Allbase

Set up the skill helper

Give your local agent a way to review and manage a skill in your project. Start with the helper, then return to the exact release in your Library.

Copy the setup request to your local agent. It will check availability and prerequisites, then help you review the setup. This page cannot access your project or install anything.

View setup request
Helper version 0.2.0

Downloads are unavailable until this release has been verified. Checking availability…

Before you start

You need Python 3.11 or newer and a local agent on macOS or Linux. It installs skills into a repository for Claude Code (.claude/skills) or Codex (.agents/skills). Your agent can check the details below.

After setup, open the exact release in Knowledge → Library, choose Use in a project, and share its request with your agent. A helper download does not mean a skill is installed or in use.

Instructions for your agent

Verify and set up the helper

No private repository checkout, Allbase API key, or package-publishing account is needed. Check Python 3.11 or newer with venv and pip and a supported local filesystem. Windows and network filesystems are not supported for managed installation.

Verify that the selected Claude Code or Codex executable supports repository skills. Report its exact executable and version; do not assume the command found on PATH is the intended installation.

If Python, an appropriate PyYAML binary, or filesystem support is missing, stop and explain what is needed. Do not install system packages or change global configuration automatically. The user can still download a skill release as a ZIP from their Library.

  1. Fetch the versioned release manifest above over HTTPS. If it is unavailable, stop. Download only its three named files from the same Allbase origin. Check each file’s byte size and SHA-256 against the manifest before using it. Never follow a substituted URL or execute downloaded setup scripts.
  2. Create a new, private, versioned Python environment outside any agent app’s skill directory—for example, ~/.local/share/allbase/skill-helper/0.2.0/venv. Use python3 -m venv with that chosen directory; do not overwrite an existing environment or change global PATH.
  3. Use that environment’s Python to install the verified lock file: <venv>/bin/python -m pip --isolated install --require-hashes --only-binary=:all: --index-url https://pypi.org/simple -r <verified requirements.txt>. This installs the exact helper wheel and pinned PyYAML binary into that environment. The lock file uses the versioned Allbase wheel URL and hash-locked upstream PyYAML; it does not require public PyPI publishing by you.
  4. Check <venv>/bin/allbase-skill-installs --help. Record the helper version and verified release manifest locally. Do not run commands from skill package content. A successful helper setup does not prove a skill is installed or being used by Claude Code or Codex.

SHA-256 checks bind these files to the manifest obtained from the trusted Allbase HTTPS origin. They are integrity checks, not an independent publisher signature. There is no automatic helper update; a new helper version needs its own verification and environment.

Continue with your exact skill

Open the release in Knowledge → Library, choose Use in a project, and copy the request to your local agent. Connect it to Allbase with OAuth if needed.

Obtain the helper before requesting private release access. The agent starts the helper’s managed-install plan and supplies the short-lived normal-use read receipt through its supported stdin handshake. Keep credentials and project paths local; never paste them into this page, a command argument, or permanent configuration.

Review the exact release, repository, destination, and proposed changes. Apply only when your explicit authorization covers that plan; existing scoped authorization counts. Changed content, destination, or capabilities require another review. Current access denial stops the operation—owner recovery is not an installation fallback.

The browser cannot access your filesystem. Ask your local agent to verify the resulting files, and separately observe that Claude Code or Codex discovers and uses it. Until then, this device remains Not verified.