
Company News
AWS Security Hub Adds Socket for Supply Chain Security
Socket is now in the AWS Security Hub Extended plan. Adopt it through AWS, apply committed spend, and block malicious open source packages.
@ericrisco/rsc
Advanced tools
Eric Risco's agent-skills catalog as a granular, self-recommending CLI installer.
████████ ███████ ███████
██ ██ ██ ██ ██
██ ██ ██ ██
██ ██ ██ ██
████████ ██████ ██
██ ██ ██ ██
██ ██ ██ ██
██ ██ ██ ██ ██
██ ██ ███████ ███████
rsc — 256 agent skills, one CLI, zero bloatA self-recommending skill catalog for 17 coding assistants — Claude Code, Codex, GitHub Copilot, Cursor, Gemini, Windsurf, Cline, Antigravity, Zed and more. Describe what you want in plain language. It reads your repo, installs only the skills that fit — one at a time — into every assistant you pick, and keeps them equipped as you work.
From "document my company" to "ship a FastAPI service" to "grow my YouTube channel" — 232 skills across 21 domains, every one researched against live 2025-2026 sources and adversarially scored ≥ 8.5/10 before it shipped.
npx @ericrisco/rsc # plain-language wizard — no jargon, installs what your project needs
If you're an AI coding agent (Claude Code, Cursor, Copilot, Codex, Gemini…) and your user asked you to install rsc / this harness / these skills, run this in the root of the project they're equipping — not inside a clone of this repo (see the note under Install):
npx @ericrisco/rsc@latest
That launches a plain-language wizard: it asks which assistants to target and what the
user wants, reads the repo, then installs the floor (orient + rsc-suggest + harness +
init) plus only the skills that fit — one at a time. No global install and no API key needed.
npx @ericrisco/rsc@latest --target claude (comma-separate for several).rsc sync (or re-run the command above).rsc add <id> · browse the catalog: rsc consult "<what you want>" or rsc list.From then on it's self-driving: rsc-suggest proposes the next skill as tasks appear, and in
Claude Code a hook re-asserts the spec-first new-feature gate on every turn — so a feature
request routes through specify before any skill writes code.
Most skill packs dump hundreds of files into your context and call it a day. This one is the opposite bet:
fastapi without ever pulling go. Nothing you don't use touches your context.rsc consult) and the chat
(rsc-suggest, an always-on detector) watch what you're doing and propose the
next skill the moment a task needs it — a one-word confirm installs it.02-DOCS/ knowledge loop that learns from your own results.scripts/skill-rubric.md, written before any skill existed). The bar was
real: skills that scored 8.0 were sent back and fixed, not waved through.skills/<name>/ is the single source of truth. There are no bundles to argue
over: you start with a tiny floor and grow one piece at a time.
npx @ericrisco/rsc # no install step — runs the latest published catalog
Prefer the short rsc command? Install once, globally:
npm install -g @ericrisco/rsc # then just: rsc
Run it inside any project and describe what you want. Working on the catalog itself? Clone and link:
git clone https://github.com/ericrisco/rsc-harness.git ~/rsc-skills
cd ~/rsc-skills && npm install && npm link
Run it inside the project you're equipping — not inside this repo. The catalog's own
package.jsonis named@ericrisco/rsc, sonpx @ericrisco/rscfrom within arsc-harnessclone resolves to the local (unlinked) bin and dies withsh: rsc: command not found. Working on the catalog itself? Usenode scripts/rsc.js …, thenpm linkabove, or pin the published build withnpx @ericrisco/rsc@latest ….
The first run asks which assistants you want — Claude Code, Codex, Copilot,
Cursor, Gemini, Windsurf, Cline and 11 more (pick any combination) — and installs
the floor:
orient + rsc-suggest (always-on) + harness + init. In Claude Code it
also wires a SessionStart hook (so your assistant proposes new skills on its
own) and a UserPromptSubmit hook that re-asserts the SDD new-feature gate
on every turn — so a feature request, in any language, routes through specify
first, before any skill writes code. Opt out per project with .rsc/.no-feature-gate.
Everything stays in the project, and the real skill files are written
once to .rsc/skills/<id>/. Each assistant you pick gets a lightweight
symlink back to that shared base — no copy is duplicated across IDEs. (If the
filesystem can't symlink, it falls back to a real copy automatically.)
