Install
$ agentstack add skill-metagit-ai-metagit-cli-metagit-bootstrap ✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ● Filesystem access Used
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
About
Metagit MCP Bootstrap Skill
Use this skill to create a local .metagit.yml using discovery-driven prompts and MCP sampling.
Purpose
Generate schema-compliant .metagit.yml files with high contextual quality while preserving safety and explicit user control.
Bundled scripts (optional)
Helper scripts require the full skill tree or the PyPI package copy. Hermes skill_manage (SKILL.md only) does not include scripts/.
SKILL_ROOT="$(python3 -c "import metagit, pathlib; print(pathlib.Path(metagit.__file__).parent / 'data/skills/metagit-bootstrap')")"
"$SKILL_ROOT/scripts/bootstrap-config.sh" [root_path] [force]
Behavior:
- Writes
.metagit.ymlwhen missing (minimal application scaffold) - Validates via Metagit config models
- Returns a compact status line for agents
Execution modes
| Mode | When | |------|------| | CLI-only | Shell agent, no MCP host, Hermes without sampling | | MCP sampling | Host supports sampling/createMessage | | Plan-only | Sampling unavailable; return draft for human/agent review |
CLI-only fallback (no MCP sampling)
Use this path when sampling/createMessage is unavailable — common in CLI-only agent sessions or Hermes installs without MCP sampling.
- Discover evidence from the target repository:
export METAGIT_AGENT_MODE=true
metagit detect repository -p . -o json
metagit detect repo -p . -o yaml
metagit detect project -p . -o yaml
metagit detect repo_map -p . -o json
- Minimal manifest when none exists:
metagit init --kind application --no-prompt
# or: "$SKILL_ROOT/scripts/bootstrap-config.sh" .
metagit config validate -c .metagit.yml
- Richer draft — agent composes YAML from detect output + schema reference:
metagit config example # full annotated exemplar
metagit config tree -c .metagit.yml --json # after minimal init
Write draft to .metagit.generated.yml, validate, then promote on confirmation:
metagit config validate -c .metagit.generated.yml
mv .metagit.generated.yml .metagit.yml # only after explicit operator approval
metagit config validate -c .metagit.yml
- Incremental refinement on an existing manifest:
metagit config show -c .metagit.yml --json
metagit config patch -c .metagit.yml --op set --path --value --save
metagit prompt repo -p P -n R -k repo-enrich --text-only # merge detect into catalog
Never call MCP-only bootstrap tools from CLI-only sessions. Do not overwrite .metagit.yml without explicit confirmation.
MCP sampling workflow
When sampling is supported:
- Gather deterministic discovery data from the target repository:
- source language/framework indicators
- package/lock/build files
- Dockerfiles and CI workflows
- terraform files and module usage
- Build a strict prompt package:
- output format contract: valid YAML only
- required schema fields and constraints
- extracted discovery evidence
- Call
sampling/createMessage. - Validate generated YAML with Metagit config models.
- Retry with validation feedback up to a fixed max attempt count.
- Return draft output and write only on explicit confirmation.
Output Modes
- Plan-only mode: return prompt + discovery summary if sampling unavailable.
- Draft mode: return
.metagit.generated.ymlcontent. - Confirmed write mode: write to
.metagit.ymlonly with explicit parameter (confirm_write=true).
Quality Bar
- Preserve discovered evidence in structured fields.
- Include workspace project and related repo entries where detectable.
- Avoid invented repositories or unverifiable dependencies.
Safety Rules
- Never overwrite
.metagit.ymlsilently. - Never emit secrets in cleartext.
- Prefer placeholders for credentials or tokens.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: metagit-ai
- Source: metagit-ai/metagit-cli
- License: MIT
- Homepage: https://metagit-ai.github.io/metagit-cli/
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet — be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.