Catalog
affaan-m/nasiko-control-plane

affaan-m

nasiko-control-plane

Manage the experimental Nasiko CLI lifecycle through ECC — read-only status checks, consent-gated install of the pinned qualified version with dry-run preview, and ownership-checked uninstall, under explicit telemetry and secrets boundaries. Use when the user asks to install, inspect, or remove the Nasiko CLI or check whether it is present.

NewUpdated Sep 27, 2026

Nasiko CLI Lifecycle Bridge

Use this skill when a user explicitly asks ECC to install, inspect, or remove the qualified Nasiko CLI. This skill does not operate a Nasiko control plane.

Safety contract

  • Begin with ecc nasiko status --json. Status is read-only.
  • Installation always requires explicit user consent and --yes.
  • Install only an ECC-qualified pinned version, currently v0.1.0.
  • Preview first with ecc nasiko install --version v0.1.0 --dry-run --json.
  • Install with ecc nasiko install --version v0.1.0 --yes --json only after the user reviews the version, registry origin, digest, and destination.
  • Remove only a still-qualified ECC-managed binary with ecc nasiko uninstall --version v0.1.0 --yes --json. Preview removal with --dry-run first.
  • The qualified source is https://github.com/Nasiko-Labs/nasiko, licensed under Apache-2.0; artifact and extracted-binary SHA-256 values are pinned.
  • Never replace the qualified command with a downloaded shell or PowerShell bootstrap script.
  • Never put secrets or credentials in command arguments, logs, skill output, install metadata, or ECC state.
  • Nasiko telemetry and any sharing with Nasiko or Ito must be opt-in and separately disclosed. Installation is not telemetry consent.

Lifecycle boundary

The initial ECC bridge supports qualified installation, read-only status, and ownership-checked uninstall. Use the canonical Nasiko CLI directly for connection, authentication, launch, deployment, or shutdown until those verbs have their own verified ECC contracts. Do not guess CLI verbs.

Installing the CLI does not prove that a control-plane server is running, an agent is governed, routing or ACLs work, observability is complete, telemetry was enabled, or Ito compute is connected. Report each state separately.

Failure behavior

  • If the platform, architecture, version, manifest, digest, archive, binary, or destination fails validation, stop without executing the artifact.
  • Do not fall back to latest.
  • Do not search arbitrary PATH entries. Use ECC's qualified location or an explicit absolute ECC_NASIKO_CLI_EXECUTABLE for development verification.
  • Do not treat a partial or ambiguous installation as success.
Files2
2 files · 1.3 KB

Select a file to preview

Overall Score

88/100

Grade

A

Excellent

Grades are signals, not a certification. Always review a skill yourself before use.

Safety

92

Quality

88

Clarity

87

Completeness

82

Summary

A lifecycle management skill for the Nasiko CLI that provides read-only status checks, consent-gated installation of a pinned qualified version with dry-run preview, and ownership-checked uninstall. The skill enforces strict safety contracts around artifact validation, credential isolation, telemetry boundaries, and version pinning to prevent supply-chain risks.

Detected Capabilities

command execution (ecc nasiko verbs)read-only status checksartifact download and installationartifact validation (digest, SHA-256)uninstall operations

Trigger Keywords

Phrases that agents use to match this skill to user intent.

install nasiko clinasiko status checkuninstall nasikonasiko cli lifecycleverify nasiko installation

Risk Signals

INFO

Download and execute third-party artifact (Nasiko binary from github.com)

SKILL.md: Safety contract section
INFO

Network access to github.com for artifact retrieval

SKILL.md: 'qualified source is https://github.com/Nasiko-Labs/nasiko'
INFO

Shell/PowerShell bootstrap scripts explicitly forbidden

SKILL.md: 'Never replace the qualified command with a downloaded shell or PowerShell bootstrap script'

Referenced Domains

External domains referenced in skill content, detected by static analysis.

github.com

Use Cases

  • Install the pinned Nasiko CLI after user consent and dry-run preview
  • Check status and readiness of an existing Nasiko CLI installation
  • Uninstall Nasiko CLI with ownership validation to prevent accidental removal
  • Verify artifact integrity through SHA-256 digest pinning before execution
  • Isolate Nasiko telemetry from CLI installation consent to prevent privacy violations

Quality Notes

  • Excellent explicit safety boundaries: version pinning, digest validation, dry-run workflow, ownership checks
  • Clear boundary conditions (no telemetry consent, no credential exposure, no arbitrary PATH search)
  • Precise failure behavior documented: validates platform, architecture, manifest, digest, archive, binary, destination
  • Well-structured safety contract with specific ECC CLI verbs and required arguments (--yes, --json, --dry-run, --version)
  • Lifecycle boundary clearly delineates what ECC controls vs. what is delegated to canonical Nasiko CLI
  • Supporting agents/openai.yaml provides agent-specific integration guidance
  • Strong telemetry/privacy guardrails: opt-in disclosure, separate from installation consent
  • Minor: no explicit error handling examples for agent implementation (e.g., what to report if digest validation fails)
Model: claude-haiku-4-5-20251001Analyzed: Sep 27, 2026

Reviews

Add this skill to your library to leave a review.

No reviews yet

Be the first to share your experience.

Version History

  1. v3.0

    Contract changed: description

    ✦ AIExpands skill activation to include status checks and presence inspection via ECC contract-gated workflows

    triggering2026-09-27

    LATEST
  2. v2.0

    Contract changed: description

    ✦ AIScope narrowed to CLI lifecycle bridge only; no longer operates or controls the Nasiko control plane. Description updated to reflect read-only and uninstall-only capabilities.

    triggering2026-09-09

    View This Version
  3. v1.0

    2026-08-16

    View This VersionInitial version

Use affaan-m/nasiko-control-plane in your dev environment

Command Palette

Search for a command to run...