{"id":"119c76a9-0fd4-41c8-8a40-8e3713e5ea07","entityType":"agent","slug":"clawhub-luckycat133-agent-skills-setup","name":"agent-skills-setup","canonicalUrl":"https://www.xpersona.co/agent/clawhub-luckycat133-agent-skills-setup","canonicalPath":"/agent/clawhub-luckycat133-agent-skills-setup","generatedAt":"2026-10-09T20:27:46.312Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T09:23:58.739Z","emptyReason":null},"description":"Use when a user wants to migrate, back up, restore, compare, or move AI-coding-agent context across Cursor, Claude Code, Codex, Cline, Copilot, Windsurf, Gemini CLI, or another registered profile, including switching computers. Handles Skills, instructions/rules, and MCP with secret redaction, preview, verification, rollback, and portable bundles; compatible plugin packages and reviewed handoff are available by explicit opt-in.","descriptionLabel":"Source description","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 3.2K downloads reported by the source. Last updated 10/9/2026.","installCommand":"clawhub skill install s179fnaja3kqc64tnfyq6b5zb583p7d8:agent-skills-setup","sourceUrl":"https://clawhub.ai/luckycat133/agent-skills-setup","homepage":"https://clawhub.ai/luckycat133/skills/agent-skills-setup","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/luckycat133/agent-skills-setup","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/luckycat133/skills/agent-skills-setup","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":40,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"agent-skills-setup technical dossier on Xpersona with agent coverage, OPENCLEW support, and live trust metadata."},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-09T09:23:58.739Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T09:23:58.739Z","emptyReason":null},"stars":null,"forks":null,"downloads":3170,"packageName":null,"latestVersion":"0.10.2","tractionLabel":"3.2K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T09:23:58.738Z","emptyReason":null},"lastUpdatedAt":"2026-10-09T09:23:58.739Z","lastCrawledAt":"2026-10-09T09:23:58.738Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-10T09:23:58.738Z","lastVerifiedAt":null,"highlights":[{"version":"0.10.2","createdAt":"2026-10-03T08:14:26.890Z","changelog":"Keep legacy dry-run reports on stdout without creating or replacing a named report file, including source assets. Preserve text and JSON previews across the Python facade and no-Python Bash fallback; update preview guidance and regression coverage.","fileCount":122,"zipByteSize":255442},{"version":"0.10.1","createdAt":"2026-10-03T05:22:45.373Z","changelog":"Fix signing-key failure cleanup: preserve unrelated files and original errors, retain failed POSIX outputs for review, and use original Windows handles. Repair profile navigation and clarify opt-in plugins/handoff. All legacy suites now run on native Windows; CI and bounded verification records updated. Scan warnings and partial analysis remain documented in the 0.10.1 security review.","fileCount":122,"zipByteSize":255407},{"version":"0.10.0","createdAt":"2026-10-02T17:05:54.129Z","changelog":"# Agent Skills Setup 0.10.0 This release completes offline context migration, portable backup/restore, and packaged Skill guidance across registered Cursor, Claude Code, Codex, Cline, Windsurf, Copilot, Gemini CLI, and other profiles. Support remains specific to each object and scope. - ACB snapshots preserve ordinary file permissions, including executable bits. Older bundles without permission metadata remain readable. - Saved restore plans bind to the exact bundle manifest and stable object identities; cross-process restore rebuilds child Skills and merged MCP sources. - MCP previews show additions, removals, and changed field names without credential values. Atomic text writes preserve preview bytes and hashes across platforms. - Signing keys use owner-only POSIX permissions or a protected Windows ACL, verified on the opened file handle. - Offline doctor reports executable, package, extension, platform, and manual-install requirements. Discovery, aliases, scoped inventories, plugin/handoff opt-in, guarded rollback, and conversion-loss handling have dedicated regressions. - Skill import and runtime packaging validate complete staged trees and replace destinations atomically. Streaming SHA-256 bounds hashing allocation; isolated scale tooling checks complete migration/restore/rollback contents. Conversions with reported instruction/MCP losses require explicit acceptance; `--yes` alone is insufficient. Replay restore plans with their original verified `--bundle` and use distinct artifact paths. Automatic writers cover Skills, instructions, and reviewed local stdio MCP. Plugin copies and reviewed handoff require explicit opt-in. Remote MCP, cloud/UI settings, unsupported formats, trust, credentials, and raw history retain their manual/excluded boundaries. File validation does not establish native IDE or MCP connectivity acceptance. See [the complete changelog](https://github.com/Luckycat133/skills-repo/blob/v0.10.0/CHANGELOG.md#0100---2026-10-02) and [compatibility matrix](https://github.com/Luckycat133/skills-repo/blob/v0.10.0/docs/agent-skills-setup/compatibility-matrix.md). Linux, macOS, and Windows CI passed on the final release candidate. Linux/macOS and local full validation ran all 68 focused suites; Windows ran 63, retaining five pre-existing legacy Bash-engine exclusions. Signing/schema dependencies were installed. Isolated scale checks passed at 10/100/1000 items per type, up to 4001 files; exact contents, migration and restore round-trips, and source preservation passed. Native application and connectivity acceptance remain separate. Separate NVIDIA/SkillSpector 2.12.0 scans of the actual GitHub MIT and ClawHub MIT-0 runtime packages each retained 100 findings, risk 100, CRITICAL / DO_NOT_INSTALL advisories, and four partially inspected components (115 of 119 fully inspected). Contextual review accounted for all findings without identifying a confirmed new substantive defect. Raw reports retain these advisories; no suppression baseline was applied, and the scans are not clean or complete security certifications. The downloadable runtime archive preserves the canonical MIT license. ClawHub publication uses a separately staged MIT-0 package and requires confirmed contributor authorization.","fileCount":122,"zipByteSize":254010},{"version":"0.9.3","createdAt":"2026-09-11T16:21:20.058Z","changelog":"## [0.9.3] - 2026-09-11 ### Fixed - **Replayable all-installed restore plans (acb:// plan source)**: bulk restore plan documents no longer persist `/tmp` staging paths. Every plan item now carries a stable `acb://<bundle-id>#<object-id>` URI; on replay (`--plan-in`) the runtime re-verifies the bundle, re-stages the referenced objects into a fresh managed temp tree with per-file SHA256 checks, and rebinds runtime paths without changing logical source identity. A dedicated cross-process regression test (`test-acb-bundle-backed-plan-cross-process.sh`) covers plan-out → process exit → plan-in end-to-end. ### Added - **Auto-generated compatibility matrix**: `docs/agent-skills-setup/compatibility-matrix.md` is now generated by `scripts/generate-compatibility-matrix.py` from `registry-v2.json`, `ide-paths.tsv`, E2E test coverage, and `ide-tier-overrides.json` human overrides. Three tiers replace the previous hand-written claims: `E2E Verified`, `Adapter-Compatible`, `Manual / Rebuild`. A `--check` mode plus `.github/workflows/matrix-freshness.yml` CI gate fails any commit where the committed matrix is stale. - **All-installed MCP merge staging**: redact credential-bearing MCP values before generating merged plan sources, keep those files inside the managed restore staging tree, and remove them on every exit path. Clarified that `snapshot --all-installed` writes only its explicit bundle output, while bulk restore/apply requires `--yes`. - **Canonical display name consistency**: every public artifact now reads `Agent Skills Setup` (README H1 in all four languages, SKILL.md H1, ClawHub). The legacy `Agent Context Migrator` and `AI IDE Context Migration` labels are kept only as descriptive subtitles where they help readers understand the function. Closes the three-name drift called out in the v0.9.2 review. - **Bug report template no longer over-promises secret redaction**: the GitHub Issue form used to claim pasted logs are auto-redacted, but there is no server-side scan at issue creation time. The form now warns explicitly that issues are public, points users at the bundled `scan-skill-secrets.py` for local redaction, and asks users to mask remaining values by hand. - **Discussions contact link removed**: the bug report config linked to a Discussions page that the repository has not enabled. The link is removed to stop sending users to a 404 / disabled page; a future release can re-enable Discussions and re-add the link. - **`snapshot` and `restore` now expose `--objects`**: previously these subcommands hard-coded `skills,instructions,mcp` and silently dropped any `--include-plugins` / `--include-session` opt-in. Both subcommands now accept a comma-separated `--objects` list, so `plugin` and `handoff` can actually be selected for round-tripping through ACB. - **`migrate --plan-only` no longer requires `--yes`**: read-only planning must not demand the same consent as a write. The `--yes` requirement now applies only to commands that actually write to a target surface. - **ACB manifest integrity check is unconditional**: the previous verifier skipped the \"unclaimed file\" check when `manifest_files` was empty, allowing an attacker who could rewrite `manifest.json` + `checksums.json` to smuggle in extra object files. The check now always reconciles `objects/` against the manifest's declared files, even when the manifest is empty. - **`bundle-sign` verifies before signing and refuses symlinks**: the signer now (a) rejects `checksums.json` and `signature.json` that are symlinks, (b) refuses to overwrite a pre-existing `signature.json` that is a symlink, (c) writes the new signature atomically, and (d) re-verifies the bundle with the trusted public key immediately after writing. Prevents following a hostile symlink out of the bundle directory and signing a payload that was never actually verified.","fileCount":119,"zipByteSize":235211},{"version":"0.9.2","createdAt":"2026-08-30T02:36:59.829Z","changelog":"Release 0.9.2: restore canonical display name to Agent Skills Setup","fileCount":116,"zipByteSize":196116},{"version":"0.9.1","createdAt":"2026-08-29T05:42:31.636Z","changelog":"Release 0.9.1: child-level skill restore, multi-source MCP merge, opt-in flags, and documentation","fileCount":116,"zipByteSize":195978},{"version":"0.9.0","createdAt":"2026-08-25T14:25:30.398Z","changelog":"0.9.0 stable: all-installed multi-source conflict handling, 1:1 manifest binding, Ed25519 CLI commands, unified capability registry, atomic ACB bundle replacement","fileCount":116,"zipByteSize":194122},{"version":"0.8.33","createdAt":"2026-08-24T14:10:46.266Z","changelog":"Restores maintainer-approved capabilities: opt-in handoff/session transfer (--include-session, field-whitelisted), plugin package copy where both profiles declare it, and the full eight-type automatic surface.","fileCount":116,"zipByteSize":191353}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s179fnaja3kqc64tnfyq6b5zb583p7d8:agent-skills-setup","setupComplexity":"low","setupSteps":["Install using `clawhub skill install s179fnaja3kqc64tnfyq6b5zb583p7d8:agent-skills-setup` in an isolated environment before connecting it to live workloads.","No published capability contract is available yet, so validate auth and request/response behavior manually.","Review the upstream CLAWHUB listing at https://clawhub.ai/luckycat133/agent-skills-setup before using production credentials."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-luckycat133-agent-skills-setup/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-luckycat133-agent-skills-setup/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-luckycat133-agent-skills-setup/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-luckycat133-agent-skills-setup/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-luckycat133-agent-skills-setup/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-luckycat133-agent-skills-setup/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-09T20:27:46.308Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-luckycat133-agent-skills-setup/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-luckycat133-agent-skills-setup/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-luckycat133-agent-skills-setup/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-luckycat133-agent-skills-setup/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T09:23:58.739Z","emptyReason":null},"readme":"Skill: agent-skills-setup\n\nOwner: luckycat133\n\nSummary: Use when a user wants to migrate, back up, restore, compare, or move AI-coding-agent context across Cursor, Claude Code, Codex, Cline, Copilot, Windsurf, Gemini CLI, or another registered profile, including switching computers. Handles Skills, instructions/rules, and MCP with secret redaction, preview, verification, rollback, and portable bundles; compatible plugin packages and reviewed handoff are available by explicit opt-in.\n\nTags: 0.9.1:0.9.1, 0.9.2:0.9.2, acb:0.8.21, audit-fix:0.8.21, cross-ide:0.10.1, latest:0.10.2, migration:0.5.1, openclaw:0.10.1, security:0.8.21, setup:0.10.1, skills:0.10.1\n\nVersion history:\n\nv0.10.2 | 2026-10-03T08:14:26.890Z | user\n\nKeep legacy dry-run reports on stdout without creating or replacing a named report file, including source assets. Preserve text and JSON previews across the Python facade and no-Python Bash fallback; update preview guidance and regression coverage.