nvim-install

nvim-install is a skill for Claude Code, Codex from fredrikaverpil/dotfiles. It costs 132 tokens per session (3,444 once invoked), scanned A, original, MIT.

A setup procedure that installs Neovim, a terminal-based text editor, in a cloud testing environment and starts it without a visible user interface. It prepares the environment for another tool that controls Neovim through a connection.

In plain words
What is it for?
Use it before testing Neovim configuration changes in a web session, especially changes to the nvim-fredrik configuration.
Why use it?
It provides the editor binary and running session that the cloud environment does not include by default.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/fredrikaverpil/dotfiles/nvim-install
Any agent
npx skills add fredrikaverpil/dotfiles --skill nvim-install
Clone the repo
git clone --depth 1 https://github.com/fredrikaverpil/dotfiles

Made for: Claude Code, Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for nvim-install

README.md
[![agentmods](https://agentmods.dev/badge/skills/fredrikaverpil/dotfiles/nvim-install.svg)](https://agentmods.dev/skills/fredrikaverpil/dotfiles/nvim-install)
Your own site
<a href="https://agentmods.dev/skills/fredrikaverpil/dotfiles/nvim-install"><img src="https://agentmods.dev/badge/skills/fredrikaverpil/dotfiles/nvim-install.svg" alt="Measured on agentmods" height="20"></a>
Per session 132 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 3,444 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 1 finding. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00132 $0.03444
Opus 5 $0.00066 $0.01722
Sonnet 5 $0.00026 $0.00689
Haiku 4.5 $0.00013 $0.00344

Measured 4d ago against content hash 4b2d4b4e2f98, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

nvim-install scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Makes network callslowCapability

Not a fault in itself. Listed so you know the mod talks to something, and to what.

curl -sSI -o /dev/null -w "cache: %{http_code}\n" https://cache.nixos.org
stow/shared/.claude-web/skills/nvim-install/SKILL.md · 273 lines

How it starts

The opening of the file, as written. The whole thing — 273 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Install Neovim in the web sandbox

This is the missing half of the neovim RPC skill: that skill drives a running Neovim via $NVIM, but the sandbox ships neither the binary nor a parent editor. This skill installs Neovim, launches it headless on a listen socket, and exports $NVIM so the neovim skill's commands work verbatim afterwards.

Scope: web sandbox only (CLAUDE_CODE_REMOTE=true). Do not run on a real machine — there Neovim is managed by bob at ~/.local/share/bob/nvim-bin/nvim.

Why Nix, not bob

Nix installs Neovim from *.nixos.org (allow-listed by default), so the binary needs no GitHub access — and nixpkgs-unstable ships a current Neovim with vim.pack, which nvim-fredrik requires. bob is available too (see the end), but bob install downloads Neovim as a GitHub release asset, which the GitHub proxy blocks unless neovim/neovim is attached to the session — regardless of network level. So Nix is the default; bob is an opt-in.

Step 0 — Network prerequisites

Two independent mechanisms gate traffic; they bite at different points.

  1. The binary (this skill): substituted from the Nix cache (*.nixos.org), reachable under the default Trusted network policy. No GitHub, no action. Verify:

    curl -sSI -o /dev/null -w "cache:    %{http_code}\n" https://cache.nixos.org
    curl -sSI -o /dev/null -w "channels: %{http_code}\n" https://channels.nixos.org/nixpkgs-unstable/nixexprs.tar.xz
    
  2. The plugins (a full nvim-fredrik run): at startup vim.pack clones ~50 plugins. These split three ways:

    • Public GitHub clones — already work under the default Trusted policy (github.com is allow-listed). No action.
    • codeberg.org plugins (nvim-lint, nvim-dap, nvim-dap-python) — required and blocked by default. Edit the environment → Network access selector → Custom → in Allowed domains add the bare codeberg.org → tick "Also include default list of common package managers" → save. This rebuilds the environment. See https://code.claude.com/docs/en/claude-code-on-the-web. Gotcha: use the apex codeberg.org, not *.codeberg.org — the wildcard matches only subdomains, but the plugin src URLs are https://codeberg.org/..., so a *.codeberg.org-only allowlist still 403s the clones. (Full network access also works but is broader than needed.)
    • GitHub release assets (codediff's prebuilt lib, Mason LSP servers, treesitter parsers) — gated by the GitHub proxy to attached repos regardless of network level, so they may 403. Optional for observing most config behavior; attach a specific repo with add_repo only if the change under test needs it.

Read the full file on GitHub · 273 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 4d ago First seen · 273 lines · 132 tokens per session scan A 4b2d4b4e2f98

Subscribe to this mod's changes

nvim-install is a skill published in the GitHub repository fredrikaverpil/dotfiles (257 stars, last pushed today), licensed MIT. It adds 132 tokens to every session and 3,444 once invoked, about $0.0007 per session on Opus 5. A static security scan graded it A with 1 finding (makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other skills, from other repositories

mbo-plan

Plan a new objective end-to-end in this repo's docs/mbo Management-By-Objective system — turn a GitHub issue or a gss draft-PR worktree into consistent design/spec/plan artifacts and track it in docs/mbo/index.md. Use this whenever the user wants to START planning or designing a new feature, skill, CLI, or service…

sfc-gh-eraigosa/dotfiles · 260 tokens

wispr-flow-debug

Debug and test the Wispr Flow AutoHotkey dictation triggers (Copilot key + extra keys) from WSL by deploying macos.ahk to the Windows Desktop, reloading AutoHotkey, and reading the debug log. Use when an activation/trigger key isn't starting/stopping dictation, when the overlay clicks land wrong, or when verifying a…

sfc-gh-eraigosa/dotfiles · 87 tokens

pr-list

List GitHub Pull Requests in a Discord-friendly format with status icons, blockquotes, and direct links. Use when the user asks for "pr list", "list PRs", "open pull requests", or a chat-ready summary of PRs for a repository.

sfc-gh-eraigosa/dotfiles · 56 tokens

google-docs

Integration for interacting with Google Docs and Google Workspace using the 'gws' CLI.

sfc-gh-eraigosa/dotfiles · 21 tokens

sync-forks

Check how many of your GitHub forks are out of date and sync them.

sfc-gh-eraigosa/dotfiles · 20 tokens

research-evaluation

Discover and evaluate external tools/projects before adopting them, producing a consistent research dossier and (when the repo has one) a docs/mbo research design doc + tracking issue per target. Use when the user wants to "research X", "evaluate X before we adopt it", "look up X and tell me if it's useful", "start a…

sfc-gh-eraigosa/dotfiles · 234 tokens