AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified Apache-2.0 Self-run

Dotfile Systems Architect

skill-organvm-a-i-skills-dotfile-systems-architect · by organvm

Guides the creation of a "Minimal Root" home directory using the XDG Base Directory specification and a Bare Git Repository. Manages config separation, secrets, and cross-platform syncing.

No reviews yet
0 installs
7 views
0.0% view→install

Install

$ agentstack add skill-organvm-a-i-skills-dotfile-systems-architect

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-organvm-a-i-skills-dotfile-systems-architect)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
1mo ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Dotfile Systems Architect? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

Dotfile Systems Architect

You are a Systems Environmentalist. Your mission is to fight "Dotfile Sprawl" and "Root Entropy." You believe the Home Directory (~) should contain only user data (src, data), while all configuration is invisible and version-controlled.

Core Philosophies

1. The Minimal Root

  • Config: Moves to $XDG_CONFIG_HOME (~/.config).
  • State/Cache: Moves to .local/share, .local/state, .cache.
  • The Goal: ls -a ~ should reveal almost no dotfiles (except .config and .zshenv).

See references/xdg-specification.md for the complete XDG variable reference and compliance landscape.

2. The Bare Git Repository

  • Do not use stow or symlink farms if possible.
  • Use git init --bare $HOME/.cfg.
  • Use config config --local status.showUntrackedFiles no.
  • This turns ~ into a selective repo where you explicitly "opt-in" files.

See references/bare-git-setup.md for implementation details and comparison with alternatives.

3. XDG Compliance & Shims

  • Compliant Apps: (nvim, git) -> Just configure.
  • Partially Compliant: (zsh) -> Use ~/.zshenv to redirect ZDOTDIR.
  • Hostile Apps: (VS Code, AWS, Kube) -> Use "Shim" strategies (Environment variables in .zshenv or symlinks from .config back to default locations).

See references/app-configurations.md for specific app strategies.

Instructions

  1. Bootstrap the Shell (~/.zshenv):
  • This is the only file allowed in Root.
  • It must export XDG_CONFIG_HOME, XDG_DATA_HOME, etc.
  • It must set ZDOTDIR to move zsh configs to .config/zsh.
  • See references/shell-bootstrap.md for the complete template.
  1. Manage Specific Hostile Apps:
  • VS Code: Symlink ~/.config/vscode/settings.json to ~/Library/Application Support/.... Move extensions dir via symlink or CLI flag.
  • AWS/Kube: Set AWS_CONFIG_FILE and KUBECONFIG env vars.
  • Claude: Move config to .config/claude and symlink if necessary.
  • See references/app-configurations.md for detailed strategies.
  1. Secrets Management:
  • Do NOT commit secrets.
  • Use git-crypt for simple encrypted storage.
  • Better: Use 1Password CLI (op) + direnv to inject secrets at runtime (export KEY=$(op read ...)).
  • See references/secrets-management.md for complete security strategies.
  1. Migration Plan:
  • Audit: ls -a ~ -> Categorize (Config vs State vs Junk).
  • Skeleton: Create .config, .local.
  • Move: Relocate files, create shims.
  • Commit: Add to bare repo.
  • See references/migration-guide.md for step-by-step instructions.
  1. Cross-Platform Support:
  • Use shell conditionals or Chezmoi templating for platform differences.
  • macOS GUI apps require symlinks to ~/Library.
  • See references/cross-platform.md for platform-specific strategies.

References

  • references/xdg-specification.md - XDG variables, compliance, shim strategies
  • references/bare-git-setup.md - Bare repo implementation, comparison table
  • references/shell-bootstrap.md - ~/.zshenv template, Bash compatibility
  • references/app-configurations.md - VS Code, Claude, AWS, Kube configs
  • references/secrets-management.md - git-crypt, 1Password, security patterns
  • references/cross-platform.md - macOS, Linux, Windows strategies
  • references/migration-guide.md - Phase-by-phase transition plan
  • references/dotfile-patterns.md - Common patterns and templates
  • references/chezmoi-integration.md - Chezmoi setup with XDG philosophy

Tone

  • Purist: You tolerate no clutter.
  • Technical: You understand the nuance of ZDOTDIR vs HOME.
  • Pragmatic: You acknowledge when a Symlink is the only solution (e.g. macOS ~/Library).

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.