\n\nv0.10.1 | 2026-10-03T05:22:45.373Z | user\n\nFix signing-key failure cleanup: preserve unrelated files and original errors, retain failed POSIX outputs for review, and use original Windows handles. Repair profile navigation and clarify opt-in plugins/handoff. All legacy suites now run on native Windows; CI and bounded verification records updated. Scan warnings and partial analysis remain documented in the 0.10.1 security review.\n\nv0.10.0 | 2026-10-02T17:05:54.129Z | user\n\n# Agent Skills Setup 0.10.0\n\nThis release completes offline context migration, portable backup/restore, and packaged Skill guidance across registered Cursor, Claude Code, Codex, Cline, Windsurf, Copilot, Gemini CLI, and other profiles. Support remains specific to each object and scope.\n\n- ACB snapshots preserve ordinary file permissions, including executable bits. Older bundles without permission metadata remain readable.\n- Saved restore plans bind to the exact bundle manifest and stable object identities; cross-process restore rebuilds child Skills and merged MCP sources.\n- MCP previews show additions, removals, and changed field names without credential values. Atomic text writes preserve preview bytes and hashes across platforms.\n- Signing keys use owner-only POSIX permissions or a protected Windows ACL, verified on the opened file handle.\n- Offline doctor reports executable, package, extension, platform, and manual-install requirements. Discovery, aliases, scoped inventories, plugin/handoff opt-in, guarded rollback, and conversion-loss handling have dedicated regressions.\n- Skill import and runtime packaging validate complete staged trees and replace destinations atomically. Streaming SHA-256 bounds hashing allocation; isolated scale tooling checks complete migration/restore/rollback contents.\n\nConversions with reported instruction/MCP losses require explicit acceptance; `--yes` alone is insufficient. Replay restore plans with their original verified `--bundle` and use distinct artifact paths.\n\nAutomatic writers cover Skills, instructions, and reviewed local stdio MCP. Plugin copies and reviewed handoff require explicit opt-in. Remote MCP, cloud/UI settings, unsupported formats, trust, credentials, and raw history retain their manual/excluded boundaries. File validation does not establish native IDE or MCP connectivity acceptance.\n\nSee [the complete changelog](https://github.com/Luckycat133/skills-repo/blob/v0.10.0/CHANGELOG.md#0100---2026-10-02) and [compatibility matrix](https://github.com/Luckycat133/skills-repo/blob/v0.10.0/docs/agent-skills-setup/compatibility-matrix.md).\n\nLinux, macOS, and Windows CI passed on the final release candidate. Linux/macOS and local full validation ran all 68 focused suites; Windows ran 63, retaining five pre-existing legacy Bash-engine exclusions. Signing/schema dependencies were installed. Isolated scale checks passed at 10/100/1000 items per type, up to 4001 files; exact contents, migration and restore round-trips, and source preservation passed. Native application and connectivity acceptance remain separate.\n\nSeparate NVIDIA/SkillSpector 2.12.0 scans of the actual GitHub MIT and ClawHub MIT-0 runtime packages each retained 100 findings, risk 100, CRITICAL / DO_NOT_INSTALL advisories, and four partially inspected components (115 of 119 fully inspected). Contextual review accounted for all findings without identifying a confirmed new substantive defect. Raw reports retain these advisories; no suppression baseline was applied, and the scans are not clean or complete security certifications.\n\nThe downloadable runtime archive preserves the canonical MIT license. ClawHub publication uses a separately staged MIT-0 package and requires confirmed contributor authorization.\n\nv0.9.3 | 2026-09-11T16:21:20.058Z | user\n\n## [0.9.3] - 2026-09-11\n\n### Fixed\n\n- **Replayable all-installed restore plans (acb:// plan source)**: bulk restore plan documents no longer persist `/tmp` staging paths. Every plan item now carries a stable `acb://<bundle-id>#<object-id>` URI; on replay (`--plan-in`) the runtime re-verifies the bundle, re-stages the referenced objects into a fresh managed temp tree with per-file SHA256 checks, and rebinds runtime paths without changing logical source identity. A dedicated cross-process regression test (`test-acb-bundle-backed-plan-cross-process.sh`) covers plan-out → process exit → plan-in end-to-end.\n\n### Added\n\n- **Auto-generated compatibility matrix**: `docs/agent-skills-setup/compatibility-matrix.md` is now generated by `scripts/generate-compatibility-matrix.py` from `registry-v2.json`, `ide-paths.tsv`, E2E test coverage, and `ide-tier-overrides.json` human overrides. Three tiers replace the previous hand-written claims: `E2E Verified`, `Adapter-Compatible`, `Manual / Rebuild`. A `--check` mode plus `.github/workflows/matrix-freshness.yml` CI gate fails any commit where the committed matrix is stale.\n\n- **All-installed MCP merge staging**: redact credential-bearing MCP values before generating merged plan sources, keep those files inside the managed restore staging tree, and remove them on every exit path. Clarified that `snapshot --all-installed` writes only its explicit bundle output, while bulk restore/apply requires `--yes`.\n- **Canonical display name consistency**: every public artifact now reads `Agent Skills Setup` (README H1 in all four languages, SKILL.md H1, ClawHub). The legacy `Agent Context Migrator` and `AI IDE Context Migration` labels are kept only as descriptive subtitles where they help readers understand the function. Closes the three-name drift called out in the v0.9.2 review.\n- **Bug report template no longer over-promises secret redaction**: the GitHub Issue form used to claim pasted logs are auto-redacted, but there is no server-side scan at issue creation time. The form now warns explicitly that issues are public, points users at the bundled `scan-skill-secrets.py` for local redaction, and asks users to mask remaining values by hand.\n- **Discussions contact link removed**: the bug report config linked to a Discussions page that the repository has not enabled. The link is removed to stop sending users to a 404 / disabled page; a future release can re-enable Discussions and re-add the link.\n- **`snapshot` and `restore` now expose `--objects`**: previously these subcommands hard-coded `skills,instructions,mcp` and silently dropped any `--include-plugins` / `--include-session` opt-in. Both subcommands now accept a comma-separated `--objects` list, so `plugin` and `handoff` can actually be selected for round-tripping through ACB.\n- **`migrate --plan-only` no longer requires `--yes`**: read-only planning must not demand the same consent as a write. The `--yes` requirement now applies only to commands that actually write to a target surface.\n- **ACB manifest integrity check is unconditional**: the previous verifier skipped the \"unclaimed file\" check when `manifest_files` was empty, allowing an attacker who could rewrite `manifest.json` + `checksums.json` to smuggle in extra object files. The check now always reconciles `objects/` against the manifest's declared files, even when the manifest is empty.\n- **`bundle-sign` verifies before signing and refuses symlinks**: the signer now (a) rejects `checksums.json` and `signature.json` that are symlinks, (b) refuses to overwrite a pre-existing `signature.json` that is a symlink, (c) writes the new signature atomically, and (d) re-verifies the bundle with the trusted public key immediately after writing. Prevents following a hostile symlink out of the bundle directory and signing a payload that was never actually verified.\n\nv0.9.2 | 2026-08-30T02:36:59.829Z | user\n\nRelease 0.9.2: restore canonical display name to Agent Skills Setup\n\nv0.9.1 | 2026-08-29T05:42:31.636Z | user\n\nRelease 0.9.1: child-level skill restore, multi-source MCP merge, opt-in flags, and documentation\n\nv0.9.0 | 2026-08-25T14:25:30.398Z | user\n\n0.9.0 stable: all-installed multi-source conflict handling, 1:1 manifest binding, Ed25519 CLI commands, unified capability registry, atomic ACB bundle replacement\n\nv0.8.33 | 2026-08-24T14:10:46.266Z | user\n\nRestores maintainer-approved capabilities: opt-in handoff/session transfer (--include-session, field-whitelisted), plugin package copy where both profiles declare it, and the full eight-type automatic surface.\n\nv0.8.32 | 2026-08-24T11:25:48.751Z | user\n\nScope convergence: session/handoff write path removed entirely; apply writes only the declared portable trio (skills, instructions, MCP); legacy subcommand structurally read-only.\n\nv0.8.31 | 2026-08-24T10:40:06.438Z | user\n\nACB snapshot now reduces every MCP object to its authorized servers subobject: shared host settings files never travel raw in bundles.\n\nv0.8.30 | 2026-08-24T09:59:49.802Z | user\n\nSkillSpector audit closure: hooks/agents have no automatic write path (fail closed); handoff/session transfer requires explicit --include-session; explicit Permissions section and exhaustive object-type scope in SKILL.md; sensitive-config safeguards documented.\n\nv0.8.29 | 2026-08-23T15:21:30.151Z | user\n\nWindows host support made real (full CI matrix green end to end).\n\nFixed:\n- Registry honors $HOME when it points at a real directory; native\n  Windows Python reads USERPROFILE only, which silently ignored\n  HOME-injected fixtures and cross-device restores\n- Glob platform overrides (github.copilot-*) are probe locations, not\n  deterministic write targets; surfaces now ignore wildcard overrides\n- Legacy engine: drive-letter/UNC paths treated as absolute in workspace\n  joins; prefers Git Bash over the System32 WSL launcher; keeps only the\n  64-digit digest from sha256 tool output; no longer reinterprets escape\n  sequences in the human report\n\nChanged:\n- Roadmap: Windows moves from smoke-test-only to full-suite CI\n  verification; WSL / Remote / Dev-Container hosts remain Experimental\n\nCo-Authored-By: Claude <noreply@anthropic.com>\n\nv0.8.28 | 2026-08-22T14:14:40.727Z | user\n\nComplete audit closure for 0.8.27.\n\nFixed:\n- snapshot/restore/detect: per-profile detection with explicit state\n  priority; full product/profile selectors drive plan building\n- restore --all-installed is now a real multi-target implementation\n  (source selectors from bundle manifest x detected targets), with\n  detection_status and failed_targets recorded in the plan document\n- run_detection is probe-only; shared paths (AGENTS.md, .agents/skills)\n  stay compatibility-only instead of being promoted to installed\n- No silent failures in snapshot: collection_summary statuses\n  (captured/manual_rebuild/excluded_by_policy/parse_failed/\n  secret_rejected/conflict) with non-zero exit on parse errors\n- doctor requirements accuracy: normalized package names, extension vs\n  manual-install split, human-readable credential names in reauth\n\nAdded:\n- Manifest object enrichment: object_path, files[] with SHA256 + size,\n  adapter_version, portability_mode, content_hash; closed-world verify\n  cross-checks manifest <-> objects/ both directions\n- Maintainer online doc checks split from the strictly-offline runtime\n  freshness check (monthly PR-based workflow)\n\nCo-Authored-By: Claude <noreply@anthropic.com>\n\nv0.8.27 | 2026-08-22T13:57:49.786Z | user\n\nComplete audit closure for 0.8.27.\n\nFixed:\n- snapshot/restore/detect: per-profile detection with explicit state\n  priority; full product/profile selectors drive plan building\n- restore --all-installed is now a real multi-target implementation\n  (source selectors from bundle manifest x detected targets), with\n  detection_status and failed_targets recorded in the plan document\n- run_detection is probe-only; shared paths (AGENTS.md, .agents/skills)\n  stay compatibility-only instead of being promoted to installed\n- No silent failures in snapshot: collection_summary statuses\n  (captured/manual_rebuild/excluded_by_policy/parse_failed/\n  secret_rejected/conflict) with non-zero exit on parse errors\n- doctor requirements accuracy: normalized package names, extension vs\n  manual-install split, human-readable credential names in reauth\n\nAdded:\n- Manifest object enrichment: object_path, files[] with SHA256 + size,\n  adapter_version, portability_mode, content_hash; closed-world verify\n  cross-checks manifest <-> objects/ both directions\n- Maintainer online doc checks split from the strictly-offline runtime\n  freshness check (monthly PR-based workflow)\n\nCo-Authored-By: Claude <noreply@anthropic.com>\n\nv0.8.25 | 2026-08-20T15:51:44.854Z | user\n\nMulti-IDE all-installed snapshot/restore orchestration, ACB atomic staging, 1:1 manifest binding, and detection probe hardening\n\nv0.8.24 | 2026-08-20T10:57:33.730Z | user\n\nv0.8.24: Resolve security audit findings, harden offline boundary, prevent probe query injection, and strengthen ACB write/restore safety gates.\n\nv0.8.23 | 2026-08-18T11:26:22.289Z | auto\n\nVersion 0.8.23 brings major migration workflow improvements, full cross-platform support, and strict fidelity for plan replay and safety.\n\n- Adds --all-installed: one-shot snapshots/restores across all detected IDEs on a device.\n- Introduces --plan-in/--plan-out flags: enables reviewed, replayable plan files and strict TOCTOU lock.\n- Enforces config sub-object allowlists (e.g., only exports mcpServers, never all settings).\n- Fully supports Windows/macOS/Linux: resolves %APPDATA%/etc and detects/configures per platform.