Install
$ agentstack add skill-elvinmorales-agent-librarian-artifact-librarian-demo ✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
About
Artifact Librarian Demo
Use this skill to run a public-safe Claude Code demo of agent-librarian. Lead with the functional agent story, not taxonomy.
Workflow
Claude Code reads package instructions
-> Claude explains safe scope
-> Claude proposes runtime-wrapper commands
-> user approves exact command
-> wrapper runs deterministic CLI backend
-> Claude summarizes CLI evidence
-> human reviews generated outputs
Steps
- Explain the agent in plain language.
- Claude is the interface layer.
- The deterministic CLI and generated outputs are the source of truth.
- The demo uses only the synthetic
examples/sample-collection.
- Inspect only allowed public demo files.
- Allowed source:
examples/sample-collection. - Allowed generated catalog:
examples/generated-catalog. - Allowed package instructions:
packages/claude/. - Do not scan private/work files, work-internal folders, credentials,
secrets, private prompts, private traces, logs, memory snapshots, state snapshots, or private generated catalogs.
- Propose commands before running anything.
- Prefer runtime-wrapper
proposecommands. - Show exact command, read scope, write scope, generated files, and
sensitivity note.
- Require exact approval.
- Do not run on vague approval.
- Do not run if the approval string is different from the command shown.
- Changed command, path, argument, sensitivity, or retry requires fresh
approval.
- Run only approved wrapper commands.
- Do not run arbitrary shell.
- Do not chain commands.
- Do not execute, edit, delete, merge, publish, or rewrite source files.
- Do not create git commits, pushes, tags, releases, or pull requests.
- Summarize deterministic outputs.
- Use runtime-wrapper output, CLI output, and generated files as evidence.
- Preserve warnings, diagnostics, validation failures, and overlap
candidates.
- Do not invent counts, files, findings, or status.
- Explain what the demo proves.
- Claude can scope a synthetic public demo.
- Claude can propose bounded wrapper commands.
- Exact approval gates local execution.
- The deterministic backend produces evidence for human review.
- Explain what the demo does not prove.
- It does not certify safety, privacy, correctness, completeness, approval,
compliance, or publication readiness.
- It does not scan private or work-internal material.
- It does not add Claude API integration, network behavior, MCP server
code, arbitrary shell execution, or autonomous publication.
Allowed Demo Commands
python -m agent_librarian.runtime_wrapper propose catalog examples/sample-collection --out examples/generated-catalog
python -m agent_librarian.runtime_wrapper propose validate examples/generated-catalog
python -m agent_librarian.runtime_wrapper propose report examples/generated-catalog
python -m agent_librarian.runtime_wrapper run report examples/generated-catalog --approve-exact "agent-librarian report examples/generated-catalog"
Wrong approval demonstration:
python -m agent_librarian.runtime_wrapper run report examples/generated-catalog --approve-exact "wrong command"
The wrong approval should fail with a nonzero exit status and must not run the backend.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: ElvinMorales
- Source: ElvinMorales/agent-librarian
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet — be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.