Borrowing it
Nothing to install: this file belongs to Aviator-Coding/home-ops. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/Aviator-Coding/home-ops/main/.claude/skills/kopiur-backups/SKILL.mdgit clone --depth 1 https://github.com/Aviator-Coding/home-opsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/aviator-coding/home-ops/kopiur-backups)<a href="https://agentmods.dev/skills/aviator-coding/home-ops/kopiur-backups"><img src="https://agentmods.dev/badge/skills/aviator-coding/home-ops/kopiur-backups.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00112 | $0.11500 |
| Opus 5 | $0.00056 | $0.05750 |
| Sonnet 5 | $0.00022 | $0.02300 |
| Haiku 4.5 | $0.00011 | $0.01150 |
Grade A, and why
kopiur-backups scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 167 lines — stays where its author put it; the contents beside it link to each section on GitHub.
kopiur backups (and the VolSync dual-engine overlap)
Relocated verbatim from AGENTS.md on 2026-09-01 so it loads only when this subsystem is in play.
The text below is unchanged; only line breaks were inserted. AGENTS.md keeps a one-sentence pointer.
Add new findings here or to the owning document, not back into AGENTS.md - see its
"Maintaining this file" section for the rule.
- kopiur is live on all 29 of the fleet's 29 VolSync-protected claims, VolSync has been RETIRED from 27 of them (migration Stage 5, waves on 2026-09-01, 2026-09-02 and 2026-09-04 - the migration is COMPLETE for every eligible claim), and deleting kopiur's CRs can delete backup data. The fleet was 30 until the
downloads/autobrrAPP was removed on 2026-09-02 (captain decision - unused). That is a distinct operation from a Stage 5 retirement, which removes an ENGINE and always leaves the claim: removing the app removed the claim, the overlay and the kopiur onboarding together. Its kopia snapshots were deliberately KEPT -docs/backups/autobrr-removal-2026-09-02.md, which also records the measuredRetainsemantics below.system/kopiur(operator + two cluster-scopedClusterRepositoryobjects:cephandr2, each on its own newkopiurbucket - MinIO is deliberately not a kopiur destination) is the staged replacement for VolSync. Stage 3 (2026-08-30) put 27 further claims onkubernetes/components/kopiuralongside an untouchedcomponents/volsync, one commit per namespace, so those claims now have two independent backups each.
27 volumes were made kopiur-ONLY, in three waves; 26 still are (autobrr left the fleet with its app). Wave one, retired 2026-09-01 as a deliberate low-stakes pilot (regenerable or reconstructible content, clean restore proofs): ai/repo-wiki, downloads/recyclarr-config, downloads/sabnzbd-config, media/seerr. Wave two, retired 2026-09-02 on the deeper proofs in docs/backups/kopiur-wave-two-reproof-2026-09-02.md part 4: downloads/prowlarr-config, selfhosted/ntfy, downloads/autobrr (app since removed), selfhosted/obsidian-livesync - and these are not all regenerable, so the authorising argument is different: completeness of proof (100% of claim content, destination-identical in content and metadata) plus, for the two 2Gi selfhosted claims, a PVC that cannot outgrow its restore cache. selfhosted/obsidian-livesync is a genuine Obsidian vault and was retired on an explicit captain decision after firstmate objected and recommended keeping it dual-engine. Wave three, retired 2026-09-04, took the remaining 19 eligible claims in three risk-tiered commits - tier A database/pgadmin, downloads/{bazarr,lidarr,radarr,readarr,sonarr}, home-automation/{esphome,matter-server,zigbee2mqtt}, media/tdarr, selfhosted/changedetection; tier B ai/{hermes,opencode}, media/{plex,calibre-web-automated}; tier C home-automation/home-assistant, selfhosted/{n8n,linkwarden,syncthing}. Same evidence standard for all 19 (every one a destination-identical PASS row in the fleet proof); the tiering is a sequencing device so a surprise stops one tier rather than the fleet. Record, exposure table and open follow-ups: docs/backups/kopiur-wave-three-retirement-2026-09-04.md. Only three claims remain dual-engine, and that is the END STATE, not a backlog: selfhosted/paperless-ngx is a permanent carve-out; selfhosted/syncthing-data (5 files / 531 B) and selfhosted/paperless-ngx-media (1 file / 0 B) were assessed in wave two, re-measured unchanged on 2026-09-04, and found NOT ready (proofs cover nothing meaningful, and both sit behind a restore cache they would cross the first time they hold real data). Assume a claim is kopiur-only unless you have checked - the dual-engine safety net that made earlier kopiur mistakes survivable is gone almost everywhere. Note selfhosted/syncthing (1Gi config claim, RETIRED) and selfhosted/syncthing-data (15Gi synced files, NOT retired) are different claims sharing one overlay file. Stage 4 (2026-08-31) onboarded both previously deferred claims: selfhosted/changedetection-config, which turned out not to need the 0:1000 root mover its deferral assumed (the app shipped no securityContext at all, so it ran as its image default (root) and wrote 2292 mode-0600 root-owned files while its overlay declared an APP_UID/APP_GID of 2000:2000 that no manifest in this repo consumes; giving it the 1000:1000 identity its data already carried and re-owning the volume removed the need for a root mover, so it onboarded with no KOPIUR_PUID/PGID override and no namespace-wide privileged-mover grant), and home-automation/matter-server with an explicit root mover (KOPIUR_PUID/PGID: 0) - the component already parameterises that, so inheritSecurityContextFrom was not used (it would not flow to the standing Restore) - plus the namespace-wide kopiur.home-operations.com/privileged-movers=true annotation.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago Changed a9c312609fee
- 3d ago First seen · 167 lines · 112 tokens per session scan A 4ff6f740e9ec
kopiur-backups is a skill published in the GitHub repository Aviator-Coding/home-ops (2 stars, last pushed today), licensed MIT. It adds 112 tokens to every session and 11,500 once invoked, about $0.0006 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-04.
Other skills, from other repositories
gke-compute-classes
Configures, optimizes, and troubleshoots GKE ComputeClasses. Use when configuring Spot VMs with on-demand fallback, targeting specific accelerators (GPUs/TPUs) or machine families, restricting ComputeClass access, or debugging pending pods related to node pool auto-creation. Do not use for cluster-level Node Auto…
gke-reliability
Improves GKE workload reliability, using PDBs, health probes, and topology spread constraints. Use when configuring GKE workload reliability, setting up PDBs, or configuring GKE health probes (liveness, readiness, startup). Don't use for disaster recovery setup or full cluster backups (use gke-backup-dr instead).
gke-workload-security
Audits, configures, and hardens workload-level security controls for Google Kubernetes Engine (GKE) applications and namespaces. Covers running cluster security audits (auditcluster.sh), configuring Workload Identity Federation (impersonation, KSA/GSA binding, and pod setup), enforcing Network Policies (default-deny…
nemo-automodel-launcher-config
Configure NeMo AutoModel job launches for interactive runs, Slurm clusters, and SkyPilot cloud execution.
azure-mgmt-botservice-dotnet
Azure Resource Manager SDK for Bot Service in .NET. Management plane operations for creating and managing Azure Bot resources, channels (Teams, DirectLine, Slack), and connection settings. Triggers: "Bot Service", "BotResource", "Azure Bot", "DirectLine channel", "Teams channel", "bot management .NET", "create bot".
cloud-architect
Designs cloud architectures, creates migration plans, generates cost optimization recommendations, and produces disaster recovery strategies across AWS, Azure, and GCP. Use when designing cloud architectures, planning migrations, or optimizing multi-cloud deployments. Invoke for Well-Architected Framework, cost…