xs-xangi-settings

xs-xangi-settings is a skill for Claude Code, Codex from karaage0703/ai-assistant-workspace. It costs 66 tokens per session (2,034 once invoked), scanned A, original, MIT.

A procedure for changing settings in xangi, an assistant service that can run through chat. It covers finding the right xangi copy, checking its current documentation, editing settings, and restarting the service.

In plain words
What is it for?
Use it to identify the xangi instance serving a Discord, Slack, web chat, or LINE session; inspect its configuration; change settings; and apply them safely, including in Docker setups.
Why use it?
It helps avoid changing the wrong copy when several xangi instances run on one machine. It also reduces mistakes caused by relying on outdated setting names or restart instructions.

Skill for Claude CodeCodex

Written for no agent in particular: nothing here depends on one. Also seen: mentions Codex.

Needs its repository: it runs a file that does not travel with it, so clone the repository first. The line is ./bin/xangi service status.

Good fit Use it to identify the xangi instance serving a Discord, Slack, web chat, or LINE session; inspect its configuration; change settings; and apply them safely, including in Docker setups.

Compare 6 skills from other repositories ↓
Install

Getting it into your agent

It runs from inside its repository, so the clone comes first — what it calls does not travel with the file alone.

Clone the repo
git clone --depth 1 https://github.com/karaage0703/ai-assistant-workspace
agentmods
npx agentmods add skills/karaage0703/ai-assistant-workspace/xs-xangi-settings

Made for: Claude Code, Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for xs-xangi-settings

README.md
[![agentmods](https://agentmods.dev/badge/skills/karaage0703/ai-assistant-workspace/xs-xangi-settings/github.svg)](https://agentmods.dev/skills/karaage0703/ai-assistant-workspace/xs-xangi-settings)
Your own site
<a href="https://agentmods.dev/skills/karaage0703/ai-assistant-workspace/xs-xangi-settings"><img src="https://agentmods.dev/badge/skills/karaage0703/ai-assistant-workspace/xs-xangi-settings/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for xs-xangi-settings

Your own site · 80×15
<a href="https://agentmods.dev/skills/karaage0703/ai-assistant-workspace/xs-xangi-settings"><img src="https://agentmods.dev/badge/skills/karaage0703/ai-assistant-workspace/xs-xangi-settings.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 66 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 2,034 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe. Third-party audits
  • NVIDIA SkillSpector warn 7 Sept 2026
SkillSpector: 2 findings, up to high

These are SkillSpector’s own severities. On a checked sample its high-severity flags on skills were ~96% false positives — a documented command, a public API, a “never do X” rule — so we show them as a caution to read, not a verdict. Why →

  • high Privilege Escalation · line 34
    Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
    Fix: Remove references to credential paths. Use environment variables or secrets managers. For docs, use placeholder paths (e.g., /path/to/config). Never load .env or token files in production code paths.
  • high Privilege Escalation · line 83
    Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
    Fix: Remove references to credential paths. Use environment variables or secrets managers. For docs, use placeholder paths (e.g., /path/to/config). Never load .env or token files in production code paths.
How audits are shown
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00066 $0.02034
Opus 5 $0.00033 $0.01017
Sonnet 5 $0.00013 $0.00407
Haiku 4.5 $0.00007 $0.00203

Measured 12d ago against content hash b85ddb787d3d, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-12, from the pricing page.

Security

Grade A, and why

xs-xangi-settings scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

skills/xs-xangi-settings/SKILL.md · 207 lines

How it starts

The opening of the file, as written. The whole thing — 207 lines — stays where its author put it; the contents beside it link to each section on GitHub.

xangi 設定変更スキル

チャットから xangi の設定確認、設定ファイル変更、反映再起動を行う。

基本方針

xangi 本体の設定項目や運用コマンドは変わる。スキル内の古い一覧だけで判断せず、作業前に対象 clone の一次情報を読む。

読む順番:

  1. [XANGI_ROOT]/docs/usage.md の環境変数・service・再起動まわり
  2. [XANGI_ROOT]/.env.example
  3. [XANGI_ROOT]/src/prompts/xangi-commands-chat-platform.ts(チャット上でAIに注入される最新運用ルール)

