install

A skill that guides installation and first-time setup of grouter, a local proxy service for routing requests. It chooses an installation path based on whether Bun or Docker is available and checks that the command works.

In plain words
What is it for?
Use it to install grouter with Bun, from source, or with Docker, verify it is on the command path, and optionally begin its setup.
Why use it?
It helps users get from an unconfigured machine to a working local grouter service while avoiding silent shell or global configuration changes.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/gxdevs/grouter/install
Any agent
npx skills add GXDEVS/grouter --skill install
Clone the repo
git clone --depth 1 https://github.com/GXDEVS/grouter

Made for: Claude Code, Codex.

Per session 173 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 2,593 The whole file, excluding the scripts and references it only reads on demand.
Security scan F 5 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00173 $0.02593
Opus 5 $0.00086 $0.01296
Sonnet 5 $0.00035 $0.00519
Haiku 4.5 $0.00017 $0.00259

Measured 2d ago against content hash 10e35aa4a61e, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade F, and why

install scanned grade F with 5 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Asks for rootmediumPrivilege escalation

A mod that escalates privileges can change anything on the machine, not only the project.

- Don't run `sudo npm install -g` — grouter is Bun-first, and a sudo install will fight the `bun link` that `setup.sh` uses.

Downloads and executes remote codehighSupply chain

curl | sh runs whatever the server returns today, which is not necessarily what it returned when this was reviewed.

| Neither bun nor docker | Stop — install [Bun](https://bun.sh) (`curl -fsSL https://bun.sh/install \| bash`) or Docker first. Tell the user which. |

Reads agent configuration directoriesmediumAgent snooping

.claude/, .codex/, .gemini/ hold keys, settings and other credentials a mod has no legitimate need for.

5. **Confirm before actions that touch global state** (global `bun install -g`, `bun link`, `docker compose up`, writing to `~/.claude/settings.json`).

Recursive force deletehighDestructive command

rm -rf with a variable or a broad path is one typo away from removing the wrong tree.

rm -rf ~/.grouter # only if the user explicitly asks

Makes network callslowCapability

Not a fault in itself. Listed so you know the mod talks to something, and to what.

| Neither bun nor docker | Stop — install [Bun](https://bun.sh) (`curl -fsSL https://bun.sh/install \| bash`) or Docker first. Tell the user which. |
.claude/skills/install/SKILL.md · 267 lines

How it starts

The opening of the file, as written. The whole thing — 267 lines — stays where its author put it; the contents beside it link to each section on GitHub.

grouter — Install & First-Run Flow

Get a user from zero to a running grouter serve with a working proxy at http://localhost:3099. There are four install paths — pick one with the user, don't run all of them.

Ground rules

  1. Never sudo. grouter installs to the user's ~/.bun/bin (or runs in a container). If a command seems to need root, stop and ask.
  2. Never overwrite the user's shell config silently. PATH fixes get printed as a one-liner for the user to run, not injected.
  3. Don't wipe ~/.grouter/. That's where accounts and the SQLite DB live. Uninstall removes the binary only unless the user explicitly asks to drop data.
  4. Verify at each step. After install, confirm grouter --version works before moving to first-run.
  5. Confirm before actions that touch global state (global bun install -g, bun link, docker compose up, writing to ~/.claude/settings.json).

Step 0 — Detect the environment

Run in parallel:

bun --version 2>/dev/null || echo "NO_BUN"
docker --version 2>/dev/null || echo "NO_DOCKER"
command -v grouter && grouter --version 2>/dev/null || echo "NO_GROUTER"
echo "$PATH" | tr ':' '\n' | grep -E "\.bun/bin$" || echo "BUN_BIN_NOT_IN_PATH"
uname -s

Decision:

State Recommend
bun present, user just wants to try Path A — bunx
bun present, user wants permanent install Path B — global install
Inside a clone of the repo, contributor Path C — from source
docker present, no bun, or user prefers containers Path D — docker
Neither bun nor docker Stop — install Bun (curl -fsSL https://bun.sh/install | bash) or Docker first. Tell the user which.

If grouter is already on PATH, ask whether the user wants to upgrade (rerun their original install path) or reinstall fresh (uninstall → install).

Path A — bunx (one-shot, no install)

Best for: "just let me try it".

bunx grouter-auth setup

That's it. No global install, no PATH fiddling. Skip to Step 2 (first-run) — bunx runs the setup wizard directly.

Read the full file on GitHub · 267 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 267 lines · 0 tokens per session scan F 10e35aa4a61e

Subscribe to this mod's changes

install is a skill published in the GitHub repository GXDEVS/grouter (55 stars, last pushed 4d ago), licensed MIT. It adds 173 tokens to every session and 2,593 once invoked, about $0.0009 per session on Opus 5. A static security scan graded it F with 5 findings (asks for root, downloads and executes remote code, reads agent configuration directories). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other skills, from other repositories

systematic-debugging

Use when encountering any bug, test failure, or unexpected behavior, before proposing fixes.

obra/superpowers · 21 tokens

brainstorming

You MUST use this before any creative work - creating features, building components, adding functionality, or modifying behavior. Explores user intent, requirements and design before implementation.

obra/superpowers · 37 tokens

chat-pet-sprite-creation

Use when creating or changing VS Code chat pet sprite art, sprite sheets, state animations, eye treatments, Stable/Insiders variants, or pet transitions under src/vs/workbench/contrib/chat/browser/widget/media/chatPet.

microsoft/vscode · 53 tokens

cpu-profile-analysis

Analyze V8/Chrome CPU profiles (.cpuprofile) and DevTools trace files (Trace-.json). Use when: profiling performance, investigating slow functions, comparing code paths, finding bottlenecks, analyzing timeToRequest, understanding call trees from sampling profiler data, analyzing layout/paint/rendering, investigating…

microsoft/vscode · 71 tokens

agent-host-chat-contributions

Build and review cross-cutting agent-host chat behavior through lifecycle contributions. Use when adding turn lifecycle side effects, prompt or context injection, restored-history transformation, protocol-action observation, or when reviewing changes that add code to AgentSideEffects or AgentService.

microsoft/vscode · 56 tokens

auto-perf-optimize

Run agent-driven VS Code performance or memory investigations. Use when asked to launch Code OSS, automate a VS Code scenario, run the Chat memory smoke runner, capture renderer heap snapshots, take workflow screenshots, compare run summaries, or drive a repeatable scenario before heap-snapshot analysis.

microsoft/vscode · 62 tokens