Install
$ agentstack add skill-hmbown-wizards-of-the-ghosts-mage-hand ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Mage Hand
Manipulate files, records, and lightweight system state with precision and minimal blast radius.
Sigil
__
.-' `-.
/ .--. \\
| / /\\ \\ |
| | \\/ | |
\\ `--' /
`-.__.-'
What This Skill Does
Use this skill for small, careful remote manipulations where dexterity matters more than force. In this grimoire, Mage Hand is treated as a hybrid spell with a shipping-now delivery profile. Canonical reference input: Mage Hand (spell).
When To Use
- Trigger this spell when the request asks for surgical, narrow edits to existing objects with explicit boundaries on what NOT to touch. Look for:
- Specific identifiers: file paths, ticket IDs, record keys, field names, audience names
- Constraint language: "only", "but don't touch", "leave X alone", "if X then stop"
- Single-field or single-value changes: "change maxattempts from 3 to 4", "patch replyto_email"
- Conditional execution with early-exit: "only if each has approval, otherwise stop and return the exception list"
- Audit expectations: "show the diff", "tell me the exact line", "report skipped IDs"
- Small batch operations with per-item validation: "move tickets A, B, C but skip any missing X"
Prerequisites
- No extra runtime dependencies beyond Hermes Agent and the normal toolset for this session.
Procedure
- Restate the target, the success condition, and any no-touch boundaries before taking action.
- Restate boundaries before acting: Name the exact target, the success condition, and what must NOT be touched.
- Scope to the smallest edit surface: Change one field, one line, one ticket state. Do not rewrite surrounding content.
- Apply with diff or state proof: Show what changed. Confirm adjacent values are untouched.
- Report exceptions, not just successes: If any item in a batch fails validation or lacks a prerequisite, stop and return the failure list. Do not silently skip.
- Package the result as the deliverables below, with confidence, assumptions, and unresolved risk called out explicitly.
Deliverables
- A minimal, well-scoped change.
- A short audit trail of touched surfaces.
- A note on adjacent objects that were intentionally left alone.
Pitfalls / Guardrails
- Keep the theatrical framing, but name the concrete mechanism that makes the skill useful right now.
- Do NOT route here when the request involves:
- Do not use for: Building new interfaces or features ("give this script a chat front end", "create a dashboard")
- Do not use for: Setting up recurring automation ("every Friday", "whenever X happens, do Y automatically")
- Do not use for: Debugging, forensics, or tracing ("find what changed", "trace which integration sent this")
- Do not use for: System recovery or access restoration ("token expired, find the recovery path")
- Do not use for: Performance tuning or capacity changes ("slow down the queue", "scale up workers")
- Do not use for: Broad refactors or rewrites ("rewrite this module", "restructure the config")
- Do not use for: The key differentiator: Mage Hand moves or edits existing specific objects with known targets. It does not build, automate recurring tasks, investigate, or recover.
Verification
- Check that the result includes every deliverable promised above.
- Check that confirmed facts, assumptions, and inferences are visibly separated.
- Check which parts are concrete actions versus framing, so the user can tell what is real now.
Example Invocation
/mage-hand make the smallest safe change needed here and show exactly what you touched
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: Hmbown
- Source: Hmbown/Wizards-of-the-Ghosts
- License: CC0-1.0
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.