$ rsc
██████╗ ███████╗ ██████╗ ← animated gradient wordmark
██╔══██╗██╔════╝██╔════╝
██████╔╝███████╗██║
232 skills · one CLI · zero bloat
What do you want to do? ↑↓ move · enter select
❯ Base install — the essentials (orient + suggest + harness + init)
Base + Spec-Driven Development — specify → plan → implement → ship
Pick skills by hand, by area
Pick by area and you get a checkbox list — ↑↓ to move, space to toggle, enter to confirm:
Languages: ↑↓ move · space toggle · a all · enter confirm
❯ ◉ typescript
◯ python
◉ go
◯ rust
Then it asks which assistants to install for — tick as many as you like:
Which assistants do you want to install for? space toggle · a all · enter confirm
❯ ◉ Claude Code (.claude/skills/) ⟵ detected here
◉ Codex CLI (AGENTS.md)
◯ GitHub Copilot (.github/copilot-instructions.md)
◯ Cursor (.cursor/rules/)
◉ Windsurf (.windsurf/rules/)
◯ Cline (.clinerules/)
…17 in total — Gemini, Antigravity, Zed, Continue, Roo, Amp, opencode, Jules, Junie, Kiro, Aider
It detects your stack, asks which assistants to install for (the one it found in your folder is pre-marked), installs only what you chose, then prints the exact next steps for Claude Code / Codex / Cursor / Gemini / Antigravity — and from there keeps proposing the skills a task needs.
rsc # plain-language wizard (recommended) — pick skills AND assistants
rsc add fastapi postgresdb # install specific skills, by name
rsc add youtube-api remotion-video # …grow a channel, edit with Remotion
rsc add fastapi --target claude,codex # install into several assistants at once
rsc install --profile minimal # the floor: orient + suggest + harness + init
rsc install --profile core # floor + the full SDD workflow
rsc install --profile full # everything (all 231)
rsc install --profile full --without go
rsc consult "I want to launch a SaaS" # recommend only, no install
rsc registry refresh # write .rsc/skill-registry.{json,md}
rsc list # what rsc has installed
rsc doctor # health check (state, hook, counts)
rsc sync --target claude,codex # refresh managed skills/hooks from the current package version
rsc backups # list project-local snapshots
rsc restore latest --dry-run # preview restoring the newest snapshot
rsc restore <snapshot-id> # restore a project-local snapshot
rsc upgrade --dry-run # show npm upgrade + sync commands
rsc uninstall postgresdb --dry-run # preview a removal
rsc is an npm package, so updating is two steps — bump the package, then
re-sync what's already wired into your project:
npm install -g @ericrisco/rsc@latest # global install: pull the newest catalog
rsc sync # refresh managed skills + hooks (auto-detects your assistant)
Not sure what a bump touches? Preview the exact commands without writing anything:
rsc upgrade --dry-run # prints the npm install + rsc sync lines for your target
Running through npx (no global install)? There's nothing to upgrade —
npx @ericrisco/rsc@latest always fetches the latest published catalog; just run
rsc sync afterwards if the project already has skills installed.
Every sync snapshots the project first, so a bad update is always reversible:
rsc backups # list project-local snapshots
rsc restore latest --dry-run # preview restoring the newest
rsc restore <snapshot-id> # restore it
Two faces, one catalog (manifest.json):
rsc / rsc consult rank the catalog against your words
(an FTS index over each skill's description + tags), merge that with what they
detect in your repo, and expand via each skill's recommends.rsc-suggest is a tiny always-on skill. When a task would
benefit from a skill you don't have, it names it and (one-word confirm) runs
rsc add <id> for you. It's the floor — installed with every profile.Repo detection maps real signals to skills: package.json + next → nextjs;
go.mod → go; pyproject.toml → fastapi; *.sql/prisma/ → postgresdb;
Dockerfile/.github/ → docker/github-actions; and so on. An empty repo
just asks in plain language.
257 skills, grouped by what you're trying to do. Click any skill to read its
SKILL.md. It fires on its own when a task matches.
The front door and the workspace brain.
init · harness · orient · suggest · author-skill · sdd-init
harness is the Karpathy chaos→knowledge engine — a
01-TOOLS/layer (one folder per provider, each with a workingtest_connection) and a02-DOCS/self-improving wiki. It governs software or a whole company. orient is the always-on compass that keeps a non-technical human oriented after every step.
