# Toolbox

> Pre/post dev toolbox — named bundles of skills/agents loaded before development work and councils of experts invoked after. Run /toolbox or the toolbox.py CLI to list, activate, initialize, export, import, and validate toolboxes. Invoke at the start or end of a dev session, when setting up a new repo, or when sharing toolboxes with a team.

- **Type:** Skill
- **Install:** `agentstack add skill-stevesolun-ctx-toolbox`
- **Verified:** Yes — security-reviewed for prompt injection and unsafe behavior
- **Seller:** [stevesolun](https://agentstack.voostack.com/s/stevesolun)
- **Installs:** 0
- **Category:** [AI & ML](https://agentstack.voostack.com/c/ai-and-ml)
- **Latest version:** 0.1.0
- **License:** MIT
- **Upstream author:** [stevesolun](https://github.com/stevesolun)
- **Source:** https://github.com/stevesolun/ctx/tree/main/skills/toolbox
- **Website:** https://stevesolun.github.io/ctx/

## Install

```sh
agentstack add skill-stevesolun-ctx-toolbox
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

# toolbox

Named bundles of skills/agents that run **before** (`pre`) or **after** (`post`)
a development task. Learn patterns from past work and propose new bundles.
Invoke slash, pre-commit, session-end, or file-save.

## Quick reference

| Task                                       | Command                                 |
|--------------------------------------------|-----------------------------------------|
| Seed 5 starter toolboxes                   | `python src/toolbox.py init`            |
| List available toolboxes                   | `python src/toolbox.py list`            |
| Inspect one                                | `python src/toolbox.py show ship-it`    |
| Activate (global)                          | `python src/toolbox.py activate ship-it`|
| Export for sharing                         | `python src/toolbox.py export ship-it`  |
| Import a shared toolbox                    | `python src/toolbox.py import file.yaml`|
| Validate config                            | `python src/toolbox.py validate`        |

## Starter templates

| Name              | When to use                                                     |
|-------------------|-----------------------------------------------------------------|
| ship-it           | End-of-feature: 7-expert council on the change set              |
| security-sweep    | Security audit with guardrail blocking HIGH findings            |
| refactor-safety   | Refactors with graph-informed blast radius                       |
| docs-review       | When touching Markdown or API docs                              |
| fresh-repo-init   | Blank repo: run intent interview and scaffold                    |

## Data model

Global: `~/.claude/toolboxes.json`.
Per-repo (overrides global): `/.toolbox.yaml`.

Each toolbox declares:
- `pre` — skills/agents to load before work starts
- `post` — agents that form the council after work ends
- `scope.analysis` — `diff` | `full` | `graph-blast` | `dynamic`
- `trigger` — `slash`, `pre_commit`, `session_end`, or `file_save` glob
- `budget.max_tokens` / `budget.max_seconds` — hard stop on runaway cost
- `dedup.policy` — `fresh` (always re-run) or `cached` (reuse within window)
- `guardrail` — if true, block commit on HIGH findings

## Invoke when

- User says "I'm done with this feature" or commits a feature branch.
- User opens a fresh repo (triggers `fresh-repo-init` suggestion).
- User touches security-sensitive paths (triggers `security-sweep` file_save).
- User asks "what toolboxes do I have?" or "run the council".

## Reasoning

See `docs/toolbox/index.md`, `docs/toolbox/starters.md`, and
`docs/toolbox/verdicts.md` for the current toolbox contract, starter bundles,
and guardrail behavior.

## Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [stevesolun](https://github.com/stevesolun)
- **Source:** [stevesolun/ctx](https://github.com/stevesolun/ctx)
- **License:** MIT
- **Homepage:** https://stevesolun.github.io/ctx/

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** no
- **Filesystem access:** no
- **Shell / process execution:** no
- **Environment & secrets:** no
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: passed — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/skill-stevesolun-ctx-toolbox
- Seller: https://agentstack.voostack.com/s/stevesolun
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