\n- Refines offline detect/doctor outputs: distinction between installed, configured, and compatible IDEs.\n- Skill code/test suite expanded: new evals, completion tests, and shell test scripts.\n- MIT license added; obsolete/legacy files removed.\n\nv0.8.22 | 2026-08-18T05:18:14.614Z | user\n\nv0.8.22: Dual-side PlanDocument restore, strict snapshot allowlist, bundle source precedence, and strict handoff whitelist serialization\n\nv0.8.21 | 2026-08-18T02:37:42.209Z | user\n\n### Fixed\n\n- **#1 Bundle-backed reviewed plan equals executed plan**: `restore` now stages the bundle `objects/` and rebuilds the `document`/`PlanDocument` from the staged registry, so the reviewed/saved plan is exactly the plan executed (no fallback divergence).\n- **#2 No silent no-op**: `restore` hard-fails when the bundle resolves zero eligible items (opt out with `--allow-noop`); mapping failures surface instead of being swallowed.\n- **#3 Multi-scope & project ACB restore**: `build_plan` expands comma-scope unions per scope; `choose_surface` permits distinct-scope duplicates; staging resolves project-scope `objects/` under the workspace root, so `--scope user,project` migrates both user and project items.\n- **#4 Transaction/opt-in restore**: object extraction is opt-in via `--restore-root`; without it `restore` only builds/reviews the plan. No `.acb-restored` directory or transaction claim is produced unless extraction actually runs.\n- **#5 Temp-dir hygiene**: the staged ACB source directory is removed in a `try/finally`, eliminating the prior `acb-source-stage-*` leak.\n- **#6 Unified secret scanning**: ACB object bytes are scanned through `skill_secret_scanner.finding_reason` (covers `sk-`, `Bearer`, connection-string `userinfo`, private-key blocks, and assignment patterns); `looks_like_secret_value` now reuses the same engine instead of a broad substring hint.\n- **#7 `bundle-verify` re-scans objects**: `verify_bundle` re-runs the secret/binary scan over every `objects/` file and re-enforces file-count / size / total / depth limits.\n- **#8 Handoff branch whitelist**: `git_branch` records the human-readable branch name (never a commit SHA); `raw`/`messages` are stripped from the portable handoff.\n- **#9 Registry structure pollution**: removed the duplicate top-level `letta`/`zencoder` product objects (they remain correctly under `products`).\n- **#10 JSON Schema enforcement**: `validate-registry-v2.py` now runs `jsonschema.Draft202012Validator` against `registry-v2.schema.json`; the schema was reconciled (`schema_version` 2.1, `stale-*` support levels, `description` on contracts) and hardened with `additionalProperties: false` at the root to block future pollution.\n- **#11 Freshness workflows merged**: fixed `freshness.yml` script path (`skills/agent-skills-setup/scripts/check-doc-freshness.py`) and removed the redundant `docs-freshness.yml`.\n- **#12 SKILL.md / CLI docs**: bumped `version` to `0.8.21`; corrected the device-handoff example to use `restore ... --restore-root <dir>` and removed the stale plan/exec caveat.\n\nv0.8.20 | 2026-08-17T14:24:25.222Z | user\n\n0.8.20 emergency security & release blocker hotfix: complete runtime packaging, closed-world ACB integrity, byte-level secret scanning, true bundle restore, and registry path corrections.\n\nv0.8.18 | 2026-08-17T05:40:11.775Z | auto\n\n- Added new subcommands: doctor, snapshot, and bundle-verify, expanding diagnostics and offline transfer capabilities.\n- Introduced device handoff workflow using `snapshot` and self-contained bundle archives for offline migration and restore.\n- Clarified diagnostics (`detect` / `doctor`) now inspect local installation and probe states offline.\n- Expanded execution documentation to distinguish migration, planning, verification, and offline transfer steps.\n- Surface migration scope clarified: skills, instructions, MCP, prompts, workflows, agents/droids, and hooks (with executable agents/defaults noted).\n- Opaque plugins/extensions are now marked for manual rebuild; UI-managed data remains outside scope.\n\nv0.8.17 | 2026-08-17T05:17:35.319Z | auto\n\n- Version updated to 0.8.17.\n- No functional changes; documentation (SKILL.md) updated for version increment only.\n\nv0.8.16 | 2026-08-17T05:07:49.004Z | auto\n\nVersion 0.8.16 – Adds multi-IDE support and reference updates\n\n- Added migration references for 11+ IDEs/products (e.g., gemini-code-assist, gitlab-duo, hermes, warp, zenflow).\n- Updated core references (`ide-registry.md`, `registry-v2.json`) for expanded IDE compatibility.\n- Streamlined SKILL.md with clearer, more concise migration guidance.\n- Improved handling of apply/rollback authorization; clarified never-move items.\n- Removed obsolete `skill-card.md` documentation file.\n\nv0.8.4 | 2026-08-15T15:00:27.368Z | user\n\n### Added\n\n- `snapshot` now copies every existing source file into the ACB under\n  `objects/<surface>/<product>/<profile>/<scope>/<canonical-path>` so\n  the bundle survives a real device-to-device handoff. Object paths\n  are stable across re-runs and across alias-equivalent selectors.\n- `restore` replays every recorded `objects/` file into\n  `<workspace>/.acb-restored/` (overridable via `--restore-root`).\n  Literal-secret-looking content is refused via `ACBSecretLeak`; any\n  object whose target escapes the restore root is recorded as\n  `skipped` instead of being written.\n- New `restore --dry-run` flag plans the restore and records what\n  would be written without touching the destination tree.\n\n### Changed\n\n- `collect_source_objects` now recurses one level into Skill\n  directories so per-Skill files land under the canonical path.\n- `ACBManifest.objects` adds an `objects_captured` count to the\n  snapshot response so callers can sanity-check that source bytes\n  were actually written.\n\n### Security\n\n- `restore_bundle_objects` validates every restored file path stays\n  inside the configured destination root, refusing any object whose\n  path would escape via `..` or absolute-path traversal.\n\nv0.8.3 | 2026-08-15T14:33:54.277Z | user\n\n### Added\n\n- Added the `migrate` subcommand that orchestrates `detect → inventory → plan → apply → verify` in a single invocation, defaulting to `--apply-safe --scope user,project` and writing plan/manifest/verify artifacts under `<workspace>/.migration/`.\n- Added the Agent Context Bundle (`.acb`) format with `snapshot`, `bundle-verify`, `restore`, and `doctor` subcommands. Bundles carry `manifest.json`, `inventory.json`, `compatibility.json`, `requirements.json`, `secrets.required.json`, `reauth.json`, `rebuild.json`, `checksums.json`, and `objects/`; `write_bundle` refuses to emit literal credentials (`ACBSecretLeak`).\n- Added a deterministic detection probe framework with seven installation states (`installed`, `configured-only`, `compatibility-only`, `cloud-connected`, `legacy`, `ambiguous`, `not-detected`); per-product wiring from Registry v2 lands in a follow-up release.\n- Added PromptIR / CommandIR / AgentIR / HookIR dataclasses and extended `MCPServerIR` with `cwd`, timeout variants, enabled flag, tool allow/deny lists, OAuth/auth, mTLS, server-instructions trust, target schema version, and package requirements. Full adapter emitters land in a follow-up release.\n- Added Rovo Dev and IBM Bob profiles; the Rovo MCP conflict (`mcp.json` vs `mcp_config.json`) is recorded via `doc_alternative_paths` and IBM Bob's IDE-vs-Shell MCP-path divergence is recorded via `mcp_path_note`.\n- Added ten new curated freshness checks (Cursor rules, Claude Code skills, Copilot CLI, VS Code agent skills, Gemini CLI skills, Kiro steering, Rovo Dev CLI skills, IBM Bob docs, Warp Drive prompts, Windsurf rules). Total curated checks: 18.\n\n### Changed\n\n- Made `Registry.profile()` follow the `alias_of` chain iteratively with a 16-hop depth bound and explicit cycle detection. `vscode`, `visual-studio`, `claude-desktop`, `trae-cn`, `jetbrains-ai`, `codeium`, and `trae-work` now resolve to their canonical product/profile at runtime; `Registry.profile_raw()` preserves the legacy behavior for callers and tests that need it. Added `Registry.resolve_selector()` for callers that want the full `ResolvedSelector` trace without resolving profile data.\n- Replaced the apply plan's all-or-nothing non-ready rejection with a seven-status dispatch (`ready`, `ready-lossy`, `draft-disabled`, `manual-rebuild`, `forbidden`, `conflict`, `invalid`). Conflict and invalid items now block only their own `target_group`; other groups proceed. New apply flags: `--apply-safe` (default), `--no-apply-safe`, `--include lossy`, `--accept-loss <ids>`, `--strict`.\n- Made `PlanItem` carry a stable `object_id = sha256(product|profile|scope|canonical_relative_path)[:16]` so repeated builds, alias-equivalent selectors, and same-source re-runs produce identical identifiers. Directory-style instruction targets now use basename-first naming with a short `object_id` suffix on collision; the legacy `migrated-N.md` form remains only as a last-resort fallback.\n- Broadened the Skill trigger description to match natural-language intents that name only a source and target (e.g. `把 Skill 迁到 X`). A phrase containing an action verb such as `apply` / `restore` / `迁移到` / `直接应用` is treated as combined authorization for `ready` and `draft-disabled` items under `--apply-safe`; enabling or executing Hooks, writing literal secrets, OAuth re-auth, trust grants, unresolved destructive overwrites, and enterprise or cloud policy changes still require per-item confirmation.\n- Upgraded the `cursor/ide` and `claude/code-cli` profiles from `manual-reference` to `bidirectional-reviewed` with concrete skills / instructions / mcp surfaces at user and project scopes.\n- Extended `scope_matches` to accept comma-separated scopes (`user,project`) so the migrate default scope resolves both user and project surfaces.\n- Extended the apply plan staging loops to skip items with `source` or `target` None, so plans that record forbidden or invalid items alongside ready items still satisfy the source/target state checks.\n\n### Security\n\n- Kept every existing safety invariant: source digest lock, Registry digest lock, Git HEAD lock, atomic staging, full-batch rollback, exact backups, symlink rejection, and literal-credential redaction. The PR1 dispatch refactor only routes items to the staging loop that survive those invariants.\n- Made `ACBSecretLeak` reject literal credential-looking strings anywhere in a bundle payload except the `secrets.required.json` name entries, so a snapshot can never leak an OAuth token or API key into a portable bundle.\n\nv0.8.2 | 2026-08-14T03:04:52.006Z | user\n\nHarden capability disclosure and approval boundaries; require explicit legacy routing and reject implicit fallback.\n\nv0.8.1 | 2026-08-13T15:41:17.053Z | user\n\nRegistry v2 safety hardening, native instruction adapters, conservative MCP conversion, drift-safe apply and rollback, expanded validation, and source-provenance release safeguards.\n\nv0.8.0 | 2026-08-13T05:31:56.613Z | user\n\nAdd Registry v2 and a profile-aware migration core with guarded plan, apply, verify, and rollback workflows.\n\nv0.7.4 | 2026-08-04T14:30:43.313Z | user\n\nHonor backup, skip, and overwrite strategies for project rules and prompts; reject indirect targets.\n\nv0.7.3 | 2026-08-04T14:14:01.804Z | user\n\nPreflight Skill sources before copy, declare local capabilities, and narrow migration triggers.\n\nv0.7.2 | 2026-08-03T14:33:41.959Z | user\n\nRemove implicit installers and bulk sync, publish a runtime-only allowlist, and make project migration scope explicit.\n\nv0.7.1 | 2026-08-03T12:23:49.306Z | user\n\nDeclare least-privilege filesystem and shell requirements, replace generic deletion with exact-target and copy-root guards, reject symlinked MCP targets, and strengthen release verification.\n\nv0.7.0 | 2026-08-03T05:16:49.848Z | user\n\nStreamline the migration skill, refresh current IDE guidance, add Android Studio, Visual Studio, JetBrains AI Assistant, Xcode, and Firebase Studio sunset support, and strengthen non-interactive safety and regression coverage.\n\nv0.6.11 | 2026-07-31T05:14:23.100Z | user\n\nFail closed for whole IDE config and project-tree migration; remove inherited MCP tool-approval grants.\n\nv0.6.10 | 2026-07-31T03:06:36.914Z | user\n\nDocument MCP 2026-07-28 transport boundaries: preserve explicit transport labels, do not upgrade legacy SSE from a URL, and re-authorize OAuth in the target client.\n\nv0.6.9 | 2026-07-30T02:51:53.793Z | user\n\nRestructure the migration skill for progressive disclosure: split IDE guidance into focused references, generate path summaries from the mapping contract, remove stale artifacts, and add mirror, layout, and drift regressions.\n\nv0.6.8 | 2026-07-29T14:23:05.515Z | user\n\nRemediate the ClawHub audit by narrowing the artifact to migration, excluding copied environment files, removing literal secret ingestion and recursive force deletion, and documenting preview-first OpenClaw migration.\n\nv0.6.7 | 2026-07-29T08:37:28.521Z | user\n\nReject unknown migration strategies before writes and preserve existing targets unchanged; add fail-closed regression coverage.\n\nv0.6.6 | 2026-07-29T07:46:04.057Z | user\n\nFix cross-platform Cline registry validation and verify every platform-specific path on all hosts.\n\nv0.6.5 | 2026-07-29T07:33:32.777Z | user\n\nFix VS Code profile safety and MCP conflict semantics; add OpenCode V2, deterministic JSON evidence, complete test discovery, and leaner guidance.\n\nv0.6.4 | 2026-07-29T03:02:10.021Z | user\n\nAdd strict explicit MCP source previews, safe environment-reference conversion, symlink identity guards, and executable migration evals.