{"id":"b39437c6-10d8-4c53-bb49-5a7443e213b4","entityType":"agent","slug":"clawhub-drumrobot-choco","name":"choco","canonicalUrl":"https://www.xpersona.co/agent/clawhub-drumrobot-choco","canonicalPath":"/agent/clawhub-drumrobot-choco","generatedAt":"2026-10-11T20:56:10.248Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-11T16:57:01.111Z","emptyReason":null},"description":"Chocolatey operations integration — post-processing after choco upgrade, nssm service path refresh, NSSM → shawl migration (syncthing v2 etc.), resync on UniGetUI/choco metadata update failures. diagnose [diagnose.md], metadata-fix [metadata-fix.md], post-upgrade [post-upgrade.md], shawl-migration [shawl-migration.md], update-path [update-path.md]. Use when: \"choco\", \"chocolatey\", \"choco upgrade\", \"choco outdated\", \"vcredist\", \"nssm\", \"nssm recovery\", \"nssm path\", \"service path refresh\", \"after choco upgrade\", \"service failure\", \"SERVICE_STOPPED\", \"shim issue\", \"syncthing nssm\", \"syncthing v2\", \"shawl migration\", \"nssm deprecation\", \"service-specific error\", \"UniGetUI\", \"metadata update failure\", \"metadata stale\", \".nuspec stale\", \"choco metadata\".","descriptionLabel":"Source description","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 1K downloads reported by the source. Last updated 10/11/2026.","installCommand":"clawhub skill install s17ay1v6v88r2m102pvvc44gz183qcrm:choco","sourceUrl":"https://clawhub.ai/drumrobot/choco","homepage":"https://clawhub.ai/drumrobot/skills/choco","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/drumrobot/choco","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/drumrobot/skills/choco","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":60,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"choco technical dossier on Xpersona with agent coverage, OPENCLEW support, and live trust metadata."},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-11T16:57:01.111Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-11T16:57:01.111Z","emptyReason":null},"stars":null,"forks":null,"downloads":1023,"packageName":null,"latestVersion":"1.0.5","tractionLabel":"1K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-11T16:57:01.050Z","emptyReason":null},"lastUpdatedAt":"2026-10-11T16:57:01.111Z","lastCrawledAt":"2026-10-11T16:57:01.050Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-12T16:57:01.050Z","lastVerifiedAt":null,"highlights":[{"version":"1.0.5","createdAt":"2026-09-18T15:52:57.014Z","changelog":"Choco 1.0.5 - Updated version to 1.0.5 in metadata. - Removed the file: skill-card.md. - No user-facing functional changes documented; minor project structure and version metadata update.","fileCount":11,"zipByteSize":18078},{"version":"1.0.4","createdAt":"2026-08-18T05:41:14.776Z","changelog":"- Updated version to 1.0.4. - Removed the file: skill-card.md. - Minor documentation edits and metadata bump in SKILL.md and CHANGELOG.md. - No changes to core functionality.","fileCount":11,"zipByteSize":18185},{"version":"1.0.3","createdAt":"2026-08-09T14:11:09.762Z","changelog":"Choco 1.0.3 - Updated metadata version to 1.0.3. - Documentation updates and minor clarifications in CHANGELOG.md, SKILL.md, and metadata-fix.md. - Removed deprecated skill-card.md file.","fileCount":11,"zipByteSize":17999},{"version":"1.0.2","createdAt":"2026-08-06T09:21:23.191Z","changelog":"- License file added for open source clarity. - Skill version updated to 1.0.2 in metadata. - Documentation improvements in SKILL.md and CHANGELOG.md. - Outdated skill-card.md removed.","fileCount":11,"zipByteSize":17789},{"version":"1.0.1","createdAt":"2026-06-26T17:03:50.949Z","changelog":"- Updated version to 1.0.1. - Removed LICENSE and skill-card.md files. - Updated CHANGELOG.md and scripts/nssm-manager.js. - No changes to skill description or functionality.","fileCount":10,"zipByteSize":17138}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s17ay1v6v88r2m102pvvc44gz183qcrm:choco","setupComplexity":"low","setupSteps":["Install using `clawhub skill install s17ay1v6v88r2m102pvvc44gz183qcrm:choco` in an isolated environment before connecting it to live workloads.","No published capability contract is available yet, so validate auth and request/response behavior manually.","Review the upstream CLAWHUB listing at https://clawhub.ai/drumrobot/choco before using production credentials."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-drumrobot-choco/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-drumrobot-choco/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-drumrobot-choco/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-drumrobot-choco/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-drumrobot-choco/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-drumrobot-choco/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-11T20:56:10.243Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-drumrobot-choco/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-drumrobot-choco/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-drumrobot-choco/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-drumrobot-choco/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-11T16:57:01.111Z","emptyReason":null},"readme":"Skill: choco\n\nOwner: drumrobot\n\nSummary: Chocolatey operations integration — post-processing after choco upgrade, nssm service path refresh, NSSM → shawl migration (syncthing v2 etc.), resync on UniGetUI/choco metadata update failures. diagnose [diagnose.md], metadata-fix [metadata-fix.md], post-upgrade [post-upgrade.md], shawl-migration [shawl-migration.md], update-path [update-path.md]. Use when: \"choco\", \"chocolatey\", \"choco upgrade\", \"choco outdated\", \"vcredist\", \"nssm\", \"nssm recovery\", \"nssm path\", \"service path refresh\", \"after choco upgrade\", \"service failure\", \"SERVICE_STOPPED\", \"shim issue\", \"syncthing nssm\", \"syncthing v2\", \"shawl migration\", \"nssm deprecation\", \"service-specific error\", \"UniGetUI\", \"metadata update failure\", \"metadata stale\", \".nuspec stale\", \"choco metadata\".\n\nTags: latest:1.0.5\n\nVersion history:\n\nv1.0.5 | 2026-09-18T15:52:57.014Z | auto\n\nChoco 1.0.5\n\n- Updated version to 1.0.5 in metadata.\n- Removed the file: skill-card.md.\n- No user-facing functional changes documented; minor project structure and version metadata update.\n\nv1.0.4 | 2026-08-18T05:41:14.776Z | auto\n\n- Updated version to 1.0.4.\n- Removed the file: skill-card.md.\n- Minor documentation edits and metadata bump in SKILL.md and CHANGELOG.md.\n- No changes to core functionality.\n\nv1.0.3 | 2026-08-09T14:11:09.762Z | auto\n\nChoco 1.0.3\n\n- Updated metadata version to 1.0.3.\n- Documentation updates and minor clarifications in CHANGELOG.md, SKILL.md, and metadata-fix.md.\n- Removed deprecated skill-card.md file.\n\nv1.0.2 | 2026-08-06T09:21:23.191Z | auto\n\n- License file added for open source clarity.\n- Skill version updated to 1.0.2 in metadata.\n- Documentation improvements in SKILL.md and CHANGELOG.md.\n- Outdated skill-card.md removed.\n\nv1.0.1 | 2026-06-26T17:03:50.949Z | auto\n\n- Updated version to 1.0.1.\n- Removed LICENSE and skill-card.md files.\n- Updated CHANGELOG.md and scripts/nssm-manager.js.\n- No changes to skill description or functionality.\n\nArchive index:\n\nArchive v1.0.5: 11 files, 18078 bytes\n\nFiles: CHANGELOG.md (2986b), diagnose.md (1257b), LICENSE (1063b), metadata-fix.md (4746b), post-upgrade.md (1240b), scripts/nssm-manager.js (7503b), shawl-migration.md (11270b), skill-card.md (2520b), SKILL.md (6022b), update-path.md (2382b), _meta.json (124b)\n\nFile v1.0.5:SKILL.md\n\n---\nname: choco\nmetadata:\n  author: es6kr\n  version: \"1.0.5\" # x-release-please-version\ndescription: |\n  Chocolatey operations integration — post-processing after choco upgrade, nssm service path refresh, NSSM → shawl migration (syncthing v2 etc.), resync on UniGetUI/choco metadata update failures. diagnose [diagnose.md], metadata-fix [metadata-fix.md], post-upgrade [post-upgrade.md], shawl-migration [shawl-migration.md], update-path [update-path.md].\n  Use when: \"choco\", \"chocolatey\", \"choco upgrade\", \"choco outdated\", \"vcredist\", \"nssm\", \"nssm recovery\", \"nssm path\", \"service path refresh\", \"after choco upgrade\", \"service failure\", \"SERVICE_STOPPED\", \"shim issue\", \"syncthing nssm\", \"syncthing v2\", \"shawl migration\", \"nssm deprecation\", \"service-specific error\", \"UniGetUI\", \"metadata update failure\", \"metadata stale\", \".nuspec stale\", \"choco metadata\".\n---\n\n# Choco\n\nChocolatey operations integration skill. Pre- and post-processing for choco upgrade, nssm service compatibility management, and metadata update failure recovery.\n\n## Core Problems\n\n| Area | Problem | Resolution Topic |\n|------|---------|------------------|\n| Package path | After choco upgrade, the nssm Application path becomes stale due to version-specific folders | [update-path.md](./update-path.md) |\n| Service compatibility | After major upgrade (e.g., syncthing v1→v2), NSSM fails with service-specific error | [shawl-migration.md](./shawl-migration.md) |\n| Metadata | Runtime install succeeds + chocolatey `.nuspec` is stale (UniGetUI shows repeated upgrades) | [metadata-fix.md](./metadata-fix.md) |\n| Diagnosis | Identify which service has issues / which package is stale | [diagnose.md](./diagnose.md) |\n| Bulk post-processing | Automatically check affected services after choco upgrade | [post-upgrade.md](./post-upgrade.md) |\n\n## Path Strategy (HARD STOP — required decision before nssm set Application)\n\n| Strategy | Example Path | Pros | Cons |\n|----------|--------------|------|------|\n| **Stable shim path (recommended)** | `%ChocolateyInstall%\\bin\\syncthing.exe` | Path remains unchanged after choco upgrade | Without `--shimgen-waitforexit`, nssm may misinterpret shim exit as a crash |\n| Version-specific actual path | `%ChocolateyInstall%\\lib\\syncthing\\tools\\...-v2.1.0\\syncthing.exe` | No shim issues | **Path breaks on every upgrade** — this is why this skill exists |\n\n**Default choice: stable shim path.** Use version-specific path + post-upgrade hook combination only for services where shim issues occur. When NSSM compatibility itself breaks (like syncthing v2), apply [shawl-migration](./shawl-migration.md).\n\n### Using environment variable paths in nssm\n\nnssm supports `REG_EXPAND_SZ` but `nssm set` defaults to `REG_SZ`. Set registry directly via PowerShell:\n\n```powershell\n$regPath = \"HKLM:\\SYSTEM\\CurrentControlSet\\Services\\<service>\\Parameters\"\nSet-ItemProperty -Path $regPath -Name \"Application\" -Value '%ChocolateyInstall%\\bin\\<exe>' -Type ExpandString\n```\n\nOr use an expanded literal path:\n\n```bash\ngsudo nssm set <service> Application \"C:\\ProgramData\\chocolatey\\bin\\<exe>\"\n```\n\n## Topics\n\n| Topic | File | Description |\n|-------|------|-------------|\n| diagnose | [diagnose.md](./diagnose.md) | nssm service diagnosis procedure |\n| metadata-fix | [metadata-fix.md](./metadata-fix.md) | Recovery for UniGetUI/choco metadata (.nuspec) update failures |\n| post-upgrade | [post-upgrade.md](./post-upgrade.md) | Post-processing after choco upgrade |\n| shawl-migration | [shawl-migration.md](./shawl-migration.md) | NSSM → shawl migration (major upgrades like syncthing v2) |\n| update-path | [update-path.md](./update-path.md) | nssm path refresh |\n\n## Scripts\n\n| Mode | Command | Description |\n|------|---------|-------------|\n| diagnose | `node <skill-dir>/scripts/nssm-manager.js diagnose` | Check all nssm services |\n| update-path | `node <skill-dir>/scripts/nssm-manager.js update-path <service>` | Output path refresh command for a specific service |\n| post-upgrade | `node <skill-dir>/scripts/nssm-manager.js post-upgrade` | Full post-processing check |\n\n`<skill-dir>` = `~/.claude/skills/choco`\n\n**Note**: `node` may not be on PATH in bash. In an fnm environment, use the full path:\n\n```bash\n\"$APPDATA/fnm/node-versions/v20.20.0/installation/node.exe\" <skill-dir>/scripts/nssm-manager.js <mode>\n```\n\n## Administrator Privileges\n\n`nssm set/stop/start` and `choco upgrade` commands require administrator privileges. Per the Windows rule, **using `gsudo` is the default**:\n\n```bash\ngsudo choco upgrade <pkg> -y\ngsudo nssm set <service> Application \"<path>\"\n```\n\nOr invoke via the PowerShell tool:\n\n```powershell\ngsudo powershell -ExecutionPolicy Bypass -File \"<script.ps1>\"\n```\n\n## Topic Dependencies\n\n```text\nchoco (main workflow)\n  ├─→ diagnose (step 1 diagnosis)\n  ├─→ metadata-fix (recover stale choco/UniGetUI metadata)\n  ├─→ post-upgrade (bulk check after choco upgrade)\n  ├─→ update-path (nssm path refresh)\n  └─→ shawl-migration (NSSM → shawl migration)\n        └─→ shawl binary (~/.local/bin/shawl.exe, downloaded from GitHub releases)\n```\n\n- Simple path refresh → `update-path`\n- Major upgrade requiring nssm deprecation → `shawl-migration`\n- Runtime OK + only chocolatey metadata stale → `metadata-fix`\n- Multiple services in bulk → `diagnose` + `post-upgrade`\n\n## Self-heal\n\nThis skill is subject to self-improvement after execution.\nIf malfunction is detected, improve it via `/skill-kit upgrade choco`.\n\nChecklist:\n1. Are the trigger keywords in description sufficient?\n2. Was the topic selection accurate? (e.g., misrouting metadata stale to update-path)\n3. Was the procedure complete? (Was no manual correction needed?)\n4. Were there no omissions in the deliverables?\n\n## References\n\n- Previous skill: `choco-nssm` (absorbed into this skill, moved to `~/.claude/.bak/`)\n- [Chocolatey docs](https://docs.chocolatey.org/)\n- [UniGetUI repo](https://github.com/Devolutions/UniGetUI)\n- [shawl repo](https://github.com/mtkennerly/shawl)\n\nFile v1.0.5:_meta.json\n\n{\n  \"ownerId\": \"kn74k8yfvftx6f062qa8fzyd8h8373jd\",\n  \"slug\": \"choco\",\n  \"version\": \"1.0.5\",\n  \"publishedAt\": 1789746777014\n}\n\nFile v1.0.5:CHANGELOG.md\n\n# Changelog\n\n## [1.0.5](https://github.com/es6kr/skills/compare/choco-v1.0.4...choco-v1.0.5) (2026-09-18)\n\n\n### Bug Fixes\n\n* **cleanup:** make the session-end report table self-sufficient ([#487](https://github.com/es6kr/skills/issues/487)) ([c4a0255](https://github.com/es6kr/skills/commit/c4a02557fb8de3b32cf337c549f62535dabf824b))\n\n## [1.0.4](https://github.com/es6kr/skills/compare/choco-v1.0.3...choco-v1.0.4) (2026-08-17)\n\n\n### Bug Fixes\n\n* **wip:** cross-ref PR-URL and TaskCreate subject repo-qualifier rules ([#186](https://github.com/es6kr/skills/issues/186)) ([4982364](https://github.com/es6kr/skills/commit/49823641a7b08123ebd0325273892bee41bc3280))\n\n## [1.0.3](https://github.com/es6kr/skills/compare/choco-v1.0.2...choco-v1.0.3) (2026-08-09)\n\n\n### Bug Fixes\n\n* declare undeclared skill-to-skill dependencies (7 skills) ([#271](https://github.com/es6kr/skills/issues/271)) ([36a9f9d](https://github.com/es6kr/skills/commit/36a9f9d7c1fac9bb1c4c96b325a067ab92ad0da7))\n* promote accumulated next-fix fixes to main ([95656e9](https://github.com/es6kr/skills/commit/95656e9b551ee0bb77904a0a571d49c53bc01cc9))\n\n## [1.0.2](https://github.com/es6kr/skills/compare/choco-v1.0.1...choco-v1.0.2) (2026-08-05)\n\n\n### Bug Fixes\n\n* **wip:** cross-ref PR-URL and TaskCreate subject repo-qualifier rules ([#186](https://github.com/es6kr/skills/issues/186)) ([951c1e6](https://github.com/es6kr/skills/commit/951c1e6871e78e226757c6a7ae5ae53efeb7bfb0))\n\n## [1.0.1](https://github.com/es6kr/skills/compare/choco-v1.0.0...choco-v1.0.1) (2026-06-27)\n\n\n### Features\n\n* decompose workflow/git rules + rename web-ui-test→web-browser ([#50](https://github.com/es6kr/skills/issues/50)) ([e10d48f](https://github.com/es6kr/skills/commit/e10d48fea4e507b95888de44812b53484d32128d))\n\n\n### Bug Fixes\n\n* **fix:** split Step 2 medium by content type — case history to failed-attempts.md ([#62](https://github.com/es6kr/skills/issues/62)) ([747b3f9](https://github.com/es6kr/skills/commit/747b3f957ca0fefdbc5044eb08f66b8aafc1e26a))\n* **skills:** apply PR [#50](https://github.com/es6kr/skills/issues/50) Phase 2 follow-up reviews ([33863d7](https://github.com/es6kr/skills/commit/33863d705f8b24051b030b839487e8b5a8bfd9df))\n\n## [0.1.1](https://github.com/es6kr/skills/compare/choco-v0.1.0...choco-v0.1.1) (2026-06-25)\n\n\n### Bug Fixes\n\n* **fix:** split Step 2 medium by content type — case history to failed-attempts.md ([#62](https://github.com/es6kr/skills/issues/62)) ([747b3f9](https://github.com/es6kr/skills/commit/747b3f957ca0fefdbc5044eb08f66b8aafc1e26a))\n* **skills:** apply PR [#50](https://github.com/es6kr/skills/issues/50) Phase 2 follow-up reviews ([33863d7](https://github.com/es6kr/skills/commit/33863d705f8b24051b030b839487e8b5a8bfd9df))\n\n## 0.1.0 (2026-06-12)\n\n\n### Features\n\n* decompose workflow/git rules + rename web-ui-test→web-browser ([#50](https://github.com/es6kr/skills/issues/50)) ([e10d48f](https://github.com/es6kr/skills/commit/e10d48fea4e507b95888de44812b53484d32128d))\n\nFile v1.0.5:diagnose.md\n\n# nssm Service Diagnosis\n\n## When to Use\n\n- nssm service is in `SERVICE_PAUSED` or `SERVICE_STOPPED` state\n- Service behavior anomalies after choco upgrade\n- When a specific service won't start\n\n## Diagnosis Procedure\n\n### 1. Run the Script\n\n```bash\nnode scripts/nssm-manager.js diagnose\n```\n\nOutput content:\n- List of all nssm services\n- Status of each service (RUNNING/STOPPED/PAUSED)\n- Shim status (chocolatey\\bin path = shim)\n- Actual binary location (inside choco lib)\n- List of commands required for fixes\n\n### 2. Manual Diagnosis (if script fails)\n\n```bash\n# Service status\nnssm status <service>\n\n# Registered path\nnssm get <service> Application\n\n# Actual binary location\nls \"C:/ProgramData/chocolatey/lib/<package>/tools/\"\n```\n\n### 3. Shim Identification Criteria\n\n| Path | Type | Service Behavior |\n|------|------|------------------|\n| `chocolatey\\bin\\*.exe` | shim (wrapper) | High failure likelihood |\n| `chocolatey\\lib\\*\\tools\\*\\*.exe` | actual binary | Normal |\n| Other paths | direct install | Normal |\n\n## Output Interpretation\n\n- `Shim: YES` → Path refresh required via update-path topic\n- `Shim: NO` → Investigate other causes (check logs, port conflicts, etc.)\n- `Actual binary: not found` → Package was removed or structure changed\n\nFile v1.0.5:metadata-fix.md\n\n# Chocolatey Metadata Update Failure Fix\n\nDiagnosis and recovery procedure for cases where **the runtime/installer succeeds but the chocolatey metadata (`.nuspec`) update fails** after invoking UniGetUI or choco upgrade.\n\n## Background\n\nStarting from UniGetUI 2026.1.7, the chocolatey bundle was removed and it became a passthrough to the system `choco`. Since UniGetUI only displays the results of `choco list`, metadata update failure is the **responsibility of chocolatey**.\n\nRelated issues:\n- [Devolutions/UniGetUI#4803](https://github.com/Devolutions/UniGetUI/issues/4803) — Inconsistent chocolatey packages since 2026.1.7\n- [Devolutions/UniGetUI#4801](https://github.com/Devolutions/UniGetUI/issues/4801) — Wrong information about installed programs (2026.1.10)\n- [Devolutions/UniGetUI#3708](https://github.com/Devolutions/UniGetUI/issues/3708) — choco.exe hang on update check\n- [Devolutions/UniGetUI#4217](https://github.com/Devolutions/UniGetUI/issues/4217) — Chocolatey shown as ready on MS Store install\n\n## Symptoms\n\n| Symptom | Meaning |\n|---------|---------|\n| \"Upgrade available\" indication persists in UniGetUI | `choco list` returns old version |\n| `choco list <pkg>` shows old version, actual EXE is new version | Only `.nuspec` is stale |\n| Same package keeps appearing in `choco outdated` | Metadata stage exits abnormally |\n| choco exits abnormally after \"already installed\" in installer log | Package stage may be skipped |\n\n## Diagnosis Procedure\n\n### 1. Compare Metadata vs Actual Version\n\n```bash\n# Version recognized by chocolatey\nchoco list <pkg>\n\n# Metadata version in .nuspec\ngrep -i version \"C:\\ProgramData\\chocolatey\\lib\\<pkg>\\<pkg>.nuspec\" | head -1\n\n# Actual installed runtime version (e.g., vcredist140)\nreg query \"HKLM\\SOFTWARE\\Microsoft\\VisualStudio\\14.0\\VC\\Runtimes\\x64\" /v Version 2>&1 | grep Version\n```\n\nIf the three values diverge, metadata stale is confirmed.\n\n### 2. Verify with choco outdated\n\n```bash\nchoco outdated 2>&1 | grep -E \"^[a-zA-Z0-9_-]+\\|\"\n```\n\nOutput line: `<pkg>|<current metadata>|<remote latest>|<pinned>`. Suspect if metadata differs from external systems (WMI/registry).\n\n## Recovery Procedure\n\n### 1. Force Resync (default)\n\n```bash\n# Invoke via PowerShell tool (bypass Bash escape)\ngsudo choco upgrade <pkg> -y\n```\n\nAfter success, verify version match with `choco list <pkg>`.