Install
$ agentstack add skill-coco-research-coco-coco-cli ✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
About
coco-cli — manage the Coco framework
Thin agent wrapper over @rkz91/coco-cli (run via npx). Drives the real CLI; does not reimplement it.
Commands
| Command | Purpose | Invocation | |---|---|---| | (default) | clone + install, auto-detecting the adapter | npx @rkz91/coco-cli | | install | clone + install with explicit flags | npx @rkz91/coco-cli install [flags] | | update | pull latest in an existing clone | npx @rkz91/coco-cli update [dir] | | uninstall | remove symlinks + the clone | npx @rkz91/coco-cli uninstall [dir] | | version | print version + check for updates | npx @rkz91/coco-cli version | | --help | print usage | npx @rkz91/coco-cli --help |
Install flags (passed through to install.sh)
--adapter— one ofclaude-code|cursor|codex|generic--systems— comma-separated, e.g.gsd,brain,team--dry-run— preview only, no writes
Examples
- Install for Cursor:
npx @rkz91/coco-cli install --adapter cursor - Selective systems:
npx @rkz91/coco-cli install --systems gsd,brain --adapter claude-code - Preview without writing:
npx @rkz91/coco-cli install --dry-run - Update an existing clone:
npx @rkz91/coco-cli update
Output contract
This CLI is human-output-oriented; it has no native --json mode. For agent use:
- Treat exit code 0 = success, non-zero = failure.
versionprints@rkz91/coco-cli vX.Y.Zplus an update hint — parse thevX.Y.Ztoken.- Capture stdout/stderr and branch on the exit code; do not assume machine-readable JSON.
Errors
- A non-zero exit means an underlying git or
install.shstep failed — surface the captured stdout + stderr to the user. - Update checks contact
github.comonly; on network failure the version check degrades quietly and the command still runs.
Notes
- Side effects:
installclones the repo and creates symlinks;uninstallremoves them.install/updatere-pull, so they are not no-ops. - Network egress:
github.comonly. No telemetry. Disable update checks withCOCO_NO_UPDATE_CHECK=1. - Prerequisites:
node/npx,git, andbash.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: coco-research
- Source: coco-research/coco
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet — be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.