AI agent skills
Opfield can become an infrastructure control plane for coding agents without giving them direct SSH access or teaching each agent your deployment process from scratch. The public Opfield skills explain how Opfield resources, permissions, Tasks, builds, delivery, diagnosis, verification, and rollback work: using-gateway is the entry point, and one skill per product area goes into the details. Opfield’s remote MCP server then gives the agent authenticated access to the resources its user is allowed to see.
The two layers have different jobs:
- Agent skill: reusable operating knowledge installed into Codex, Claude Code, Cursor, and other compatible agents.
- Opfield MCP: live tools from your Opfield installation, protected by OAuth, resource scopes, plan entitlements, confirmations, and audit logging.
Install the Opfield skills
Section titled “Install the Opfield skills”From a project where the agent should use Opfield, install the whole set:
npx skills add the-square-labs/gateway-skills --skill '*'The installer lets you select the compatible agents configured on your machine. To make the skills available across projects, install them globally with -g. To install one skill, name it, for example --skill publishing-html-pages; using-gateway alone routes the agent to the other skills and tells it where to read them.
| Skill | Covers |
|---|---|
using-gateway |
Connecting over MCP, tool discovery, safety rules, Tasks and verification; routes to the skills below |
publishing-html-pages |
Publishing generated HTML reports and static sites to Pages and sharing the link |
deploying-workloads |
Containers, blue/green Deployments, Compose Projects, Git builds, volumes and migration |
high-availability |
Running a workload on several Docker Nodes with replicas or failover |
ingress-and-domains |
Domains, DNS, TLS, Routes, Access Lists, Secure Links and maintenance mode |
internal-pki |
Private certificate authorities and internal certificates |
databases |
Managed and external PostgreSQL, Redis and ClickHouse, bindings, queries and backups |
storage |
Storage connections, managed object storage, copy jobs and the MinIO migration |
managing-nodes |
Enrolling, updating and repairing Nodes, console and files |
observability |
Logging, SIEM export, alerts, webhooks, status pages and the audit log |
access-control |
Users, groups, scopes, API tokens and OAuth grants |
The skill is plain Markdown with focused references. You can inspect it before installation in the the-square-labs/gateway-skills repository and keep it under version control when installing at project scope.
Install as a native plugin
Section titled “Install as a native plugin”Claude Code and Codex can also install the same canonical skill as a native plugin. Choose either the plugin route or npx skills for a given agent; installing both is unnecessary.
For Claude Code:
claude plugin marketplace add the-square-labs/gateway-skillsclaude plugin install gateway@gateway-skillsFor Codex:
codex plugin marketplace add the-square-labs/gateway-skills --ref maincodex plugin add gateway@gateway-skillsStart a new session after installing or updating the plugin. The repository contains no always-on hooks: installation alone does not connect to Opfield or change infrastructure.
The complete installation, update, and verification commands are maintained in the repository’s INSTALL.md.
Skills served by your Opfield
Section titled “Skills served by your Opfield”Every Opfield installation since 2.11 serves the same skills over MCP, matching its own release: the index is the resource gateway://skills, each file is gateway://skills/<name>/SKILL.md, and each skill is also an MCP prompt named skill-<name>. An agent connected to Opfield can read them without installing anything. The skills are also published at https://docs.opfield.dev/agent/<name>/SKILL.md, listed in /agent/index.json and in llms.txt.
Connect the agent to Opfield
Section titled “Connect the agent to Opfield”An administrator first enables Settings → Features → OAuth and MCP access → MCP server and grants the user Use MCP (mcp:use) together with the ordinary scopes for the resources the agent may access.
For Codex:
codex mcp add good-gateway --url https://gateway.example.com/api/mcpcodex mcp login good-gatewaycodex mcp listFor Claude Code:
claude mcp add --transport http good-gateway --scope user https://gateway.example.com/api/mcpclaude mcp login good-gatewayclaude mcp get good-gatewayReplace gateway.example.com with the canonical public hostname of your Opfield installation. Authentication completes through Opfield OAuth in a browser. Do not create or paste an API token for MCP.
For callback policy, compact tool discovery, and connection errors, use the complete REST API and MCP guide.
Start with a read-only task
Section titled “Start with a read-only task”Verify the connection and permission boundary before asking the agent to make a change:
Use $using-gateway. List the Opfield Nodes and workloads I can access,summarize warnings and active Tasks, and recommend the safest next action.Do not change anything.Then try a scoped delivery request:
Use $using-gateway to inspect how this application is currentlypublished. Propose a Opfield-native update and rollback plan. Wait for myapproval before changing infrastructure.The skill tells the agent to read current state first, preserve resource ownership, avoid direct host changes, follow asynchronous Tasks, and verify the actual resource or HTTPS result instead of treating an accepted request as success.
Permissions and safety
Section titled “Permissions and safety”Create a dedicated Opfield user or group for agent access and grant only the necessary resources and actions. MCP does not bypass Opfield authorization: removing mcp:use, changing group membership, or narrowing resource scopes affects future calls made with the existing connection.
An agent whose user may work only in some folders, Nodes, or resources stays inside them. When the connection is limited, Opfield adds a summary of that access to the MCP server instructions at connect time. The using-gateway and access-control skills tell the agent to call get_my_access, or read gateway://access, when a list comes back empty or a create at the root is refused, and to pass folderId when creating; a refused create also names the folders it may use. See Find out what the caller can access.
Use separate identities and Opfield installations for development and production. A skill gives an agent instructions, not authority; the connected user’s scopes and the user’s explicit request determine what it can do.