\n\n### 2. Use --force (when 1 has no effect)\n\n```bash\ngsudo choco upgrade <pkg> -y --force\n```\n\n`--force` re-runs the package stage even if already at the latest version to update `.nuspec`.\n\n### 3. Bulk Update\n\n```bash\ngsudo choco upgrade all -y\n```\n\nCleans up large amounts of outdated entries. Effective when UniGetUI has accumulated stale indicators.\n\n### 4. Manual nuspec Patch (last resort)\n\nIf choco refuses to update for any reason, directly modify the `<version>` node in `.nuspec`. **Not recommended** — risk of being overwritten by the next upgrade or causing dependency mismatch.\n\n## Don't / Do Table\n\n| # | Don't | Do |\n|---|-------|-----|\n| 1 | Repeatedly upgrade the same package in UniGetUI GUI | Run `gsudo choco upgrade <pkg> -y` directly in an elevated terminal |\n| 2 | Directly edit `.nuspec` when suspecting metadata stale | Use `--force` so chocolatey performs a proper update |\n| 3 | File an issue in the UniGetUI repository | UniGetUI is a passthrough — report to chocolatey-core (chocolatey/choco) or the package maintainer |\n| 4 | Invoke `choco upgrade` from Bash (without elevation) | PowerShell tool + `gsudo` or administrator PowerShell |\n| 5 | Conclude success from the `choco upgrade` output line alone | Immediately cross-verify with `choco list <pkg>` + `.nuspec` version |\n\n## Self-check (every time a UniGetUI/choco metadata stale report is received)\n\n1. Compare three values: `choco list <pkg>` + `.nuspec` version + actual runtime version\n2. All three match → possible UniGetUI cache issue. Restart UniGetUI or refresh the package\n3. Only choco metadata and .nuspec are stale → `gsudo choco upgrade <pkg> -y`\n4. If step 1 has no effect → `gsudo choco upgrade <pkg> -y --force`\n5. If step 4 also fails → report an issue to the package maintainer (chocolatey.org package page)\n\n## Violation / Application Cases\n\n**2026-05-21 (1st occurrence)**: vcredist140 14.51.36231 → 14.51.36247 metadata update failure. UniGetUI repeatedly attempted updates but the system runtime was already 14.51.36247. `gsudo choco upgrade vcredist140 -y` completed the .nuspec update at once. The log shows `Runtime for architecture x64 version 14.51.36247 is already installed` — a case where only the package stage needed updating.\n\n## References\n\n- [UniGetUI repo](https://github.com/Devolutions/UniGetUI)\n- [chocolatey/choco repo](https://github.com/chocolatey/choco)\n\nFile v1.0.5:post-upgrade.md\n\n# choco upgrade Post-Processing\n\n## When to Use\n\n- After running `choco upgrade all`\n- After upgrading specific packages, to check services\n\n## Procedure\n\n### 1. Run Full Check\n\n```bash\nnode scripts/nssm-manager.js post-upgrade\n```\n\nOutput:\n- One-line summary of shim status for all nssm services\n- List of services requiring updates\n- Administrator PowerShell commands (bulk/individual)\n\n### 2. Run Update Commands\n\nExecute the commands output by the script with administrator privileges:\n\n```bash\n# Bulk execution (the \"Administrator PowerShell commands\" section from script output)\npowershell -Command \"Start-Process powershell -ArgumentList '-Command', '<commands>' -Verb RunAs -Wait\"\n```\n\n### 3. Check Service Status\n\n```bash\nnssm status <service>\n```\n\n## Check Targets\n\nThe script automatically finds nssm-managed services in `Win32_Service` and checks them:\n- All services where `BINARY_PATH_NAME` contains `nssm`\n- Verifies whether each service's Application path is a shim\n- If shim, searches choco lib for the actual binary\n\n## Notes\n\n- Administrator privileges required (UAC prompt)\n- If services are already healthy right after upgrade, refresh is unnecessary\n- Binary location may differ per package (within tools/ subfolders)\n\nFile v1.0.5:shawl-migration.md\n\n# nssm → shawl Migration\n\n## Background\n\nNSSM is flagged as malware by some security solutions, so starting from syncthing v2 the official Windows Setup transitioned to **shawl**. During major upgrades (v1→v2), the existing nssm registration causes the following problems:\n\n| Symptom | Cause |\n|---------|-------|\n| `service-specific error 3` (path not found) | LocalSystem/user context difference makes `%LOCALAPPDATA%\\Syncthing` inaccessible |\n| `service-specific error 3547` | nssm service times out during syncthing v2's SQLite migration |\n| Dies immediately on start, no entry in syncthing log | nssm lacks LOAD_USER_PROFILE → cannot find home directory |\n| v2.0.4+ migration re-runs on every restart | issue [#10340](https://github.com/syncthing/syncthing/issues/10340) |\n\n## Applicable Cases\n\n- nssm service start failure after syncthing v1.x → v2.x major upgrade\n- Environments where NSSM is blocked as malware\n- Other chocolatey packages with similar service model changes (same compatibility pattern)\n\n## Prerequisites\n\nVerify the shawl binary (`~/.local/bin/shawl.exe`) is available:\n\n```bash\n~/.local/bin/shawl.exe --version\n```\n\nIf not installed → download from GitHub releases and place in `~/.local/bin/`:\n\n```bash\nmkdir -p ~/.local/bin && cd /tmp\ncurl -sL https://github.com/mtkennerly/shawl/releases/latest/download/shawl-v1.9.0-win64.zip -o shawl.zip\nunzip -o shawl.zip\nmv shawl.exe ~/.local/bin/\nrm shawl.zip\n```\n\n(Based on v1.9.0. Query latest version via `https://api.github.com/repos/mtkennerly/shawl/releases/latest`)\n\n## Migration Procedure\n\n### 1. Diagnosis — Extract All Existing Service Settings (HARD STOP)\n\nBefore migration, extract all settings of the existing service to **preserve them as-is during shawl re-registration**. Applies the `common.md` \"user-specified value change prohibition\" rule.\n\n```bash\nsc query <service>             # Check SERVICE_STOPPED + error code\nnssm get <service> Application # Current path\nnssm get <service> AppParameters\nnssm get <service> ObjectName  # ⚠️ Execution account — preservation target\nnssm get <service> AppDirectory\nnssm get <service> AppStdout   # Preserve log path\nnssm get <service> AppStderr\nsc qc <service>                # ObjectName fallback (admin required)\ntasklist | grep <service>      # Lingering processes\nnetstat -ano | grep \":<port>\"  # Port occupation\n```\n\n**Record extracted values (required)**: Preserve each value as a variable for use in the next step. Especially if `ObjectName` is not `LocalSystem`, specify the user account explicitly. Even if it is `LocalSystem`, services synchronizing user data like syncthing are recommended to use a user account (see \"3. Determining Execution Account\" below).\n\nRun directly in the console to verify the syncthing binary itself is healthy:\n\n```bash\n\"<app-path>\" --no-console --no-browser\n```\n\nConsole runs fine + service fails → this topic applies.\n\n### 2. Migration Script (PowerShell, Administrator)\n\n```powershell\n$ErrorActionPreference = \"Continue\"\n\n$serviceName = \"syncthing\"\n$shawlExe = \"$env:USERPROFILE\\.local\\bin\\shawl.exe\"\n$appExe = \"C:\\ProgramData\\chocolatey\\bin\\syncthing.exe\"\n$homePath = \"$env:USERPROFILE\\AppData\\Local\\Syncthing\"\n\n# ⚠️ Values extracted in diagnosis step — must be filled in by the user\n$objectName = \".\\<USERNAME>\"        # Same as the existing nssm ObjectName. If LocalSystem, replace with a user account for user-data services like syncthing\n$objectPassword = \"<USER_PASSWORD>\" # User's Windows password (don't hardcode plaintext in scripts — use SecureString or prompt for input)\n\n# 1. Stop and remove existing nssm service\nsc.exe stop $serviceName\nStart-Sleep -Seconds 2\nnssm.exe remove $serviceName confirm\n\n# 2. Re-register with shawl (specify --home: access user config)\n& $shawlExe add --name $serviceName -- $appExe --no-browser --home=$homePath\n\n# 3. Configure ObjectName + LOAD_USER_PROFILE (preserve user account)\nif ($objectName -ne \"LocalSystem\") {\n    sc.exe config $serviceName obj= \"$objectName\" password= \"$objectPassword\"\n    sc.exe privs $serviceName SeBackupPrivilege/SeRestorePrivilege/SeAssignPrimaryTokenPrivilege  # if needed\n}\n\n# 4. Start\nsc.exe start $serviceName\nStart-Sleep -Seconds 8\n\n# 5. Verify (validate StartName preservation)\nsc.exe query $serviceName\nGet-CimInstance Win32_Service -Filter \"Name='$serviceName'\" | Format-List Name,State,StartName,PathName\nnetstat -an | Select-String \"8384\"\n```\n\nSave the script to `C:\\Users\\<user>\\migrate-<service>-to-shawl.ps1`, then:\n\n```bash\n# Bash tool breaks -File argument due to backslash escape issues → use PowerShell tool directly\n# In PowerShell tool:\ngsudo powershell -ExecutionPolicy Bypass -File \"C:\\Users\\<user>\\migrate-<service>-to-shawl.ps1\"\n```\n\n### 3. Determining Execution Account (HARD STOP — preserving existing ObjectName is the top priority)\n\n**Default principle**: Preserve the `ObjectName` extracted in the diagnosis step as-is. Changes only on explicit user instruction.\n\n| Service Type | Recommended Account | Reason |\n|--------------|---------------------|--------|\n| **User data sync/consume** (Syncthing, Dropbox, Resilio Sync, OneDrive, etc.) | `.\\<USERNAME>` | The owner/permission of synced files is the user. Running as LocalSystem risks owner mismatch, permission denied, and file hash changes |\n| **System daemon** (DB, web server, monitoring agent, etc.) | `LocalSystem` or `NT SERVICE\\<name>` | Independent of user context. No password management needed |\n| **GUI-dependent tools** | User account + `Interactive` (not recommended) | Requires user logon session — prefer daemon mode if possible |\n\n#### Don't / Do\n\n| # | Don't | Do |\n|---|-------|-----|\n| 1 | Leave shawl re-registration at LocalSystem (default) when existing nssm `ObjectName=.\\USERNAME` | Specify the extracted value (`.\\USERNAME`) explicitly via `sc.exe config obj=` |\n| 2 | Assume \"LocalSystem + `--home` specification\" can serve as a workaround | `--home` only resolves config path — ownership/ACL problems of synced files are separate. User account execution is the proper fix |\n| 3 | Hardcode plaintext password in script | Use `Read-Host -AsSecureString` or Group Managed Service Account (gMSA). If you must hardcode plaintext, apply `chmod 600` or `.gitignore` + remove immediately |\n| 4 | Fail to update credentials when user password changes → service fails to start | Immediately update via `sc.exe config <svc> password= <new_pw>`. Be aware of Windows password rotation policy |\n\n#### Verification After User Account Registration\n\n```powershell\nGet-CimInstance Win32_Service -Filter \"Name='syncthing'\" | Select-Object Name,State,StartName\n# StartName should display as .\\<USERNAME>. If LocalSystem, registration failed\n```\n\nAfter the service runs, verify in the syncthing GUI (`http://localhost:8384`) that sync folders scan correctly + new files created have the user account as owner.\n\n## Don't / Do Table\n\n| # | Don't | Do |\n|---|-------|-----|\n| 1 | Keep using nssm after v1→v2 major upgrade | Migrate to shawl (especially syncthing v2+) |\n| 2 | LocalSystem account + omit `--home` | Specify `--home=\"C:\\Users\\<u>\\AppData\\Local\\Syncthing\"` |\n| 2b | Skip extracting existing ObjectName before migration | Mandatory `nssm get <svc> ObjectName` in diagnosis step + use that value for shawl re-registration |\n| 2c | Register user data sync services as LocalSystem | Specify the `.\\USERNAME` user account. Preserve owner/permission |\n| 3 | Attempt to install shawl via scoop/choco | No scoop manifest, no choco package. Download directly from GitHub releases |\n| 4 | Call `gsudo powershell -File C:\\...` directly from Bash | Bash escape breaks backslashes. Use PowerShell tool or `/c/Users/...` path |\n| 5 | Forget to escape arguments in shawl add | Pass execution command as-is after the `--` separator. shawl preserves raw args |\n\n## Applying to Other Packages\n\nThe same pattern (major upgrade + service model change) can occur in other chocolatey packages and use the same procedure:\n\n- syncthing (case above, v1→v2)\n- Other packages that changed service models (add to this section when cases are found)\n\n## Follow-up Case — choco upgrade also Removes shawl Service (HARD STOP)\n\n**Phenomenon**: With syncthing service registered via shawl, running `choco upgrade syncthing` → after the new version installs, the service disappears. `sc query syncthing` returns `service does not exist`.\n\n**Cause**: The chocolatey syncthing package's `chocolateyBeforeModify.ps1` assumes nssm when a Windows service named \"syncthing\" exists, and calls stop/remove. Removal happens by name match, regardless of the registration tool (nssm vs shawl).\n\n**Mitigation — always check service existence after choco upgrade**:\n\n```bash\nsc query syncthing 2>&1 | grep -E \"SERVICE_NAME|STATE\"\n# Empty result → re-registration needed\n```\n\nOne-time re-registration script (skip only the nssm remove step in shawl-migration.md \"2. Migration Script\"):\n\n```powershell\n$shawlExe = \"$env:USERPROFILE\\.local\\bin\\shawl.exe\"\n$appExe = \"C:\\ProgramData\\chocolatey\\bin\\syncthing.exe\"\n$homePath = \"$env:USERPROFILE\\AppData\\Local\\Syncthing\"\n\n& $shawlExe add --name syncthing -- $appExe --no-browser --home=$homePath\nsc.exe start syncthing\n```\n\n**Root solution (TODO)**: When registering with shawl, rename the service (e.g., `syncthing-shawl`) to avoid conflict with chocolateyBeforeModify's nssm assumption. However, GUI environment variables and existing automation may depend on the `syncthing` name, so compatibility review is required.\n\n## Violation Cases\n\n**2026-05-21 (1st occurrence)**: On a Windows machine, syncthing 2.1.0 nssm service immediately failed with service-specific error 3. Console syncthing.exe started normally (PID 28208, 8384 LISTENING). Initially suspected nssm shim path / user password, but the actual cause was v1→v2 major compatibility. Resolved via shawl migration:\n- nssm remove syncthing confirm\n- shawl add --name syncthing -- syncthing.exe --no-browser --home=...AppData\\Local\\Syncthing\n- Service RUNNING + 8384 LISTENING recovery complete.\n\n**2026-05-21 (2nd occurrence)**: Immediately after the 1st migration in the same session, `choco upgrade` or auto-upgrade transitioned syncthing 2.1.0 → 2.1.1. The shawl service was automatically removed by chocolateyBeforeModify. `sc query` showed service does not exist. Recovered via re-registration. → Created the \"Follow-up Case\" section in this topic.\n\n**2026-05-21 (3rd occurrence)**: During 1st/2nd shawl re-registration, the existing nssm `ObjectName=.\\<USERNAME>` was not extracted/preserved and was registered with the default LocalSystem. Risk of owner/permission mismatch for services like syncthing that sync user data. User pointed out \"registered with the wrong user\". Reinforced by adding ObjectName extraction in the diagnosis step + `sc.exe config obj=` step in the migration script + restructuring the execution account decision table.\n\n## References\n\n- [Syncthing v2.0 release notes](https://github.com/syncthing/syncthing/releases/tag/v2.0.0)\n- [Syncthing v2 forum migration thread](https://forum.syncthing.net/t/syncthing-2-0-august-2025/24758)\n- [shawl GitHub](https://github.com/mtkennerly/shawl)\n- [issue #10340 — re-migrate every start](https://github.com/syncthing/syncthing/issues/10340)\n\nFile v1.0.5:skill-card.md\n\n## Description:\n\nHelps agents diagnose and recover Chocolatey upgrade issues involving NSSM service paths, NSSM-to-shawl migrations, and stale Chocolatey metadata.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[drumrobot](https://clawhub.ai/user/drumrobot)\n\n### License/Terms of Use:\n\nMIT\n\n## Use Case:\n\nDevelopers and Windows administrators use this skill to plan and review Chocolatey package maintenance, NSSM service path refreshes, service migration to shawl, and metadata resynchronization after upgrades.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill may recommend broad administrator-level Chocolatey package or Windows service changes.\n\nMitigation: Review each package and service name before execution, prefer targeted commands, and avoid choco upgrade all -y unless broad system changes are intended.\n\nRisk: Service path refreshes or NSSM-to-shawl migrations can stop, remove, or misconfigure Windows services.\n\nMitigation: Record existing service configuration before changes and verify service account, path, status, and application behavior after each change.\n\nRisk: The shawl migration workflow may involve downloading an executable and handling Windows service credentials.\n\nMitigation: Verify any downloaded shawl binary and avoid saving plaintext Windows passwords in scripts or logs.\n\n## Reference(s):\n\n- [Chocolatey documentation](https://docs.chocolatey.org/)\n- [UniGetUI repository](https://github.com/Devolutions/UniGetUI)\n- [chocolatey/choco repository](https://github.com/chocolatey/choco)\n- [shawl repository](https://github.com/mtkennerly/shawl)\n- [Syncthing v2.0 release notes](https://github.com/syncthing/syncthing/releases/tag/v2.0.0)\n- [Syncthing issue 10340](https://github.com/syncthing/syncthing/issues/10340)\n\n## Skill Output:\n\n**Output Type(s):** [Text, Markdown, Code, Shell commands, Configuration, Guidance]\n\n**Output Format:** [Markdown guidance with inline Bash, PowerShell, and JSON snippets]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [May include administrator-level commands for Windows package and service maintenance]\n\n## Skill Version(s):\n\n1.0.5 (source: frontmatter, changelog, server release metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nFile v1.0.5:update-path.md\n\n# nssm Path Refresh\n\n## When to Use\n\n- When refreshing the path of a specific service detected as a shim by diagnose\n- When the existing binary path no longer exists after choco upgrade because the version folder changed (stale path)\n\n## Procedure\n\n### 1. Check Refresh Command\n\n```bash\nnode scripts/nssm-manager.js update-path <service-name>\n```\n\nJSON output:\n```json\n{\n  \"service\": \"syncthing\",\n  \"current\": \"C:\\\\ProgramData\\\\chocolatey\\\\bin\\\\syncthing.exe\",\n  \"actual\": \"C:\\\\ProgramData\\\\chocolatey\\\\lib\\\\syncthing\\\\tools\\\\syncthing-windows-amd64-v2.0.15\\\\syncthing.exe\",\n  \"commands\": [\n    \"nssm stop \\\"syncthing\\\"\",\n    \"nssm set \\\"syncthing\\\" Application \\\"...actual path...\\\"\",\n    \"nssm start \\\"syncthing\\\"\"\n  ]\n}\n```\n\n### 2. Run with Administrator Privileges\n\n```bash\npowershell -Command \"Start-Process powershell -ArgumentList '-Command', 'nssm stop \\\"<svc>\\\"; nssm set \\\"<svc>\\\" Application \\\"<actual-path>\\\"; nssm start \\\"<svc>\\\"' -Verb RunAs -Wait\"\n```\n\n### 3. Verify\n\n```bash\nnssm status <service>\nnssm get <service> Application\n```\n\n## Path Selection Strategy\n\n### Stable Shim Path (recommended)\n\n`%ChocolateyInstall%\\bin\\<exe>` — Path remains unchanged after choco upgrade.\n\n```bash\ngsudo nssm set <service> Application \"C:\\ProgramData\\chocolatey\\bin\\<exe>\"\n```\n\nUse the version-specific actual path only when the shim conflicts with the service (immediate process termination → nssm misinterprets as crash).\n\n### Version-Specific Actual Path (only when shim conflicts)\n\n`chocolatey\\lib\\*\\tools\\*` — Stable, but **breaks on every upgrade**. Using this path requires a post-upgrade hook.\n\n## Path Change Pattern During Version Upgrades\n\n```\nv1.27.x: chocolatey\\lib\\syncthing\\tools\\syncthing-windows-amd64-v1.27.x\\syncthing.exe\nv2.0.15: chocolatey\\lib\\syncthing\\tools\\syncthing-windows-amd64-v2.0.15\\syncthing.exe\nv2.0.16: chocolatey\\lib\\syncthing\\tools\\syncthing-windows-amd64-v2.0.16\\syncthing.exe\n```\n\nFolder name changes with each version, requiring refresh every time.\n\n### Real Case: syncthing v2.0.15 → v2.0.16 (2026-04-30)\n\n- After `choco upgrade syncthing`, NSSM pointed to the v2.0.15 path → `SERVICE_STOPPED`\n- Not a shim, but the **previous version's path of the actual binary** — undetectable by `isChocoShim()`\n- Resolved by adding `isStaleChocoPath()`: if a path under `chocolatey\\lib\\` exists but the file does not, it is treated as stale\n\nFile v1.0.5:LICENSE\n\nMIT License\n\nCopyright (c) 2026 es6.kr\n\nPermission is hereby granted, free of charge, to any person obtaining a copy\nof this software and associated documentation files (the \"Software\"), to deal\nin the Software without restriction, including without limitation the rights\nto use, copy, modify, merge, publish, distribute, sublicense, and/or sell\ncopies of the Software, and to permit persons to whom the Software is\nfurnished to do so, subject to the following conditions:\n\nThe above copyright notice and this permission notice shall be included in all\ncopies or substantial portions of the Software.