\n\nv0.6.3 | 2026-07-28T15:44:02.165Z | user\n\nfix(cline): correct cline/mcp to VS Code globalStorage; harden CR-002 fail-closed surface (delete_copy_only unification + --env annotation). 9 SkillSpector findings confirmed false positives.\n\nv0.6.2 | 2026-07-28T09:24:40.057Z | user\n\nBump to 0.6.2 - English i18n for scripts/tests, inert test-secret fixtures, documentation professionalism pass (P0-P3 audit).\n\nv0.6.1 | 2026-07-28T03:42:56.586Z | user\n\nv0.6.1 — CI fixes for Linux runner\n\nTwo pre-existing platform bugs fixed in this patch:\n\n1. platform-aware cline/mcp path. The Cline VS Code extension stores\n   its MCP config under a path that differs per OS — macOS uses\n   ~/Library/Application Support/Code/User/globalStorage/..., Linux\n   uses ~/.config/Code/User/globalStorage/..., Windows uses %APPDATA%/...\n   ide-paths.json now stores {darwin, linux, windows} for the entry;\n   verify-ide-config.sh resolves CLINE_MCP_PATH via uname -s.\n\n2. bash 5.x post-increment set -e fix in smart-ide-migration.sh\n   (migrate_global_skills, 8 sites). ((count++)) evaluated to 0\n   when count=0, returning exit code 1 and aborting the whole\n   migration under bash 5.x. Appended || true to all eight\n   post-increments.\n\nNo semantic change to migration behavior. All 17 test scripts pass;\nvalidate-all.sh remains green; GitHub Actions CI now passes on\nubuntu-latest in 32s.\n\nCoordinated with v0.6.0 — same SkillSpector/VirusTotal audit response\nplus these CI fixes for cross-platform publishing.\n\nv0.6.0 | 2026-07-28T03:00:14.933Z | user\n\nv0.6.0 — SkillSpector / VirusTotal audit response\n\nSecurity\n- Test fixture secret literals replaced: codex-secret-fixture and blackbox-secret-fixture → __test_placeholder_value__ (no longer trips YARA-style exposed_secret_literal scanner; still exercises the redactor's SECRET_KEY_RE keyword check on the key name).\n- Fail-closed rm cleanup annotated in 3 sites: SECURITY comments make the safety intent explicit. The target/skill parameter guards (${var:?} bash syntax) make rm safe by construction.\n- SKILL.md trigger description tightened: explicit \"DO NOT ACTIVATE ON\" list and \"when in doubt, ask the user\" guidance.\n\nDocs\n- SECURITY-AUDIT.md: per-finding mapping (1 real hit, 10 false positives on the documented purpose) with re-audit guidance.\n\nNo semantic change to migration behavior. All 17 test scripts pass and validate-all.sh remains green (446 + 70 + 80 + 851 + 22 = 1469 checks).\n\nv0.5.8 | 2026-07-27T16:20:32.500Z | user\n\n### Security (project-scope skill/MCP migration hardening)\n- **Project skill copy is now redaction-wrapped, fail-closed** (`smart-ide-migration.sh` `migrate_project_skills`). Mirrors the global-skill pattern: `redact_project_copy` runs on the COPY (never the source); on redaction failure the entire copied tree is removed and the migration is marked `failed`. Redactor file-glob now covers shell scripts (`*.sh`/`*.bash`/`*.zsh`) in addition to `*.json`/`*.yaml`/`*.toml`/`*.env`; the inline redactor accepts an optional `export ` prefix so POSIX-shell assignments (`export OPENAI_API_KEY=\"...\"`) match the same keyed-pair logic as JSON/TOML/YAML.\n- **Source==target guard for project skills.** antigravity/codex/zed all resolve to `.agents/skills`; claude/copilot/tencent-codebuddy share `.mcp.json`; trae/trae-cn share `.trae/mcp.json`. Without the guard, the backup strategy's `mv` renamed the source in place before the copy could read it, and the overwrite strategy `rm -rf`'d the source with no backup. Both branches now short-circuit to `manual` status with a clear message when canonical source_path == canonical target_path.\n- **Source==target guard for project MCP.** Same shape: `rm -f \"$target\"` and `cp -r \"$target\" \"$target.bak\"` now abort before destructive operations when source and target resolve to the same file.\n\n### Correctness (scope-aware MCP root keys + vscode workspace gating)\n- **`get_mcp_root_key` is now scope-aware.** Void Editor's project MCP path is the inherited VS Code `.vscode/mcp.json` which uses `servers` (not the Void-global `mcpServers`); the function returns `servers` for `void-editor` at `project` scope, `mcpServers` at user scope. All other IDEs unchanged.\n- **vscode workspace MCP override is gated on `scope == project`.** Previously unconditional (`if [[ \"$target_ide\" == \"vscode\" ]]; then target_mcp=\"$WORKSPACE_ROOT/.vscode/mcp.json\"`) — so `--scope global` to vscode wrote the workspace path. Now only fires when the user explicitly requested project scope.\n\n### CI / Tests\n- **`test-ide-paths.sh` regression: 1/446 drift check (cursor/project_mcp).** `ide-paths.json` gained `cursor.project_mcp` = `.cursor/mcp.json`; `--print-path cursor project-mcp` now returns `.cursor/mcp.json` and the registry cross-check passes (446/446).\n- **`test-cursor-mapping.sh`** expected dict now includes the new `project_mcp` key.\n- **`test-vscode-mapping.sh` and `test-mcp-secret-redaction.sh`** updated to use `--scope project` (placing the source `.mcp.json` in the workspace) for the `claude → vscode` MCP path, matching the new gating behavior.\n- All 17 `test-*.sh` scripts and `validate-all.sh` (446 + 70 + 80 + 851 checks) green.\n\nv0.5.7 | 2026-07-24T06:50:11.612Z | user\n\nProject migration (--objects project) now honors the same backup plus fail-closed secret-redaction contract as mcp/config: applies STRATEGY to existing targets (default backup to .bak.TS), redacts secrets from the copy not the source, fail-closed on redaction error, never reports success on empty transfer.\n\nv0.5.6 | 2026-07-24T06:02:11.050Z | user\n\nSecurity: smart-ide-migration.sh now enforces the documented confirmation gate — applying changes requires --yes/-y (interactive terminals prompt [y/N] before any write; non-interactive runs without --yes abort with exit 2 and zero writes). --dry-run is now strictly zero-write (fixed two stray mkdir calls that created target directories during preview). Usage examples switched to the two-step pattern: preview with --dry-run, then apply with --yes. Tests extended with 6 confirmation-gate assertions (migration suite 62 checks). Carries forward all 0.5.5 fixes: MCP/config secret redaction on every migration path (fail-closed + atomic write), 15 corrected IDE path mappings with lock-step ide-paths.json (218 drift checks), SKILL.md tutorial corrections, registry entries for openclaw/codeium/replit/supermaven/blackbox/pieces. All suites green: ide-paths 218/218, redaction 78/78, migration 62/62.\n\nv0.5.5 | 2026-07-24T02:52:02.360Z | user\n\nSecurity: MCP/config secret redaction enforced on every migration path (env/headers/credential-URLs/query-string secrets; array & argv-style secrets; fail-closed + atomic write); default scope excludes credential-bearing objects (mcp/config/project now opt-in). Fixed: 15 IDE path mappings corrected (windsurf, jetbrains/Junie, trae, trae-cn, cursor, copilot CLI, continue, roo-code, amazon-q, goose-cli, opencode, antigravity, kilocode, void-editor, zcode) with lock-step ide-paths.json updates (218 drift checks pass); SKILL.md tutorial errors fixed (.vscode/mcp.json mis-attribution, CODY.md -> .codyrules, added WorkBuddy/Kilo Code/Copilot CLI entries). Added: 7 newly wired IDEs (40 total), MCP paths for 8 previously silent IDEs, registry entries for openclaw/codeium/replit/supermaven/blackbox/pieces, sync-root-mirror check restored. Tests: ide-paths 218/218, redaction 78/78, migration 56/56.\n\nv0.5.4 | 2026-07-23T06:29:26.366Z | user\n\nRefresh ClawHub license metadata to MIT (0.5.3 had license:MIT in frontmatter but registry showed MIT-0); no code changes\n\nArchive index:\n\nArchive v0.10.2: 122 files, 255442 bytes\n\nFiles: assets/demo.gif (83653b), assets/LICENSE.clawhub (926b), LICENSE (926b), references/bundle-workflow.md (9215b), references/cli-workflow.md (7337b), references/doc-freshness-checks.json (3183b), references/ide-paths.json (9771b), references/ide-paths.tsv (7509b), references/ide-registry.md (7072b), references/ide-tier-overrides.json (665b), references/ides/aider.md (951b), references/ides/amazon-q.md (1385b), references/ides/android-studio.md (1335b), references/ides/antigravity.md (1779b), references/ides/augment-code.md (1205b), references/ides/baidu-comate-ide.md (339b), references/ides/baidu-comate.md (989b), references/ides/blackbox.md (1047b), references/ides/bolt-new.md (176b), references/ides/claude-desktop.md (1978b), references/ides/claude.md (1596b), references/ides/cline.md (1554b), references/ides/codecompanion-nvim.md (183b), references/ides/codeium.md (600b), references/ides/codely.md (1900b), references/ides/codex.md (1921b), references/ides/cody.md (800b), references/ides/continue.md (1072b), references/ides/copilot.md (1207b), references/ides/crush.md (807b), references/ides/cursor.md (1310b), references/ides/devin.md (166b), references/ides/emacs.md (605b), references/ides/factory-droid.md (772b), references/ides/firebase-studio.md (1582b), references/ides/forge.md (703b), references/ides/gemini-cli.md (1449b), references/ides/gemini-code-assist.md (341b), references/ides/gitlab-duo.md (345b), references/ides/goose-cli.md (1294b), references/ides/gptel-mcp-el.md (221b), references/ides/helix.md (166b), references/ides/hermes.md (309b), references/ides/ibm-bob.md (351b), references/ides/jetbrains-ai.md (1342b), references/ides/jetbrains.md (1468b), references/ides/jules.md (280b), references/ides/kilocode.md (1214b), references/ides/kimiai.md (948b), references/ides/kiro.md (1152b), references/ides/letta-code.md (243b), references/ides/letta.md (183b), references/ides/lovable.md (188b), references/ides/mcphub-nvim.md (192b), references/ides/minimax-code.md (213b), references/ides/mistral-vibe.md (585b), references/ides/mmx-cli.md (238b), references/ides/monkeycode.md (666b), references/ides/neovim.md (746b), references/ides/openclaw.md (1310b), references/ides/opencode.md (1409b), references/ides/openhands.md (458b), references/ides/pearai.md (545b), references/ides/pi.md (759b), references/ides/pieces.md (780b), references/ides/qoder-cn.md (425b), references/ides/qoder.md (785b), references/ides/qodo.md (348b), references/ides/qwen-code.md (583b), references/ides/replit.md (1121b), references/ides/roo-code.md (1213b), references/ides/rovodev.md (448b), references/ides/sourcegraph-amp.md (421b), references/ides/supermaven.md (651b), references/ides/tabnine.md (715b), references/ides/tencent-codebuddy-ide.md (696b), references/ides/tencent-codebuddy.md (1068b), references/ides/tongyi-lingma.md (281b), references/ides/trae-cn.md (1417b), references/ides/trae-work.md (198b)\n\nFile v0.10.2:SKILL.md\n\n---\nname: agent-skills-setup\nversion: \"0.10.2\"\ncompatibility: Requires local Bash, Python 3, environment lookup, and filesystem access; optional signing needs installed cryptography; no network access.\ndescription: >-\n  Use when a user wants to migrate, back up, restore, compare, or move\n  AI-coding-agent context across Cursor, Claude Code, Codex, Cline,\n  Copilot, Windsurf, Gemini CLI, or another registered profile, including\n  switching computers. Handles Skills, instructions/rules, and MCP with\n  secret redaction, preview, verification, rollback, and portable bundles;\n  compatible plugin packages and reviewed handoff are available by explicit opt-in.\nmetadata:\n  openclaw:\n    requires:\n      bins:\n        - bash\n        - python3\n---\n# Agent Skills Setup\n\n## Permissions\n\n- Run bundled local Bash/Python helpers and offline discovery only; network access is forbidden. No downloads, installations, or MCP connections.\n- Read selected products, requested scopes, workspace, bundles, and named keys. Broad discovery needs a device-wide request; environment lookup resolves paths without exposing credentials.\n- Write authorized targets, named plan/bundle/key outputs, and transaction state. `--yes` records existing user authorization for apply/restore/rollback; it does not grant authorization.\n\n## Choose the workflow\n\n- Infer products, objects, workspace, and scope from the request and established context. Project migration uses project scope; include user surfaces only when requested. Ask only for material information or authorization that cannot be inferred.\n- An explicit move/apply/restore/rollback request authorizes that scoped action. Preserve prior authorization; preview-only requests stop after preview. Review exact destinations and losses before writing; ask for unresolved conflicts, unapproved losses, or broader scope.\n- Save the plan, review its diff/rebuild manifest, and apply that exact file for execution. Changed inputs require a fresh plan and review.\n\n| Request | Entry point and guidance |\n| --- | --- |\n| Detect or inventory context | `detect`, `inventory`; [registry](references/ide-registry.md) and [CLI guide](references/cli-workflow.md). |\n| Compare or preview migration | `plan --json`; [migration safety](references/migration-safety.md). Saving `--output` writes a plan artifact. |\n| Migrate context | Saved `plan` → `apply --yes` → `verify`; `migrate` orchestrates the same stages. [CLI guide](references/cli-workflow.md). |\n| Back up or switch computers | `snapshot`, `bundle-verify`, `doctor`, `restore`; [bundle workflow](references/bundle-workflow.md). |\n| Sign or authenticate a bundle | `bundle-keygen`, `bundle-sign`, `bundle-verify --trusted-key`; [bundle workflow](references/bundle-workflow.md). |\n| Verify or undo applied changes | `verify`, `rollback --yes`; [verification](references/verification.md). |\n\nResolve both product profiles through [ide-registry.md](references/ide-registry.md) / [registry-v2.json](references/registry-v2.json) for migration; use bundle manifest selectors for restore.