Imported from MalekYala/yala-agentic-toolkit (
AGENTS.md). Install upstream withnpx skills add MalekYala/yala-agentic-toolkit. Copyright stays with the author.
AGENTS.md — using yala-toolkit from a coding-harness agent
529 standalone Python/Go/Bash/TS utilities for system, network, security, AI, infra, and dev work. This file is the routing table; everything else is discoverable at runtime.
Setup (once per checkout)
python -m venv .venv && source .venv/bin/activate
pip install -e . # slim base; extras: .[browser], .[crawl], .[voice], .[db], .[crypto], .[all]
Discovery — do NOT read category READMEs (they cost thousands of tokens)
yala find <task words> # top ~10 matching tools, one-liners (cheapest, start here)
yala find <query> --json # same, machine-readable
yala info <tool> # tool's docstring + exact run command
yala list <category> # tools in one category
cat tools/data/manifest.json # full manifest: every tool + mutates/json_output/flags
Invocation
yala <category> <tool> [args...] # preferred; tool names are hyphenated
yala <tool> [args...] # works when the name is unique
python src/<category>/<tool>.py … # direct invocation always works too
Conventions contract (rely on these)
- Every tool supports
--help;yala <cat> <tool> --helpforwards to it. - Mutating tools support
--dry-run("mutates": truein the manifest). Always dry-run first when changing files/state. - Data-producing tools generally support
--json("json_output": truein the manifest) — prefer it for parsing. - Secrets come from environment variables only, never CLI args.
- Exit codes:
0success,1finding/failure (scanners exit 1 when they find something — that is not a crash),2usage error. - Dual-use tools (
network-recon,network-tunneling,api-toolshardening,sqli-defenseprobes, load testing) are authorized-use only — targets must be owned or explicitly authorized.
Category routing table
| Category | Use it for |
|---|---|
system-process |
CPU/mem/disk diagnostics, process + service management |
file-data |
organize, dedupe, rename, sync, back up, convert files |
compression |
codec benchmarks, archives, lossless recompress |
security |
secret scanning, CVE checks, file integrity, permissions |
sqli-defense |
SQL-injection source/log scanning + prevention |
ai-detection |
C2PA/provenance + heuristics for AI-made content |
antivirus |
static triage, signature scan, quarantine, ClamAV |
crypto |
AEAD file encryption, TRNG keys, PGP |
vault |
Vault AppRole, unseal, backup/restore, rotation |
config-secrets |
layered config render/validate/diff, .env hygiene, rotation |
network |
DNS, TLS expiry, ports, bandwidth (authorized hosts) |
network-recon |
port scan, host discovery (owned networks ONLY) |
network-tunneling |
SSH tunnels, proxies, WireGuard configs |
ssh |
config lint, known_hosts/authorized_keys hygiene, exec |
development |
git helpers, TODO extraction, license/dep checks |
github / gitlab |
PR/MR triage, pipelines, releases, security alerts |
cicd |
lint/generate/run pipelines, semver, changelog, deploy gates |
nextjs / react-dev / component-libs |
JS stack bootstrap, audits, codegen |
code-intelligence |
gitnexus/codegraph reports: hotspots, impact, arch |
coding-loops |
iterate-until-goal loops (coverage, CVEs, flaky tests) |
agent-loops |
ReAct/plan-execute/reflexion/RAG agent patterns (LLM API) |
llm-tuning |
prompt A/B, param sweeps, eval harnesses (Ollama) |
deep-research |
multi-source cited research report agent |
web-search |
SearXNG search/crawl |
crawlee |
resilient crawlers, SEO audits, sitemaps |
browser-automation |
Playwright: screenshots, link checks, form smoke tests |
libretto |
Libretto TS workflows: sessions, harvest, network capture |
nl2sql |
plain-English → safe read-only PostgreSQL |
database / db-migrations |
PG/SQLite DBA dashboards, schema diff, migration runner |
redis / message-queue / messaging-streams |
Redis/RabbitMQ/Streams/Kafka ops |