\n\nTHE SOFTWARE IS PROVIDED \"AS IS\", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR\nIMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,\nFITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE\nAUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER\nLIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,\nOUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE\nSOFTWARE.\n\nArchive v1.0.4: 11 files, 18185 bytes\n\nFiles: CHANGELOG.md (2664b), diagnose.md (1257b), LICENSE (1063b), metadata-fix.md (4746b), post-upgrade.md (1240b), scripts/nssm-manager.js (7503b), shawl-migration.md (11270b), skill-card.md (2927b), SKILL.md (6022b), update-path.md (2382b), _meta.json (124b)\n\nFile v1.0.4:SKILL.md\n\n---\nname: choco\nmetadata:\n  author: es6kr\n  version: \"1.0.4\" # x-release-please-version\ndescription: |\n  Chocolatey operations integration — post-processing after choco upgrade, nssm service path refresh, NSSM → shawl migration (syncthing v2 etc.), resync on UniGetUI/choco metadata update failures. diagnose [diagnose.md], metadata-fix [metadata-fix.md], post-upgrade [post-upgrade.md], shawl-migration [shawl-migration.md], update-path [update-path.md].\n  Use when: \"choco\", \"chocolatey\", \"choco upgrade\", \"choco outdated\", \"vcredist\", \"nssm\", \"nssm recovery\", \"nssm path\", \"service path refresh\", \"after choco upgrade\", \"service failure\", \"SERVICE_STOPPED\", \"shim issue\", \"syncthing nssm\", \"syncthing v2\", \"shawl migration\", \"nssm deprecation\", \"service-specific error\", \"UniGetUI\", \"metadata update failure\", \"metadata stale\", \".nuspec stale\", \"choco metadata\".\n---\n\n# Choco\n\nChocolatey operations integration skill. Pre- and post-processing for choco upgrade, nssm service compatibility management, and metadata update failure recovery.\n\n## Core Problems\n\n| Area | Problem | Resolution Topic |\n|------|---------|------------------|\n| Package path | After choco upgrade, the nssm Application path becomes stale due to version-specific folders | [update-path.md](./update-path.md) |\n| Service compatibility | After major upgrade (e.g., syncthing v1→v2), NSSM fails with service-specific error | [shawl-migration.md](./shawl-migration.md) |\n| Metadata | Runtime install succeeds + chocolatey `.nuspec` is stale (UniGetUI shows repeated upgrades) | [metadata-fix.md](./metadata-fix.md) |\n| Diagnosis | Identify which service has issues / which package is stale | [diagnose.md](./diagnose.md) |\n| Bulk post-processing | Automatically check affected services after choco upgrade | [post-upgrade.md](./post-upgrade.md) |\n\n## Path Strategy (HARD STOP — required decision before nssm set Application)\n\n| Strategy | Example Path | Pros | Cons |\n|----------|--------------|------|------|\n| **Stable shim path (recommended)** | `%ChocolateyInstall%\\bin\\syncthing.exe` | Path remains unchanged after choco upgrade | Without `--shimgen-waitforexit`, nssm may misinterpret shim exit as a crash |\n| Version-specific actual path | `%ChocolateyInstall%\\lib\\syncthing\\tools\\...-v2.1.0\\syncthing.exe` | No shim issues | **Path breaks on every upgrade** — this is why this skill exists |\n\n**Default choice: stable shim path.** Use version-specific path + post-upgrade hook combination only for services where shim issues occur. When NSSM compatibility itself breaks (like syncthing v2), apply [shawl-migration](./shawl-migration.md).\n\n### Using environment variable paths in nssm\n\nnssm supports `REG_EXPAND_SZ` but `nssm set` defaults to `REG_SZ`. Set registry directly via PowerShell:\n\n```powershell\n$regPath = \"HKLM:\\SYSTEM\\CurrentControlSet\\Services\\<service>\\Parameters\"\nSet-ItemProperty -Path $regPath -Name \"Application\" -Value '%ChocolateyInstall%\\bin\\<exe>' -Type ExpandString\n```\n\nOr use an expanded literal path:\n\n```bash\ngsudo nssm set <service> Application \"C:\\ProgramData\\chocolatey\\bin\\<exe>\"\n```\n\n## Topics\n\n| Topic | File | Description |\n|-------|------|-------------|\n| diagnose | [diagnose.md](./diagnose.md) | nssm service diagnosis procedure |\n| metadata-fix | [metadata-fix.md](./metadata-fix.md) | Recovery for UniGetUI/choco metadata (.nuspec) update failures |\n| post-upgrade | [post-upgrade.md](./post-upgrade.md) | Post-processing after choco upgrade |\n| shawl-migration | [shawl-migration.md](./shawl-migration.md) | NSSM → shawl migration (major upgrades like syncthing v2) |\n| update-path | [update-path.md](./update-path.md) | nssm path refresh |\n\n## Scripts\n\n| Mode | Command | Description |\n|------|---------|-------------|\n| diagnose | `node <skill-dir>/scripts/nssm-manager.js diagnose` | Check all nssm services |\n| update-path | `node <skill-dir>/scripts/nssm-manager.js update-path <service>` | Output path refresh command for a specific service |\n| post-upgrade | `node <skill-dir>/scripts/nssm-manager.js post-upgrade` | Full post-processing check |\n\n`<skill-dir>` = `~/.claude/skills/choco`\n\n**Note**: `node` may not be on PATH in bash. In an fnm environment, use the full path:\n\n```bash\n\"$APPDATA/fnm/node-versions/v20.20.0/installation/node.exe\" <skill-dir>/scripts/nssm-manager.js <mode>\n```\n\n## Administrator Privileges\n\n`nssm set/stop/start` and `choco upgrade` commands require administrator privileges. Per the Windows rule, **using `gsudo` is the default**:\n\n```bash\ngsudo choco upgrade <pkg> -y\ngsudo nssm set <service> Application \"<path>\"\n```\n\nOr invoke via the PowerShell tool:\n\n```powershell\ngsudo powershell -ExecutionPolicy Bypass -File \"<script.ps1>\"\n```\n\n## Topic Dependencies\n\n```text\nchoco (main workflow)\n  ├─→ diagnose (step 1 diagnosis)\n  ├─→ metadata-fix (recover stale choco/UniGetUI metadata)\n  ├─→ post-upgrade (bulk check after choco upgrade)\n  ├─→ update-path (nssm path refresh)\n  └─→ shawl-migration (NSSM → shawl migration)\n        └─→ shawl binary (~/.local/bin/shawl.exe, downloaded from GitHub releases)\n```\n\n- Simple path refresh → `update-path`\n- Major upgrade requiring nssm deprecation → `shawl-migration`\n- Runtime OK + only chocolatey metadata stale → `metadata-fix`\n- Multiple services in bulk → `diagnose` + `post-upgrade`\n\n## Self-heal\n\nThis skill is subject to self-improvement after execution.\nIf malfunction is detected, improve it via `/skill-kit upgrade choco`.\n\nChecklist:\n1. Are the trigger keywords in description sufficient?\n2. Was the topic selection accurate? (e.g., misrouting metadata stale to update-path)\n3. Was the procedure complete? (Was no manual correction needed?)\n4. Were there no omissions in the deliverables?\n\n## References\n\n- Previous skill: `choco-nssm` (absorbed into this skill, moved to `~/.claude/.bak/`)\n- [Chocolatey docs](https://docs.chocolatey.org/)\n- [UniGetUI repo](https://github.com/Devolutions/UniGetUI)\n- [shawl repo](https://github.com/mtkennerly/shawl)\n\nFile v1.0.4:_meta.json\n\n{\n  \"ownerId\": \"kn74k8yfvftx6f062qa8fzyd8h8373jd\",\n  \"slug\": \"choco\",\n  \"version\": \"1.0.4\",\n  \"publishedAt\": 1787031674776\n}\n\nFile v1.0.4:CHANGELOG.md\n\n# Changelog\n\n## [1.0.4](https://github.com/es6kr/skills/compare/choco-v1.0.3...choco-v1.0.4) (2026-08-17)\n\n\n### Bug Fixes\n\n* **wip:** cross-ref PR-URL and TaskCreate subject repo-qualifier rules ([#186](https://github.com/es6kr/skills/issues/186)) ([4982364](https://github.com/es6kr/skills/commit/49823641a7b08123ebd0325273892bee41bc3280))\n\n## [1.0.3](https://github.com/es6kr/skills/compare/choco-v1.0.2...choco-v1.0.3) (2026-08-09)\n\n\n### Bug Fixes\n\n* declare undeclared skill-to-skill dependencies (7 skills) ([#271](https://github.com/es6kr/skills/issues/271)) ([36a9f9d](https://github.com/es6kr/skills/commit/36a9f9d7c1fac9bb1c4c96b325a067ab92ad0da7))\n* promote accumulated next-fix fixes to main ([95656e9](https://github.com/es6kr/skills/commit/95656e9b551ee0bb77904a0a571d49c53bc01cc9))\n\n## [1.0.2](https://github.com/es6kr/skills/compare/choco-v1.0.1...choco-v1.0.2) (2026-08-05)\n\n\n### Bug Fixes\n\n* **wip:** cross-ref PR-URL and TaskCreate subject repo-qualifier rules ([#186](https://github.com/es6kr/skills/issues/186)) ([951c1e6](https://github.com/es6kr/skills/commit/951c1e6871e78e226757c6a7ae5ae53efeb7bfb0))\n\n## [1.0.1](https://github.com/es6kr/skills/compare/choco-v1.0.0...choco-v1.0.1) (2026-06-27)\n\n\n### Features\n\n* decompose workflow/git rules + rename web-ui-test→web-browser ([#50](https://github.com/es6kr/skills/issues/50)) ([e10d48f](https://github.com/es6kr/skills/commit/e10d48fea4e507b95888de44812b53484d32128d))\n\n\n### Bug Fixes\n\n* **fix:** split Step 2 medium by content type — case history to failed-attempts.md ([#62](https://github.com/es6kr/skills/issues/62)) ([747b3f9](https://github.com/es6kr/skills/commit/747b3f957ca0fefdbc5044eb08f66b8aafc1e26a))\n* **skills:** apply PR [#50](https://github.com/es6kr/skills/issues/50) Phase 2 follow-up reviews ([33863d7](https://github.com/es6kr/skills/commit/33863d705f8b24051b030b839487e8b5a8bfd9df))\n\n## [0.1.1](https://github.com/es6kr/skills/compare/choco-v0.1.0...choco-v0.1.1) (2026-06-25)\n\n\n### Bug Fixes\n\n* **fix:** split Step 2 medium by content type — case history to failed-attempts.md ([#62](https://github.com/es6kr/skills/issues/62)) ([747b3f9](https://github.com/es6kr/skills/commit/747b3f957ca0fefdbc5044eb08f66b8aafc1e26a))\n* **skills:** apply PR [#50](https://github.com/es6kr/skills/issues/50) Phase 2 follow-up reviews ([33863d7](https://github.com/es6kr/skills/commit/33863d705f8b24051b030b839487e8b5a8bfd9df))\n\n## 0.1.0 (2026-06-12)\n\n\n### Features\n\n* decompose workflow/git rules + rename web-ui-test→web-browser ([#50](https://github.com/es6kr/skills/issues/50)) ([e10d48f](https://github.com/es6kr/skills/commit/e10d48fea4e507b95888de44812b53484d32128d))\n\nFile v1.0.4:diagnose.md\n\n# nssm Service Diagnosis\n\n## When to Use\n\n- nssm service is in `SERVICE_PAUSED` or `SERVICE_STOPPED` state\n- Service behavior anomalies after choco upgrade\n- When a specific service won't start\n\n## Diagnosis Procedure\n\n### 1. Run the Script\n\n```bash\nnode scripts/nssm-manager.js diagnose\n```\n\nOutput content:\n- List of all nssm services\n- Status of each service (RUNNING/STOPPED/PAUSED)\n- Shim status (chocolatey\\bin path = shim)\n- Actual binary location (inside choco lib)\n- List of commands required for fixes\n\n### 2. Manual Diagnosis (if script fails)\n\n```bash\n# Service status\nnssm status <service>\n\n# Registered path\nnssm get <service> Application\n\n# Actual binary location\nls \"C:/ProgramData/chocolatey/lib/<package>/tools/\"\n```\n\n### 3. Shim Identification Criteria\n\n| Path | Type | Service Behavior |\n|------|------|------------------|\n| `chocolatey\\bin\\*.exe` | shim (wrapper) | High failure likelihood |\n| `chocolatey\\lib\\*\\tools\\*\\*.exe` | actual binary | Normal |\n| Other paths | direct install | Normal |\n\n## Output Interpretation\n\n- `Shim: YES` → Path refresh required via update-path topic\n- `Shim: NO` → Investigate other causes (check logs, port conflicts, etc.)\n- `Actual binary: not found` → Package was removed or structure changed\n\nFile v1.0.4:metadata-fix.md\n\n# Chocolatey Metadata Update Failure Fix\n\nDiagnosis and recovery procedure for cases where **the runtime/installer succeeds but the chocolatey metadata (`.nuspec`) update fails** after invoking UniGetUI or choco upgrade.\n\n## Background\n\nStarting from UniGetUI 2026.1.7, the chocolatey bundle was removed and it became a passthrough to the system `choco`. Since UniGetUI only displays the results of `choco list`, metadata update failure is the **responsibility of chocolatey**.\n\nRelated issues:\n- [Devolutions/UniGetUI#4803](https://github.com/Devolutions/UniGetUI/issues/4803) — Inconsistent chocolatey packages since 2026.1.7\n- [Devolutions/UniGetUI#4801](https://github.com/Devolutions/UniGetUI/issues/4801) — Wrong information about installed programs (2026.1.10)\n- [Devolutions/UniGetUI#3708](https://github.com/Devolutions/UniGetUI/issues/3708) — choco.exe hang on update check\n- [Devolutions/UniGetUI#4217](https://github.com/Devolutions/UniGetUI/issues/4217) — Chocolatey shown as ready on MS Store install\n\n## Symptoms\n\n| Symptom | Meaning |\n|---------|---------|\n| \"Upgrade available\" indication persists in UniGetUI | `choco list` returns old version |\n| `choco list <pkg>` shows old version, actual EXE is new version | Only `.nuspec` is stale |\n| Same package keeps appearing in `choco outdated` | Metadata stage exits abnormally |\n| choco exits abnormally after \"already installed\" in installer log | Package stage may be skipped |\n\n## Diagnosis Procedure\n\n### 1. Compare Metadata vs Actual Version\n\n```bash\n# Version recognized by chocolatey\nchoco list <pkg>\n\n# Metadata version in .nuspec\ngrep -i version \"C:\\ProgramData\\chocolatey\\lib\\<pkg>\\<pkg>.nuspec\" | head -1\n\n# Actual installed runtime version (e.g., vcredist140)\nreg query \"HKLM\\SOFTWARE\\Microsoft\\VisualStudio\\14.0\\VC\\Runtimes\\x64\" /v Version 2>&1 | grep Version\n```\n\nIf the three values diverge, metadata stale is confirmed.\n\n### 2. Verify with choco outdated\n\n```bash\nchoco outdated 2>&1 | grep -E \"^[a-zA-Z0-9_-]+\\|\"\n```\n\nOutput line: `<pkg>|<current metadata>|<remote latest>|<pinned>`. Suspect if metadata differs from external systems (WMI/registry).\n\n## Recovery Procedure\n\n### 1. Force Resync (default)\n\n```bash\n# Invoke via PowerShell tool (bypass Bash escape)\ngsudo choco upgrade <pkg> -y\n```\n\nAfter success, verify version match with `choco list <pkg>`.\n\n### 2. Use --force (when 1 has no effect)\n\n```bash\ngsudo choco upgrade <pkg> -y --force\n```\n\n`--force` re-runs the package stage even if already at the latest version to update `.nuspec`.\n\n### 3. Bulk Update\n\n```bash\ngsudo choco upgrade all -y\n```\n\nCleans up large amounts of outdated entries. Effective when UniGetUI has accumulated stale indicators.\n\n### 4. Manual nuspec Patch (last resort)\n\nIf choco refuses to update for any reason, directly modify the `<version>` node in `.nuspec`. **Not recommended** — risk of being overwritten by the next upgrade or causing dependency mismatch.\n\n## Don't / Do Table\n\n| # | Don't | Do |\n|---|-------|-----|\n| 1 | Repeatedly upgrade the same package in UniGetUI GUI | Run `gsudo choco upgrade <pkg> -y` directly in an elevated terminal |\n| 2 | Directly edit `.nuspec` when suspecting metadata stale | Use `--force` so chocolatey performs a proper update |\n| 3 | File an issue in the UniGetUI repository | UniGetUI is a passthrough — report to chocolatey-core (chocolatey/choco) or the package maintainer |\n| 4 | Invoke `choco upgrade` from Bash (without elevation) | PowerShell tool + `gsudo` or administrator PowerShell |\n| 5 | Conclude success from the `choco upgrade` output line alone | Immediately cross-verify with `choco list <pkg>` + `.nuspec` version |\n\n## Self-check (every time a UniGetUI/choco metadata stale report is received)\n\n1. Compare three values: `choco list <pkg>` + `.nuspec` version + actual runtime version\n2. All three match → possible UniGetUI cache issue. Restart UniGetUI or refresh the package\n3. Only choco metadata and .nuspec are stale → `gsudo choco upgrade <pkg> -y`\n4. If step 1 has no effect → `gsudo choco upgrade <pkg> -y --force`\n5. If step 4 also fails → report an issue to the package maintainer (chocolatey.org package page)\n\n## Violation / Application Cases\n\n**2026-05-21 (1st occurrence)**: vcredist140 14.51.36231 → 14.51.36247 metadata update failure. UniGetUI repeatedly attempted updates but the system runtime was already 14.51.36247. `gsudo choco upgrade vcredist140 -y` completed the .nuspec update at once. The log shows `Runtime for architecture x64 version 14.51.36247 is already installed` — a case where only the package stage needed updating.\n\n## References\n\n- [UniGetUI repo](https://github.com/Devolutions/UniGetUI)\n- [chocolatey/choco repo](https://github.com/chocolatey/choco)\n\nFile v1.0.4:post-upgrade.md\n\n# choco upgrade Post-Processing\n\n## When to Use\n\n- After running `choco upgrade all`\n- After upgrading specific packages, to check services\n\n## Procedure\n\n### 1. Run Full Check\n\n```bash\nnode scripts/nssm-manager.js post-upgrade\n```\n\nOutput:\n- One-line summary of shim status for all nssm services\n- List of services requiring updates\n- Administrator PowerShell commands (bulk/individual)\n\n### 2. Run Update Commands\n\nExecute the commands output by the script with administrator privileges:\n\n```bash\n# Bulk execution (the \"Administrator PowerShell commands\" section from script output)\npowershell -Command \"Start-Process powershell -ArgumentList '-Command', '<commands>' -Verb RunAs -Wait\"\n```\n\n### 3. Check Service Status\n\n```bash\nnssm status <service>\n```\n\n## Check Targets\n\nThe script automatically finds nssm-managed services in `Win32_Service` and checks them:\n- All services where `BINARY_PATH_NAME` contains `nssm`\n- Verifies whether each service's Application path is a shim\n- If shim, searches choco lib for the actual binary\n\n## Notes\n\n- Administrator privileges required (UAC prompt)\n- If services are already healthy right after upgrade, refresh is unnecessary\n- Binary location may differ per package (within tools/ subfolders)\n\nFile v1.0.4:shawl-migration.md\n\n# nssm → shawl Migration\n\n## Background\n\nNSSM is flagged as malware by some security solutions, so starting from syncthing v2 the official Windows Setup transitioned to **shawl**. During major upgrades (v1→v2), the existing nssm registration causes the following problems:\n\n| Symptom | Cause |\n|---------|-------|\n| `service-specific error 3` (path not found) | LocalSystem/user context difference makes `%LOCALAPPDATA%\\Syncthing` inaccessible |\n| `service-specific error 3547` | nssm service times out during syncthing v2's SQLite migration |\n| Dies immediately on start, no entry in syncthing log | nssm lacks LOAD_USER_PROFILE → cannot find home directory |\n| v2.0.4+ migration re-runs on every restart | issue [#10340](https://github.com/syncthing/syncthing/issues/10340) |\n\n## Applicable Cases\n\n- nssm service start failure after syncthing v1.x → v2.x major upgrade\n- Environments where NSSM is blocked as malware\n- Other chocolatey packages with similar service model changes (same compatibility pattern)\n\n## Prerequisites\n\nVerify the shawl binary (`~/.local/bin/shawl.exe`) is available:\n\n```bash\n~/.local/bin/shawl.exe --version\n```\n\nIf not installed → download from GitHub releases and place in `~/.local/bin/`:\n\n```bash\nmkdir -p ~/.local/bin && cd /tmp\ncurl -sL https://github.com/mtkennerly/shawl/releases/latest/download/shawl-v1.9.0-win64.zip -o shawl.zip\nunzip -o shawl.zip\nmv shawl.exe ~/.local/bin/\nrm shawl.zip\n```\n\n(Based on v1.9.0. Query latest version via `https://api.github.com/repos/mtkennerly/shawl/releases/latest`)\n\n## Migration Procedure\n\n### 1. Diagnosis — Extract All Existing Service Settings (HARD STOP)\n\nBefore migration, extract all settings of the existing service to **preserve them as-is during shawl re-registration**. Applies the `common.md` \"user-specified value change prohibition\" rule.\n\n```bash\nsc query <service>             # Check SERVICE_STOPPED + error code\nnssm get <service> Application # Current path\nnssm get <service> AppParameters\nnssm get <service> ObjectName  # ⚠️ Execution account — preservation target\nnssm get <service> AppDirectory\nnssm get <service> AppStdout   # Preserve log path\nnssm get <service> AppStderr\nsc qc <service>                # ObjectName fallback (admin required)\ntasklist | grep <service>      # Lingering processes\nnetstat -ano | grep \":<port>\"  # Port occupation\n```\n\n**Record extracted values (required)**: Preserve each value as a variable for use in the next step. Especially if `ObjectName` is not `LocalSystem`, specify the user account explicitly. Even if it is `LocalSystem`, services synchronizing user data like syncthing are recommended to use a user account (see \"3. Determining Execution Account\" below).\n\nRun directly in the console to verify the syncthing binary itself is healthy:\n\n```bash\n\"<app-path>\" --no-console --no-browser\n```\n\nConsole runs fine + service fails → this topic applies.\n\n### 2. Migration Script (PowerShell, Administrator)\n\n```powershell\n$ErrorActionPreference = \"Continue\"\n\n$serviceName = \"syncthing\"\n$shawlExe = \"$env:USERPROFILE\\.local\\bin\\shawl.exe\"\n$appExe = \"C:\\ProgramData\\chocolatey\\bin\\syncthing.exe\"\n$homePath = \"$env:USERPROFILE\\AppData\\Local\\Syncthing\"\n\n# ⚠️ Values extracted in diagnosis step — must be filled in by the user\n$objectName = \".