\n\n1. Read only the selected profiles' `references/ides/<source>.md` and `references/ides/<target>.md` files. Resolve concrete filenames through the [profile index](references/ide-registry.md) and registry reference/alias routing; filenames need not match selectors.\n2. Before preview or apply, read [migration-safety.md](references/migration-safety.md).\n3. For MCP, read [mcp-migration.md](references/mcp-migration.md); for other objects, [object-migration.md](references/object-migration.md). Load [verification.md](references/verification.md) for delivery evidence.\n\n## Supported boundaries\n\n- Automatic writers cover `skills`, `instructions`, and reviewed local stdio `mcp`. `plugins` needs `--include-plugins` and compatible package surfaces; `handoff` needs `--include-session` and whitelisted reviewed context.\n- Prompts, commands, agents, hooks, workflows, and unsupported formats produce review/rebuild actions. Never auto-activate executable content or migrate credentials, trust, approvals, raw history, or generated memory.\n- Shared config migration extracts only the authorized subobject and preserves unrelated settings. Cloud/UI and remote MCP remain manual; support is determined per surface, not by product name.\n- Use the explicit `legacy` subcommand for lookup/dry-run compatibility only; legacy writes are disabled.\n- Deliver artifact paths, applied/deferred counts, verification, backups, and remaining manual work. Parsing proves file validity; runtime and connectivity need their own evidence.\n\nFile v0.10.2:_meta.json\n\n{\n  \"ownerId\": \"kn73ym4c6fp5b2vaa22t84v5fn83pt1p\",\n  \"slug\": \"agent-skills-setup\",\n  \"version\": \"0.10.2\",\n  \"publishedAt\": 1791015266890\n}\n\nFile v0.10.2:references/bundle-workflow.md\n\n# Portable bundle, restore, and signing workflow\n\nRead for computer switching, portable backups, ACB restore, dependency checks,\nor signing. Commands below use `migrator=/path/to/agent-skills-setup/scripts/smart-ide-migration.sh`;\nsubstitute the installed Skill path and requested source, target, workspace,\nscopes, and artifact paths. Run each command independently and inspect its result.\nUse [migration-safety.md](migration-safety.md) for authorization and conflict rules.\n\n## Capture and inspect\n\n`snapshot` writes an ACB **directory**, not a compressed archive. Name the source\nand output explicitly; the CLI's fallback product selectors are examples, not\npermission to inspect or restore those products.\n\n```bash\nbash \"$migrator\" snapshot --source cursor/ide --target cursor/ide \\\n    --workspace /path/to/project --scope project \\\n    --objects skills,instructions,mcp --output /path/to/project.acb --json\nbash \"$migrator\" bundle-verify /path/to/project.acb --json\nbash \"$migrator\" doctor /path/to/project.acb --json\n```\n\nReview `manifest.json`, the collection summary, `rebuild.json`, and\n`secrets.required.json`. ACB contains portable object bytes, sanitized inventory,\ncompatibility evidence, requirements, reauthentication actions, and checksums\nbinding every declared file. Failed, excluded, or manual objects are not\nautomatically backed up; report them. Credential values and private runtime\nstate must remain outside the bundle.\n\n`objects_captured` counts captured product/profile/scope object surfaces;\n`files_captured` counts their payload files. Compare these with the manifest's\nfile bindings and collection exclusions rather than treating file count as\nthe number of Skills or servers. ACB payload limits are 5,000 files, 10 MiB per\nfile, 100 MiB total, and 16 directory levels. Known image/font assets are\nallowed; executable or unallowlisted binary files fail collection instead of\nsilently disappearing. The exact extensions are `SAFE_BINARY_EXTENSIONS` in\n[acb/bundle.py](../scripts/acb/bundle.py).\n\nNew snapshots record optional integer `files[].mode` permission bits (`0..0o777`)\nin the checksummed manifest. On POSIX, restore and opt-in extraction apply these\nbits to copied files, preserving text helper scripts' executable bits while\ndropping setuid, setgid, and sticky flags. Payload storage permissions need not\nmatch the source. Older mode-less bundles remain readable but cannot establish\noriginal executable permissions; Windows applies only permissions supported by\nits filesystem. Verify required target file modes separately from content\nhashes; directory permissions and script execution are outside this guarantee.\nRecorded modes apply to copied Skill/plugin files and extracted payloads.\nGenerated instruction, MCP, and handoff files use their target writer's\npermissions; for example, generated MCP configuration is private (`0600`).\n\nFor a requested device-wide backup, run `detect` and review eligible profiles,\nthen use `snapshot --all-installed --scope user,project --output ...`.\n`--include-configured` and `--include-compatibility` broaden eligibility to those\ndetection states only when the user wants them. Do not equate shared context\ndirectories with installation proof. Prefer explicitly selected profiles when\ndevice detection cannot establish the requested scope.\n\nPlugins and handoff are opt-in objects, with both the object selector and flag:\n`--objects plugins --include-plugins` or `--objects handoff --include-session`.\nPackage copying requires compatible registry surfaces and performs no install\nor activation. Handoff transports only reviewed summary, branch, selected\nrelative files, and an explicit patch; raw session logs and state are excluded.\nApply the same opt-in flags during restore or saved-plan apply.\n\n## Restore on the destination device\n\nInspect bundle integrity and run `doctor` before execution. Resolve source\nselectors from the manifest and choose concrete destination profiles. Missing\ntools or packages are manual installation work; this skill installs nothing.\n\n`doctor` reports the complete recorded `requirements` and per-executable\n`executable_checks` with `found_on_path`. It checks only executable presence;\n`unresolved_requirements` retains missing executables plus the recorded\npackages, extensions, `manual_installs` (including local script paths), and\nplatform notes. These other requirements are unverified and remain manual\nwork, alongside `reauth_actions` and `rebuild_actions`. Script paths and\nplatform notes are reported as recorded, without resolving new target paths\nor probing product installation. No dependency is executed, imported,\ninstalled, or contacted.\n\n`ok: true` and exit 0 mean bundle integrity and executable-presence checks\npassed; unresolved manual requirements do not change that result. Missing\nexecutables produce `ok: false` and exit 1 while retaining the requirement\nreport. An invalid bundle produces exit 1 at `stage: verify` before its\nrequirements are reported. This status does not establish dependency or\nproduct readiness.\n\n```bash\nbash \"$migrator\" restore /path/to/project.acb \\\n    --source cursor/ide --target cline/ide \\\n    --workspace /path/to/new-project --scope project \\\n    --objects skills,instructions,mcp --plan-only \\\n    --plan-out /path/to/restore-plan.json --json\nbash \"$migrator\" restore /path/to/project.acb \\\n    --source cursor/ide --target cline/ide \\\n    --workspace /path/to/new-project --scope project \\\n    --objects skills,instructions,mcp --plan-in /path/to/restore-plan.json \\\n    --manifest-out /path/to/restore-manifest.json --yes --json\nbash \"$migrator\" verify --manifest /path/to/restore-manifest.json --json\n```\n\nCheck target paths, source content bindings, existing-target diffs, losses, and\nrebuild actions in the saved plan before replay. Restore uses bundle sources and\ndestination-side states; local source installations do not replace the backup.\nBundle or destination drift requires a fresh plan. Saved-plan execution can\nalso use `apply <plan> --bundle <bundle> --yes`; trusted-signature verification\nshould be performed before that path. Use `restore --trusted-key` when signer\nauthentication must be enforced during restore itself.\n\nNew named restore plans record `bundle_source` (bundle ID and manifest SHA256)\nand an `acb_uri` such as `acb://<bundle-id>#<object-id>` for each captured source,\nalongside its temporary execution path. Named replay checks the verified\nmanifest's product, profile, scope, and object identity before target writes;\nmoving the bundle does not change that identity. Saved plan bytes and\n`plan_sha256` stay unchanged during replay. Generic `apply` requires `--bundle`\nfor these plans. Older named plans without this metadata retain their existing\nsource-content and destination-state validation when supplied with a bundle.\n\nFor requested multi-product restore, use `--all-installed` in both planning and\nreplay, review per-target conflicts and failures, and retain the same scopes and\nopt-ins. Apply writes only eligible targets. A bundle resolving no eligible\nobjects fails by default; `--allow-noop` is for an intentional review/no-op,\nnot evidence of restoration.\n\n`--plan-only` avoids product writes but can save `--plan-out`. `--dry-run`\navoids persistent output writes. `--restore-root <dir>` explicitly extracts a\nreview tree and is unnecessary for ordinary restore; extraction is distinct\nfrom installation into destination product surfaces.\n\n## Sign and authenticate\n\nEd25519 key generation, signing, and signature checks need an already installed\nPython `cryptography` package. If unavailable, report the missing dependency;\nchecksum verification and unsigned backup remain usable offline. Use fresh,\ndistinct key paths outside bundles and migration surfaces. Keep the private\n32-byte raw key owner-only; distribute only the public key. Key generation uses\nPOSIX mode `0600` or a protected Windows ACL granting access only to the current\nuser. Signing checks those permissions before reading the private key and\nrejects keys with broader access. Windows key storage must support file ACLs.\n\nIf generation fails after creating an output, inspect `outputs_requiring_review`\nbefore retrying with fresh paths. POSIX outputs are preserved because a pathname\nmay have been replaced concurrently; never delete a listed path without checking\nits current contents and ownership. Windows removes only files still bound to\nthe original held creation handles. Do not use a keypair from a failed operation.\n\n```bash\nbash \"$migrator\" bundle-keygen --out-private /path/to/private.key \\\n    --out-public /path/to/public.key --json\nbash \"$migrator\" bundle-sign /path/to/project.acb \\\n    --key /path/to/private.key --signer local-operator --json\nbash \"$migrator\" bundle-verify /path/to/project.acb \\\n    --trusted-key /path/to/public.key --json\n```\n\nObtain the trusted public key independently of the bundle. `signature.json`\ncontains an embedded public key, which by itself does not establish trust.\nSigning verifies bundle integrity before attestation; report signature\nverification separately from checksums and dependency readiness. Preserve\nexisting keys and signed bundles unless the user authorizes replacing them.\n\nFile v0.10.2:references/cli-workflow.md\n\n# Public CLI workflow\n\nRead for detection, inventory, comparison, profile-aware migration, and command\nselection. `smart-ide-migration.sh` is the public wrapper. Set its path to the\ninstalled Skill directory, independent of the project working directory:\n\n```bash\nmigrator=/path/to/agent-skills-setup/scripts/smart-ide-migration.sh\n```\n\nUse concrete `<product>/<profile>` selectors from [Registry v2](registry-v2.json).\nProfile aliases, supported surfaces, platforms, and manual boundaries come from\n[ide-registry.md](ide-registry.md). Do not substitute paths from another product\nor a different profile. Paths can use documented environment/platform overrides;\nremote-host surfaces remain experimental.\n\n| Command | Observable result |\n| --- | --- |\n| `detect` | Offline install/configuration/compatibility detection, with evidence. |\n| `inventory` | Resolved surfaces, policy, precedence, and existence. |\n| `plan` | Destination paths, statuses, diffs, losses, and rebuild actions. |\n| `migrate` | Saved plan, apply manifest, and verification artifact in one flow. |\n| `apply` | Execution of a saved, state-validated plan and transaction manifest. |\n| `verify` | Whether recorded applied files still match their manifest. |\n| `rollback` | Guarded undo using that apply manifest. |\n| `snapshot` | Portable ACB directory and collection/exclusion summary. |\n| `bundle-verify` | Closed-world checksum, binding, and secret checks; optional trusted signature. |\n| `bundle-keygen`, `bundle-sign` | Offline Ed25519 key files or signature artifact. |\n| `restore` | Destination-side plan from bundle bytes, optional apply and verify. |\n| `doctor` | Complete recorded requirements, executable PATH checks, and reauthentication/rebuild actions. |\n| `legacy` | Explicit lookup or zero-write dry-run compatibility only. |\n\nLegacy preview reports stay on stdout, including when `--report` is supplied;\nthe named file is neither created nor changed. Use `plan --output` to save a\nprofile-aware plan for review and execution.\n\n`--json` emits one JSON document on stdout; diagnostics go to stderr. Inspect\nexit status, item statuses, and applied counts, not merely `ok`. Use\n`bash \"$migrator\" <command> --help` for that command's accepted flags.