@agent-core

Skills

The first-party SKILL.md bundles agent-core ships: management, execution patterns, research, and inspection.

agent-core ships sixteen skill bundles under its package-root skills/ directory, in the standard agentskills.io-aligned layout — one directory per skill with a SKILL.md and, for the route-wrapping bundles, scripts/ siblings. Agents activate them with execute action="skill"; script-backed skills authenticate their API calls with the per-stream session ticket, so every call runs with the real caller's role and feature grants.

A skill’s frontmatter description is always visible in the package catalog even though its body is loaded only on activation. It is therefore a routing contract: say what outcome the skill enables, which natural requests or failure states should activate it, and the decisive distinction from neighboring capabilities. Keep the multi-step procedure in the body rather than duplicating it in the description.

Each skill declares requiredFeatures in its frontmatter. A user whose role lacks the feature never sees the skill — it is absent from the system prompt and the catalog, not shown as locked. See features and access.

Conversation and agent management

SkillRequiresWhat it does
manage-agentscore.agentsBulk-manage agents — list, create, get, update, delete, browse the team catalog, batch-create from team templates, resync from a template, and manage per-agent MCP API keys. 12 scripts wrapping the agents routes.
manage-conversationscore.executeBulk-manage an agent's conversations — list, create, rename, delete, read messages, generate titles, edit / undo / rewind / retry turns, fork a conversation and list its forks, summarize, switch history-mode, apply a live guard, stop the turn a conversation is running (including one no browser is driving), message another agent's conversation, batch-summarize, and read the machine-extracted record of what a conversation verifiably did — files changed, commands run, background shells, subagent runs, messages received, tool failures. 21 scripts wrapping the conversations routes.
manage-workflowsworkflow.readSet up, run and read this project's workflows (the Calendar) with the workflow tool, and do the rest through 16 scripts — install and upgrade package-shipped templates, archive, restore or permanently delete, bind channels, cancel a run, add extra webhooks, and revoke a webhook key. Issuing a key stays a human action: a secret must never travel through the model.
context-managementcore.executeCompaction patterns, durable session working-state, and long-conversation strategies built on compact_history and todos.
mcp-serversmcp.connectConfigure, connect, authorize, diagnose, and filter the caller's external MCP servers across supported transports. It explains the OAuth and credential ladder, while keeping server registration and human consent as explicit management actions.
manage-channelsworkflow.readRead and operate the messaging-channel connections a workflow can fire from — the route-list preserves full safe visibility for channels.manage, while connect keeps a narrower model view; the 8 scripts cover listing, pending pairings, linked peers, approval/rejection, unlinking, re-checking, disconnect/reconnect and guarded deletion. Creating a connection stays a human action: it needs a bot token, and a secret must never travel through the model.
git-remotesgit.connectInspect and disconnect your own git remote credentials, and start the git host's OAuth flow for a human to consent to (github.com, gitlab.com, bitbucket.org, codeberg.org; any other host is refused by name). Disconnecting removes the token and the OAuth pair together, so a revoked host cannot keep a usable push token. Connecting with a token is a human action, for the same reason.
my-credentialscredentials.selfRead-only: which declared credential slots you can see, and which you have personally filled in. Use it to name the exact missing id when something fails for want of a key. It cannot set values — a value passed as a tool argument would pass through the model and persist in the conversation log.

Execution patterns

SkillRequiresWhat it does
execute-skillcore.executePatterns for the execute tool — shell mode and skill activation.
delegate-skillcore.executeHow to brief subagents, run them in parallel, recover from partial failures, and run them in the background — watching, stopping and continuing a detached run.
plancore.executeWrite and work from a plan file for multi-phase or multi-session engineering work — phases, decisions, blockers, graduating it to the plans area — driven by a session goal and todos.

Research

SkillRequiresWhat it does
deep-researchcore.webA multi-round, citation-grounded research protocol: decompose the question, fan out research-mode searches, verify claims against two or more independent sources, write a structured report with numbered citations. It drives the web_search and web_fetch tools; web_fetch returns the whole page up to max_chars, so raising that beats re-fetching.
geo-auditcore.webAudits a URL for AI-answer-engine visibility (GEO/AEO) — answer-first structure, fact density, schema.org, crawler policy, llms.txt — and produces a scored recommendation list.

Inspection

SkillRequiresWhat it does
inspect-agent-corecore.observeRead-only inspection of the runtime — agent setup context, packages overview, diagnostics, tools, files, models, context window, usage, Codex subscription usage, logs, and MCP servers. 11 scripts wrap the read-only routes; the setup snapshot explicitly excludes live conversation state and reports tokens as a UTF-8 bytes/4 estimate.
workspace-overviewcore.observeHow to orient in a new session: understand the loaded packages, tools, and sources.

Self-improvement

SkillRequiresWhat it does
learningcore.agents, core.execute, drive.read, drive.writeA bounded, memory-first learning pass. Its primary outputs are a dated report and privacy-safe linked memory across conversations, plans, commits, workflow reports, governed sources, and owning READMEs; it never writes a conversation folder directly — a conversation summary is requested only through the official summarize operation (artifact-only). It checkpoints traversal limits and applies a deterministic authority/privacy matrix; the Learning workflow is its scheduled driver.

How the route-wrapping bundles work

manage-agents, manage-conversations, and inspect-agent-core are thin script bundles: each script is a small curl wrapper around one REST route under /api/packages/@neuralis/agent-core/*. The model activates the skill, then runs the scripts through execute action="shell" with cwd: "${SKILL_DIR}". Authentication is implicit — the session ticket in the script environment carries the live stream's verified identity, and the route dispatcher enforces each route's declared feature against the caller's real grants. There is no separate service account: a member running manage-agents can do exactly what that member could do in the UI, no more.

On this page