\\<USERNAME>\"        # Same as the existing nssm ObjectName. If LocalSystem, replace with a user account for user-data services like syncthing\n$objectPassword = \"<USER_PASSWORD>\" # User's Windows password (don't hardcode plaintext in scripts — use SecureString or prompt for input)\n\n# 1. Stop and remove existing nssm service\nsc.exe stop $serviceName\nStart-Sleep -Seconds 2\nnssm.exe remove $serviceName confirm\n\n# 2. Re-register with shawl (specify --home: access user config)\n& $shawlExe add --name $serviceName -- $appExe --no-browser --home=$homePath\n\n# 3. Configure ObjectName + LOAD_USER_PROFILE (preserve user account)\nif ($objectName -ne \"LocalSystem\") {\n    sc.exe config $serviceName obj= \"$objectName\" password= \"$objectPassword\"\n    sc.exe privs $serviceName SeBackupPrivilege/SeRestorePrivilege/SeAssignPrimaryTokenPrivilege  # if needed\n}\n\n# 4. Start\nsc.exe start $serviceName\nStart-Sleep -Seconds 8\n\n# 5. Verify (validate StartName preservation)\nsc.exe query $serviceName\nGet-CimInstance Win32_Service -Filter \"Name='$serviceName'\" | Format-List Name,State,StartName,PathName\nnetstat -an | Select-String \"8384\"\n```\n\nSave the script to `C:\\Users\\<user>\\migrate-<service>-to-shawl.ps1`, then:\n\n```bash\n# Bash tool breaks -File argument due to backslash escape issues → use PowerShell tool directly\n# In PowerShell tool:\ngsudo powershell -ExecutionPolicy Bypass -File \"C:\\Users\\<user>\\migrate-<service>-to-shawl.ps1\"\n```\n\n### 3. Determining Execution Account (HARD STOP — preserving existing ObjectName is the top priority)\n\n**Default principle**: Preserve the `ObjectName` extracted in the diagnosis step as-is. Changes only on explicit user instruction.\n\n| Service Type | Recommended Account | Reason |\n|--------------|---------------------|--------|\n| **User data sync/consume** (Syncthing, Dropbox, Resilio Sync, OneDrive, etc.) | `.\\<USERNAME>` | The owner/permission of synced files is the user. Running as LocalSystem risks owner mismatch, permission denied, and file hash changes |\n| **System daemon** (DB, web server, monitoring agent, etc.) | `LocalSystem` or `NT SERVICE\\<name>` | Independent of user context. No password management needed |\n| **GUI-dependent tools** | User account + `Interactive` (not recommended) | Requires user logon session — prefer daemon mode if possible |\n\n#### Don't / Do\n\n| # | Don't | Do |\n|---|-------|-----|\n| 1 | Leave shawl re-registration at LocalSystem (default) when existing nssm `ObjectName=.\\USERNAME` | Specify the extracted value (`.\\USERNAME`) explicitly via `sc.exe config obj=` |\n| 2 | Assume \"LocalSystem + `--home` specification\" can serve as a workaround | `--home` only resolves config path — ownership/ACL problems of synced files are separate. User account execution is the proper fix |\n| 3 | Hardcode plaintext password in script | Use `Read-Host -AsSecureString` or Group Managed Service Account (gMSA). If you must hardcode plaintext, apply `chmod 600` or `.gitignore` + remove immediately |\n| 4 | Fail to update credentials when user password changes → service fails to start | Immediately update via `sc.exe config <svc> password= <new_pw>`. Be aware of Windows password rotation policy |\n\n#### Verification After User Account Registration\n\n```powershell\nGet-CimInstance Win32_Service -Filter \"Name='syncthing'\" | Select-Object Name,State,StartName\n# StartName should display as .\\<USERNAME>. If LocalSystem, registration failed\n```\n\nAfter the service runs, verify in the syncthing GUI (`http://localhost:8384`) that sync folders scan correctly + new files created have the user account as owner.\n\n## Don't / Do Table\n\n| # | Don't | Do |\n|---|-------|-----|\n| 1 | Keep using nssm after v1→v2 major upgrade | Migrate to shawl (especially syncthing v2+) |\n| 2 | LocalSystem account + omit `--home` | Specify `--home=\"C:\\Users\\<u>\\AppData\\Local\\Syncthing\"` |\n| 2b | Skip extracting existing ObjectName before migration | Mandatory `nssm get <svc> ObjectName` in diagnosis step + use that value for shawl re-registration |\n| 2c | Register user data sync services as LocalSystem | Specify the `.\\USERNAME` user account. Preserve owner/permission |\n| 3 | Attempt to install shawl via scoop/choco | No scoop manifest, no choco package. Download directly from GitHub releases |\n| 4 | Call `gsudo powershell -File C:\\...` directly from Bash | Bash escape breaks backslashes. Use PowerShell tool or `/c/Users/...` path |\n| 5 | Forget to escape arguments in shawl add | Pass execution command as-is after the `--` separator. shawl preserves raw args |\n\n## Applying to Other Packages\n\nThe same pattern (major upgrade + service model change) can occur in other chocolatey packages and use the same procedure:\n\n- syncthing (case above, v1→v2)\n- Other packages that changed service models (add to this section when cases are found)\n\n## Follow-up Case — choco upgrade also Removes shawl Service (HARD STOP)\n\n**Phenomenon**: With syncthing service registered via shawl, running `choco upgrade syncthing` → after the new version installs, the service disappears. `sc query syncthing` returns `service does not exist`.\n\n**Cause**: The chocolatey syncthing package's `chocolateyBeforeModify.ps1` assumes nssm when a Windows service named \"syncthing\" exists, and calls stop/remove. Removal happens by name match, regardless of the registration tool (nssm vs shawl).\n\n**Mitigation — always check service existence after choco upgrade**:\n\n```bash\nsc query syncthing 2>&1 | grep -E \"SERVICE_NAME|STATE\"\n# Empty result → re-registration needed\n```\n\nOne-time re-registration script (skip only the nssm remove step in shawl-migration.md \"2. Migration Script\"):\n\n```powershell\n$shawlExe = \"$env:USERPROFILE\\.local\\bin\\shawl.exe\"\n$appExe = \"C:\\ProgramData\\chocolatey\\bin\\syncthing.exe\"\n$homePath = \"$env:USERPROFILE\\AppData\\Local\\Syncthing\"\n\n& $shawlExe add --name syncthing -- $appExe --no-browser --home=$homePath\nsc.exe start syncthing\n```\n\n**Root solution (TODO)**: When registering with shawl, rename the service (e.g., `syncthing-shawl`) to avoid conflict with chocolateyBeforeModify's nssm assumption. However, GUI environment variables and existing automation may depend on the `syncthing` name, so compatibility review is required.\n\n## Violation Cases\n\n**2026-05-21 (1st occurrence)**: On a Windows machine, syncthing 2.1.0 nssm service immediately failed with service-specific error 3. Console syncthing.exe started normally (PID 28208, 8384 LISTENING). Initially suspected nssm shim path / user password, but the actual cause was v1→v2 major compatibility. Resolved via shawl migration:\n- nssm remove syncthing confirm\n- shawl add --name syncthing -- syncthing.exe --no-browser --home=...AppData\\Local\\Syncthing\n- Service RUNNING + 8384 LISTENING recovery complete.\n\n**2026-05-21 (2nd occurrence)**: Immediately after the 1st migration in the same session, `choco upgrade` or auto-upgrade transitioned syncthing 2.1.0 → 2.1.1. The shawl service was automatically removed by chocolateyBeforeModify. `sc query` showed service does not exist. Recovered via re-registration. → Created the \"Follow-up Case\" section in this topic.\n\n**2026-05-21 (3rd occurrence)**: During 1st/2nd shawl re-registration, the existing nssm `ObjectName=.\\<USERNAME>` was not extracted/preserved and was registered with the default LocalSystem. Risk of owner/permission mismatch for services like syncthing that sync user data. User pointed out \"registered with the wrong user\". Reinforced by adding ObjectName extraction in the diagnosis step + `sc.exe config obj=` step in the migration script + restructuring the execution account decision table.\n\n## References\n\n- [Syncthing v2.0 release notes](https://github.com/syncthing/syncthing/releases/tag/v2.0.0)\n- [Syncthing v2 forum migration thread](https://forum.syncthing.net/t/syncthing-2-0-august-2025/24758)\n- [shawl GitHub](https://github.com/mtkennerly/shawl)\n- [issue #10340 — re-migrate every start](https://github.com/syncthing/syncthing/issues/10340)\n\nFile v1.0.4:skill-card.md\n\n## Description:\n\nHelps agents diagnose and repair Chocolatey upgrade fallout, including stale NSSM service paths, NSSM-to-shawl migrations, and stale Chocolatey metadata after UniGetUI or choco updates.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[drumrobot](https://clawhub.ai/user/drumrobot)\n\n### License/Terms of Use:\n\nMIT\n\n## Use Case:\n\nDevelopers and operations engineers use this skill to investigate Windows Chocolatey package upgrade issues and produce reviewed commands for repairing NSSM-managed services, migrating selected services to shawl, or resynchronizing stale package metadata.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Elevated commands can reconfigure persistent Windows services or alter Chocolatey package state.\n\nMitigation: Manually review generated commands, export existing service settings, and run only the specific elevated operations required for the confirmed service or package.\n\nRisk: The shawl migration workflow may download and elevate an executable from GitHub releases.\n\nMitigation: Verify the release source, hash, or signature before use, and avoid elevation until the binary is trusted.\n\nRisk: Service migration examples include account and password handling that could expose credentials if saved in scripts.\n\nMitigation: Use secure prompts or managed service accounts, do not persist plaintext passwords, and remove temporary migration scripts after execution.\n\nRisk: Bulk package or service operations can affect unrelated packages and services.\n\nMitigation: Prefer diagnosis and targeted package or service repair before running broad package upgrades or bulk service changes.\n\n## Reference(s):\n\n- [Chocolatey documentation](https://docs.chocolatey.org/)\n- [UniGetUI repository](https://github.com/Devolutions/UniGetUI)\n- [chocolatey/choco repository](https://github.com/chocolatey/choco)\n- [shawl GitHub](https://github.com/mtkennerly/shawl)\n- [Syncthing v2.0 release notes](https://github.com/syncthing/syncthing/releases/tag/v2.0.0)\n- [Syncthing v2 forum migration thread](https://forum.syncthing.net/t/syncthing-2-0-august-2025/24758)\n- [Syncthing issue #10340](https://github.com/syncthing/syncthing/issues/10340)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, shell commands, configuration, guidance]\n\n**Output Format:** [Markdown guidance with inline shell, PowerShell, and JSON command examples]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Commands commonly require Windows administrator review before execution.]\n\n## Skill Version(s):\n\n1.0.4 (source: frontmatter, CHANGELOG, server release metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nFile v1.0.4:update-path.md\n\n# nssm Path Refresh\n\n## When to Use\n\n- When refreshing the path of a specific service detected as a shim by diagnose\n- When the existing binary path no longer exists after choco upgrade because the version folder changed (stale path)\n\n## Procedure\n\n### 1. Check Refresh Command\n\n```bash\nnode scripts/nssm-manager.js update-path <service-name>\n```\n\nJSON output:\n```json\n{\n  \"service\": \"syncthing\",\n  \"current\": \"C:\\\\ProgramData\\\\chocolatey\\\\bin\\\\syncthing.exe\",\n  \"actual\": \"C:\\\\ProgramData\\\\chocolatey\\\\lib\\\\syncthing\\\\tools\\\\syncthing-windows-amd64-v2.0.15\\\\syncthing.exe\",\n  \"commands\": [\n    \"nssm stop \\\"syncthing\\\"\",\n    \"nssm set \\\"syncthing\\\" Application \\\"...actual path...\\\"\",\n    \"nssm start \\\"syncthing\\\"\"\n  ]\n}\n```\n\n### 2. Run with Administrator Privileges\n\n```bash\npowershell -Command \"Start-Process powershell -ArgumentList '-Command', 'nssm stop \\\"<svc>\\\"; nssm set \\\"<svc>\\\" Application \\\"<actual-path>\\\"; nssm start \\\"<svc>\\\"' -Verb RunAs -Wait\"\n```\n\n### 3. Verify\n\n```bash\nnssm status <service>\nnssm get <service> Application\n```\n\n## Path Selection Strategy\n\n### Stable Shim Path (recommended)\n\n`%ChocolateyInstall%\\bin\\<exe>` — Path remains unchanged after choco upgrade.\n\n```bash\ngsudo nssm set <service> Application \"C:\\ProgramData\\chocolatey\\bin\\<exe>\"\n```\n\nUse the version-specific actual path only when the shim conflicts with the service (immediate process termination → nssm misinterprets as crash).\n\n### Version-Specific Actual Path (only when shim conflicts)\n\n`chocolatey\\lib\\*\\tools\\*` — Stable, but **breaks on every upgrade**. Using this path requires a post-upgrade hook.\n\n## Path Change Pattern During Version Upgrades\n\n```\nv1.27.x: chocolatey\\lib\\syncthing\\tools\\syncthing-windows-amd64-v1.27.x\\syncthing.exe\nv2.0.15: chocolatey\\lib\\syncthing\\tools\\syncthing-windows-amd64-v2.0.15\\syncthing.exe\nv2.0.16: chocolatey\\lib\\syncthing\\tools\\syncthing-windows-amd64-v2.0.16\\syncthing.exe\n```\n\nFolder name changes with each version, requiring refresh every time.\n\n### Real Case: syncthing v2.0.15 → v2.0.16 (2026-04-30)\n\n- After `choco upgrade syncthing`, NSSM pointed to the v2.0.15 path → `SERVICE_STOPPED`\n- Not a shim, but the **previous version's path of the actual binary** — undetectable by `isChocoShim()`\n- Resolved by adding `isStaleChocoPath()`: if a path under `chocolatey\\lib\\` exists but the file does not, it is treated as stale\n\nFile v1.0.4:LICENSE\n\nMIT License\n\nCopyright (c) 2026 es6.kr\n\nPermission is hereby granted, free of charge, to any person obtaining a copy\nof this software and associated documentation files (the \"Software\"), to deal\nin the Software without restriction, including without limitation the rights\nto use, copy, modify, merge, publish, distribute, sublicense, and/or sell\ncopies of the Software, and to permit persons to whom the Software is\nfurnished to do so, subject to the following conditions:\n\nThe above copyright notice and this permission notice shall be included in all\ncopies or substantial portions of the Software.\n\nTHE SOFTWARE IS PROVIDED \"AS IS\", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR\nIMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,\nFITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE\nAUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER\nLIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,\nOUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE\nSOFTWARE.\n\nArchive v1.0.3: 11 files, 17999 bytes\n\nFiles: CHANGELOG.md (2335b), diagnose.md (1257b), LICENSE (1063b), metadata-fix.md (4746b), post-upgrade.md (1240b), scripts/nssm-manager.js (7503b), shawl-migration.md (11270b), skill-card.md (2652b), SKILL.md (6022b), update-path.md (2382b), _meta.json (124b)\n\nFile v1.0.3:SKILL.md\n\n---\nname: choco\nmetadata:\n  author: es6kr\n  version: \"1.0.3\" # x-release-please-version\ndescription: |\n  Chocolatey operations integration — post-processing after choco upgrade, nssm service path refresh, NSSM → shawl migration (syncthing v2 etc.), resync on UniGetUI/choco metadata update failures. diagnose [diagnose.md], metadata-fix [metadata-fix.md], post-upgrade [post-upgrade.md], shawl-migration [shawl-migration.md], update-path [update-path.md].\n  Use when: \"choco\", \"chocolatey\", \"choco upgrade\", \"choco outdated\", \"vcredist\", \"nssm\", \"nssm recovery\", \"nssm path\", \"service path refresh\", \"after choco upgrade\", \"service failure\", \"SERVICE_STOPPED\", \"shim issue\", \"syncthing nssm\", \"syncthing v2\", \"shawl migration\", \"nssm deprecation\", \"service-specific error\", \"UniGetUI\", \"metadata update failure\", \"metadata stale\", \".nuspec stale\", \"choco metadata\".\n---\n\n# Choco\n\nChocolatey operations integration skill. Pre- and post-processing for choco upgrade, nssm service compatibility management, and metadata update failure recovery.\n\n## Core Problems\n\n| Area | Problem | Resolution Topic |\n|------|---------|------------------|\n| Package path | After choco upgrade, the nssm Application path becomes stale due to version-specific folders | [update-path.md](./update-path.md) |\n| Service compatibility | After major upgrade (e.g., syncthing v1→v2), NSSM fails with service-specific error | [shawl-migration.md](./shawl-migration.md) |\n| Metadata | Runtime install succeeds + chocolatey `.nuspec` is stale (UniGetUI shows repeated upgrades) | [metadata-fix.md](./metadata-fix.md) |\n| Diagnosis | Identify which service has issues / which package is stale | [diagnose.md](./diagnose.md) |\n| Bulk post-processing | Automatically check affected services after choco upgrade | [post-upgrade.md](./post-upgrade.md) |\n\n## Path Strategy (HARD STOP — required decision before nssm set Application)\n\n| Strategy | Example Path | Pros | Cons |\n|----------|--------------|------|------|\n| **Stable shim path (recommended)** | `%ChocolateyInstall%\\bin\\syncthing.exe` | Path remains unchanged after choco upgrade | Without `--shimgen-waitforexit`, nssm may misinterpret shim exit as a crash |\n| Version-specific actual path | `%ChocolateyInstall%\\lib\\syncthing\\tools\\...-v2.1.0\\syncthing.exe` | No shim issues | **Path breaks on every upgrade** — this is why this skill exists |\n\n**Default choice: stable shim path.** Use version-specific path + post-upgrade hook combination only for services where shim issues occur. When NSSM compatibility itself breaks (like syncthing v2), apply [shawl-migration](./shawl-migration.md).\n\n### Using environment variable paths in nssm\n\nnssm supports `REG_EXPAND_SZ` but `nssm set` defaults to `REG_SZ`. Set registry directly via PowerShell:\n\n```powershell\n$regPath = \"HKLM:\\SYSTEM\\CurrentControlSet\\Services\\<service>\\Parameters\"\nSet-ItemProperty -Path $regPath -Name \"Application\" -Value '%ChocolateyInstall%\\bin\\<exe>' -Type ExpandString\n```\n\nOr use an expanded literal path:\n\n```bash\ngsudo nssm set <service> Application \"C:\\ProgramData\\chocolatey\\bin\\<exe>\"\n```\n\n## Topics\n\n| Topic | File | Description |\n|-------|------|-------------|\n| diagnose | [diagnose.md](./diagnose.md) | nssm service diagnosis procedure |\n| metadata-fix | [metadata-fix.md](./metadata-fix.md) | Recovery for UniGetUI/choco metadata (.nuspec) update failures |\n| post-upgrade | [post-upgrade.md](./post-upgrade.md) | Post-processing after choco upgrade |\n| shawl-migration | [shawl-migration.md](./shawl-migration.md) | NSSM → shawl migration (major upgrades like syncthing v2) |\n| update-path | [update-path.md](./update-path.md) | nssm path refresh |\n\n## Scripts\n\n| Mode | Command | Description |\n|------|---------|-------------|\n| diagnose | `node <skill-dir>/scripts/nssm-manager.js diagnose` | Check all nssm services |\n| update-path | `node <skill-dir>/scripts/nssm-manager.js update-path <service>` | Output path refresh command for a specific service |\n| post-upgrade | `node <skill-dir>/scripts/nssm-manager.js post-upgrade` | Full post-processing check |\n\n`<skill-dir>` = `~/.claude/skills/choco`\n\n**Note**: `node` may not be on PATH in bash. In an fnm environment, use the full path:\n\n```bash\n\"$APPDATA/fnm/node-versions/v20.20.0/installation/node.exe\" <skill-dir>/scripts/nssm-manager.js <mode>\n```\n\n## Administrator Privileges\n\n`nssm set/stop/start` and `choco upgrade` commands require administrator privileges. Per the Windows rule, **using `gsudo` is the default**:\n\n```bash\ngsudo choco upgrade <pkg> -y\ngsudo nssm set <service> Application \"<path>\"\n```\n\nOr invoke via the PowerShell tool:\n\n```powershell\ngsudo powershell -ExecutionPolicy Bypass -File \"<script.ps1>\"\n```\n\n## Topic Dependencies\n\n```text\nchoco (main workflow)\n  ├─→ diagnose (step 1 diagnosis)\n  ├─→ metadata-fix (recover stale choco/UniGetUI metadata)\n  ├─→ post-upgrade (bulk check after choco upgrade)\n  ├─→ update-path (nssm path refresh)\n  └─→ shawl-migration (NSSM → shawl migration)\n        └─→ shawl binary (~/.local/bin/shawl.exe, downloaded from GitHub releases)\n```\n\n- Simple path refresh → `update-path`\n- Major upgrade requiring nssm deprecation → `shawl-migration`\n- Runtime OK + only chocolatey metadata stale → `metadata-fix`\n- Multiple services in bulk → `diagnose` + `post-upgrade`\n\n## Self-heal\n\nThis skill is subject to self-improvement after execution.\nIf malfunction is detected, improve it via `/skill-kit upgrade choco`.\n\nChecklist:\n1. Are the trigger keywords in description sufficient?\n2. Was the topic selection accurate? (e.g., misrouting metadata stale to update-path)\n3. Was the procedure complete? (Was no manual correction needed?)