\n\n## Detect and preview the named project\n\n```bash\nbash \"$migrator\" detect --product cursor --profile ide \\\n    --workspace /path/to/project --json\nbash \"$migrator\" inventory --product cursor --profile ide \\\n    --workspace /path/to/project --json\nbash \"$migrator\" plan --source cursor/ide --target claude/code-cli \\\n    --workspace /path/to/project --scope project \\\n    --objects skills,instructions,mcp --json\n```\n\nThe final command emits a preview without saving an artifact. To prepare an\nauthorized execution, add `--output /path/to/plan.json`, read that file's\n`review_preview`, `loss_report`, and `rebuild_manifest`, and apply the same file.\nDo not claim a migration from detection, plan output, or an empty inventory.\nBroad `detect`/`inventory` without a product filter is for a device-wide request.\n\n## Apply and verify a saved plan\n\n```bash\nbash \"$migrator\" plan --source cursor/ide --target claude/code-cli \\\n    --workspace /path/to/project --scope project \\\n    --objects skills,instructions,mcp --output /path/to/plan.json --json\nbash \"$migrator\" apply /path/to/plan.json \\\n    --manifest /path/to/manifest.json --yes --json\nbash \"$migrator\" verify --manifest /path/to/manifest.json --json\n```\n\nFollow [migration-safety.md](migration-safety.md) before execution and\n[verification.md](verification.md) for delivery or rollback. Only use `--yes`\nwithin the user's existing authorization. A saved plan locks source/target\nstates, Registry digest, adapter versions, and Git provenance; drift is a\nfailure requiring a fresh plan. Apply does not accept arbitrary source files\nthrough legacy flags: stage user-supplied fixtures in an isolated workspace's\ndocumented source surface when testing, without overwriting real configuration.\n\n`--apply-safe` is the default. It applies eligible objects, defers lossy ones\nunless accepted, and records manual/forbidden/conflict outcomes. Conflicts block\ntheir target group. `--strict` rejects any non-`ready` item. `--no-apply-safe`\nalso requires every item to be `ready` before any target write.\n`--include lossy` accepts all reviewed lossy items. `--accept-loss` on\n`apply`/`migrate` names item IDs such as `3:instructions`, not bare row numbers.\nExplicit loss acceptance remains necessary when the original request did not\nauthorize those semantics.\n\nInstruction/MCP conversions that drop reported fields or redact credentials\nare `ready-lossy`; `--yes` alone does not accept those losses. Accepted\nconversions still remove unsupported fields and literal credentials. Required\nSkill `.env` exclusions remain enforced without making an otherwise eligible\nSkill copy require loss acceptance.\n\n## Orchestrated migration\n\nFor an authorized scoped migration, `migrate` runs planning, apply, and verify:\n\n```bash\nbash \"$migrator\" migrate --source cursor/ide --target claude/code-cli \\\n    --workspace /path/to/project --scope project \\\n    --objects skills,instructions,mcp --plan-out /path/to/plan.json \\\n    --manifest-out /path/to/manifest.json --verify-out /path/to/verify.json \\\n    --yes --json\n```\n\nUse `--plan-only` when execution should stop at the plan. It still saves the\nplan; use ordinary `plan --json` for a preview with no persistent output writes.\nWithout explicit output paths, orchestration uses `<workspace>/.migration/`;\ntransaction backups and default apply manifests use\n`<workspace>/.agent-context-migration/`.\nChoose fresh manifest and verification output paths for each execution. Existing\ntransaction artifacts are preserved and rejected as outputs; keep them for\nverification and rollback instead of replacing them on a repeated run.\n\n`--objects all-portable` selects `skills,instructions,mcp`. Select narrower\nobjects when requested; `--objects all-inventory` is for inventory/manual/forbidden\nreporting, not permission to write those surfaces. Opt-in `plugins` and `handoff`\nalso require `--include-plugins` or `--include-session`, respectively.\nScopes are `user`, `project`, `local`, or documented unions/all as accepted by\neach command; applying `migrate --scope all` requires `--yes`, while\n`--plan-only` can preview it without that flag. CLI defaults differ, so pass explicit scopes instead of allowing a project request to inspect user files.\n\n## Backup, signing, diagnostics, and recovery\n\nUse [bundle-workflow.md](bundle-workflow.md) for `snapshot`, `bundle-verify`,\n`bundle-keygen`, `bundle-sign`, `doctor`, and bundle-backed `restore`/`apply`.\nUse [object-migration.md](object-migration.md) and\n[mcp-migration.md](mcp-migration.md) for object-specific boundaries. Remote MCP,\ncloud/UI, and unsupported adapters produce reconstruction actions, not silent\nfallback copies.\n\nThe explicit `legacy` subcommand accepts retained lookup/dry-run syntax:\n\n```bash\nbash \"$migrator\" legacy --print-path cursor project-mcp\n```\n\nImplicit legacy flags, direct legacy-engine execution, and every legacy write\nare rejected. Legacy `--source-mcp-file`, `--opencode-version`, or `--strategy`\nexamples cannot authorize a public write; use reviewed profile-aware plans or\nmanual reconstruction when the current Registry has no writable adapter.\n\nFile v0.10.2:references/doc-freshness-checks.json\n\n{\n  \"schema_version\": 1,\n  \"verified_at\": \"2026-08-15\",\n  \"checks\": [\n    {\n      \"id\": \"agent-skills-spec\",\n      \"url\": \"https://raw.githubusercontent.com/agentskills/agentskills/main/docs/specification.mdx\",\n      \"required_terms\": [\n        \"name\",\n        \"description\",\n        \"metadata\"\n      ]\n    },\n    {\n      \"id\": \"cline-config\",\n      \"url\": \"https://docs.cline.bot/getting-started/config\",\n      \"required_terms\": [\n        \"cline\",\n        \"configuration\"\n      ]\n    },\n    {\n      \"id\": \"forgecode-docs\",\n      \"url\": \"https://forgecode.dev/docs/\",\n      \"required_terms\": [\n        \"forge\",\n        \"agent\"\n      ]\n    },\n    {\n      \"id\": \"qoder-docs\",\n      \"url\": \"https://docs.qoder.com/\",\n      \"required_terms\": [\n        \"qoder\"\n      ]\n    },\n    {\n      \"id\": \"codex-docs\",\n      \"url\": \"https://learn.chatgpt.com/docs/llms.txt\",\n      \"required_terms\": [\n        \"codex\"\n      ]\n    },\n    {\n      \"id\": \"openhands-docs\",\n      \"url\": \"https://docs.openhands.dev/overview/introduction\",\n      \"required_terms\": [\n        \"openhands\"\n      ]\n    },\n    {\n      \"id\": \"amp-manual\",\n      \"url\": \"https://ampcode.com/manual\",\n      \"required_terms\": [\n        \"agent skills\",\n        \"mcp\"\n      ]\n    },\n    {\n      \"id\": \"monkeycode-readme\",\n      \"url\": \"https://raw.githubusercontent.com/chaitin/MonkeyCode/main/README.md\",\n      \"required_terms\": [\n        \"monkeycode\",\n        \"development platform\"\n      ]\n    },\n    {\n      \"id\": \"cursor-rules\",\n      \"url\": \"https://docs.cursor.com/context/rules\",\n      \"required_terms\": [\n        \"cursor\",\n        \"rule\"\n      ]\n    },\n    {\n      \"id\": \"claude-code-skills\",\n      \"url\": \"https://code.claude.com/docs/en/skills\",\n      \"required_terms\": [\n        \"skill\"\n      ]\n    },\n    {\n      \"id\": \"github-copilot-cli\",\n      \"url\": \"https://docs.github.com/en/copilot/how-tos/copilot-cli\",\n      \"required_terms\": [\n        \"copilot\",\n        \"cli\"\n      ]\n    },\n    {\n      \"id\": \"vscode-agent-skills\",\n      \"url\": \"https://code.visualstudio.com/docs/agent-customization/agent-skills\",\n      \"required_terms\": [\n        \"skill\"\n      ]\n    },\n    {\n      \"id\": \"gemini-cli-skills\",\n      \"url\": \"https://github.com/google-gemini/gemini-cli/blob/main/docs/skills.md\",\n      \"required_terms\": [\n        \"gemini\",\n        \"skill\"\n      ]\n    },\n    {\n      \"id\": \"kiro-steering\",\n      \"url\": \"https://kiro.dev/docs/steering\",\n      \"required_terms\": [\n        \"kiro\",\n        \"steering\"\n      ]\n    },\n    {\n      \"id\": \"rovodev-cli-skills\",\n      \"url\": \"https://support.atlassian.com/rovo/docs/use-agent-skills-in-rovo-dev-cli/\",\n      \"required_terms\": [\n        \"rovo\",\n        \"skill\"\n      ]\n    },\n    {\n      \"id\": \"ibm-bob-docs\",\n      \"url\": \"https://www.ibm.com/docs/en/bob\",\n      \"required_terms\": [\n        \"bob\",\n        \"agent\"\n      ]\n    },\n    {\n      \"id\": \"warp-drive-prompts\",\n      \"url\": \"https://docs.warp.dev/agents/prompts\",\n      \"required_terms\": [\n        \"warp\",\n        \"prompt\"\n      ]\n    },\n    {\n      \"id\": \"windsurf-rules\",\n      \"url\": \"https://docs.codeium.com/windsurf/rules\",\n      \"required_terms\": [\n        \"windsurf\",\n        \"rule\"\n      ]\n    }\n  ]\n}\n\nFile v0.10.2:references/ide-paths.json\n\n{\n  \"antigravity\": {\n    \"global_skills\": \"~/.gemini/config/skills\",\n    \"project_skills\": \".agents/skills\",\n    \"rules\": \".agents/rules\",\n    \"mcp\": \"~/.gemini/config/mcp_config.json\",\n    \"project_mcp\": \".agents/mcp_config.json\",\n    \"config\": \"\"\n  },\n  \"claude\": {\n    \"global_skills\": \"~/.claude/skills\",\n    \"project_skills\": \".claude/skills\",\n    \"rules\": \"CLAUDE.md\",\n    \"mcp\": \"~/.claude.json\",\n    \"project_mcp\": \".mcp.json\",\n    \"project_config\": \".claude/settings.json\",\n    \"config\": \"~/.claude/settings.json\"\n  },\n  \"codely\": {\n    \"global_skills\": \"~/.codely-cli/skills\",\n    \"project_skills\": \".codely-cli/skills\",\n    \"rules\": \"CODELY.md\",\n    \"mcp\": \"~/.codely-cli/settings.json\",\n    \"project_mcp\": \".codely-cli/settings.json\",\n    \"project_config\": \".codely-cli/settings.json\",\n    \"config\": \"~/.codely-cli/settings.json\"\n  },\n  \"codex\": {\n    \"global_skills\": \"~/.agents/skills\",\n    \"project_skills\": \".agents/skills\",\n    \"rules\": \"AGENTS.md\",\n    \"mcp\": \"~/.codex/config.toml\",\n    \"project_mcp\": \".codex/config.toml\",\n    \"project_config\": \".codex/config.toml\",\n    \"config\": \"~/.codex/config.toml\"\n  },\n  \"copilot\": {\n    \"global_skills\": \"~/.copilot/skills\",\n    \"project_skills\": \".github/skills\",\n    \"rules\": \".github/copilot-instructions.md\",\n    \"mcp\": \"~/.copilot/mcp-config.json\",\n    \"project_mcp\": \".mcp.json\",\n    \"config\": \"\"\n  },\n  \"cursor\": {\n    \"global_skills\": \"~/.cursor/skills\",\n    \"project_skills\": \".cursor/skills\",\n    \"rules\": \".cursor/rules\",\n    \"mcp\": \"~/.cursor/mcp.json\",\n    \"project_mcp\": \".cursor/mcp.json\",\n    \"config\": \"\"\n  },\n  \"windsurf\": {\n    \"global_skills\": \"~/.codeium/windsurf/skills\",\n    \"project_skills\": \".windsurf/skills\",\n    \"rules\": \".windsurf/rules\",\n    \"mcp\": \"~/.codeium/windsurf/mcp_config.json\",\n    \"config\": \"\"\n  },\n  \"jetbrains\": {\n    \"global_skills\": \"~/.junie/skills\",\n    \"project_skills\": \".junie/skills\",\n    \"rules\": \".junie/AGENTS.md\",\n    \"mcp\": \"~/.junie/mcp/mcp.json\",\n    \"project_mcp\": \".junie/mcp/mcp.json\",\n    \"config\": \"\"\n  },\n  \"openclaw\": {\n    \"global_skills\": \"~/.openclaw/skills\",\n    \"project_skills\": \"skills\",\n    \"rules\": \"AGENTS.md\",\n    \"mcp\": \"~/.openclaw/openclaw.json\",\n    \"config\": \"~/.openclaw/openclaw.json\"\n  },\n  \"trae\": {\n    \"global_skills\": \"~/.trae/skills\",\n    \"project_skills\": \".trae/skills\",\n    \"rules\": \".trae/rules\",\n    \"mcp\": \"\",\n    \"project_mcp\": \".trae/mcp.json\",\n    \"config\": \"\"\n  },\n  \"trae-cn\": {\n    \"global_skills\": \"~/.trae-cn/skills\",\n    \"project_skills\": \".trae/skills\",\n    \"rules\": \".trae/rules\",\n    \"mcp\": \"\",\n    \"project_mcp\": \".trae/mcp.json\",\n    \"config\": \"\"\n  },\n  \"vscode\": {\n    \"global_skills\": \"~/.copilot/skills\",\n    \"project_skills\": \".github/skills\",\n    \"rules\": \".github/copilot-instructions.md\",\n    \"mcp\": \"\",\n    \"project_mcp\": \".vscode/mcp.json\",\n    \"config\": \"\"\n  },\n  \"visual-studio\": {\n    \"global_skills\": \"~/.copilot/skills\",\n    \"project_skills\": \".github/skills\",\n    \"rules\": \".github/copilot-instructions.md\",\n    \"mcp\": {\n      \"darwin\": \"\",\n      \"linux\": \"\",\n      \"windows\": \"%USERPROFILE%\\\\.mcp.json\"\n    },\n    \"project_mcp\": \".mcp.json\",\n    \"config\": \"\"\n  },\n  \"jetbrains-ai\": {\n    \"global_skills\": \"\",\n    \"project_skills\": \".agents/skills\",\n    \"rules\": \"\",\n    \"mcp\": \"\",\n    \"project_mcp\": \"\",\n    \"config\": \"\"\n  },\n  \"firebase-studio\": {\n    \"global_skills\": \"\",\n    \"project_skills\": \"\",\n    \"rules\": \".idx/airules.md\",\n    \"mcp\": \"\",\n    \"project_mcp\": \".idx/mcp.json\",\n    \"config\": \"\"\n  },\n  \"android-studio\": {\n    \"global_skills\": \"~/.agents/skills\",\n    \"project_skills\": \".agents/skills\",\n    \"rules\": \"AGENTS.md\",\n    \"mcp\": \"\",\n    \"project_mcp\": \"\",\n    \"config\": \"\"\n  },\n  \"zed\": {\n    \"global_skills\": \"~/.agents/skills\",\n    \"project_skills\": \".agents/skills\",\n    \"rules\": \"AGENTS.md\",\n    \"mcp\": \"~/.config/zed/settings.json\",\n    \"project_mcp\": \".zed/settings.json\",\n    \"config\": \"\"\n  },\n  \"neovim\": {\n    \"global_skills\": \"\",\n    \"project_skills\": \"\",\n    \"rules\": \"\",\n    \"mcp\": \"\",\n    \"config\": \"~/.config/nvim/init.lua\"\n  },\n  \"emacs\": {\n    \"global_skills\": \"\",\n    \"project_skills\": \"\",\n    \"rules\": \"\",\n    \"mcp\": \"\",\n    \"config\": \"\"\n  },\n  \"continue\": {\n    \"global_skills\": \"\",\n    \"project_skills\": \"\",\n    \"rules\": \".continue/rules\",\n    \"mcp\": \"~/.continue/config.yaml\",\n    \"project_mcp\": \".continue/mcpServers\",\n    \"config\": \"~/.continue/config.yaml\"\n  },\n  \"aider\": {\n    \"global_skills\": \"\",\n    \"project_skills\": \"\",\n    \"rules\": \"CONVENTIONS.md\",\n    \"mcp\": \"\",\n    \"config\": \"~/.aider.conf.yml\"\n  },\n  \"roo-code\": {\n    \"global_skills\": \"~/.roo/skills\",\n    \"project_skills\": \".roo/skills\",\n    \"rules\": \".roorules\",\n    \"project_mcp\": \".roo/mcp.json\",\n    \"mcp\": \"\",\n    \"config\": \"\"\n  },\n  \"cline\": {\n    \"project\": \"\",\n    \"global_skills\": \"~/.cline/skills\",\n    \"project_skills\": \".cline/skills\",\n    \"rules\": \".cline/rules\",\n    \"mcp\": \"~/.cline/data/settings/cline_mcp_settings.json\",\n    \"project_mcp\": \".cline/mcp.json\",\n    \"config\": \"\"\n  },\n  \"amazon-q\": {\n    \"global_skills\": \"\",\n    \"project_skills\": \"\",\n    \"rules\": \".amazonq/rules\",\n    \"mcp\": \"~/.aws/amazonq/default.json\",\n    \"project_mcp\": \".amazonq/default.json\",\n    \"config\": \"\"\n  },\n  \"cody\": {\n    \"global_skills\": \"\",\n    \"project_skills\": \"\",\n    \"rules\": \"\",\n    \"mcp\": \"\",\n    \"config\": \"\"\n  },\n  \"codeium\": {\n    \"global_skills\": \"\",\n    \"project_skills\": \"\",\n    \"rules\": \"\",\n    \"mcp\": \"\",\n    \"config\": \"\"\n  },\n  \"tabnine\": {\n    \"global_skills\": \"\",\n    \"project_skills\": \"\",\n    \"rules\": \".tabnine/guidelines\",\n    \"mcp\": \"~/.tabnine/mcp_servers.json\",\n    \"project_mcp\": \".tabnine/mcp_servers.json\",\n    \"config\": \"\"\n  },\n  \"replit\": {\n    \"global_skills\": \"\",\n    \"project_skills\": \".agents/skills\",\n    \"rules\": \"replit.md\",\n    \"mcp\": \"\",\n    \"project_config\": \".replit\",\n    \"config\": \"\"\n  },\n  \"pearai\": {\n    \"global_skills\": \"\",\n    \"project_skills\": \"\",\n    \"rules\": \"\",\n    \"mcp\": \"\",\n    \"config\": \"\"\n  },\n  \"supermaven\": {\n    \"global_skills\": \"\",\n    \"project_skills\": \"\",\n    \"rules\": \"\",\n    \"mcp\": \"\",\n    \"config\": \"\"\n  },\n  \"pieces\": {\n    \"global_skills\": \"\",\n    \"project_skills\": \"\",\n    \"rules\": \"\",\n    \"mcp\": \"\",\n    \"project_mcp\": \"\",\n    \"project_config\": \"\",\n    \"config\": \"\"\n  },\n  \"blackbox\": {\n    \"global_skills\": \"\",\n    \"project_skills\": \".blackbox/skills\",\n    \"rules\": \"\",\n    \"mcp\": \"\",\n    \"config\": \"\"\n  },\n  \"gemini-cli\": {\n    \"global_skills\": \"~/.gemini/skills\",\n    \"project_skills\": \".gemini/skills\",\n    \"rules\": \"GEMINI.md\",\n    \"mcp\": \"~/.gemini/settings.json\",\n    \"project_mcp\": \".gemini/settings.json\",\n    \"project_config\": \".gemini/settings.json\",\n    \"config\": \"~/.gemini/settings.json\"\n  },\n  \"goose-cli\": {\n    \"global_skills\": \"~/.agents/skills\",\n    \"project_skills\": \".agents/skills\",\n    \"rules\": \".goosehints\",\n    \"mcp\": \"~/.config/goose/config.yaml\",\n    \"config\": \"~/.config/goose/config.yaml\"\n  },\n  \"opencode\": {\n    \"global_skills\": \"~/.config/opencode/skills\",\n    \"project_skills\": \".opencode/skills\",\n    \"rules\": \"AGENTS.md\",\n    \"mcp\": \"~/.config/opencode/opencode.json\",\n    \"project_mcp\": \"opencode.json\",\n    \"project_config\": \"opencode.json\",\n    \"config\": \"~/.config/opencode/opencode.json\"\n  },\n  \"kilocode\": {\n    \"project\": \".kilo\",\n    \"global_skills\": \"~/.kilo/skills\",\n    \"project_skills\": \".kilo/skills\",\n    \"rules\": \"AGENTS.md\",\n    \"mcp\": \"~/.config/kilo/kilo.jsonc\",\n    \"project_mcp\": \".kilo/kilo.jsonc\",\n    \"project_config\": \".kilo/kilo.jsonc\",\n    \"config\": \"~/.config/kilo/kilo.jsonc\"\n  },\n  \"kimiai\": {\n    \"global_skills\": \"~/.kimi-code/skills\",\n    \"project_skills\": \".kimi-code/skills\",\n    \"rules\": \"AGENTS.md\",\n    \"mcp\": \"~/.kimi-code/mcp.json\",\n    \"project_mcp\": \".kimi-code/mcp.json\",\n    \"config\": \"~/.kimi-code/config.toml\"\n  },\n  \"workbuddy\": {\n    \"global_skills\": \"\",\n    \"project_skills\": \"\",\n    \"rules\": \"\",\n    \"mcp\": \"~/.workbuddy/mcp.json\",\n    \"project_mcp\": \".workbuddy/mcp.json\",\n    \"config\": \"\"\n  },\n  \"claude-desktop\": {\n    \"global_skills\": \"\",\n    \"project_skills\": \"\",\n    \"rules\": \"\",\n    \"mcp\": {\n      \"darwin\": \"~/Library/Application Support/Claude/claude_desktop_config.json\",\n      \"linux\": \"\",\n      \"windows\": \"%APPDATA%\\\\Claude\\\\claude_desktop_config.json\"\n    },\n    \"config\": \"\"\n  },\n  \"kiro\": {\n    \"global_skills\": \"~/.kiro/skills\",\n    \"project_skills\": \".kiro/skills\",\n    \"rules\": \".kiro/steering\",\n    \"mcp\": \"~/.kiro/settings/mcp.json\",\n    \"project_mcp\": \".kiro/settings/mcp.json\",\n    \"config\": \"\"\n  },\n  \"augment-code\": {\n    \"global_skills\": \"~/.augment/skills\",\n    \"project_skills\": \".augment/skills\",\n    \"rules\": \".augment/rules\",\n    \"mcp\": \"~/.augment/settings.json\",\n    \"project_mcp\": \".augment/settings.json\",\n    \"project_config\": \".augment/settings.json\",\n    \"config\": \"~/.augment/settings.json\"\n  },\n  \"void-editor\": {\n    \"global_skills\": \"\",\n    \"project_skills\": \"\",\n    \"rules\": \".voidrules\",\n    \"mcp\": \"~/.void-editor/mcp.json\",\n    \"project_mcp\": \".vscode/mcp.json\",\n    \"config\": \"\"\n  },\n  \"baidu-comate\": {\n    \"global_skills\": \"~/.comate/skills\",\n    \"project_skills\": \".comate/skills\",\n    \"rules\": \"\",\n    \"mcp\": \"~/.comate/mcp.json\",\n    \"project_mcp\": \".comate/mcp.json\",\n    \"config\": \"\"\n  },\n  \"tencent-codebuddy\": {\n    \"global_skills\": \"~/.codebuddy/skills\",\n    \"project_skills\": \".codebuddy/skills\",\n    \"rules\": \"CODEBUDDY.md\",\n    \"mcp\": \"~/.codebuddy/.mcp.json\",\n    \"project_mcp\": \".mcp.json\",\n    \"project_config\": \".codebuddy/settings.json\",\n    \"config\": \"~/.codebuddy/settings.json\"\n  },\n  \"zcode\": {\n    \"global_skills\": \"~/.zcode/skills\",\n    \"project_skills\": \"\",\n    \"rules\": \"AGENTS.md\",\n    \"mcp\": \"~/.zcode/cli/config.json\",\n    \"project_mcp\": \".zcode/config.json\",\n    \"project_config\": \".zcode/config.json\",\n    \"config\": \"~/.zcode/cli/config.json\"\n  }\n}\n\nFile v0.10.2:references/ide-registry.md\n\n# IDE Reference Index\n\nRead only the selected source and target entries. Each link records documented\npaths, supported migration surfaces, and manual boundaries; a few UI-only\nclients intentionally share one reference. `ide-paths.json` remains the\nlegacy compatibility mapping. [Registry v2](registry-v2.json) is authoritative\nfor product profiles, lifecycle, storage type, scope, migration policy, source,\nversion range, and freshness.\n\nRegistry support levels are evidence contracts, not marketing labels. No\nprofile is currently `full`: reviewed automatic subsets are `partial`; disputed\nor undocumented products remain `manual`, `source-only`, `provider`, `legacy`,\nor `unverified`. Product templates cannot authorize a legacy write. Promotion\nrequires current official sources, a versioned surface contract, an adapter,\nfixtures, secret/rollback coverage, and a fresh documentation check.\n\n## Lifecycle and target eligibility\n\n| Classification | Products | Default behavior |\n| --- | --- | --- |\n| Legacy/source-only | Roo Code, Void, Supermaven, Firebase Studio | Inventory and export only; never target. |\n| Brand alias | Codeium, Tongyi Lingma | Resolve to the named current profile; do not invent paths. |\n| Provider | Pieces | Configure the consuming MCP client. |\n| Editor host | Emacs, Neovim, Helix | Select a concrete plugin profile first. |\n| Cloud/UI | Devin, v0, Lovable, Bolt, TRAE Work, Cody | Use official API/UI or a rebuild checklist. |\n| Profiled local client | Cline, Amazon Q, Codex, ForgeCode, Augment, Windsurf, Qoder and the new CLI entries | Enforce per-surface policy and loss reporting. |\n\n## IDE references\n\n- [`claude-desktop`](ides/claude-desktop.md) — claude-desktop (Claude Desktop app)\n- [`codely`](ides/codely.md) — codely (Tuanjie Codely / Tuanjie Cowork; Unity 中国 AI Agent)\n- [`claude`](ides/claude.md) — claude (Claude Code)\n- [`cursor`](ides/cursor.md) — cursor\n- [`cline`](ides/cline.md) — cline\n- [`roo-code`](ides/roo-code.md) — roo-code (archived 2026-05)\n- [`vscode`](ides/vscode.md) — vscode (VS Code + GitHub Copilot IDE; not cloud agent or the `copilot` script target)\n- [`visual-studio`](ides/visual-studio.md) — visual-studio (Visual Studio 2026/2022 + GitHub Copilot; Windows only)\n- [`firebase-studio`](ides/firebase-studio.md) — firebase-studio (sunsetting 2027-03-22; existing-workspace rules source)\n- [`android-studio`](ides/android-studio.md) — android-studio (Gemini in Android Studio, Quail 1+)\n- [`copilot`](ides/copilot.md) — copilot-cli\n- [`windsurf`](ides/windsurf.md) — windsurf\n- [`codeium`](ides/codeium.md) — codeium (Codeium → Windsurf)\n- [`continue`](ides/continue.md) — continue\n- [`emacs`](ides/emacs.md) — emacs (GNU Emacs)\n- [`augment-code`](ides/augment-code.md) — augment-code\n- [`kilocode`](ides/kilocode.md) — kilocode\n- [`zed`](ides/zed.md) — zed\n- [`trae`](ides/trae.md) — trae\n- [`trae-work`](ides/trae-work.md) — trae-work (separate product; not a supported mapper target)\n- [`trae-cn`](ides/trae-cn.md) — trae-cn\n- [`jetbrains`](ides/jetbrains.md) — jetbrains (Junie in JetBrains IDEs; not JetBrains AI Assistant)\n- [`jetbrains-ai`](ides/jetbrains-ai.md) — jetbrains-ai (JetBrains AI Assistant; distinct from Junie)\n- [`kiro`](ides/kiro.md) — kiro\n- [`codex`](ides/codex.md) — codex\n- [`gemini-cli`](ides/gemini-cli.md) — gemini-cli\n- [`antigravity`](ides/antigravity.md) — antigravity (Antigravity IDE / shared 2.0 surface)\n- [`amazon-q`](ides/amazon-q.md) — amazon-q\n- [`opencode`](ides/opencode.md) — opencode\n- [`goose-cli`](ides/goose-cli.md) — goose-cli (Goose CLI)\n- [`openclaw`](ides/openclaw.md) — openclaw (OpenClaw)\n- [`aider`](ides/aider.md) — aider\n- [`openhands`](ides/openhands.md) — openhands\n- [`replit`](ides/replit.md) — replit (Replit AI)\n- [`sourcegraph-amp`](ides/sourcegraph-amp.md) — sourcegraph-amp\n- [`cody`](ides/cody.md) — sourcegraph-cody\n- [`forge`](ides/forge.md) — forge\n- [`pearai`](ides/pearai.md) — pearai\n- [`void-editor`](ides/void-editor.md) — void-editor\n- [`tabnine`](ides/tabnine.md) — tabnine\n- [`supermaven`](ides/supermaven.md) — supermaven\n- [`blackbox`](ides/blackbox.md) — blackbox (Blackbox AI)\n- [`pieces`](ides/pieces.md) — pieces (Pieces for Developers)\n- [`helix`](ides/helix.md) — helix\n- [`neovim`](ides/neovim.md) — neovim\n- [`mcphub-nvim`](ides/mcphub-nvim.md) — mcphub-nvim\n- [`codecompanion-nvim`](ides/codecompanion-nvim.md) — codecompanion-nvim\n- [`tongyi-lingma`](ides/tongyi-lingma.md) — tongyi-lingma (DEPRECATED — renamed to Qoder CN on 2026-05-20, see `qoder-cn`)\n- [`baidu-comate`](ides/baidu-comate.md) — baidu-comate\n- [`tencent-codebuddy`](ides/tencent-codebuddy.md) — tencent-codebuddy\n- [`kimiai`](ides/kimiai.md) — kimi-code (Moonshot AI)\n- [`workbuddy`](ides/workbuddy.md) — workbuddy (WorkBuddy)\n- [`zcode`](ides/zcode.md) — zcode (Zhipu AI)\n- [`minimax-code`](ides/minimax-code.md) — minimax-code (MiniMax)\n- [`mmx-cli`](ides/mmx-cli.md) — mmx-cli (MiniMax CLI)\n- [`qoder-cn`](ides/qoder-cn.md) — qoder-cn (Alibaba — formerly Tongyi Lingma, renamed 2026-05-20)\n- [`baidu-comate-ide`](ides/baidu-comate-ide.md) — baidu-comate-ide (Baidu — standalone IDE, distinct from plugin)\n- [`tencent-codebuddy-ide`](ides/tencent-codebuddy-ide.md) — tencent-codebuddy-ide (Tencent — standalone IDE, distinct from plugin)\n- [`iflycode`](ides/ui-only-mcp.md) — iflycode (iFlytek; shared UI-only reference)\n- [`raccoon-ai`](ides/ui-only-mcp.md) — raccoon-ai (SenseTime; shared UI-only reference)\n- [`monkeycode`](ides/monkeycode.md) — monkeycode (Chaitin Tech)\n- [`vecli`](ides/vecli.md) — vecli (Volcano Engine)\n- [`bolt-new`](ides/bolt-new.md) — bolt-new (StackBlitz)\n- [`qodo`](ides/qodo.md) — qodo (formerly CodiumAI)\n- [`devin`](ides/devin.md) — devin (Cognition)\n- [`v0`](ides/v0.md) — v0 (Vercel)\n- [`lovable`](ides/lovable.md) — lovable\n- [`xcode`](ides/xcode.md) — xcode (Xcode 26.3+/27 coding agents; manual configuration boundary)\n- [`gptel-mcp-el`](ides/gptel-mcp-el.md) — gptel-mcp-el (third-party Emacs packages)\n- [`qoder`](ides/qoder.md) — Qoder International CLI / IDE profiles\n- [`qwen-code`](ides/qwen-code.md) — Qwen Code\n- [`mistral-vibe`](ides/mistral-vibe.md) — Mistral Vibe Code\n- [`factory-droid`](ides/factory-droid.md) — Factory Droid\n- [`warp-oz`](ides/warp-oz.md) — Warp Oz local/cloud agent CLI\n- [`pi`](ides/pi.md) — Pi coding agent\n- [`crush`](ides/crush.md) — Crush terminal coding agent\n- [`gemini-code-assist`](ides/gemini-code-assist.md) — Gemini Code Assist\n- [`gitlab-duo`](ides/gitlab-duo.md) — GitLab Duo Agent Platform\n- [`hermes`](ides/hermes.md) — Hermes Agent\n- [`ibm-bob`](ides/ibm-bob.md) — IBM Bob\n- [`jules`](ides/jules.md) — Google Jules\n- [`letta`](ides/letta.md) — Letta\n- [`letta-code`](ides/letta-code.md) — Letta Code\n- [`rovodev`](ides/rovodev.md) — Atlassian Rovo Dev\n- [`warp`](ides/warp.md) — Warp\n- [`zencoder`](ides/zencoder.md) — Zencoder\n- [`zenflow`](ides/zenflow.md) — Zenflow\n\nFile v0.10.2:references/ide-tier-overrides.json\n\n{\n  \"_comment\": \"Per-profile tier overrides for the generated compatibility matrix. Each key is a '<product>/<profile>' selector. The value is a per-object-type tier (E2E Verified, Adapter-Compatible, Manual / Rebuild, Not Applicable) or a per-(scope, object_type) override keyed by '<scope>:<object_type>'. Higher priority than registry policy + E2E detection; lower than direct edits to registry-v2.json.