Skip to content

AI agent skills

Opfield can become an infrastructure control plane for coding agents without giving them direct SSH access or teaching each agent your deployment process from scratch. The public Opfield skills explain how Opfield resources, permissions, Tasks, builds, delivery, diagnosis, verification, and rollback work: using-gateway is the entry point, and one skill per product area goes into the details. Opfield’s remote MCP server then gives the agent authenticated access to the resources its user is allowed to see.

The two layers have different jobs:

  • Agent skill: reusable operating knowledge installed into Codex, Claude Code, Cursor, and other compatible agents.
  • Opfield MCP: live tools from your Opfield installation, protected by OAuth, resource scopes, plan entitlements, confirmations, and audit logging.

From a project where the agent should use Opfield, install the whole set:

Terminal window
npx skills add the-square-labs/gateway-skills --skill '*'

The installer lets you select the compatible agents configured on your machine. To make the skills available across projects, install them globally with -g. To install one skill, name it, for example --skill publishing-html-pages; using-gateway alone routes the agent to the other skills and tells it where to read them.

Skill Covers
using-gateway Connecting over MCP, tool discovery, safety rules, Tasks and verification; routes to the skills below
publishing-html-pages Publishing generated HTML reports and static sites to Pages and sharing the link
deploying-workloads Containers, blue/green Deployments, Compose Projects, Git builds, volumes and migration
high-availability Running a workload on several Docker Nodes with replicas or failover
ingress-and-domains Domains, DNS, TLS, Routes, Access Lists, Secure Links and maintenance mode
internal-pki Private certificate authorities and internal certificates
databases Managed and external PostgreSQL, Redis and ClickHouse, bindings, queries and backups
storage Storage connections, managed object storage, copy jobs and the MinIO migration
managing-nodes Enrolling, updating and repairing Nodes, console and files
observability Logging, SIEM export, alerts, webhooks, status pages and the audit log
access-control Users, groups, scopes, API tokens and OAuth grants

The skill is plain Markdown with focused references. You can inspect it before installation in the the-square-labs/gateway-skills repository and keep it under version control when installing at project scope.

Claude Code and Codex can also install the same canonical skill as a native plugin. Choose either the plugin route or npx skills for a given agent; installing both is unnecessary.

For Claude Code:

Terminal window
claude plugin marketplace add the-square-labs/gateway-skills
claude plugin install gateway@gateway-skills

For Codex:

Terminal window
codex plugin marketplace add the-square-labs/gateway-skills --ref main
codex plugin add gateway@gateway-skills

Start a new session after installing or updating the plugin. The repository contains no always-on hooks: installation alone does not connect to Opfield or change infrastructure.

The complete installation, update, and verification commands are maintained in the repository’s INSTALL.md.

Every Opfield installation since 2.11 serves the same skills over MCP, matching its own release: the index is the resource gateway://skills, each file is gateway://skills/<name>/SKILL.md, and each skill is also an MCP prompt named skill-<name>. An agent connected to Opfield can read them without installing anything. The skills are also published at https://docs.opfield.dev/agent/<name>/SKILL.md, listed in /agent/index.json and in llms.txt.

An administrator first enables Settings → Features → OAuth and MCP access → MCP server and grants the user Use MCP (mcp:use) together with the ordinary scopes for the resources the agent may access.

For Codex:

Terminal window
codex mcp add good-gateway --url https://gateway.example.com/api/mcp
codex mcp login good-gateway
codex mcp list

For Claude Code:

Terminal window
claude mcp add --transport http good-gateway --scope user https://gateway.example.com/api/mcp
claude mcp login good-gateway
claude mcp get good-gateway

Replace gateway.example.com with the canonical public hostname of your Opfield installation. Authentication completes through Opfield OAuth in a browser. Do not create or paste an API token for MCP.

For callback policy, compact tool discovery, and connection errors, use the complete REST API and MCP guide.

Verify the connection and permission boundary before asking the agent to make a change:

Use $using-gateway. List the Opfield Nodes and workloads I can access,
summarize warnings and active Tasks, and recommend the safest next action.
Do not change anything.

Then try a scoped delivery request:

Use $using-gateway to inspect how this application is currently
published. Propose a Opfield-native update and rollback plan. Wait for my
approval before changing infrastructure.

The skill tells the agent to read current state first, preserve resource ownership, avoid direct host changes, follow asynchronous Tasks, and verify the actual resource or HTTPS result instead of treating an accepted request as success.

Create a dedicated Opfield user or group for agent access and grant only the necessary resources and actions. MCP does not bypass Opfield authorization: removing mcp:use, changing group membership, or narrowing resource scopes affects future calls made with the existing connection.

An agent whose user may work only in some folders, Nodes, or resources stays inside them. When the connection is limited, Opfield adds a summary of that access to the MCP server instructions at connect time. The using-gateway and access-control skills tell the agent to call get_my_access, or read gateway://access, when a list comes back empty or a create at the root is refused, and to pass folderId when creating; a refused create also names the folders it may use. See Find out what the caller can access.

Use separate identities and Opfield installations for development and production. A skill gives an agent instructions, not authority; the connected user’s scopes and the user’s explicit request determine what it can do.