\n4. Were there no omissions in the deliverables?\n\n## References\n\n- Previous skill: `choco-nssm` (absorbed into this skill, moved to `~/.claude/.bak/`)\n- [Chocolatey docs](https://docs.chocolatey.org/)\n- [UniGetUI repo](https://github.com/Devolutions/UniGetUI)\n- [shawl repo](https://github.com/mtkennerly/shawl)\n\nFile v1.0.3:_meta.json\n\n{\n  \"ownerId\": \"kn74k8yfvftx6f062qa8fzyd8h8373jd\",\n  \"slug\": \"choco\",\n  \"version\": \"1.0.3\",\n  \"publishedAt\": 1786284669762\n}\n\nFile v1.0.3:CHANGELOG.md\n\n# Changelog\n\n## [1.0.3](https://github.com/es6kr/skills/compare/choco-v1.0.2...choco-v1.0.3) (2026-08-09)\n\n\n### Bug Fixes\n\n* declare undeclared skill-to-skill dependencies (7 skills) ([#271](https://github.com/es6kr/skills/issues/271)) ([36a9f9d](https://github.com/es6kr/skills/commit/36a9f9d7c1fac9bb1c4c96b325a067ab92ad0da7))\n* promote accumulated next-fix fixes to main ([95656e9](https://github.com/es6kr/skills/commit/95656e9b551ee0bb77904a0a571d49c53bc01cc9))\n\n## [1.0.2](https://github.com/es6kr/skills/compare/choco-v1.0.1...choco-v1.0.2) (2026-08-05)\n\n\n### Bug Fixes\n\n* **wip:** cross-ref PR-URL and TaskCreate subject repo-qualifier rules ([#186](https://github.com/es6kr/skills/issues/186)) ([951c1e6](https://github.com/es6kr/skills/commit/951c1e6871e78e226757c6a7ae5ae53efeb7bfb0))\n\n## [1.0.1](https://github.com/es6kr/skills/compare/choco-v1.0.0...choco-v1.0.1) (2026-06-27)\n\n\n### Features\n\n* decompose workflow/git rules + rename web-ui-test→web-browser ([#50](https://github.com/es6kr/skills/issues/50)) ([e10d48f](https://github.com/es6kr/skills/commit/e10d48fea4e507b95888de44812b53484d32128d))\n\n\n### Bug Fixes\n\n* **fix:** split Step 2 medium by content type — case history to failed-attempts.md ([#62](https://github.com/es6kr/skills/issues/62)) ([747b3f9](https://github.com/es6kr/skills/commit/747b3f957ca0fefdbc5044eb08f66b8aafc1e26a))\n* **skills:** apply PR [#50](https://github.com/es6kr/skills/issues/50) Phase 2 follow-up reviews ([33863d7](https://github.com/es6kr/skills/commit/33863d705f8b24051b030b839487e8b5a8bfd9df))\n\n## [0.1.1](https://github.com/es6kr/skills/compare/choco-v0.1.0...choco-v0.1.1) (2026-06-25)\n\n\n### Bug Fixes\n\n* **fix:** split Step 2 medium by content type — case history to failed-attempts.md ([#62](https://github.com/es6kr/skills/issues/62)) ([747b3f9](https://github.com/es6kr/skills/commit/747b3f957ca0fefdbc5044eb08f66b8aafc1e26a))\n* **skills:** apply PR [#50](https://github.com/es6kr/skills/issues/50) Phase 2 follow-up reviews ([33863d7](https://github.com/es6kr/skills/commit/33863d705f8b24051b030b839487e8b5a8bfd9df))\n\n## 0.1.0 (2026-06-12)\n\n\n### Features\n\n* decompose workflow/git rules + rename web-ui-test→web-browser ([#50](https://github.com/es6kr/skills/issues/50)) ([e10d48f](https://github.com/es6kr/skills/commit/e10d48fea4e507b95888de44812b53484d32128d))\n\nFile v1.0.3:diagnose.md\n\n# nssm Service Diagnosis\n\n## When to Use\n\n- nssm service is in `SERVICE_PAUSED` or `SERVICE_STOPPED` state\n- Service behavior anomalies after choco upgrade\n- When a specific service won't start\n\n## Diagnosis Procedure\n\n### 1. Run the Script\n\n```bash\nnode scripts/nssm-manager.js diagnose\n```\n\nOutput content:\n- List of all nssm services\n- Status of each service (RUNNING/STOPPED/PAUSED)\n- Shim status (chocolatey\\bin path = shim)\n- Actual binary location (inside choco lib)\n- List of commands required for fixes\n\n### 2. Manual Diagnosis (if script fails)\n\n```bash\n# Service status\nnssm status <service>\n\n# Registered path\nnssm get <service> Application\n\n# Actual binary location\nls \"C:/ProgramData/chocolatey/lib/<package>/tools/\"\n```\n\n### 3. Shim Identification Criteria\n\n| Path | Type | Service Behavior |\n|------|------|------------------|\n| `chocolatey\\bin\\*.exe` | shim (wrapper) | High failure likelihood |\n| `chocolatey\\lib\\*\\tools\\*\\*.exe` | actual binary | Normal |\n| Other paths | direct install | Normal |\n\n## Output Interpretation\n\n- `Shim: YES` → Path refresh required via update-path topic\n- `Shim: NO` → Investigate other causes (check logs, port conflicts, etc.)\n- `Actual binary: not found` → Package was removed or structure changed\n\nFile v1.0.3:metadata-fix.md\n\n# Chocolatey Metadata Update Failure Fix\n\nDiagnosis and recovery procedure for cases where **the runtime/installer succeeds but the chocolatey metadata (`.nuspec`) update fails** after invoking UniGetUI or choco upgrade.\n\n## Background\n\nStarting from UniGetUI 2026.1.7, the chocolatey bundle was removed and it became a passthrough to the system `choco`. Since UniGetUI only displays the results of `choco list`, metadata update failure is the **responsibility of chocolatey**.\n\nRelated issues:\n- [Devolutions/UniGetUI#4803](https://github.com/Devolutions/UniGetUI/issues/4803) — Inconsistent chocolatey packages since 2026.1.7\n- [Devolutions/UniGetUI#4801](https://github.com/Devolutions/UniGetUI/issues/4801) — Wrong information about installed programs (2026.1.10)\n- [Devolutions/UniGetUI#3708](https://github.com/Devolutions/UniGetUI/issues/3708) — choco.exe hang on update check\n- [Devolutions/UniGetUI#4217](https://github.com/Devolutions/UniGetUI/issues/4217) — Chocolatey shown as ready on MS Store install\n\n## Symptoms\n\n| Symptom | Meaning |\n|---------|---------|\n| \"Upgrade available\" indication persists in UniGetUI | `choco list` returns old version |\n| `choco list <pkg>` shows old version, actual EXE is new version | Only `.nuspec` is stale |\n| Same package keeps appearing in `choco outdated` | Metadata stage exits abnormally |\n| choco exits abnormally after \"already installed\" in installer log | Package stage may be skipped |\n\n## Diagnosis Procedure\n\n### 1. Compare Metadata vs Actual Version\n\n```bash\n# Version recognized by chocolatey\nchoco list <pkg>\n\n# Metadata version in .nuspec\ngrep -i version \"C:\\ProgramData\\chocolatey\\lib\\<pkg>\\<pkg>.nuspec\" | head -1\n\n# Actual installed runtime version (e.g., vcredist140)\nreg query \"HKLM\\SOFTWARE\\Microsoft\\VisualStudio\\14.0\\VC\\Runtimes\\x64\" /v Version 2>&1 | grep Version\n```\n\nIf the three values diverge, metadata stale is confirmed.\n\n### 2. Verify with choco outdated\n\n```bash\nchoco outdated 2>&1 | grep -E \"^[a-zA-Z0-9_-]+\\|\"\n```\n\nOutput line: `<pkg>|<current metadata>|<remote latest>|<pinned>`. Suspect if metadata differs from external systems (WMI/registry).\n\n## Recovery Procedure\n\n### 1. Force Resync (default)\n\n```bash\n# Invoke via PowerShell tool (bypass Bash escape)\ngsudo choco upgrade <pkg> -y\n```\n\nAfter success, verify version match with `choco list <pkg>`.\n\n### 2. Use --force (when 1 has no effect)\n\n```bash\ngsudo choco upgrade <pkg> -y --force\n```\n\n`--force` re-runs the package stage even if already at the latest version to update `.nuspec`.\n\n### 3. Bulk Update\n\n```bash\ngsudo choco upgrade all -y\n```\n\nCleans up large amounts of outdated entries. Effective when UniGetUI has accumulated stale indicators.\n\n### 4. Manual nuspec Patch (last resort)\n\nIf choco refuses to update for any reason, directly modify the `<version>` node in `.nuspec`. **Not recommended** — risk of being overwritten by the next upgrade or causing dependency mismatch.\n\n## Don't / Do Table\n\n| # | Don't | Do |\n|---|-------|-----|\n| 1 | Repeatedly upgrade the same package in UniGetUI GUI | Run `gsudo choco upgrade <pkg> -y` directly in an elevated terminal |\n| 2 | Directly edit `.nuspec` when suspecting metadata stale | Use `--force` so chocolatey performs a proper update |\n| 3 | File an issue in the UniGetUI repository | UniGetUI is a passthrough — report to chocolatey-core (chocolatey/choco) or the package maintainer |\n| 4 | Invoke `choco upgrade` from Bash (without elevation) | PowerShell tool + `gsudo` or administrator PowerShell |\n| 5 | Conclude success from the `choco upgrade` output line alone | Immediately cross-verify with `choco list <pkg>` + `.nuspec` version |\n\n## Self-check (every time a UniGetUI/choco metadata stale report is received)\n\n1. Compare three values: `choco list <pkg>` + `.nuspec` version + actual runtime version\n2. All three match → possible UniGetUI cache issue. Restart UniGetUI or refresh the package\n3. Only choco metadata and .nuspec are stale → `gsudo choco upgrade <pkg> -y`\n4. If step 1 has no effect → `gsudo choco upgrade <pkg> -y --force`\n5. If step 4 also fails → report an issue to the package maintainer (chocolatey.org package page)\n\n## Violation / Application Cases\n\n**2026-05-21 (1st occurrence)**: vcredist140 14.51.36231 → 14.51.36247 metadata update failure. UniGetUI repeatedly attempted updates but the system runtime was already 14.51.36247. `gsudo choco upgrade vcredist140 -y` completed the .nuspec update at once. The log shows `Runtime for architecture x64 version 14.51.36247 is already installed` — a case where only the package stage needed updating.\n\n## References\n\n- [UniGetUI repo](https://github.com/Devolutions/UniGetUI)\n- [chocolatey/choco repo](https://github.com/chocolatey/choco)\n\nFile v1.0.3:post-upgrade.md\n\n# choco upgrade Post-Processing\n\n## When to Use\n\n- After running `choco upgrade all`\n- After upgrading specific packages, to check services\n\n## Procedure\n\n### 1. Run Full Check\n\n```bash\nnode scripts/nssm-manager.js post-upgrade\n```\n\nOutput:\n- One-line summary of shim status for all nssm services\n- List of services requiring updates\n- Administrator PowerShell commands (bulk/individual)\n\n### 2. Run Update Commands\n\nExecute the commands output by the script with administrator privileges:\n\n```bash\n# Bulk execution (the \"Administrator PowerShell commands\" section from script output)\npowershell -Command \"Start-Process powershell -ArgumentList '-Command', '<commands>' -Verb RunAs -Wait\"\n```\n\n### 3. Check Service Status\n\n```bash\nnssm status <service>\n```\n\n## Check Targets\n\nThe script automatically finds nssm-managed services in `Win32_Service` and checks them:\n- All services where `BINARY_PATH_NAME` contains `nssm`\n- Verifies whether each service's Application path is a shim\n- If shim, searches choco lib for the actual binary\n\n## Notes\n\n- Administrator privileges required (UAC prompt)\n- If services are already healthy right after upgrade, refresh is unnecessary\n- Binary location may differ per package (within tools/ subfolders)\n\nFile v1.0.3:shawl-migration.md\n\n# nssm → shawl Migration\n\n## Background\n\nNSSM is flagged as malware by some security solutions, so starting from syncthing v2 the official Windows Setup transitioned to **shawl**. During major upgrades (v1→v2), the existing nssm registration causes the following problems:\n\n| Symptom | Cause |\n|---------|-------|\n| `service-specific error 3` (path not found) | LocalSystem/user context difference makes `%LOCALAPPDATA%\\Syncthing` inaccessible |\n| `service-specific error 3547` | nssm service times out during syncthing v2's SQLite migration |\n| Dies immediately on start, no entry in syncthing log | nssm lacks LOAD_USER_PROFILE → cannot find home directory |\n| v2.0.4+ migration re-runs on every restart | issue [#10340](https://github.com/syncthing/syncthing/issues/10340) |\n\n## Applicable Cases\n\n- nssm service start failure after syncthing v1.x → v2.x major upgrade\n- Environments where NSSM is blocked as malware\n- Other chocolatey packages with similar service model changes (same compatibility pattern)\n\n## Prerequisites\n\nVerify the shawl binary (`~/.local/bin/shawl.exe`) is available:\n\n```bash\n~/.local/bin/shawl.exe --version\n```\n\nIf not installed → download from GitHub releases and place in `~/.local/bin/`:\n\n```bash\nmkdir -p ~/.local/bin && cd /tmp\ncurl -sL https://github.com/mtkennerly/shawl/releases/latest/download/shawl-v1.9.0-win64.zip -o shawl.zip\nunzip -o shawl.zip\nmv shawl.exe ~/.local/bin/\nrm shawl.zip\n```\n\n(Based on v1.9.0. Query latest version via `https://api.github.com/repos/mtkennerly/shawl/releases/latest`)\n\n## Migration Procedure\n\n### 1. Diagnosis — Extract All Existing Service Settings (HARD STOP)\n\nBefore migration, extract all settings of the existing service to **preserve them as-is during shawl re-registration**. Applies the `common.md` \"user-specified value change prohibition\" rule.\n\n```bash\nsc query <service>             # Check SERVICE_STOPPED + error code\nnssm get <service> Application # Current path\nnssm get <service> AppParameters\nnssm get <service> ObjectName  # ⚠️ Execution account — preservation target\nnssm get <service> AppDirectory\nnssm get <service> AppStdout   # Preserve log path\nnssm get <service> AppStderr\nsc qc <service>                # ObjectName fallback (admin required)\ntasklist | grep <service>      # Lingering processes\nnetstat -ano | grep \":<port>\"  # Port occupation\n```\n\n**Record extracted values (required)**: Preserve each value as a variable for use in the next step. Especially if `ObjectName` is not `LocalSystem`, specify the user account explicitly. Even if it is `LocalSystem`, services synchronizing user data like syncthing are recommended to use a user account (see \"3. Determining Execution Account\" below).\n\nRun directly in the console to verify the syncthing binary itself is healthy:\n\n```bash\n\"<app-path>\" --no-console --no-browser\n```\n\nConsole runs fine + service fails → this topic applies.\n\n### 2. Migration Script (PowerShell, Administrator)\n\n```powershell\n$ErrorActionPreference = \"Continue\"\n\n$serviceName = \"syncthing\"\n$shawlExe = \"$env:USERPROFILE\\.local\\bin\\shawl.exe\"\n$appExe = \"C:\\ProgramData\\chocolatey\\bin\\syncthing.exe\"\n$homePath = \"$env:USERPROFILE\\AppData\\Local\\Syncthing\"\n\n# ⚠️ Values extracted in diagnosis step — must be filled in by the user\n$objectName = \".\\<USERNAME>\"        # Same as the existing nssm ObjectName. If LocalSystem, replace with a user account for user-data services like syncthing\n$objectPassword = \"<USER_PASSWORD>\" # User's Windows password (don't hardcode plaintext in scripts — use SecureString or prompt for input)\n\n# 1. Stop and remove existing nssm service\nsc.exe stop $serviceName\nStart-Sleep -Seconds 2\nnssm.exe remove $serviceName confirm\n\n# 2. Re-register with shawl (specify --home: access user config)\n& $shawlExe add --name $serviceName -- $appExe --no-browser --home=$homePath\n\n# 3. Configure ObjectName + LOAD_USER_PROFILE (preserve user account)\nif ($objectName -ne \"LocalSystem\") {\n    sc.exe config $serviceName obj= \"$objectName\" password= \"$objectPassword\"\n    sc.exe privs $serviceName SeBackupPrivilege/SeRestorePrivilege/SeAssignPrimaryTokenPrivilege  # if needed\n}\n\n# 4. Start\nsc.exe start $serviceName\nStart-Sleep -Seconds 8\n\n# 5. Verify (validate StartName preservation)\nsc.exe query $serviceName\nGet-CimInstance Win32_Service -Filter \"Name='$serviceName'\" | Format-List Name,State,StartName,PathName\nnetstat -an | Select-String \"8384\"\n```\n\nSave the script to `C:\\Users\\<user>\\migrate-<service>-to-shawl.ps1`, then:\n\n```bash\n# Bash tool breaks -File argument due to backslash escape issues → use PowerShell tool directly\n# In PowerShell tool:\ngsudo powershell -ExecutionPolicy Bypass -File \"C:\\Users\\<user>\\migrate-<service>-to-shawl.ps1\"\n```\n\n### 3. Determining Execution Account (HARD STOP — preserving existing ObjectName is the top priority)\n\n**Default principle**: Preserve the `ObjectName` extracted in the diagnosis step as-is. Changes only on explicit user instruction.\n\n| Service Type | Recommended Account | Reason |\n|--------------|---------------------|--------|\n| **User data sync/consume** (Syncthing, Dropbox, Resilio Sync, OneDrive, etc.) | `.\\<USERNAME>` | The owner/permission of synced files is the user. Running as LocalSystem risks owner mismatch, permission denied, and file hash changes |\n| **System daemon** (DB, web server, monitoring agent, etc.) | `LocalSystem` or `NT SERVICE\\<name>` | Independent of user context. No password management needed |\n| **GUI-dependent tools** | User account + `Interactive` (not recommended) | Requires user logon session — prefer daemon mode if possible |\n\n#### Don't / Do\n\n| # | Don't | Do |\n|---|-------|-----|\n| 1 | Leave shawl re-registration at LocalSystem (default) when existing nssm `ObjectName=.\\USERNAME` | Specify the extracted value (`.\\USERNAME`) explicitly via `sc.exe config obj=` |\n| 2 | Assume \"LocalSystem + `--home` specification\" can serve as a workaround | `--home` only resolves config path — ownership/ACL problems of synced files are separate. User account execution is the proper fix |\n| 3 | Hardcode plaintext password in script | Use `Read-Host -AsSecureString` or Group Managed Service Account (gMSA). If you must hardcode plaintext, apply `chmod 600` or `.gitignore` + remove immediately |\n| 4 | Fail to update credentials when user password changes → service fails to start | Immediately update via `sc.exe config <svc> password= <new_pw>`. Be aware of Windows password rotation policy |\n\n#### Verification After User Account Registration\n\n```powershell\nGet-CimInstance Win32_Service -Filter \"Name='syncthing'\" | Select-Object Name,State,StartName\n# StartName should display as .\\<USERNAME>. If LocalSystem, registration failed\n```\n\nAfter the service runs, verify in the syncthing GUI (`http://localhost:8384`) that sync folders scan correctly + new files created have the user account as owner.\n\n## Don't / Do Table\n\n| # | Don't | Do |\n|---|-------|-----|\n| 1 | Keep using nssm after v1→v2 major upgrade | Migrate to shawl (especially syncthing v2+) |\n| 2 | LocalSystem account + omit `--home` | Specify `--home=\"C:\\Users\\<u>\\AppData\\Local\\Syncthing\"` |\n| 2b | Skip extracting existing ObjectName before migration | Mandatory `nssm get <svc> ObjectName` in diagnosis step + use that value for shawl re-registration |\n| 2c | Register user data sync services as LocalSystem | Specify the `.\\USERNAME` user account. Preserve owner/permission |\n| 3 | Attempt to install shawl via scoop/choco | No scoop manifest, no choco package. Download directly from GitHub releases |\n| 4 | Call `gsudo powershell -File C:\\...` directly from Bash | Bash escape breaks backslashes. Use PowerShell tool or `/c/Users/...` path |\n| 5 | Forget to escape arguments in shawl add | Pass execution command as-is after the `--` separator. shawl preserves raw args |\n\n## Applying to Other Packages\n\nThe same pattern (major upgrade + service model change) can occur in other chocolatey packages and use the same procedure:\n\n- syncthing (case above, v1→v2)\n- Other packages that changed service models (add to this section when cases are found)\n\n## Follow-up Case — choco upgrade also Removes shawl Service (HARD STOP)\n\n**Phenomenon**: With syncthing service registered via shawl, running `choco upgrade syncthing` → after the new version installs, the service disappears. `sc query syncthing` returns `service does not exist`.\n\n**Cause**: The chocolatey syncthing package's `chocolateyBeforeModify.ps1` assumes nssm when a Windows service named \"syncthing\" exists, and calls stop/remove. Removal happens by name match, regardless of the registration tool (nssm vs shawl).\n\n**Mitigation — always check service existence after choco upgrade**:\n\n```bash\nsc query syncthing 2>&1 | grep -E \"SERVICE_NAME|STATE\"\n# Empty result → re-registration needed\n```\n\nOne-time re-registration script (skip only the nssm remove step in shawl-migration.md \"2. Migration Script\"):\n\n```powershell\n$shawlExe = \"$env:USERPROFILE\\.local\\bin\\shawl.exe\"\n$appExe = \"C:\\ProgramData\\chocolatey\\bin\\syncthing.exe\"\n$homePath = \"$env:USERPROFILE\\AppData\\Local\\Syncthing\"\n\n& $shawlExe add --name syncthing -- $appExe --no-browser --home=$homePath\nsc.exe start syncthing\n```\n\n**Root solution (TODO)**: When registering with shawl, rename the service (e.g., `syncthing-shawl`) to avoid conflict with chocolateyBeforeModify's nssm assumption. However, GUI environment variables and existing automation may depend on the `syncthing` name, so compatibility review is required.\n\n## Violation Cases\n\n**2026-05-21 (1st occurrence)**: On a Windows machine, syncthing 2.1.0 nssm service immediately failed with service-specific error 3. Console syncthing.exe started normally (PID 28208, 8384 LISTENING). Initially suspected nssm shim path / user password, but the actual cause was v1→v2 major compatibility. Resolved via shawl migration:\n- nssm remove syncthing confirm\n- shawl add --name syncthing -- syncthing.exe --no-browser --home=...AppData\\Local\\Syncthing\n- Service RUNNING + 8384 LISTENING recovery complete.