api-tools / api-docs / api-versioning / api-gateway |
probe/lint/harden APIs, OpenAPI gen, versioning, gateway |
rate-limiting |
limiter algorithms, Redis limiter, enforcing proxy |
webhooks |
HMAC sign/verify, receiver, delivery, replay, relay |
feature-flags |
flag engine, A/B stats, rollouts, hygiene audit |
observability / dashboards-alerting |
traces, Prometheus, SLO monitors, dashboards |
logging |
JSON logs, parse/query/aggregate, redact, ship, alert |
load-testing |
HTTP load gen, benchmarks, soak tests, regression gates |
chaos-engineering |
fault injection, resilience experiments |
iac-provisioning / kubernetes |
Terraform/Ansible, k8s manifests/ops |
cloud-cost |
cost/billing analysis and optimization |
backup-dr |
backup, restore, disaster recovery drills |
data-pipeline |
ETL/orchestration helpers |
progressive-delivery |
canary/blue-green release automation |
local-environment |
dev-service dashboards, repo health, Obsidian, nginx |
gpu-stack |
NVIDIA GPU/CUDA, Ollama/LiteLLM health |
go-tools |
Go hardware (I2C/GPIO/serial) + Go toolchain wrappers |
jq |
advanced jq JSON wrangling recipes |
bash |
certs, disk/mem alerts, service waits, backups |
document-conversion |
any document → Markdown |
streaming |
capture/transcribe .m3u8 streams |
audio-voice |
Whisper transcription, diarization, voice ID |
localization |
i18n string extract/translate/validate/merge |
market-data |
stocks/crypto prices, alerts (read-only) |
news-trends |
news digests, trend snapshots |
messaging |
email via SMTP, SMS/calls via Twilio-compatible API |
vector-pageindex |
vector DB + page-index tools (local embeddings) |
Notes for harness builders
tools/data/manifest.jsoncarries per-toolmutates/json_outputflags — use them to gate confirmations before running mutating tools.yalapropagates the tool's own exit code;yalaitself exits2on dispatch errors (unknown/ambiguous tool).- New tools must be added to
tools/data/tool_index.json, thenpython tools/gen_readmes.pyregenerates READMEs + registry + manifest;python tools/gen_readmes.py --checkfails CI on any drift.
Testing (contributing)
Three pytest tiers, all under tests/:
| File | What it covers | Runtime |
|---|---|---|
test_pure_logic.py |
in-process unit tests of tool internals (rate_limiter algos, webhook sign/verify, feature-flag engine, config render/validate, file encrypt round-trip) | ~0.2s |
test_yala_cli.py |
registry integrity + dispatcher smoke tests (list/find/info/run/doctor, exit codes) | ~1s |
test_validate.py |
subprocess smoke tests of ~60 tools in isolated tmp dirs (needs psutil/PyYAML/requests + a few host binaries; skips when absent) | ~25s |
Run everything: python -m pytest tests/. A bare checkout without pytest can still run the smoke suite via python tests/validate.py (legacy wrapper).
GitNexus — Code Intelligence
This project is indexed by GitNexus as yala-toolkit (5273 symbols, 11337 relationships, 300 execution flows). Use the GitNexus MCP tools to understand code, assess impact, and navigate safely.
If any GitNexus tool warns the index is stale, run
npx gitnexus analyzein terminal first.
Always Do
- MUST run impact analysis before editing any symbol. Before modifying a function, class, or method, run
gitnexus_impact({target: "symbolName", direction: "upstream"})and report the blast radius (direct callers, affected processes, risk level) to the user. - MUST run
gitnexus_detect_changes()before committing to verify your changes only affect expected symbols and execution flows. - MUST warn the user if impact analysis returns HIGH or CRITICAL risk before proceeding with edits.
- When exploring unfamiliar code, use
gitnexus_query({query: "concept"})to find execution flows instead of grepping. It returns process-grouped results ranked by relevance. - When you need full context on a specific symbol — callers, callees, which execution flows it participates in — use
gitnexus_context({name: "symbolName"}).