[XANGI_ROOT] は設定変更対象の xangi clone。[WORKSPACE] はこのワークスペース。

実行フロー

Step 1: 対象インスタンスを特定

複数の xangi clone が同じマシンで動くことがあるため、まず対象 clone を決める。

# 実行中コンテキストが xangi 上なら cwd/repo を確認
pwd
git rev-parse --show-toplevel 2>/dev/null

# xangi clone 候補と設定ファイルを確認
find "$HOME" -maxdepth 2 -name .env -path "$HOME/xangi-*/*" -print 2>/dev/null

# WORKSPACE_PATH / XANGI_INSTANCE_ID / XANGI_PROCESS_NAME / DATA_DIR を見て対象を絞る
for f in "$HOME"/xangi-*/.env; do
  [ -f "$f" ] || continue
  echo "## $f"
  grep -E '^(WORKSPACE_PATH|XANGI_INSTANCE_ID|XANGI_PROCESS_NAME|DATA_DIR)=' "$f" || true
done

判定の目安:

  • 現在の Discord / Slack / Web Chat / LINE セッションを動かしている clone を優先
  • WORKSPACE_PATH がこのワークスペースを指す clone を優先
  • XANGI_PROCESS_NAME./bin/xangi service ... の PM2 対象名
  • Docker運用では host 側の compose / 設定ファイルを対象にし、コンテナ内だけを書き換えない

Step 2: 最新ドキュメントを確認

対象 clone が /path/to/xangi なら:

cd /path/to/xangi
rg -n "service start|service stop|service restart|service status|XANGI_PROCESS_NAME|TIMEOUT_MS|CHANNEL_OVERRIDES|AUTO_REPLY_CHANNELS|SLACK_AUTO_REPLY_CHANNELS|system_settings|system_restart" \
  docs/usage.md .env.example src/prompts/xangi-commands-chat-platform.ts

運用ルールの現在形:

  • 起動・停止・再起動・状態確認は対象 clone の ./bin/xangi service start|stop|restart|status を使う
  • PATHから使う場合は xangi-dev / xangi-prod のような名前付き symlink を使う
  • xangi tool system_restart は起動中プロセスに graceful shutdown を要求する低レベル操作
  • system_settings は確認用。AI は system_settings で設定変更しない
  • 設定ファイル変更後は対象 clone で ./bin/xangi service restart する

Step 3: 要望の種類を判定

  • 設定確認 → Step 4a
  • 設定変更 → Step 4b

Step 4a: 設定確認

cd /path/to/xangi

# service 状態
./bin/xangi service status

# 現在の設定を確認(トークン等は表示しない)
grep -vE '(TOKEN|SECRET|PASSWORD|API_KEY)=' .env | grep -v '^#' | grep -v '^$'

Read the full file on GitHub · 207 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 12d ago First seen · 207 lines · 66 tokens per session scan A b85ddb787d3d

Subscribe to this mod's changes

xs-xangi-settings is a skill published in the GitHub repository karaage0703/ai-assistant-workspace (137 stars, last pushed 25d ago), licensed MIT. It adds 66 tokens to every session and 2,034 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other skills, from other repositories

systematic-debugging

Use when encountering any bug, test failure, or unexpected behavior, before proposing fixes.

obra/superpowers · 21 tokens

local-ai-agents

Build local-first AI agents that run entirely on a developer workstation with Microsoft Foundry Local and Qwen function-calling models. Covers Small Language Models (SLMs), the OpenAI-compatible local endpoint, sandboxed local tools, local RAG with Chroma, local MCP servers, hybrid cloud/local routing, and the…

microsoft/ai-agents-for-beginners · 200 tokens

next-cache-components-adoption

Turn on Cache Components in a Next.js app and resolve the blocking routes it surfaces. Use when the user wants to enable, adopt, or migrate to Cache Components, flip the cacheComponents flag, work through a flood of blocking-prerender / instant validation errors, run the cache-components-instant-false codemod, or…

vercel/next.js · 95 tokens

chat-pet-sprite-creation

Use when creating or changing VS Code chat pet sprite art, sprite sheets, state animations, eye treatments, Stable/Insiders variants, or pet transitions under src/vs/workbench/contrib/chat/browser/widget/media/chatPet.

microsoft/vscode · 53 tokens

cpu-profile-analysis

Analyze V8/Chrome CPU profiles (.cpuprofile) and DevTools trace files (Trace-.json). Use when: profiling performance, investigating slow functions, comparing code paths, finding bottlenecks, analyzing timeToRequest, understanding call trees from sampling profiler data, analyzing layout/paint/rendering, investigating…

microsoft/vscode · 71 tokens

insight-error-page

Write or audit an insight-kind error page for the Next.js dev overlay. Use when creating a new errors/ .mdx page, auditing an existing one, or checking that a page matches the framework fix cards. Covers page structure, title alignment, FixCard cards with Copy prompt button, code snippets, terminology verification…

vercel/next.js · 83 tokens