\n\n**2026-05-21 (2nd occurrence)**: Immediately after the 1st migration in the same session, `choco upgrade` or auto-upgrade transitioned syncthing 2.1.0 → 2.1.1. The shawl service was automatically removed by chocolateyBeforeModify. `sc query` showed service does not exist. Recovered via re-registration. → Created the \"Follow-up Case\" section in this topic.\n\n**2026-05-21 (3rd occurrence)**: During 1st/2nd shawl re-registration, the existing nssm `ObjectName=.\\<USERNAME>` was not extracted/preserved and was registered with the default LocalSystem. Risk of owner/permission mismatch for services like syncthing that sync user data. User pointed out \"registered with the wrong user\". Reinforced by adding ObjectName extraction in the diagnosis step + `sc.exe config obj=` step in the migration script + restructuring the execution account decision table.\n\n## References\n\n- [Syncthing v2.0 release notes](https://github.com/syncthing/syncthing/releases/tag/v2.0.0)\n- [Syncthing v2 forum migration thread](https://forum.syncthing.net/t/syncthing-2-0-august-2025/24758)\n- [shawl GitHub](https://github.com/mtkennerly/shawl)\n- [issue #10340 — re-migrate every start](https://github.com/syncthing/syncthing/issues/10340)\n\nFile v1.0.3:skill-card.md\n\n## Description:\n\nChocolatey operations integration for post-processing after choco upgrades, refreshing NSSM service paths, migrating NSSM-managed services to shawl, and recovering UniGetUI or Chocolatey metadata update failures.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[drumrobot](https://clawhub.ai/user/drumrobot)\n\n### License/Terms of Use:\n\nMIT\n\n## Use Case:\n\nDevelopers and system administrators use this skill to diagnose Chocolatey and NSSM service issues after Windows package upgrades, generate repair commands, and apply guided migration or metadata recovery workflows.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill can suggest administrator-level Chocolatey and Windows service operations that may disrupt services if applied broadly or without review.\n\nMitigation: Apply commands only to specific packages or services you have identified, review pending Chocolatey changes first, and avoid bulk upgrade operations unless service disruption is acceptable.\n\nRisk: Migrating NSSM services to shawl can change the Windows service execution account or lose existing service settings.\n\nMitigation: Export or record the existing service configuration, especially ObjectName, paths, arguments, and log settings, before re-registering the service.\n\nRisk: The shawl workflow may require downloading a Windows binary outside the package manager path.\n\nMitigation: Verify downloaded shawl binaries independently before installing or using them.\n\n## Reference(s):\n\n- [Choco Skill on ClawHub](https://clawhub.ai/drumrobot/skills/choco)\n- [Publisher Profile](https://clawhub.ai/user/drumrobot)\n- [Chocolatey Documentation](https://docs.chocolatey.org/)\n- [UniGetUI Repository](https://github.com/Devolutions/UniGetUI)\n- [shawl Repository](https://github.com/mtkennerly/shawl)\n- [chocolatey/choco Repository](https://github.com/chocolatey/choco)\n\n## Skill Output:\n\n**Output Type(s):** [Analysis, Shell commands, Configuration instructions, Code, Guidance]\n\n**Output Format:** [Markdown with inline shell, PowerShell, and JSON snippets]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [May propose administrator-level Windows service and Chocolatey commands that require user review before execution.]\n\n## Skill Version(s):\n\n1.0.3 (source: frontmatter, changelog, server release metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nFile v1.0.3:update-path.md\n\n# nssm Path Refresh\n\n## When to Use\n\n- When refreshing the path of a specific service detected as a shim by diagnose\n- When the existing binary path no longer exists after choco upgrade because the version folder changed (stale path)\n\n## Procedure\n\n### 1. Check Refresh Command\n\n```bash\nnode scripts/nssm-manager.js update-path <service-name>\n```\n\nJSON output:\n```json\n{\n  \"service\": \"syncthing\",\n  \"current\": \"C:\\\\ProgramData\\\\chocolatey\\\\bin\\\\syncthing.exe\",\n  \"actual\": \"C:\\\\ProgramData\\\\chocolatey\\\\lib\\\\syncthing\\\\tools\\\\syncthing-windows-amd64-v2.0.15\\\\syncthing.exe\",\n  \"commands\": [\n    \"nssm stop \\\"syncthing\\\"\",\n    \"nssm set \\\"syncthing\\\" Application \\\"...actual path...\\\"\",\n    \"nssm start \\\"syncthing\\\"\"\n  ]\n}\n```\n\n### 2. Run with Administrator Privileges\n\n```bash\npowershell -Command \"Start-Process powershell -ArgumentList '-Command', 'nssm stop \\\"<svc>\\\"; nssm set \\\"<svc>\\\" Application \\\"<actual-path>\\\"; nssm start \\\"<svc>\\\"' -Verb RunAs -Wait\"\n```\n\n### 3. Verify\n\n```bash\nnssm status <service>\nnssm get <service> Application\n```\n\n## Path Selection Strategy\n\n### Stable Shim Path (recommended)\n\n`%ChocolateyInstall%\\bin\\<exe>` — Path remains unchanged after choco upgrade.\n\n```bash\ngsudo nssm set <service> Application \"C:\\ProgramData\\chocolatey\\bin\\<exe>\"\n```\n\nUse the version-specific actual path only when the shim conflicts with the service (immediate process termination → nssm misinterprets as crash).\n\n### Version-Specific Actual Path (only when shim conflicts)\n\n`chocolatey\\lib\\*\\tools\\*` — Stable, but **breaks on every upgrade**. Using this path requires a post-upgrade hook.\n\n## Path Change Pattern During Version Upgrades\n\n```\nv1.27.x: chocolatey\\lib\\syncthing\\tools\\syncthing-windows-amd64-v1.27.x\\syncthing.exe\nv2.0.15: chocolatey\\lib\\syncthing\\tools\\syncthing-windows-amd64-v2.0.15\\syncthing.exe\nv2.0.16: chocolatey\\lib\\syncthing\\tools\\syncthing-windows-amd64-v2.0.16\\syncthing.exe\n```\n\nFolder name changes with each version, requiring refresh every time.\n\n### Real Case: syncthing v2.0.15 → v2.0.16 (2026-04-30)\n\n- After `choco upgrade syncthing`, NSSM pointed to the v2.0.15 path → `SERVICE_STOPPED`\n- Not a shim, but the **previous version's path of the actual binary** — undetectable by `isChocoShim()`\n- Resolved by adding `isStaleChocoPath()`: if a path under `chocolatey\\lib\\` exists but the file does not, it is treated as stale\n\nFile v1.0.3:LICENSE\n\nMIT License\n\nCopyright (c) 2026 es6.kr\n\nPermission is hereby granted, free of charge, to any person obtaining a copy\nof this software and associated documentation files (the \"Software\"), to deal\nin the Software without restriction, including without limitation the rights\nto use, copy, modify, merge, publish, distribute, sublicense, and/or sell\ncopies of the Software, and to permit persons to whom the Software is\nfurnished to do so, subject to the following conditions:\n\nThe above copyright notice and this permission notice shall be included in all\ncopies or substantial portions of the Software.\n\nTHE SOFTWARE IS PROVIDED \"AS IS\", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR\nIMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,\nFITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE\nAUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER\nLIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,\nOUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE\nSOFTWARE.\n\nArchive v1.0.2: 11 files, 17789 bytes\n\nFiles: CHANGELOG.md (1880b), diagnose.md (1257b), LICENSE (1063b), metadata-fix.md (4840b), post-upgrade.md (1240b), scripts/nssm-manager.js (7503b), shawl-migration.md (11270b), skill-card.md (2300b), SKILL.md (6022b), update-path.md (2382b), _meta.json (124b)\n\nFile v1.0.2:SKILL.md\n\n---\nname: choco\nmetadata:\n  author: es6kr\n  version: \"1.0.2\" # x-release-please-version\ndescription: |\n  Chocolatey operations integration — post-processing after choco upgrade, nssm service path refresh, NSSM → shawl migration (syncthing v2 etc.), resync on UniGetUI/choco metadata update failures. diagnose [diagnose.md], metadata-fix [metadata-fix.md], post-upgrade [post-upgrade.md], shawl-migration [shawl-migration.md], update-path [update-path.md].\n  Use when: \"choco\", \"chocolatey\", \"choco upgrade\", \"choco outdated\", \"vcredist\", \"nssm\", \"nssm recovery\", \"nssm path\", \"service path refresh\", \"after choco upgrade\", \"service failure\", \"SERVICE_STOPPED\", \"shim issue\", \"syncthing nssm\", \"syncthing v2\", \"shawl migration\", \"nssm deprecation\", \"service-specific error\", \"UniGetUI\", \"metadata update failure\", \"metadata stale\", \".nuspec stale\", \"choco metadata\".\n---\n\n# Choco\n\nChocolatey operations integration skill. Pre- and post-processing for choco upgrade, nssm service compatibility management, and metadata update failure recovery.\n\n## Core Problems\n\n| Area | Problem | Resolution Topic |\n|------|---------|------------------|\n| Package path | After choco upgrade, the nssm Application path becomes stale due to version-specific folders | [update-path.md](./update-path.md) |\n| Service compatibility | After major upgrade (e.g., syncthing v1→v2), NSSM fails with service-specific error | [shawl-migration.md](./shawl-migration.md) |\n| Metadata | Runtime install succeeds + chocolatey `.nuspec` is stale (UniGetUI shows repeated upgrades) | [metadata-fix.md](./metadata-fix.md) |\n| Diagnosis | Identify which service has issues / which package is stale | [diagnose.md](./diagnose.md) |\n| Bulk post-processing | Automatically check affected services after choco upgrade | [post-upgrade.md](./post-upgrade.md) |\n\n## Path Strategy (HARD STOP — required decision before nssm set Application)\n\n| Strategy | Example Path | Pros | Cons |\n|----------|--------------|------|------|\n| **Stable shim path (recommended)** | `%ChocolateyInstall%\\bin\\syncthing.exe` | Path remains unchanged after choco upgrade | Without `--shimgen-waitforexit`, nssm may misinterpret shim exit as a crash |\n| Version-specific actual path | `%ChocolateyInstall%\\lib\\syncthing\\tools\\...-v2.1.0\\syncthing.exe` | No shim issues | **Path breaks on every upgrade** — this is why this skill exists |\n\n**Default choice: stable shim path.** Use version-specific path + post-upgrade hook combination only for services where shim issues occur. When NSSM compatibility itself breaks (like syncthing v2), apply [shawl-migration](./shawl-migration.md).\n\n### Using environment variable paths in nssm\n\nnssm supports `REG_EXPAND_SZ` but `nssm set` defaults to `REG_SZ`. Set registry directly via PowerShell:\n\n```powershell\n$regPath = \"HKLM:\\SYSTEM\\CurrentControlSet\\Services\\<service>\\Parameters\"\nSet-ItemProperty -Path $regPath -Name \"Application\" -Value '%ChocolateyInstall%\\bin\\<exe>' -Type ExpandString\n```\n\nOr use an expanded literal path:\n\n```bash\ngsudo nssm set <service> Application \"C:\\ProgramData\\chocolatey\\bin\\<exe>\"\n```\n\n## Topics\n\n| Topic | File | Description |\n|-------|------|-------------|\n| diagnose | [diagnose.md](./diagnose.md) | nssm service diagnosis procedure |\n| metadata-fix | [metadata-fix.md](./metadata-fix.md) | Recovery for UniGetUI/choco metadata (.nuspec) update failures |\n| post-upgrade | [post-upgrade.md](./post-upgrade.md) | Post-processing after choco upgrade |\n| shawl-migration | [shawl-migration.md](./shawl-migration.md) | NSSM → shawl migration (major upgrades like syncthing v2) |\n| update-path | [update-path.md](./update-path.md) | nssm path refresh |\n\n## Scripts\n\n| Mode | Command | Description |\n|------|---------|-------------|\n| diagnose | `node <skill-dir>/scripts/nssm-manager.js diagnose` | Check all nssm services |\n| update-path | `node <skill-dir>/scripts/nssm-manager.js update-path <service>` | Output path refresh command for a specific service |\n| post-upgrade | `node <skill-dir>/scripts/nssm-manager.js post-upgrade` | Full post-processing check |\n\n`<skill-dir>` = `~/.claude/skills/choco`\n\n**Note**: `node` may not be on PATH in bash. In an fnm environment, use the full path:\n\n```bash\n\"$APPDATA/fnm/node-versions/v20.20.0/installation/node.exe\" <skill-dir>/scripts/nssm-manager.js <mode>\n```\n\n## Administrator Privileges\n\n`nssm set/stop/start` and `choco upgrade` commands require administrator privileges. Per the Windows rule, **using `gsudo` is the default**:\n\n```bash\ngsudo choco upgrade <pkg> -y\ngsudo nssm set <service> Application \"<path>\"\n```\n\nOr invoke via the PowerShell tool:\n\n```powershell\ngsudo powershell -ExecutionPolicy Bypass -File \"<script.ps1>\"\n```\n\n## Topic Dependencies\n\n```text\nchoco (main workflow)\n  ├─→ diagnose (step 1 diagnosis)\n  ├─→ metadata-fix (recover stale choco/UniGetUI metadata)\n  ├─→ post-upgrade (bulk check after choco upgrade)\n  ├─→ update-path (nssm path refresh)\n  └─→ shawl-migration (NSSM → shawl migration)\n        └─→ shawl binary (~/.local/bin/shawl.exe, downloaded from GitHub releases)\n```\n\n- Simple path refresh → `update-path`\n- Major upgrade requiring nssm deprecation → `shawl-migration`\n- Runtime OK + only chocolatey metadata stale → `metadata-fix`\n- Multiple services in bulk → `diagnose` + `post-upgrade`\n\n## Self-heal\n\nThis skill is subject to self-improvement after execution.\nIf malfunction is detected, improve it via `/skill-kit upgrade choco`.\n\nChecklist:\n1. Are the trigger keywords in description sufficient?\n2. Was the topic selection accurate? (e.g., misrouting metadata stale to update-path)\n3. Was the procedure complete? (Was no manual correction needed?)\n4. Were there no omissions in the deliverables?\n\n## References\n\n- Previous skill: `choco-nssm` (absorbed into this skill, moved to `~/.claude/.bak/`)\n- [Chocolatey docs](https://docs.chocolatey.org/)\n- [UniGetUI repo](https://github.com/Devolutions/UniGetUI)\n- [shawl repo](https://github.com/mtkennerly/shawl)\n\nFile v1.0.2:_meta.json\n\n{\n  \"ownerId\": \"kn74k8yfvftx6f062qa8fzyd8h8373jd\",\n  \"slug\": \"choco\",\n  \"version\": \"1.0.2\",\n  \"publishedAt\": 1786008083191\n}\n\nFile v1.0.2:CHANGELOG.md\n\n# Changelog\n\n## [1.0.2](https://github.com/es6kr/skills/compare/choco-v1.0.1...choco-v1.0.2) (2026-08-05)\n\n\n### Bug Fixes\n\n* **wip:** cross-ref PR-URL and TaskCreate subject repo-qualifier rules ([#186](https://github.com/es6kr/skills/issues/186)) ([951c1e6](https://github.com/es6kr/skills/commit/951c1e6871e78e226757c6a7ae5ae53efeb7bfb0))\n\n## [1.0.1](https://github.com/es6kr/skills/compare/choco-v1.0.0...choco-v1.0.1) (2026-06-27)\n\n\n### Features\n\n* decompose workflow/git rules + rename web-ui-test→web-browser ([#50](https://github.com/es6kr/skills/issues/50)) ([e10d48f](https://github.com/es6kr/skills/commit/e10d48fea4e507b95888de44812b53484d32128d))\n\n\n### Bug Fixes\n\n* **fix:** split Step 2 medium by content type — case history to failed-attempts.md ([#62](https://github.com/es6kr/skills/issues/62)) ([747b3f9](https://github.com/es6kr/skills/commit/747b3f957ca0fefdbc5044eb08f66b8aafc1e26a))\n* **skills:** apply PR [#50](https://github.com/es6kr/skills/issues/50) Phase 2 follow-up reviews ([33863d7](https://github.com/es6kr/skills/commit/33863d705f8b24051b030b839487e8b5a8bfd9df))\n\n## [0.1.1](https://github.com/es6kr/skills/compare/choco-v0.1.0...choco-v0.1.1) (2026-06-25)\n\n\n### Bug Fixes\n\n* **fix:** split Step 2 medium by content type — case history to failed-attempts.md ([#62](https://github.com/es6kr/skills/issues/62)) ([747b3f9](https://github.com/es6kr/skills/commit/747b3f957ca0fefdbc5044eb08f66b8aafc1e26a))\n* **skills:** apply PR [#50](https://github.com/es6kr/skills/issues/50) Phase 2 follow-up reviews ([33863d7](https://github.com/es6kr/skills/commit/33863d705f8b24051b030b839487e8b5a8bfd9df))\n\n## 0.1.0 (2026-06-12)\n\n\n### Features\n\n* decompose workflow/git rules + rename web-ui-test→web-browser ([#50](https://github.com/es6kr/skills/issues/50)) ([e10d48f](https://github.com/es6kr/skills/commit/e10d48fea4e507b95888de44812b53484d32128d))\n\nFile v1.0.2:diagnose.md\n\n# nssm Service Diagnosis\n\n## When to Use\n\n- nssm service is in `SERVICE_PAUSED` or `SERVICE_STOPPED` state\n- Service behavior anomalies after choco upgrade\n- When a specific service won't start\n\n## Diagnosis Procedure\n\n### 1. Run the Script\n\n```bash\nnode scripts/nssm-manager.js diagnose\n```\n\nOutput content:\n- List of all nssm services\n- Status of each service (RUNNING/STOPPED/PAUSED)\n- Shim status (chocolatey\\bin path = shim)\n- Actual binary location (inside choco lib)\n- List of commands required for fixes\n\n### 2. Manual Diagnosis (if script fails)\n\n```bash\n# Service status\nnssm status <service>\n\n# Registered path\nnssm get <service> Application\n\n# Actual binary location\nls \"C:/ProgramData/chocolatey/lib/<package>/tools/\"\n```\n\n### 3. Shim Identification Criteria\n\n| Path | Type | Service Behavior |\n|------|------|------------------|\n| `chocolatey\\bin\\*.exe` | shim (wrapper) | High failure likelihood |\n| `chocolatey\\lib\\*\\tools\\*\\*.exe` | actual binary | Normal |\n| Other paths | direct install | Normal |\n\n## Output Interpretation\n\n- `Shim: YES` → Path refresh required via update-path topic\n- `Shim: NO` → Investigate other causes (check logs, port conflicts, etc.)\n- `Actual binary: not found` → Package was removed or structure changed\n\nFile v1.0.2:metadata-fix.md\n\n# Chocolatey Metadata Update Failure Fix\n\nDiagnosis and recovery procedure for cases where **the runtime/installer succeeds but the chocolatey metadata (`.nuspec`) update fails** after invoking UniGetUI or choco upgrade.\n\n## Background\n\nStarting from UniGetUI 2026.1.7, the chocolatey bundle was removed and it became a passthrough to the system `choco`. Since UniGetUI only displays the results of `choco list`, metadata update failure is the **responsibility of chocolatey**.\n\nRelated issues:\n- [Devolutions/UniGetUI#4803](https://github.com/Devolutions/UniGetUI/issues/4803) — Inconsistent chocolatey packages since 2026.1.7\n- [Devolutions/UniGetUI#4801](https://github.com/Devolutions/UniGetUI/issues/4801) — Wrong information about installed programs (2026.1.10)\n- [Devolutions/UniGetUI#3708](https://github.com/Devolutions/UniGetUI/issues/3708) — choco.exe hang on update check\n- [Devolutions/UniGetUI#4217](https://github.com/Devolutions/UniGetUI/issues/4217) — Chocolatey shown as ready on MS Store install\n\n## Symptoms\n\n| Symptom | Meaning |\n|---------|---------|\n| \"Upgrade available\" indication persists in UniGetUI | `choco list` returns old version |\n| `choco list <pkg>` shows old version, actual EXE is new version | Only `.nuspec` is stale |\n| Same package keeps appearing in `choco outdated` | Metadata stage exits abnormally |\n| choco exits abnormally after \"already installed\" in installer log | Package stage may be skipped |\n\n## Diagnosis Procedure\n\n### 1. Compare Metadata vs Actual Version\n\n```bash\n# Version recognized by chocolatey\nchoco list <pkg>\n\n# Metadata version in .nuspec\ngrep -i version \"C:\\ProgramData\\chocolatey\\lib\\<pkg>\\<pkg>.nuspec\" | head -1\n\n# Actual installed runtime version (e.g., vcredist140)\nreg query \"HKLM\\SOFTWARE\\Microsoft\\VisualStudio\\14.0\\VC\\Runtimes\\x64\" /v Version 2>&1 | grep Version\n```\n\nIf the three values diverge, metadata stale is confirmed.\n\n### 2. Verify with choco outdated\n\n```bash\nchoco outdated 2>&1 | grep -E \"^[a-zA-Z0-9_-]+\\|\"\n```\n\nOutput line: `<pkg>|<current metadata>|<remote latest>|<pinned>`. Suspect if metadata differs from external systems (WMI/registry).\n\n## Recovery Procedure\n\n### 1. Force Resync (default)\n\n```bash\n# Invoke via PowerShell tool (bypass Bash escape)\ngsudo choco upgrade <pkg> -y\n```\n\nAfter success, verify version match with `choco list <pkg>`.\n\n### 2. Use --force (when 1 has no effect)\n\n```bash\ngsudo choco upgrade <pkg> -y --force\n```\n\n`--force` re-runs the package stage even if already at the latest version to update `.nuspec`.\n\n### 3. Bulk Update\n\n```bash\ngsudo choco upgrade all -y\n```\n\nCleans up large amounts of outdated entries. Effective when UniGetUI has accumulated stale indicators.\n\n### 4. Manual nuspec Patch (last resort)\n\nIf choco refuses to update for any reason, directly modify the `<version>` node in `.nuspec`. **Not recommended** — risk of being overwritten by the next upgrade or causing dependency mismatch.