gap

A Claude Code add-on for gap, a system that represents robot tasks as connected graphs of actions. It can use registered robot skills and run tasks in LIBERO, a robotics simulation environment.

In plain words
What is it for?
It is for finding, creating, testing, debugging, and running robot task graphs, including safety-gated tasks on real robots.
Why use it?
It helps developers check whether the needed robot tools and skills exist before running a task, and inspect what happened when execution fails.

Plugin for Claude Code

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Claude Code
/plugin marketplace add graph-robots/graph-as-policy
agentmods
npx agentmods add plugins/graph-robots/graph-as-policy/marketplace
Clone the repo
git clone --depth 1 https://github.com/graph-robots/graph-as-policy

Made for: Claude Code.

Per session not measured What this adds to a session before it is invoked.
When invoked not measured Not applicable: nothing here is loaded into a session.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Security

Grade A, and why

gap scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.claude-plugin/marketplace.json · 30 lines

What it actually says

{
  "name": "gap",
  "owner": { "name": "graph-as-policy authors", "url": "https://github.com/graph-robots" },
  "metadata": {
    "description": "Agent skills for gap (graph as policy): drive the robot-graph engine from Claude Code — search skill registries, check capabilities, and run, author, and test verified robot task graphs.",
    "version": "0.1.0"
  },
  "plugins": [
    {
      "name": "gap",
      "source": "./agent",
      "description": "Operate the gap robot-graph engine: search robot skill registries (open-robot-skills and your own), check tool/model/skill capabilities (gap check), run graphs in LIBERO sim, generate graphs from language, author skill bundles and registries with scaffolded unit tests, debug traces, and execute safety-gated real-robot tasks.",
      "author": { "name": "graph-as-policy authors" },
      "homepage": "https://github.com/graph-robots/graph-as-policy",
      "repository": "https://github.com/graph-robots/graph-as-policy",
      "license": "MIT",
      "category": "robotics",
      "keywords": ["robotics", "robot-manipulation", "robot-skills", "skill-registry", "LIBERO", "simulation", "task-graphs"]
    },
    {
      "name": "open-robot-skills",
      "source": { "source": "github", "repo": "graph-robots/open-robot-skills" },
      "description": "Optional: the robot skill/tool bundle contracts from the canonical open-robot-skills registry, loadable as agent skills. Same content as that repo's own marketplace — install from one route, not both.",
      "skills": ["./tools"],
      "license": "MIT",
      "category": "robotics"
    }
  ]
}
Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 30 lines scan A 6b9bd23660c3

Subscribe to this mod's changes

gap is a plugin published in the GitHub repository graph-robots/graph-as-policy (124 stars, last pushed 1mo ago), licensed Apache-2.0. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.