When Debugging
gitnexus_query({query: "<error or symptom>"})— find execution flows related to the issuegitnexus_context({name: "<suspect function>"})— see all callers, callees, and process participationREAD gitnexus://repo/yala-toolkit/process/{processName}— trace the full execution flow step by step- For regressions:
gitnexus_detect_changes({scope: "compare", base_ref: "main"})— see what your branch changed
When Refactoring
- Renaming: MUST use
gitnexus_rename({symbol_name: "old", new_name: "new", dry_run: true})first. Review the preview — graph edits are safe, text_search edits need manual review. Then run withdry_run: false. - Extracting/Splitting: MUST run
gitnexus_context({name: "target"})to see all incoming/outgoing refs, thengitnexus_impact({target: "target", direction: "upstream"})to find all external callers before moving code. - After any refactor: run
gitnexus_detect_changes({scope: "all"})to verify only expected files changed.
Never Do
- NEVER edit a function, class, or method without first running
gitnexus_impacton it. - NEVER ignore HIGH or CRITICAL risk warnings from impact analysis.
- NEVER rename symbols with find-and-replace — use
gitnexus_renamewhich understands the call graph. - NEVER commit changes without running
gitnexus_detect_changes()to check affected scope.
Tools Quick Reference
| Tool | When to use | Command |
|---|---|---|
query |
Find code by concept | gitnexus_query({query: "auth validation"}) |
context |
360-degree view of one symbol | gitnexus_context({name: "validateUser"}) |
impact |
Blast radius before editing | gitnexus_impact({target: "X", direction: "upstream"}) |
detect_changes |
Pre-commit scope check | gitnexus_detect_changes({scope: "staged"}) |
rename |
Safe multi-file rename | gitnexus_rename({symbol_name: "old", new_name: "new", dry_run: true}) |
cypher |
Custom graph queries | gitnexus_cypher({query: "MATCH ..."}) |
Impact Risk Levels
| Depth | Meaning | Action |
|---|---|---|
| d=1 | WILL BREAK — direct callers/importers | MUST update these |
| d=2 | LIKELY AFFECTED — indirect deps | Should test |
| d=3 | MAY NEED TESTING — transitive | Test if critical path |
Resources
| Resource | Use for |
|---|---|
gitnexus://repo/yala-toolkit/context |
Codebase overview, check index freshness |
gitnexus://repo/yala-toolkit/clusters |
All functional areas |
gitnexus://repo/yala-toolkit/processes |
All execution flows |
gitnexus://repo/yala-toolkit/process/{name} |
Step-by-step execution trace |
Self-Check Before Finishing
Before completing any code modification task, verify:
gitnexus_impactwas run for all modified symbols- No HIGH/CRITICAL risk warnings were ignored
gitnexus_detect_changes()confirms changes match expected scope- All d=1 (WILL BREAK) dependents were updated
Keeping the Index Fresh
After committing code changes, the GitNexus index becomes stale. Re-run analyze to update it:
npx gitnexus analyze
If the index previously included embeddings, preserve them by adding --embeddings:
npx gitnexus analyze --embeddings
To check whether embeddings exist, inspect .gitnexus/meta.json — the stats.embeddings field shows the count (0 means no embeddings). Running analyze without --embeddings will delete any previously generated embeddings.
Claude Code users: A PostToolUse hook handles this automatically after
git commitandgit merge.
CLI
| Task | Read this skill file |
|---|---|
| Understand architecture / "How does X work?" | .claude/skills/gitnexus/gitnexus-exploring/SKILL.md |
| Blast radius / "What breaks if I change X?" | .claude/skills/gitnexus/gitnexus-impact-analysis/SKILL.md |
| Trace bugs / "Why is X failing?" | .claude/skills/gitnexus/gitnexus-debugging/SKILL.md |
| Rename / extract / split / refactor | .claude/skills/gitnexus/gitnexus-refactoring/SKILL.md |
| Tools, resources, schema reference | .claude/skills/gitnexus/gitnexus-guide/SKILL.md |
| Index, status, clean, wiki CLI commands | .claude/skills/gitnexus/gitnexus-cli/SKILL.md |