\n\n## Don't / Do Table\n\n| # | Don't | Do |\n|---|-------|-----|\n| 1 | Repeatedly upgrade the same package in UniGetUI GUI | Run `gsudo choco upgrade <pkg> -y` directly in an elevated terminal |\n| 2 | Directly edit `.nuspec` when suspecting metadata stale | Use `--force` so chocolatey performs a proper update |\n| 3 | File an issue in the UniGetUI repository | UniGetUI is a passthrough — report to chocolatey-core (chocolatey/choco) or the package maintainer |\n| 4 | Invoke `choco upgrade` from Bash (without elevation) | PowerShell tool + `gsudo` or administrator PowerShell |\n| 5 | Conclude success from the `choco upgrade` output line alone | Immediately cross-verify with `choco list <pkg>` + `.nuspec` version |\n\n## Self-check (every time a UniGetUI/choco metadata stale report is received)\n\n1. Compare three values: `choco list <pkg>` + `.nuspec` version + actual runtime version\n2. All three match → possible UniGetUI cache issue. Restart UniGetUI or refresh the package\n3. Only choco metadata and .nuspec are stale → `gsudo choco upgrade <pkg> -y`\n4. If step 1 has no effect → `gsudo choco upgrade <pkg> -y --force`\n5. If step 4 also fails → report an issue to the package maintainer (chocolatey.org package page)\n\n## Violation / Application Cases\n\n**2026-05-21 (1st occurrence)**: vcredist140 14.51.36231 → 14.51.36247 metadata update failure. UniGetUI repeatedly attempted updates but the system runtime was already 14.51.36247. `gsudo choco upgrade vcredist140 -y` completed the .nuspec update at once. The log shows `Runtime for architecture x64 version 14.51.36247 is already installed` — a case where only the package stage needed updating.\n\n## References\n\n- [UniGetUI repo](https://github.com/Devolutions/UniGetUI)\n- [chocolatey/choco repo](https://github.com/chocolatey/choco)\n- \"choco metadata\" keyword in `~/.claude/skills/cleanup/data/failed-attempts.md` (if present)\n\nFile v1.0.2:post-upgrade.md\n\n# choco upgrade Post-Processing\n\n## When to Use\n\n- After running `choco upgrade all`\n- After upgrading specific packages, to check services\n\n## Procedure\n\n### 1. Run Full Check\n\n```bash\nnode scripts/nssm-manager.js post-upgrade\n```\n\nOutput:\n- One-line summary of shim status for all nssm services\n- List of services requiring updates\n- Administrator PowerShell commands (bulk/individual)\n\n### 2. Run Update Commands\n\nExecute the commands output by the script with administrator privileges:\n\n```bash\n# Bulk execution (the \"Administrator PowerShell commands\" section from script output)\npowershell -Command \"Start-Process powershell -ArgumentList '-Command', '<commands>' -Verb RunAs -Wait\"\n```\n\n### 3. Check Service Status\n\n```bash\nnssm status <service>\n```\n\n## Check Targets\n\nThe script automatically finds nssm-managed services in `Win32_Service` and checks them:\n- All services where `BINARY_PATH_NAME` contains `nssm`\n- Verifies whether each service's Application path is a shim\n- If shim, searches choco lib for the actual binary\n\n## Notes\n\n- Administrator privileges required (UAC prompt)\n- If services are already healthy right after upgrade, refresh is unnecessary\n- Binary location may differ per package (within tools/ subfolders)\n\nFile v1.0.2:shawl-migration.md\n\n# nssm → shawl Migration\n\n## Background\n\nNSSM is flagged as malware by some security solutions, so starting from syncthing v2 the official Windows Setup transitioned to **shawl**. During major upgrades (v1→v2), the existing nssm registration causes the following problems:\n\n| Symptom | Cause |\n|---------|-------|\n| `service-specific error 3` (path not found) | LocalSystem/user context difference makes `%LOCALAPPDATA%\\Syncthing` inaccessible |\n| `service-specific error 3547` | nssm service times out during syncthing v2's SQLite migration |\n| Dies immediately on start, no entry in syncthing log | nssm lacks LOAD_USER_PROFILE → cannot find home directory |\n| v2.0.4+ migration re-runs on every restart | issue [#10340](https://github.com/syncthing/syncthing/issues/10340) |\n\n## Applicable Cases\n\n- nssm service start failure after syncthing v1.x → v2.x major upgrade\n- Environments where NSSM is blocked as malware\n- Other chocolatey packages with similar service model changes (same compatibility pattern)\n\n## Prerequisites\n\nVerify the shawl binary (`~/.local/bin/shawl.exe`) is available:\n\n```bash\n~/.local/bin/shawl.exe --version\n```\n\nIf not installed → download from GitHub releases and place in `~/.local/bin/`:\n\n```bash\nmkdir -p ~/.local/bin && cd /tmp\ncurl -sL https://github.com/mtkennerly/shawl/releases/latest/download/shawl-v1.9.0-win64.zip -o shawl.zip\nunzip -o shawl.zip\nmv shawl.exe ~/.local/bin/\nrm shawl.zip\n```\n\n(Based on v1.9.0. Query latest version via `https://api.github.com/repos/mtkennerly/shawl/releases/latest`)\n\n## Migration Procedure\n\n### 1. Diagnosis — Extract All Existing Service Settings (HARD STOP)\n\nBefore migration, extract all settings of the existing service to **preserve them as-is during shawl re-registration**. Applies the `common.md` \"user-specified value change prohibition\" rule.\n\n```bash\nsc query <service>             # Check SERVICE_STOPPED + error code\nnssm get <service> Application # Current path\nnssm get <service> AppParameters\nnssm get <service> ObjectName  # ⚠️ Execution account — preservation target\nnssm get <service> AppDirectory\nnssm get <service> AppStdout   # Preserve log path\nnssm get <service> AppStderr\nsc qc <service>                # ObjectName fallback (admin required)\ntasklist | grep <service>      # Lingering processes\nnetstat -ano | grep \":<port>\"  # Port occupation\n```\n\n**Record extracted values (required)**: Preserve each value as a variable for use in the next step. Especially if `ObjectName` is not `LocalSystem`, specify the user account explicitly. Even if it is `LocalSystem`, services synchronizing user data like syncthing are recommended to use a user account (see \"3. Determining Execution Account\" below).\n\nRun directly in the console to verify the syncthing binary itself is healthy:\n\n```bash\n\"<app-path>\" --no-console --no-browser\n```\n\nConsole runs fine + service fails → this topic applies.\n\n### 2. Migration Script (PowerShell, Administrator)\n\n```powershell\n$ErrorActionPreference = \"Continue\"\n\n$serviceName = \"syncthing\"\n$shawlExe = \"$env:USERPROFILE\\.local\\bin\\shawl.exe\"\n$appExe = \"C:\\ProgramData\\chocolatey\\bin\\syncthing.exe\"\n$homePath = \"$env:USERPROFILE\\AppData\\Local\\Syncthing\"\n\n# ⚠️ Values extracted in diagnosis step — must be filled in by the user\n$objectName = \".\\<USERNAME>\"        # Same as the existing nssm ObjectName. If LocalSystem, replace with a user account for user-data services like syncthing\n$objectPassword = \"<USER_PASSWORD>\" # User's Windows password (don't hardcode plaintext in scripts — use SecureString or prompt for input)\n\n# 1. Stop and remove existing nssm service\nsc.exe stop $serviceName\nStart-Sleep -Seconds 2\nnssm.exe remove $serviceName confirm\n\n# 2. Re-register with shawl (specify --home: access user config)\n& $shawlExe add --name $serviceName -- $appExe --no-browser --home=$homePath\n\n# 3. Configure ObjectName + LOAD_USER_PROFILE (preserve user account)\nif ($objectName -ne \"LocalSystem\") {\n    sc.exe config $serviceName obj= \"$objectName\" password= \"$objectPassword\"\n    sc.exe privs $serviceName SeBackupPrivilege/SeRestorePrivilege/SeAssignPrimaryTokenPrivilege  # if needed\n}\n\n# 4. Start\nsc.exe start $serviceName\nStart-Sleep -Seconds 8\n\n# 5. Verify (validate StartName preservation)\nsc.exe query $serviceName\nGet-CimInstance Win32_Service -Filter \"Name='$serviceName'\" | Format-List Name,State,StartName,PathName\nnetstat -an | Select-String \"8384\"\n```\n\nSave the script to `C:\\Users\\<user>\\migrate-<service>-to-shawl.ps1`, then:\n\n```bash\n# Bash tool breaks -File argument due to backslash escape issues → use PowerShell tool directly\n# In PowerShell tool:\ngsudo powershell -ExecutionPolicy Bypass -File \"C:\\Users\\<user>\\migrate-<service>-to-shawl.ps1\"\n```\n\n### 3. Determining Execution Account (HARD STOP — preserving existing ObjectName is the top priority)\n\n**Default principle**: Preserve the `ObjectName` extracted in the diagnosis step as-is. Changes only on explicit user instruction.\n\n| Service Type | Recommended Account | Reason |\n|--------------|---------------------|--------|\n| **User data sync/consume** (Syncthing, Dropbox, Resilio Sync, OneDrive, etc.) | `.\\<USERNAME>` | The owner/permission of synced files is the user. Running as LocalSystem risks owner mismatch, permission denied, and file hash changes |\n| **System daemon** (DB, web server, monitoring agent, etc.) | `LocalSystem` or `NT SERVICE\\<name>` | Independent of user context. No password management needed |\n| **GUI-dependent tools** | User account + `Interactive` (not recommended) | Requires user logon session — prefer daemon mode if possible |\n\n#### Don't / Do\n\n| # | Don't | Do |\n|---|-------|-----|\n| 1 | Leave shawl re-registration at LocalSystem (default) when existing nssm `ObjectName=.\\USERNAME` | Specify the extracted value (`.\\USERNAME`) explicitly via `sc.exe config obj=` |\n| 2 | Assume \"LocalSystem + `--home` specification\" can serve as a workaround | `--home` only resolves config path — ownership/ACL problems of synced files are separate. User account execution is the proper fix |\n| 3 | Hardcode plaintext password in script | Use `Read-Host -AsSecureString` or Group Managed Service Account (gMSA). If you must hardcode plaintext, apply `chmod 600` or `.gitignore` + remove immediately |\n| 4 | Fail to update credentials when user password changes → service fails to start | Immediately update via `sc.exe config <svc> password= <new_pw>`. Be aware of Windows password rotation policy |\n\n#### Verification After User Account Registration\n\n```powershell\nGet-CimInstance Win32_Service -Filter \"Name='syncthing'\" | Select-Object Name,State,StartName\n# StartName should display as .\\<USERNAME>. If LocalSystem, registration failed\n```\n\nAfter the service runs, verify in the syncthing GUI (`http://localhost:8384`) that sync folders scan correctly + new files created have the user account as owner.\n\n## Don't / Do Table\n\n| # | Don't | Do |\n|---|-------|-----|\n| 1 | Keep using nssm after v1→v2 major upgrade | Migrate to shawl (especially syncthing v2+) |\n| 2 | LocalSystem account + omit `--home` | Specify `--home=\"C:\\Users\\<u>\\AppData\\Local\\Syncthing\"` |\n| 2b | Skip extracting existing ObjectName before migration | Mandatory `nssm get <svc> ObjectName` in diagnosis step + use that value for shawl re-registration |\n| 2c | Register user data sync services as LocalSystem | Specify the `.\\USERNAME` user account. Preserve owner/permission |\n| 3 | Attempt to install shawl via scoop/choco | No scoop manifest, no choco package. Download directly from GitHub releases |\n| 4 | Call `gsudo powershell -File C:\\...` directly from Bash | Bash escape breaks backslashes. Use PowerShell tool or `/c/Users/...` path |\n| 5 | Forget to escape arguments in shawl add | Pass execution command as-is after the `--` separator. shawl preserves raw args |\n\n## Applying to Other Packages\n\nThe same pattern (major upgrade + service model change) can occur in other chocolatey packages and use the same procedure:\n\n- syncthing (case above, v1→v2)\n- Other packages that changed service models (add to this section when cases are found)\n\n## Follow-up Case — choco upgrade also Removes shawl Service (HARD STOP)\n\n**Phenomenon**: With syncthing service registered via shawl, running `choco upgrade syncthing` → after the new version installs, the service disappears. `sc query syncthing` returns `service does not exist`.\n\n**Cause**: The chocolatey syncthing package's `chocolateyBeforeModify.ps1` assumes nssm when a Windows service named \"syncthing\" exists, and calls stop/remove. Removal happens by name match, regardless of the registration tool (nssm vs shawl).\n\n**Mitigation — always check service existence after choco upgrade**:\n\n```bash\nsc query syncthing 2>&1 | grep -E \"SERVICE_NAME|STATE\"\n# Empty result → re-registration needed\n```\n\nOne-time re-registration script (skip only the nssm remove step in shawl-migration.md \"2. Migration Script\"):\n\n```powershell\n$shawlExe = \"$env:USERPROFILE\\.local\\bin\\shawl.exe\"\n$appExe = \"C:\\ProgramData\\chocolatey\\bin\\syncthing.exe\"\n$homePath = \"$env:USERPROFILE\\AppData\\Local\\Syncthing\"\n\n& $shawlExe add --name syncthing -- $appExe --no-browser --home=$homePath\nsc.exe start syncthing\n```\n\n**Root solution (TODO)**: When registering with shawl, rename the service (e.g., `syncthing-shawl`) to avoid conflict with chocolateyBeforeModify's nssm assumption. However, GUI environment variables and existing automation may depend on the `syncthing` name, so compatibility review is required.\n\n## Violation Cases\n\n**2026-05-21 (1st occurrence)**: On a Windows machine, syncthing 2.1.0 nssm service immediately failed with service-specific error 3. Console syncthing.exe started normally (PID 28208, 8384 LISTENING). Initially suspected nssm shim path / user password, but the actual cause was v1→v2 major compatibility. Resolved via shawl migration:\n- nssm remove syncthing confirm\n- shawl add --name syncthing -- syncthing.exe --no-browser --home=...AppData\\Local\\Syncthing\n- Service RUNNING + 8384 LISTENING recovery complete.\n\n**2026-05-21 (2nd occurrence)**: Immediately after the 1st migration in the same session, `choco upgrade` or auto-upgrade transitioned syncthing 2.1.0 → 2.1.1. The shawl service was automatically removed by chocolateyBeforeModify. `sc query` showed service does not exist. Recovered via re-registration. → Created the \"Follow-up Case\" section in this topic.\n\n**2026-05-21 (3rd occurrence)**: During 1st/2nd shawl re-registration, the existing nssm `ObjectName=.\\<USERNAME>` was not extracted/preserved and was registered with the default LocalSystem. Risk of owner/permission mismatch for services like syncthing that sync user data. User pointed out \"registered with the wrong user\". Reinforced by adding ObjectName extraction in the diagnosis step + `sc.exe config obj=` step in the migration script + restructuring the execution account decision table.\n\n## References\n\n- [Syncthing v2.0 release notes](https://github.com/syncthing/syncthing/releases/tag/v2.0.0)\n- [Syncthing v2 forum migration thread](https://forum.syncthing.net/t/syncthing-2-0-august-2025/24758)\n- [shawl GitHub](https://github.com/mtkennerly/shawl)\n- [issue #10340 — re-migrate every start](https://github.com/syncthing/syncthing/issues/10340)\n\nFile v1.0.2:skill-card.md\n\n## Description:\n\nProvides Chocolatey operations guidance for post-upgrade checks, NSSM service path refresh, NSSM-to-shawl migration, and UniGetUI or Chocolatey metadata update recovery.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[drumrobot](https://clawhub.ai/user/drumrobot)\n\n### License/Terms of Use:\n\nMIT\n\n## Use Case:\n\nDevelopers, engineers, and Windows operators use this skill to diagnose and repair Chocolatey upgrade side effects, especially stale NSSM service paths, NSSM-to-shawl migration cases, and stale Chocolatey package metadata.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Administrator-level Chocolatey and Windows service commands can make broad system changes.\n\nMitigation: Confirm the package or service name and intended admin scope before running generated commands.\n\nRisk: Bulk upgrades and service stop/start operations can disrupt running workloads.\n\nMitigation: Use a maintenance window, and avoid `choco upgrade all -y` unless a system-wide upgrade is intended.\n\nRisk: Service migration guidance may involve Windows account credentials.\n\nMitigation: Use prompted or secure credential handling, and do not paste or store Windows passwords in scripts or chat logs.\n\n## Reference(s):\n\n- [Chocolatey Documentation](https://docs.chocolatey.org/)\n- [UniGetUI Repository](https://github.com/Devolutions/UniGetUI)\n- [shawl Repository](https://github.com/mtkennerly/shawl)\n- [Chocolatey CLI Repository](https://github.com/chocolatey/choco)\n- [Syncthing issue 10340](https://github.com/syncthing/syncthing/issues/10340)\n\n## Skill Output:\n\n**Output Type(s):** [guidance, shell commands, configuration, code]\n\n**Output Format:** [Markdown with inline shell, PowerShell, and JSON code blocks]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [May include generated administrator commands and diagnostic JSON for Windows service operations.]\n\n## Skill Version(s):\n\n1.0.2 (source: frontmatter, CHANGELOG, server release metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nFile v1.0.2:update-path.md\n\n# nssm Path Refresh\n\n## When to Use\n\n- When refreshing the path of a specific service detected as a shim by diagnose\n- When the existing binary path no longer exists after choco upgrade because the version folder changed (stale path)\n\n## Procedure\n\n### 1. Check Refresh Command\n\n```bash\nnode scripts/nssm-manager.js update-path <service-name>\n```\n\nJSON output:\n```json\n{\n  \"service\": \"syncthing\",\n  \"current\": \"C:\\\\ProgramData\\\\chocolatey\\\\bin\\\\syncthing.exe\",\n  \"actual\": \"C:\\\\ProgramData\\\\chocolatey\\\\lib\\\\syncthing\\\\tools\\\\syncthing-windows-amd64-v2.0.15\\\\syncthing.exe\",\n  \"commands\": [\n    \"nssm stop \\\"syncthing\\\"\",\n    \"nssm set \\\"syncthing\\\" Application \\\"...actual path...\\\"\",\n    \"nssm start \\\"syncthing\\\"\"\n  ]\n}\n```\n\n### 2. Run with Administrator Privileges\n\n```bash\npowershell -Command \"Start-Process powershell -ArgumentList '-Command', 'nssm stop \\\"<svc>\\\"; nssm set \\\"<svc>\\\" Application \\\"<actual-path>\\\"; nssm start \\\"<svc>\\\"' -Verb RunAs -Wait\"\n```\n\n### 3. Verify\n\n```bash\nnssm status <service>\nnssm get <service> Application\n```\n\n## Path Selection Strategy\n\n### Stable Shim Path (recommended)\n\n`%ChocolateyInstall%\\bin\\<exe>` — Path remains unchanged after choco upgrade.\n\n```bash\ngsudo nssm set <service> Application \"C:\\ProgramData\\chocolatey\\bin\\<exe>\"\n```\n\nUse the version-specific actual path only when the shim conflicts with the service (immediate process termination → nssm misinterprets as crash).\n\n### Version-Specific Actual Path (only when shim conflicts)\n\n`chocolatey\\lib\\*\\tools\\*` — Stable, but **breaks on every upgrade**. Using this path requires a post-upgrade hook.\n\n## Path Change Pattern During Version Upgrades\n\n```\nv1.27.x: chocolatey\\lib\\syncthing\\tools\\syncthing-windows-amd64-v1.27.x\\syncthing.exe\nv2.0.15: chocolatey\\lib\\syncthing\\tools\\syncthing-windows-amd64-v2.0.15\\syncthing.exe\nv2.0.16: chocolatey\\lib\\syncthing\\tools\\syncthing-windows-amd64-v2.0.16\\syncthing.exe\n```\n\nFolder name changes with each version, requiring refresh every time.\n\n### Real Case: syncthing v2.0.15 → v2.0.16 (2026-04-30)\n\n- After `choco upgrade syncthing`, NSSM pointed to the v2.0.15 path → `SERVICE_STOPPED`\n- Not a shim, but the **previous version's path of the actual binary** — undetectable by `isChocoShim()`\n- Resolved by adding `isStaleChocoPath()`: if a path under `chocolatey\\lib\\` exists but the file does not, it is treated as stale\n\nFile v1.0.2:LICENSE\n\nMIT License\n\nCopyright (c) 2026 es6.kr\n\nPermission is hereby granted, free of charge, to any person obtaining a copy\nof this software and associated documentation files (the \"Software\"), to deal\nin the Software without restriction, including without limitation the rights\nto use, copy, modify, merge, publish, distribute, sublicense, and/or sell\ncopies of the Software, and to permit persons to whom the Software is\nfurnished to do so, subject to the following conditions:\n\nThe above copyright notice and this permission notice shall be included in all\ncopies or substantial portions of the Software.\n\nTHE SOFTWARE IS PROVIDED \"AS IS\", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR\nIMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,\nFITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE\nAUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER\nLIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,\nOUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE\nSOFTWARE.\n\nArchive v1.0.1: 10 files, 17138 bytes\n\nFiles: CHANGELOG.md (793b), diagnose.md (1257b), metadata-fix.md (4840b), post-upgrade.md (1240b), scripts/nssm-manager.js (7503b), shawl-migration.md (11270b), skill-card.md (2993b), SKILL.md (5995b), update-path.md (2382b), _meta.json (124b)\n\nFile v1.0.1:SKILL.md\n\n---\nname: choco\nmetadata:\n  author: es6kr\n  version: \"0.0.0\"\ndescription: |\n  Chocolatey operations integration — post-processing after choco upgrade, nssm service path refresh, NSSM → shawl migration (syncthing v2 etc.), resync on UniGetUI/choco metadata update failures. diagnose [diagnose.md], metadata-fix [metadata-fix.md], post-upgrade [post-upgrade.md], shawl-migration [shawl-migration.md], update-path [update-path.md].