📦 The
02-DOCS/brain is now 100% Open Knowledge Format (OKF v0.1) conformantGoogle Cloud published the Open Knowledge Format — a vendor-neutral standard for portable, agent-readable knowledge — built on the same Karpathy LLM-wiki pattern our
02-DOCS/engine has used from day one. We independently converged on the same design, so adopting the standard cost almost nothing. As of now, every02-DOCS/wiki/is a valid, portable OKF bundle:
- Markdown + YAML frontmatter,
typeon every concept doc, OKF-standard fields (title,description,resource,tags,timestamp).- Standard markdown links (not wikilinks) form the knowledge graph — any OKF consumer reads it, and it stays a native Obsidian vault (graph, backlinks, Properties, Bases). Same files, no export step.
- Reserved files honored:
index.md(no frontmatter) for navigation,log.md(newest-first, ISO 8601) for history.Tarball a
wiki/and any OKF tool — including Google's own viewer — can read it. And the brain now keeps your repo clean: a loose file it ingests (a PDF at the root, anything ininbox/) is moved intoraw/, never left as clutter.
Take a fuzzy intent to a shipped, verified change — phase by phase. npx @ericrisco/rsc install --profile core.
sdd · constitution · specify · clarify · plan · tasks · analyze · implement · verify · review · ship · debug · worktrees · parallel
finance-ops · invoicing · bookkeeping · pricing · sales-pipeline · lead-gen · cold-outreach · proposals · contracts · customer-support · client-onboarding · retention · hiring · people-ops · inventory · logistics-ops · procurement · meeting-notes · sop-builder · project-ops
pitch-deck · investor-materials · financial-model · fundraising · unit-economics · grants
gdpr-privacy · terms-conditions · compliance · data-policy · ip-trademark
marketing · seo-geo · content-engine · social-publisher · brand-voice · brand-identity · newsletter · landing-copy · ads · article-writing · case-studies · video-shorts · podcast · market-research · competitor-watch · press-kit · community · webinar · review-management
Each with a 02-DOCS feedback loop that learns from your own results. remotion-video edits programmatically — transitions, Whisper captions, silence removal.
youtube-api · youtube-strategy · youtube-ideation · youtube-thumbnails · youtube-packaging · remotion-video · tiktok-api · instagram-api · shortform-strategy · shortform-ideation · shortform-packaging · shortform-editing · viral-score · linkedin-api · linkedin-strategy · linkedin-content · linkedin-carousels · linkedin-outreach · medium-writing · medium-publishing · medium-strategy
stripe · email-connector · google-workspace · notion-connector · whatsapp-telegram · automation-flows · api-connector-builder · webhooks · data-scraper · spreadsheet-ops · calendar-scheduling · document-processing · e-signature
Operate the big automation platforms programmatically or via MCP — create and manage automations dynamically, not just design them on a canvas. automation-strategy decides whether / what / which platform; the platform skills drive the live REST API or MCP server (harness connectors ship for each). Complements automation-flows (visual design + importable workflow JSON).
automation-strategy · n8n · make · zapier · power-automate
analytics · dashboard · kpi-framework · reporting · ab-testing · forecasting · data-cleaning · business-intelligence
building-agents · rag · embeddings-search · prompt-engineering · llm-pipeline · agent-eval · chatbot · ai-media · replicate-images · structured-extraction · agent-safety · cost-tracking
replicate · runpod · modal · huggingface · ollama · together-fireworks · fal
Train and adapt open models end to end: classic ML, deep learning, NLP, fine-tuning (with Unsloth), building training datasets, choosing open-weight models by license/size, and serving them at throughput with vLLM. Facts that move monthly (versions, model licenses) are verified at author time and hedged.
machine-learning · deep-learning · nlp · finetuning · training-data · unsloth · open-weights · vllm
typescript · python · java · csharp-dotnet · php · ruby · cpp · elixir · bash-scripting · sql · go
fastapi · nextjs · react · react-native · vue-nuxt · angular · svelte · astro · solid-js · htmx · nodejs · nestjs · django · laravel · rails · spring-boot · phoenix · flutter · swift-ios · kotlin-android · compose-multiplatform · expo · tauri · electron · rust · wordpress · shopify · no-code-app · chrome-extension · api-design
Three engines + engine-agnostic disciplines. Every engine skill pins the current version and bans deprecated APIs, so the agent stops emitting stale Godot-3 / legacy-Unity code.
