />`references/ides/amazon-q.md`<br />`references/ides/android-studio.md`<br />`references/ides/antigravity.md`<br />`references/ides/augment-code.md`<br />`references/ides/baidu-comate-ide.md`<br />`references/ides/baidu-comate.md`<br />`references/ides/blackbox.md`<br />`references/ides/bolt-new.md`<br />`references/ides/claude-desktop.md`<br />`references/ides/claude.md`<br />`references/ides/cline.md`<br />`references/ides/codecompanion-nvim.md`<br />`references/ides/codeium.md`<br />`references/ides/codely.md`<br />`references/ides/codex.md`<br />`references/ides/cody.md`<br />`references/ides/continue.md`<br />`references/ides/copilot.md`<br />`references/ides/crush.md`<br />`references/ides/cursor.md`<br />`references/ides/devin.md`<br />`references/ides/emacs.md`<br />`references/ides/factory-droid.md`<br />`references/ides/firebase-studio.md`<br />`references/ides/forge.md`<br />`references/ides/gemini-cli.md`<br />`references/ides/gemini-code-assist.md`<br />`references/ides/gitlab-duo.md`<br />`references/ides/goose-cli.md`<br />`references/ides/gptel-mcp-el.md`<br />`references/ides/helix.md`<br />`references/ides/hermes.md`<br />`references/ides/ibm-bob.md`<br />`references/ides/jetbrains-ai.md`<br />`references/ides/jetbrains.md`<br />`references/ides/jules.md`<br />`references/ides/kilocode.md`<br />`references/ides/kimiai.md`<br />`references/ides/kiro.md`<br />`references/ides/letta-code.md`<br />`references/ides/letta.md`<br />`references/ides/lovable.md`<br />`references/ides/mcphub-nvim.md`<br />`references/ides/minimax-code.md`<br />`references/ides/mistral-vibe.md`<br />`references/ides/mmx-cli.md`<br />`references/ides/monkeycode.md`<br />`references/ides/neovim.md`<br />`references/ides/openclaw.md`<br />`references/ides/opencode.md`<br />`references/ides/openhands.md`<br />`references/ides/pearai.md`<br />`references/ides/pi.md`<br />`references/ides/pieces.md`<br />`references/ides/qoder-cn.md`<br />`references/ides/qoder.md`<br />`references/ides/qodo.md`<br />`references/ides/qwen-code.md`<br />`references/ides/replit.md`<br />`references/ides/roo-code.md`<br />`references/ides/rovodev.md`<br />`references/ides/sourcegraph-amp.md`<br />`references/ides/supermaven.md`<br />`references/ides/tabnine.md`<br />`references/ides/tencent-codebuddy-ide.md`<br />`references/ides/tencent-codebuddy.md`<br />`references/ides/tongyi-lingma.md`<br />`references/ides/trae-cn.md`<br />`references/ides/trae-work.md`<br />`references/ides/trae.md`<br />`references/ides/ui-only-mcp.md`<br />`references/ides/v0.md`<br />`references/ides/vecli.md`<br />`references/ides/visual-studio.md`<br />`references/ides/void-editor.md`<br />`references/ides/vscode.md`<br />`references/ides/warp-oz.md`<br />`references/ides/warp.md`<br />`references/ides/windsurf.md`<br />`references/ides/workbuddy.md`<br />`references/ides/xcode.md`<br />`references/ides/zcode.md`<br />`references/ides/zed.md`<br />`references/ides/zencoder.md`<br />`references/ides/zenflow.md`<br />`references/mcp-migration.md`<br />`references/mcp-transport.md`<br />`references/migration-safety.md`<br />`references/object-migration.md`<br />`references/registry-v2.json`<br />`references/registry-v2.schema.json`<br />`references/verification.md`<br />`scripts/README.md`<br />`scripts/acb/__init__.py`<br />`scripts/acb/bundle.py`<br />`scripts/check-doc-freshness.py`<br />`scripts/common.sh`<br />`scripts/context-migrator.py`<br />`scripts/detect/__init__.py`<br />`scripts/detect/probes.py`<br />`scripts/doc_freshness.py`<br />`scripts/ide-paths.tsv`<br />`scripts/legacy-smart-ide-migration.sh`<br />`scripts/migration_core.py`<br />`scripts/registry/__init__.py`<br />`scripts/registry/alias_resolver.py`<br />`scripts/registry/exceptions.py`<br />`scripts/scan-skill-secrets.py`<br />`scripts/skill_secret_scanner.py`<br />`scripts/smart-ide-migration.sh`<br />`scripts/sync-ide-reference-summaries.py`<br />`scripts/test-acb-all-installed.sh`<br />`scripts/test-acb-bundle-backed-plan.sh`<br />`scripts/test-acb-multiscope-restore.sh`<br />`scripts/test-acb-p0-audit-regressions.sh`<br />`scripts/test-acb-restore-noop.sh`<br />`scripts/test-acb-secret-scan-unified.sh`<br />`scripts/test-acb-security-boundary.sh`<br />`scripts/test-acb-snapshot-restore.sh`<br />`scripts/test-acb-true-restore.sh`<br />`scripts/test-alias-resolution.sh`<br />`scripts/test-antigravity-migration.sh`<br />`scripts/test-audit-e2e-matrix.sh`<br />`scripts/test-claude-code-mapping.sh`<br />`scripts/test-claude-desktop-mapping.sh`<br />`scripts/test-codex-migration.sh`<br />`scripts/test-conflict-strategies.sh`<br />`scripts/test-copilot-mapping.sh`<br />`scripts/test-cursor-mapping.sh`<br />`scripts/test-detection-probes.sh`<br />`scripts/test-doc-freshness.sh`<br />`scripts/test-emacs-mapping.sh`<br />`scripts/test-eval-coverage.sh`<br />`scripts/test-freshness-expanded.sh`<br />`scripts/test-ide-paths.sh`<br />`scripts/test-ide-reference-generation.sh`<br />`scripts/test-ir-schemas.sh`<br />`scripts/test-jetbrains-junie-mapping.sh`<br />`scripts/test-legacy-registry-gate.sh`<br />`scripts/test-mcp-adapters.sh`<br />`scripts/test-mcp-secret-redaction.sh`<br />`scripts/test-migrate-command.sh`<br />`scripts/test-migration-core.sh`<br />`scripts/test-migration-default-scope.sh`<br />`scripts/test-migration-evidence.sh`<br />`scripts/test-migration-handoff-branch.sh`<br />`scripts/test-migration.sh`<br />`scripts/test-modern-ide-mappings.sh`<br />`scripts/test-opencode-v2-mapping.sh`<br />`scripts/test-partial-safe-apply.sh`<br />`scripts/test-profile-contracts.sh`<br />`scripts/test-progressive-disclosure.sh`<br />`scripts/test-reference-composition.sh`<br />`scripts/test-reference-layout.sh`<br />`scripts/test-registry-v2.sh`<br />`scripts/test-remaining-ide-mappings.sh`<br />`scripts/test-root-mirror-links.sh`<br />`scripts/test-skill-metadata.sh`<br />`scripts/test-skill-secret-preflight.sh`<br />`scripts/test-smart-ide-migration.sh`<br />`scripts/test-stable-object-ids.sh`<br />`scripts/test-trae-boundary.sh`<br />`scripts/test-vscode-mapping.sh`<br />`scripts/test-windsurf-mapping.sh`<br />`scripts/test-zed-mapping.sh`<br />`scripts/validate-registry-v2.py` |
| [agent-supply-chain](../skills/agent-supply-chain/SKILL.md)<br />`gh skills install github/awesome-copilot agent-supply-chain` | Verify supply chain integrity for AI agent plugins, tools, and dependencies. Use this skill when:<br />- Generating SHA-256 integrity manifests for agent plugins or tool packages<br />- Verifying that installed plugins match their published manifests<br />- Detecting tampered, modified, or untracked files in agent tool directories<br />- Auditing dependency pinning and version policies for agent components<br />- Building provenance chains for agent plugin promotion (dev → staging → production)<br />- Any request like "verify plugin integrity", "generate manifest", "check supply chain", or "sign this plugin" | None |
| [agentic-eval](../skills/agentic-eval/SKILL.md)<br />`gh skills install github/awesome-copilot agentic-eval` | Patterns and techniques for evaluating and improving AI agent outputs. Use this skill when:<br />- Implementing self-critique and reflection loops<br />- Building evaluator-optimizer pipelines for quality-critical generation<br />- Creating test-driven code refinement workflows<br />- Designing rubric-based or LLM-as-judge evaluation systems<br />- Adding iterative improvement to agent outputs (code, reports, analysis)<br />- Measuring and improving agent response quality | None |
| [ai-prompt-engineering-safety-review](../skills/ai-prompt-engineering-safety-review/SKILL.md)<br />`gh skills install github/awesome-copilot ai-prompt-engineering-safety-review` | Comprehensive AI prompt engineering safety review and improvement prompt. Analyzes prompts for safety, bias, security vulnerabilities, and effectiveness while providing detailed improvement recommendations with extensive frameworks, testing methodologies, and educational content. | None |
Expand Down
59 changes: 59 additions & 0 deletions skills/agent-skills-setup/agent-skills-setup/SKILL.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,59 @@
---
name: agent-skills-setup
license: MIT
compatibility: Requires local Bash, Python 3, environment lookup, and filesystem reads. Writes only approved migration targets; no network access.
metadata:
version: "0.9.2"
permissions.shell: "bundled offline Bash/Python scripts plus local read-only detection commands"
permissions.env: "read environment variables to resolve product paths"
permissions.file_read: "named source products, workspace tree, bundled references"
permissions.file_write: "reviewed plan targets after explicit --yes consent"
permissions.network: "denied"
description: >-
Use when a user wants to migrate, back up, restore, compare, or move
AI-coding-agent context across Cursor, Claude Code, Codex, Cline,
Copilot, Windsurf, Gemini CLI, or another supported profile, including
switching computers. Handles reviewed Skills, instructions/rules, and
MCP with secret redaction, preview, verification, and rollback.
---