\n  Use when: \"choco\", \"chocolatey\", \"choco upgrade\", \"choco outdated\", \"vcredist\", \"nssm\", \"nssm recovery\", \"nssm path\", \"service path refresh\", \"after choco upgrade\", \"service failure\", \"SERVICE_STOPPED\", \"shim issue\", \"syncthing nssm\", \"syncthing v2\", \"shawl migration\", \"nssm deprecation\", \"service-specific error\", \"UniGetUI\", \"metadata update failure\", \"metadata stale\", \".nuspec stale\", \"choco metadata\".\n---\n\n# Choco\n\nChocolatey operations integration skill. Pre- and post-processing for choco upgrade, nssm service compatibility management, and metadata update failure recovery.\n\n## Core Problems\n\n| Area | Problem | Resolution Topic |\n|------|---------|------------------|\n| Package path | After choco upgrade, the nssm Application path becomes stale due to version-specific folders | [update-path.md](./update-path.md) |\n| Service compatibility | After major upgrade (e.g., syncthing v1→v2), NSSM fails with service-specific error | [shawl-migration.md](./shawl-migration.md) |\n| Metadata | Runtime install succeeds + chocolatey `.nuspec` is stale (UniGetUI shows repeated upgrades) | [metadata-fix.md](./metadata-fix.md) |\n| Diagnosis | Identify which service has issues / which package is stale | [diagnose.md](./diagnose.md) |\n| Bulk post-processing | Automatically check affected services after choco upgrade | [post-upgrade.md](./post-upgrade.md) |\n\n## Path Strategy (HARD STOP — required decision before nssm set Application)\n\n| Strategy | Example Path | Pros | Cons |\n|----------|--------------|------|------|\n| **Stable shim path (recommended)** | `%ChocolateyInstall%\\bin\\syncthing.exe` | Path remains unchanged after choco upgrade | Without `--shimgen-waitforexit`, nssm may misinterpret shim exit as a crash |\n| Version-specific actual path | `%ChocolateyInstall%\\lib\\syncthing\\tools\\...-v2.1.0\\syncthing.exe` | No shim issues | **Path breaks on every upgrade** — this is why this skill exists |\n\n**Default choice: stable shim path.** Use version-specific path + post-upgrade hook combination only for services where shim issues occur. When NSSM compatibility itself breaks (like syncthing v2), apply [shawl-migration](./shawl-migration.md).\n\n### Using environment variable paths in nssm\n\nnssm supports `REG_EXPAND_SZ` but `nssm set` defaults to `REG_SZ`. Set registry directly via PowerShell:\n\n```powershell\n$regPath = \"HKLM:\\SYSTEM\\CurrentControlSet\\Services\\<service>\\Parameters\"\nSet-ItemProperty -Path $regPath -Name \"Application\" -Value '%ChocolateyInstall%\\bin\\<exe>' -Type ExpandString\n```\n\nOr use an expanded literal path:\n\n```bash\ngsudo nssm set <service> Application \"C:\\ProgramData\\chocolatey\\bin\\<exe>\"\n```\n\n## Topics\n\n| Topic | File | Description |\n|-------|------|-------------|\n| diagnose | [diagnose.md](./diagnose.md) | nssm service diagnosis procedure |\n| metadata-fix | [metadata-fix.md](./metadata-fix.md) | Recovery for UniGetUI/choco metadata (.nuspec) update failures |\n| post-upgrade | [post-upgrade.md](./post-upgrade.md) | Post-processing after choco upgrade |\n| shawl-migration | [shawl-migration.md](./shawl-migration.md) | NSSM → shawl migration (major upgrades like syncthing v2) |\n| update-path | [update-path.md](./update-path.md) | nssm path refresh |\n\n## Scripts\n\n| Mode | Command | Description |\n|------|---------|-------------|\n| diagnose | `node <skill-dir>/scripts/nssm-manager.js diagnose` | Check all nssm services |\n| update-path | `node <skill-dir>/scripts/nssm-manager.js update-path <service>` | Output path refresh command for a specific service |\n| post-upgrade | `node <skill-dir>/scripts/nssm-manager.js post-upgrade` | Full post-processing check |\n\n`<skill-dir>` = `~/.claude/skills/choco`\n\n**Note**: `node` may not be on PATH in bash. In an fnm environment, use the full path:\n\n```bash\n\"$APPDATA/fnm/node-versions/v20.20.0/installation/node.exe\" <skill-dir>/scripts/nssm-manager.js <mode>\n```\n\n## Administrator Privileges\n\n`nssm set/stop/start` and `choco upgrade` commands require administrator privileges. Per the Windows rule, **using `gsudo` is the default**:\n\n```bash\ngsudo choco upgrade <pkg> -y\ngsudo nssm set <service> Application \"<path>\"\n```\n\nOr invoke via the PowerShell tool:\n\n```powershell\ngsudo powershell -ExecutionPolicy Bypass -File \"<script.ps1>\"\n```\n\n## Topic Dependencies\n\n```text\nchoco (main workflow)\n  ├─→ diagnose (step 1 diagnosis)\n  ├─→ metadata-fix (recover stale choco/UniGetUI metadata)\n  ├─→ post-upgrade (bulk check after choco upgrade)\n  ├─→ update-path (nssm path refresh)\n  └─→ shawl-migration (NSSM → shawl migration)\n        └─→ shawl binary (~/.local/bin/shawl.exe, downloaded from GitHub releases)\n```\n\n- Simple path refresh → `update-path`\n- Major upgrade requiring nssm deprecation → `shawl-migration`\n- Runtime OK + only chocolatey metadata stale → `metadata-fix`\n- Multiple services in bulk → `diagnose` + `post-upgrade`\n\n## Self-heal\n\nThis skill is subject to self-improvement after execution.\nIf malfunction is detected, improve it via `/skill-kit upgrade choco`.\n\nChecklist:\n1. Are the trigger keywords in description sufficient?\n2. Was the topic selection accurate? (e.g., misrouting metadata stale to update-path)\n3. Was the procedure complete? (Was no manual correction needed?)\n4. Were there no omissions in the deliverables?\n\n## References\n\n- Previous skill: `choco-nssm` (absorbed into this skill, moved to `~/.claude/.bak/`)\n- [Chocolatey docs](https://docs.chocolatey.org/)\n- [UniGetUI repo](https://github.com/Devolutions/UniGetUI)\n- [shawl repo](https://github.com/mtkennerly/shawl)\n\nFile v1.0.1:_meta.json\n\n{\n  \"ownerId\": \"kn74k8yfvftx6f062qa8fzyd8h8373jd\",\n  \"slug\": \"choco\",\n  \"version\": \"1.0.1\",\n  \"publishedAt\": 1782493430949\n}\n\nFile v1.0.1:CHANGELOG.md\n\n# Changelog\n\n## [1.0.1](https://github.com/es6kr/skills/compare/choco-v1.0.0...choco-v1.0.1) (2026-06-25)\n\n\n### Bug Fixes\n\n* **fix:** split Step 2 medium by content type — case history to failed-attempts.md ([#62](https://github.com/es6kr/skills/issues/62)) ([747b3f9](https://github.com/es6kr/skills/commit/747b3f957ca0fefdbc5044eb08f66b8aafc1e26a))\n* **skills:** apply PR [#50](https://github.com/es6kr/skills/issues/50) Phase 2 follow-up reviews ([33863d7](https://github.com/es6kr/skills/commit/33863d705f8b24051b030b839487e8b5a8bfd9df))\n\n## 1.0.0 (2026-06-12)\n\n\n### Features\n\n* decompose workflow/git rules + rename web-ui-test→web-browser ([#50](https://github.com/es6kr/skills/issues/50)) ([e10d48f](https://github.com/es6kr/skills/commit/e10d48fea4e507b95888de44812b53484d32128d))\n\nFile v1.0.1:diagnose.md\n\n# nssm Service Diagnosis\n\n## When to Use\n\n- nssm service is in `SERVICE_PAUSED` or `SERVICE_STOPPED` state\n- Service behavior anomalies after choco upgrade\n- When a specific service won't start\n\n## Diagnosis Procedure\n\n### 1. Run the Script\n\n```bash\nnode scripts/nssm-manager.js diagnose\n```\n\nOutput content:\n- List of all nssm services\n- Status of each service (RUNNING/STOPPED/PAUSED)\n- Shim status (chocolatey\\bin path = shim)\n- Actual binary location (inside choco lib)\n- List of commands required for fixes\n\n### 2. Manual Diagnosis (if script fails)\n\n```bash\n# Service status\nnssm status <service>\n\n# Registered path\nnssm get <service> Application\n\n# Actual binary location\nls \"C:/ProgramData/chocolatey/lib/<package>/tools/\"\n```\n\n### 3. Shim Identification Criteria\n\n| Path | Type | Service Behavior |\n|------|------|------------------|\n| `chocolatey\\bin\\*.exe` | shim (wrapper) | High failure likelihood |\n| `chocolatey\\lib\\*\\tools\\*\\*.exe` | actual binary | Normal |\n| Other paths | direct install | Normal |\n\n## Output Interpretation\n\n- `Shim: YES` → Path refresh requi","readmeExcerpt":"Skill: choco Owner: drumrobot Summary: Chocolatey operations integration — post-processing after choco upgrade, nssm service path refresh, NSSM → shawl migration (syncthing v2 etc.), resync on UniGetUI/choco metadata update failures. diagnose [diagnose.md], metadata-fix [metadata-fix.md], post-upgrade [post-upgrade.md], shawl-migration [shawl-migration.md], update-path [update-path.md]. Use when: \"choco\", \"chocolatey","codeSnippets":[],"executableExamples":[{"language":"powershell","snippet":"$regPath = \"HKLM:\\SYSTEM\\CurrentControlSet\\Services\\<service>\\Parameters\"\nSet-ItemProperty -Path $regPath -Name \"Application\" -Value '%ChocolateyInstall%\\bin\\<exe>' -Type ExpandString"},{"language":"bash","snippet":"gsudo nssm set <service> Application \"C:\\ProgramData\\chocolatey\\bin\\<exe>\""},{"language":"bash","snippet":"\"$APPDATA/fnm/node-versions/v20.20.0/installation/node.exe\" <skill-dir>/scripts/nssm-manager.js <mode>"},{"language":"bash","snippet":"gsudo choco upgrade <pkg> -y\ngsudo nssm set <service> Application \"<path>\""},{"language":"powershell","snippet":"gsudo powershell -ExecutionPolicy Bypass -File \"<script.ps1>\""},{"language":"text","snippet":"choco (main workflow)\n  ├─→ diagnose (step 1 diagnosis)\n  ├─→ metadata-fix (recover stale choco/UniGetUI metadata)\n  ├─→ post-upgrade (bulk check after choco upgrade)\n  ├─→ update-path (nssm path refresh)\n  └─→ shawl-migration (NSSM → shawl migration)\n        └─→ shawl binary (~/.local/bin/shawl.exe, downloaded from GitHub releases)"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: choco\nmetadata:\n  author: es6kr\n  version: \"1.0.5\" # x-release-please-version\ndescription: |\n  Chocolatey operations integration — post-processing after choco upgrade, nssm service path refresh, NSSM → shawl migration (syncthing v2 etc.), resync on UniGetUI/choco metadata update failures. diagnose [diagnose.md], metadata-fix [metadata-fix.md], post-upgrade [post-upgrade.md], shawl-migration [shawl-migration.md], update-path [update-path.md].\n  Use when: \"choco\", \"chocolatey\", \"choco upgrade\", \"choco outdated\", \"vcredist\", \"nssm\", \"nssm recovery\", \"nssm path\", \"service path refresh\", \"after choco upgrade\", \"service failure\", \"SERVICE_STOPPED\", \"shim issue\", \"syncthing nssm\", \"syncthing v2\", \"shawl migration\", \"nssm deprecation\", \"service-specific error\", \"UniGetUI\", \"metadata update failure\", \"metadata stale\", \".nuspec stale\", \"choco metadata\".\n---\n\n# Choco\n\nChocolatey operations integration skill. Pre- and post-processing for choco upgrade, nssm service compatibility management, and metadata update failure recovery.\n\n## Core Problems\n\n| Area | Problem | Resolution Topic |\n|------|---------|------------------|\n| Package path | After choco upgrade, the nssm Application path becomes stale due to version-specific folders | [update-path.md](./update-path.md) |\n| Service compatibility | After major upgrade (e.g., syncthing v1→v2), NSSM fails with service-specific error | [shawl-migration.md](./shawl-migration.md) |\n| Metadata | Runtime install succeeds + chocolatey `.nuspec` is stale (UniGetUI shows repeated upgrades) | [metadata-fix.md](./metadata-fix.md) |\n| Diagnosis | Identify which service has issues / which package is stale | [diagnose.md](./diagnose.md) |\n| Bulk post-processing | Automatically check affected services after choco upgrade | [post-upgrade.md](./post-upgrade.md) |\n\n## Path Strategy (HARD STOP — required decision before nssm set Application)\n\n| Strategy | Example Path | Pros | Cons |\n|----------|--------------|------|------|\n| **Stable shim path (recommended)** | `%ChocolateyInstall%\\bin\\syncthing.exe` | Path remains unchanged after choco upgrade | Without `--shimgen-waitforexit`, nssm may misinterpret shim exit as a crash |\n| Version-specific actual path | `%ChocolateyInstall%\\lib\\syncthing\\tools\\...-v2.1.0\\syncthing.exe` | No shim issues | **Path breaks on every upgrade** — this is why this skill exists |\n\n**Default choice: stable shim path.** Use version-specific path + post-upgrade hook combination only for services where shim issues occur. When NSSM compatibility itself breaks (like syncthing v2), apply [shawl-migration](./shawl-migration.md).\n\n### Using environment variable paths in nssm\n\nnssm supports `REG_EXPAND_SZ` but `nssm set` defaults to `REG_SZ`. Set registry directly via PowerShell:\n\n```powershell\n$regPath = \"HKLM:\\SYSTEM\\CurrentControlSet\\Services\\<service>\\Parameters\"\nSet-ItemProperty -Path $regPath -Name \"Application\" -Value '%ChocolateyInstall%\\bin\\<exe>' -Type ExpandString\n```\n\nOr use an expanded literal"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn74k8yfvftx6f062qa8fzyd8h8373jd\",\n  \"slug\": \"choco\",\n  \"version\": \"1.0.5\",\n  \"publishedAt\": 1789746777014\n}"},{"path":"CHANGELOG.md","content":"# Changelog\n\n## [1.0.5](https://github.com/es6kr/skills/compare/choco-v1.0.4...choco-v1.0.5) (2026-09-18)\n\n\n### Bug Fixes\n\n* **cleanup:** make the session-end report table self-sufficient ([#487](https://github.com/es6kr/skills/issues/487)) ([c4a0255](https://github.com/es6kr/skills/commit/c4a02557fb8de3b32cf337c549f62535dabf824b))\n\n## [1.0.4](https://github.com/es6kr/skills/compare/choco-v1.0.3...choco-v1.0.4) (2026-08-17)\n\n\n### Bug Fixes\n\n* **wip:** cross-ref PR-URL and TaskCreate subject repo-qualifier rules ([#186](https://github.com/es6kr/skills/issues/186)) ([4982364](https://github.com/es6kr/skills/commit/49823641a7b08123ebd0325273892bee41bc3280))\n\n## [1.0.3](https://github.com/es6kr/skills/compare/choco-v1.0.2...choco-v1.0.3) (2026-08-09)\n\n\n### Bug Fixes\n\n* declare undeclared skill-to-skill dependencies (7 skills) ([#271](https://github.com/es6kr/skills/issues/271)) ([36a9f9d](https://github.com/es6kr/skills/commit/36a9f9d7c1fac9bb1c4c96b325a067ab92ad0da7))\n* promote accumulated next-fix fixes to main ([95656e9](https://github.com/es6kr/skills/commit/95656e9b551ee0bb77904a0a571d49c53bc01cc9))\n\n## [1.0.2](https://github.com/es6kr/skills/compare/choco-v1.0.1...choco-v1.0.2) (2026-08-05)\n\n\n### Bug Fixes\n\n* **wip:** cross-ref PR-URL and TaskCreate subject repo-qualifier rules ([#186](https://github.com/es6kr/skills/issues/186)) ([951c1e6](https://github.com/es6kr/skills/commit/951c1e6871e78e226757c6a7ae5ae53efeb7bfb0))\n\n## [1.0.1](https://github.com/es6kr/skills/compare/choco-v1.0.0...choco-v1.0.1) (2026-06-27)\n\n\n### Features\n\n* decompose workflow/git rules + rename web-ui-test→web-browser ([#50](https://github.com/es6kr/skills/issues/50)) ([e10d48f](https://github.com/es6kr/skills/commit/e10d48fea4e507b95888de44812b53484d32128d))\n\n\n### Bug Fixes\n\n* **fix:** split Step 2 medium by content type — case history to failed-attempts.md ([#62](https://github.com/es6kr/skills/issues/62)) ([747b3f9](https://github.com/es6kr/skills/commit/747b3f957ca0fefdbc5044eb08f66b8aafc1e26a))\n* **skills:** apply PR [#50](https://github.com/es6kr/skills/issues/50) Phase 2 follow-up reviews ([33863d7](https://github.com/es6kr/skills/commit/33863d705f8b24051b030b839487e8b5a8bfd9df))\n\n## [0.1.1](https://github.com/es6kr/skills/compare/choco-v0.1.0...choco-v0.1.1) (2026-06-25)\n\n\n### Bug Fixes\n\n* **fix:** split Step 2 medium by content type — case history to failed-attempts.md ([#62](https://github.com/es6kr/skills/issues/62)) ([747b3f9](https://github.com/es6kr/skills/commit/747b3f957ca0fefdbc5044eb08f66b8aafc1e26a))\n* **skills:** apply PR [#50](https://github.com/es6kr/skills/issues/50) Phase 2 follow-up reviews ([33863d7](https://github.com/es6kr/skills/commit/33863d705f8b24051b030b839487e8b5a8bfd9df))\n\n## 0.1.0 (2026-06-12)\n\n\n### Features\n\n* decompose workflow/git rules + rename web-ui-test→web-browser ([#50](https://github.com/es6kr/skills/issues/50)) ([e10d48f](https://github.com/es6kr/skills/commit/e10d48fea4e507b95888de44812b53484d32128d))"},{"path":"diagnose.md","content":"# nssm Service Diagnosis\n\n## When to Use\n\n- nssm service is in `SERVICE_PAUSED` or `SERVICE_STOPPED` state\n- Service behavior anomalies after choco upgrade\n- When a specific service won't start\n\n## Diagnosis Procedure\n\n### 1. Run the Script\n\n```bash\nnode scripts/nssm-manager.js diagnose\n```\n\nOutput content:\n- List of all nssm services\n- Status of each service (RUNNING/STOPPED/PAUSED)\n- Shim status (chocolatey\\bin path = shim)\n- Actual binary location (inside choco lib)\n- List of commands required for fixes\n\n### 2. Manual Diagnosis (if script fails)\n\n```bash\n# Service status\nnssm status <service>\n\n# Registered path\nnssm get <service> Application\n\n# Actual binary location\nls \"C:/ProgramData/chocolatey/lib/<package>/tools/\"\n```\n\n### 3. Shim Identification Criteria\n\n| Path | Type | Service Behavior |\n|------|------|------------------|\n| `chocolatey\\bin\\*.exe` | shim (wrapper) | High failure likelihood |\n| `chocolatey\\lib\\*\\tools\\*\\*.exe` | actual binary | Normal |\n| Other paths | direct install | Normal |\n\n## Output Interpretation\n\n- `Shim: YES` → Path refresh required via update-path topic\n- `Shim: NO` → Investigate other causes (check logs, port conflicts, etc.)\n- `Actual binary: not found` → Package was removed or structure changed"},{"path":"metadata-fix.md","content":"# Chocolatey Metadata Update Failure Fix\n\nDiagnosis and recovery procedure for cases where **the runtime/installer succeeds but the chocolatey metadata (`.nuspec`) update fails** after invoking UniGetUI or choco upgrade.\n\n## Background\n\nStarting from UniGetUI 2026.1.7, the chocolatey bundle was removed and it became a passthrough to the system `choco`. Since UniGetUI only displays the results of `choco list`, metadata update failure is the **responsibility of chocolatey**.\n\nRelated issues:\n- [Devolutions/UniGetUI#4803](https://github.com/Devolutions/UniGetUI/issues/4803) — Inconsistent chocolatey packages since 2026.1.7\n- [Devolutions/UniGetUI#4801](https://github.com/Devolutions/UniGetUI/issues/4801) — Wrong information about installed programs (2026.1.10)\n- [Devolutions/UniGetUI#3708](https://github.com/Devolutions/UniGetUI/issues/3708) — choco.exe hang on update check\n- [Devolutions/UniGetUI#4217](https://github.com/Devolutions/UniGetUI/issues/4217) — Chocolatey shown as ready on MS Store install\n\n## Symptoms\n\n| Symptom | Meaning |\n|---------|---------|\n| \"Upgrade available\" indication persists in UniGetUI | `choco list` returns old version |\n| `choco list <pkg>` shows old version, actual EXE is new version | Only `.nuspec` is stale |\n| Same package keeps appearing in `choco outdated` | Metadata stage exits abnormally |\n| choco exits abnormally after \"already installed\" in installer log | Package stage may be skipped |\n\n## Diagnosis Procedure\n\n### 1. Compare Metadata vs Actual Version\n\n```bash\n# Version recognized by chocolatey\nchoco list <pkg>\n\n# Metadata version in .nuspec\ngrep -i version \"C:\\ProgramData\\chocolatey\\lib\\<pkg>\\<pkg>.nuspec\" | head -1\n\n# Actual installed runtime version (e.g., vcredist140)\nreg query \"HKLM\\SOFTWARE\\Microsoft\\VisualStudio\\14.0\\VC\\Runtimes\\x64\" /v Version 2>&1 | grep Version\n```\n\nIf the three values diverge, metadata stale is confirmed.\n\n### 2. Verify with choco outdated\n\n```bash\nchoco outdated 2>&1 | grep -E \"^[a-zA-Z0-9_-]+\\|\"\n```\n\nOutput line: `<pkg>|<current metadata>|<remote latest>|<pinned>`. Suspect if metadata differs from external systems (WMI/registry).\n\n## Recovery Procedure\n\n### 1. Force Resync (default)\n\n```bash\n# Invoke via PowerShell tool (bypass Bash escape)\ngsudo choco upgrade <pkg> -y\n```\n\nAfter success, verify version match with `choco list <pkg>`.\n\n### 2. Use --force (when 1 has no effect)\n\n```bash\ngsudo choco upgrade <pkg> -y --force\n```\n\n`--force` re-runs the package stage even if already at the latest version to update `.nuspec`.\n\n### 3. Bulk Update\n\n```bash\ngsudo choco upgrade all -y\n```\n\nCleans up large amounts of outdated entries. Effective when UniGetUI has accumulated stale indicators.\n\n### 4. Manual nuspec Patch (last resort)\n\nIf choco refuses to update for any reason, directly modify the `<version>` node in `.nuspec`. **Not recommended** — risk of being overwritten by the next upgrade or causing dependency mismatch.\n\n## Don't / Do Table\n\n| # | Don't | Do |\n|---|-------|-----|\n| 1 | Re"}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":null,"editorialQuality":{"score":100,"threshold":65,"status":"thin","wordCount":1486,"uniquenessScore":43,"reasons":["uniqueness-below-45"]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-11T16:57:01.111Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-11T16:57:01.111Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-11T20:56:10.248Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}