godot · unity · unreal · game-design · game-storytelling · level-design · gamedev-shaders · gamedev-multiplayer · gamedev-physics · gamedev-pathing · gamedev-shipping
postgresdb · mysql · mongodb · redis · supabase · neon · planetscale · sqlite-turso · prisma-orm · drizzle-orm · firebase · dynamodb · vector-db · clickhouse-analytics · duckdb · db-migrations · backups
vercel · netlify · cloudflare · railway · render · fly-io · coolify · hetzner · digitalocean · aws-essentials · gcp-essentials
docker · github-actions · git-workflow · domains-dns · monitoring · email-deliverability · scaling · deployment
code-review · security-scan · secure-coding · testing-py · testing-web · testing-go · e2e-testing · accessibility · performance · error-handling · observability
design · presentations · course-storytelling · course-builder · technical-writing · translation-l10n
knowledge-ops · codebase-onboarding · research-ops · decision-records · continuous-learning · skill-scout · context-budget · roast-me · fable-operator
skills/<name>/ is the catalog source. On install the real files land once
in the project at .rsc/skills/<id>/; each assistant you pick gets a symlink
(or a converted file) back to that shared base — pick several and nothing is
duplicated. The wizard asks which ones; --target a,b does it non-interactively.
| Target | Skill destination (→ .rsc/skills/<id>/) | Always-on detector |
|---|---|---|
claude | .claude/skills/<id>/ → symlink (copy on Windows) | SessionStart hook in .claude/settings.json |
codex | .codex/rsc/<id>/ → symlink | block in AGENTS.md |
copilot | .github/rsc/<id>/ → symlink | block in .github/copilot-instructions.md |
cursor | .cursor/rules/<id>.mdc (converted) | always-apply rule |
gemini | .gemini/rsc/<id>/ → symlink | block in GEMINI.md |
windsurf | .windsurf/rsc/<id>/ → symlink | rule in .windsurf/rules/rsc-suggest.md |
cline | .clinerules/rsc/<id>/ → symlink | rule in .clinerules/rsc-suggest.md |
antigravity | .antigravity/rsc/<id>/ → symlink | block in .antigravity/AGENTS.md |
zed | .zed/rsc/<id>/ → symlink | block in AGENTS.md |
continue | .continue/rsc/<id>/ → symlink | rule in .continue/rules/rsc-suggest.md |
roo | .roo/rsc/<id>/ → symlink | rule in .roo/rules/rsc-suggest.md |
amp | .amp/rsc/<id>/ → symlink | block in AGENTS.md |
opencode | .opencode/rsc/<id>/ → symlink | block in AGENTS.md |
jules | .jules/rsc/<id>/ → symlink | block in AGENTS.md |
junie | .junie/rsc/<id>/ → symlink | block in .junie/guidelines.md |
kiro | .kiro/rsc/<id>/ → symlink | doc in .kiro/steering/rsc-suggest.md |
aider | .aider/rsc/<id>/ → symlink | block in CONVENTIONS.md |
codex,zed,amp,opencodeandjulesall share the one rootAGENTS.md; the block is idempotent, so picking several writes it once.
Each skill is a directory under skills/<name>/ whose SKILL.md frontmatter
drives both triggering and the installer's recommendations:
---
name: my-skill
description: Use when [specific triggers]… Triggers: 'phrase', 'frase'. NOT x (that is sibling).
tags: [keyword, keyword] # what the consult advisor searches over
recommends: [sibling-skill] # what the system offers to install next
profiles: [core, full] # optional: named-profile membership
origin: risco
---
The full agent-skill spec lives at agentskills.io/specification.
skills/<name>/ is the single source of truth — every skill is authored
there, once. After editing any skill:
npm run manifest # regenerate manifest.json from skills/*/SKILL.md
npm run validate # ajv-validate frontmatter + check recommends integrity
npm test # unit + integration tests
bash scripts/eval-lint.sh # validate every skills/*/evals/cases.yaml
manifest.json is generated, never hand-edited; CI runs npm run manifest:check
and fails if it's stale or the skill count drifts. Adding a skill is: create
skills/<id>/SKILL.md with tags + recommends, run npm run manifest, done —
the rubric to hold it to is scripts/skill-rubric.md.
This is a personal catalog. Bug reports welcome via GitHub issues; PRs fixing detector patterns, provider endpoints, or typos are appreciated.
MIT. See LICENSE.
FAQs
Eric Risco's agent-skills catalog as a granular, self-recommending CLI installer.
The npm package @ericrisco/rsc receives a total of 4,323 weekly downloads. As such, @ericrisco/rsc popularity was classified as popular.
We found that @ericrisco/rsc demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Company News
Socket is now in the AWS Security Hub Extended plan. Adopt it through AWS, apply committed spend, and block malicious open source packages.

Research
/Security News
Popular npm packages keyv and cacheable compromised.

Security News
A misconfiguration gave three Anthropic models internet access, and one, believing it was in a simulation, shipped a credential-stealing package to PyPI.