# AI IDE Context Migration

## Permissions

- `shell`: bundled offline scripts plus local read-only detection commands (git, version, mdfind). No downloads or binary installations.
- `env`: path resolution only; credential-looking values are redacted, never copied or printed.
- `file_read`: named source products, workspace tree, bundled `references/`; no probing of unlisted products.
- `file_write`: reviewed plan targets after `--yes` consent; state under `<workspace>/.agent-context-migration/`.
- `network`: denied. Every subcommand is offline; no downloads, telemetry, or remote calls.

## Capabilities and authorization

- `detect`, `doctor`, `inventory`, `plan`, `snapshot`, and `bundle-verify` read only named products and workspace; network access is forbidden.
- A generic migration request authorizes planning only; separate explicit user approval (`--yes`) or explicit action verbs (apply, restore, 迁到) under `--apply-safe` authorize write.
- Save the plan, review its diff/rebuild manifest, and apply that exact file. ACB `restore` constructs a dual-side plan binding bundle sources to destination targets, supporting replayable plans (`--plan-in`) with strict TOCTOU state guards.

## Route

1. Resolve both product profiles through [ide-registry.md](references/ide-registry.md) / [registry-v2.json](references/registry-v2.json).
2. Read only [references/ides/<source>.md](references/ides/) and [references/ides/<target>.md](references/ides/).
3. Load reference by need:
- Before preview or apply: [references/migration-safety.md](references/migration-safety.md)
- MCP objects: [references/mcp-migration.md](references/mcp-migration.md)
- Other file objects: [references/object-migration.md](references/object-migration.md)
- Approved apply / proof: [references/verification.md](references/verification.md)

## Execution & Scope

- High-level: `bash scripts/smart-ide-migration.sh migrate --source <src> --target <dst> --workspace . --objects all-portable --yes`
- Step-by-step: `plan --output <plan.json>` -> `apply <plan.json> --manifest <manifest.json> --yes` -> `verify --manifest <manifest.json>` -> `rollback --manifest <manifest.json> --yes`.
- Device handoff (ACB): `snapshot` captures portable skills/instructions/MCP with atomic staging and 1:1 manifest bindings; `bundle-verify` re-checks checksums, bindings, secrets, and signatures; `restore [--plan-only | --plan-in <plan> --yes]` reviews then executes the dual-side plan. `--all-installed` bulk mode requires review and `--yes`.
- Cross-platform: `%APPDATA%` / `%USERPROFILE%` / `$APPDATA` resolution, platform detection, per-surface path isolation (remote hosts experimental). `detect` / `doctor` inspect installation state offline.
- The explicit `legacy` subcommand is read-only lookup compatibility (`--print-path`, `--dry-run`); legacy writes are disabled and enforced by the Python wrapper.
- Object-type scope (exhaustive — apply writes nothing outside it):
- Auto-migratable (`ready`): `skills`, `instructions`, `mcp`; opaque plugin package copy where both profiles declare it.
- Draft-only, never auto-written: `prompts`, `commands`, `agents`, `hooks`, `workflows`. Executable surfaces have no staging writer; replayed plans marking them eligible fail closed.
- Opt-in session transfer: `handoff` needs `--objects handoff` AND `--include-session`; only reviewed summary, git branch, relative selected files, and an explicit patch travel. Raw conversation, tokens, session state, machine paths, logs discarded.
- Never migrated: trust state, generated memory, cloud knowledge, approvals, chat history.
- Sensitive shared settings files are read only for the named migration's authorized MCP subobject; trust sections (`never-migrate`) and sibling settings never enter plans or bundles; strict secret redaction before output. See [references/mcp-migration.md](references/mcp-migration.md).
- Claude Desktop app MCP in **Settings → Extensions** and **Settings → Connectors** is UI-managed; do not infer or rewrite it from legacy JSON.
Original file line number Diff line number Diff line change
@@ -0,0 +1,17 @@
MIT No Attribution

Copyright 2026 agent-skills-setup contributors

Permission is hereby granted, free of charge, to any person obtaining a copy of
this software and associated documentation files (the "Software"), to deal in
the Software without restriction, including without limitation the rights to
use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of
the Software, and to permit persons to whom the Software is furnished to do so.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
SOFTWARE.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Loading