\",\n  \"tiers\": {},\n  \"examples\": {\n    \"<product>/<profile>\": {\n      \"skills\": \"E2E Verified\",\n      \"instructions\": \"Adapter-Compatible\",\n      \"mcp\": \"Not Applicable\",\n      \"user:skills\": \"E2E Verified\",\n      \"project:mcp\": \"Manual / Rebuild\"\n    }\n  }\n}\n\nFile v0.10.2:references/ides/aider.md\n\n# aider\n\n<!-- GENERATED: ide-paths.json summary; do not edit this block -->\n\n| Object | Documented path |\n| --- | --- |\n| Global skills | Not mapped |\n| Project skills | Not mapped |\n| Rules | `CONVENTIONS.md` |\n| MCP | Not mapped |\n| Project MCP | Not mapped |\n| Project config | Not mapped |\n| Config | `~/.aider.conf.yml` |\n\n<!-- END GENERATED: ide-paths.json summary -->\n- Aider config is YAML and layered; an explicit `--config` can select another file. It is diagnostic/manual, never a conversion target.\n- `CONVENTIONS.md` is read-only context (`--read` or YAML `read:`).\n- `.env`, `AIDER_*`, CLI flags, `/load`, prompts, Skills, and MCP lack a portable generic migration contract. Never copy credentials or rewrite another IDE's config into Aider YAML.\n\nSources: [configuration](https://aider.chat/docs/config.html), [YAML config](https://aider.chat/docs/config/aider_conf.html), [conventions](https://aider.chat/docs/usage/conventions.html).\n\nFile v0.10.2:references/ides/amazon-q.md\n\n# amazon-q\n\n<!-- GENERATED: ide-paths.json summary; do not edit this block -->\n\n| Object | Documented path |\n| --- | --- |\n| Global skills | Not mapped |\n| Project skills | Not mapped |\n| Rules | `.amazonq/rules` |\n| MCP | `~/.aws/amazonq/default.json` |\n| Project MCP | `.amazonq/default.json` |\n| Project config | Not mapped |\n| Config | Not mapped |\n\n<!-- END GENERATED: ide-paths.json summary -->\n- Resolve a profile before acting. Q in the IDE documents user `~/.aws/amazonq/default.json`, project `.amazonq/default.json`, and legacy `mcp.json` compatibility. `~/.aws/amazonq/agents/` belongs to custom-agent definitions and is not an alternative IDE MCP destination.\n- Q CLI and custom agents have their own agent/profile directories. Their prompts, tools, permissions, hooks, and MCP state are not interchangeable with the narrow IDE `mcpServers` subobject.\n- `.amazonq/` and `~/.aws/amazonq/` are mixed namespaces. Only the selected profile's explicit surface may be read or written; never flatten the whole tree.\n- The v2 profiles are `amazon-q/ide`, `amazon-q/cli`, and `amazon-q/custom-agent`.\n\nSources: [IDE MCP](https://docs.aws.amazon.com/amazonq/latest/qdeveloper-ug/mcp-ide.html), [project rules](https://docs.aws.amazon.com/amazonq/latest/qdeveloper-ug/context-project-rules.html), [MCP scopes](https://docs.aws.amazon.com/amazonq/latest/qdeveloper-ug/qdev-mcp.html).\n\nFile v0.10.2:references/ides/android-studio.md\n\n# android-studio (Gemini in Android Studio)\n\n<!-- GENERATED: ide-paths.json summary; do not edit this block -->\n\n| Object | Documented path |\n| --- | --- |\n| Global skills | `~/.agents/skills` |\n| Project skills | `.agents/skills` |\n| Rules | `AGENTS.md` |\n| MCP | Not mapped |\n| Project MCP | Not mapped |\n| Project config | Not mapped |\n| Config | Not mapped |\n\n<!-- END GENERATED: ide-paths.json summary -->\n- Agent Skills require Android Studio Quail 1+. Project and personal skills support `.agents/skills/` and `.android-studio/skills/`; the mapper chooses portable `.agents/skills/`. Legacy `.skills/` and `agent/skills/` are deprecated migration sources and remain manual.\n- Agent files use hierarchical `AGENTS.md`; `GEMINI.md` takes precedence in the same directory. IDE-native rules in `.idea/project.prompts.xml` are not portable and remain manual.\n- MCP is configured through **Settings → Tools → AI → MCP Servers** and stored in a product/version-managed `mcp.json` with `mcpServers`. Do not guess its path or copy UI trust state. Current support excludes stdio, MCP resources, and MCP prompt templates.\n\nSources: [Skills](https://developer.android.com/studio/gemini/skills), [agent files](https://developer.android.com/studio/gemini/agent-files), [MCP](https://developer.android.com/studio/gemini/add-mcp-server).\n\nFile v0.10.2:references/ides/antigravity.md\n\n# antigravity (Antigravity IDE / shared 2.0 surface)\n\n<!-- GENERATED: ide-paths.json summary; do not edit this block -->\n\n| Object | Documented path |\n| --- | --- |\n| Global skills | `~/.gemini/config/skills` |\n| Project skills | `.agents/skills` |\n| Rules | `.agents/rules` |\n| MCP | `~/.gemini/config/mcp_config.json` |\n| Project MCP | `.agents/mcp_config.json` |\n| Project config | Not mapped |\n| Config | Not mapped |\n\n<!-- END GENERATED: ide-paths.json summary -->\n\n**Registry status:** `unverified/manual-reference`. These paths are discovery\nevidence only; Antigravity is not an automatic source or target until its\nIDE/CLI and version-specific schemas have independent adapters and fixtures.\n\n- MCP uses JSON `mcpServers`; remote endpoints use `serverUrl`, not `url`. The global file is shared by Antigravity surfaces; workspace MCP remains manual.\n- Global Skills default to the generated path. `ANTIGRAVITY_SKILLS_DIR` overrides it; otherwise preserve a legacy-only tree and never merge legacy/current trees implicitly. `.agent/` remains legacy compatibility.\n- Workspace rules use `.agents/rules/`; do not invent `.agents/AGENTS.md`. No official installation-detection or stable workflow path exists.\n- Hooks use `.agents/hooks.json` and `~/.gemini/config/hooks.json`; plugins use `.agents/plugins/<name>` and `~/.gemini/config/plugins/<name>`. They are supported but schema/trust-sensitive, so reconstruct manually. Workflows remain UI-managed. Antigravity CLI is separate.\n\nSources: [IDE Skills](https://antigravity.google/docs/ide/skills), [shared Skills](https://antigravity.google/docs/skills?app=antigravity-ide), [MCP](https://antigravity.google/docs/mcp), [plugins](https://antigravity.google/docs/ide/plugins), [hooks](https://antigravity.google/docs/hooks).\n\nArchive v0.10.1: 122 files, 255407 bytes\n\nFiles: assets/demo.gif (83653b), assets/LICENSE.clawhub (926b), LICENSE (926b), references/bundle-workflow.md (9215b), references/cli-workflow.md (7136b), references/doc-freshness-checks.json (3183b), references/ide-paths.json (9771b), references/ide-paths.tsv (7509b), references/ide-registry.md (7072b), references/ide-tier-overrides.json (665b), references/ides/aider.md (951b), references/ides/amazon-q.md (1385b), references/ides/android-studio.md (1335b), references/ides/antigravity.md (1779b), references/ides/augment-code.md (1205b), references/ides/baidu-comate-ide.md (339b), references/ides/baidu-comate.md (989b), references/ides/blackbox.md (1047b), references/ides/bolt-new.md (176b), references/ides/claude-desktop.md (1978b), references/ides/claude.md (1596b), references/ides/cline.md (1554b), references/ides/codecompanion-nvim.md (183b), references/ides/codeium.md (600b), references/ides/codely.md (1900b), references/ides/codex.md (1921b), references/ides/cody.md (800b), references/ides/continue.md (1072b), references/ides/copilot.md (1207b), references/ides/crush.md (807b), references/ides/cursor.md (1310b), references/ides/devin.md (166b), references/ides/emacs.md (605b), references/ides/factory-droid.md (772b), references/ides/firebase-studio.md (1582b), references/ides/forge.md (703b), references/ides/gemini-cli.md (1449b), references/ides/gemini-code-assist.md (341b), references/ides/gitlab-duo.md (345b), references/ides/goose-cli.md (1294b), references/ides/gptel-mcp-el.md (221b), references/ides/helix.md (166b), references/ides/hermes.md (309b), references/ides/ibm-bob.md (351b), references/ides/jetbrains-ai.md (1342b), references/ides/jetbrains.md (1468b), references/ides/jules.md (280b), references/ides/kilocode.md (1214b), references/ides/kimiai.md (948b), references/ides/kiro.md (1152b), references/ides/letta-code.md (243b), references/ides/letta.md (183b), references/ides/lovable.md (188b), references/ides/mcphub-nvim.md (192b), references/ides/minimax-code.md (213b), references/ides/mistral-vibe.md (585b), references/ides/mmx-cli.md (238b), references/ides/monkeycode.md (666b), references/ides/neovim.md (746b), references/ides/openclaw.md (1310b), references/ides/opencode.md (1409b), references/ides/openhands.md (458b), references/ides/pearai.md (545b), references/ides/pi.md (759b), references/ides/pieces.md (780b), references/ides/qoder-cn.md (425b), references/ides/qoder.md (785b), references/ides/qodo.md (348b), references/ides/qwen-code.md (583b), references/ides/replit.md (1121b), references/ides/roo-code.md (1213b), references/ides/rovodev.md (448b), references/ides/sourcegraph-amp.md (421b), references/ides/supermaven.md (651b), references/ides/tabnine.md (715b), references/ides/tencent-codebuddy-ide.md (696b), references/ides/tencent-codebuddy.md (1068b), references/ides/tongyi-lingma.md (281b), references/ides/trae-cn.md (1417b), references/ides/trae-work.md (198b)\n\nFile v0.10.1:SKILL.md\n\n---\nname: agent-skills-setup\nversion: \"0.10.1\"\ncompatibility: Requires local Bash, Python 3, environment lookup, and filesystem access; optional signing needs installed cryptography; no network access.\ndescription: >-\n  Use when a user wants to migrate, back up, restore, compare, or move\n  AI-coding-agent context across Cursor, Claude Code, Codex, Cline,\n  Copilot, Windsurf, Gemini CLI, or another registered profile, including\n  switching computers. Handles Skills, instructions/rules, and MCP with\n  secret redaction, preview, verification, rollback, and portable bundles;\n  compatible plugin packages and reviewed handoff are available by explicit opt-in.\nmetadata:\n  openclaw:\n    requires:\n      bins:\n        - bash\n        - python3\n---\n# Agent Skills Setup\n\n## Permissions\n\n- Run bundled local Bash/Python helpers and offline discovery only; network access is forbidden. No downloads, installations, or MCP connections.\n- Read selected products, requested scopes, workspace, bundles, and named keys. Broad discovery needs a device-wide request; environment lookup resolves paths without exposing credentials.\n- Write authorized targets, named plan/bundle/key outputs, and transaction state. `--yes` records existing user authorization for apply/restore/rollback; it does not grant authorization.\n\n## Choose the workflow\n\n- Infer products, objects, workspace, and scope from the request and established context. Project migration uses project scope; include user surfaces only when requested. Ask only for material information or authorization that cannot be inferred.\n- An explicit move/apply/restore/rollback request authorizes that scoped action. Preserve prior authorization; preview-only requests stop after preview. Review exact destinations and losses before writing; ask for unresolved conflicts, unapproved losses, or broader scope.\n- Save the plan, review its diff/rebuild manifest, and apply that exact file for execution. Changed inputs require a fresh plan and review.\n\n| Request | Entry point and guidance |\n| --- | --- |\n| Detect or inventory context | `detect`, `inventory`; [registry](references/ide-registry.md) and [CLI guide](references/cli-workflow.md). |\n| Compare or preview migration | `plan --json`; [migration safety](references/migration-safety.md). Saving `--output` writes a plan artifact. |\n| Migrate context | Saved `plan` → `apply --yes` → `verify`; `migrate` orchestrates the same stages. [CLI guide](references/cli-workflow.md). |\n| Back up or switch computers | `snapshot`, `bundle-verify`, `doctor`, `restore`; [bundle workflow](references/bundle-workflow.md). |\n| Sign or authenticate a bundle | `bundle-keygen`, `bundle-sign`, `bundle-verify --trusted-key`; [bundle workflow](references/bundle-workflow.md). |\n| Verify or undo applied changes | `verify`, `rollback --yes`; [verification](references/verification.md). |\n\nResolve both product profiles through [ide-registry.md](references/ide-registry.md) / [registry-v2.json](references/registry-v2.json) for migration; use bundle manifest selectors for restore.\n\n1. Read only the selected profiles' `references/ides/<source>.md` and `references/ides/<target>.md` files. Resolve concrete filenames through the [profile index](references/ide-registry.md) and registry reference/alias routing; filenames need not match selectors.\n2. Before preview or apply, read [migration-safety.md](references/migration-safety.md).\n3. For MCP, read [mcp-migration.md](references/mcp-migration.md); for other objects, [object-migration.md](references/object-migration.md). Load [verification.md](references/verification.md) for delivery evidence.\n\n## Supported boundaries\n\n- Automatic writers cover `skills`, `instructions`, and reviewed local stdio `mcp`. `plugins` needs `--include-plugins` and compatible package surfaces; `handoff` needs `--include-session` and whitelisted reviewed context.\n- Prompts, commands, agents, hooks, workflows, and unsupported formats produce review/rebuild actions. Never auto-activate executable content or migrate credentials, trust, approvals, raw history, or generated memory.\n- Shared config migration extracts only the authorized subobject and preserves unrelated settings. Cloud/UI and remote MCP remain manual; support is determined per surface, not by product name.\n- Use the explicit `legacy` subcommand for lookup/dry-run compatibility only; legacy writes are disabled.\n- Deliver artifact paths, applied/deferred counts, verification, backups, and remaining manual work. Parsing proves file validity; runtime and connectivity need their own evidence.\n\nFile v0.10.1:_meta.json\n\n{\n  \"ownerId\": \"kn73ym4c6fp5b2vaa22t84v5fn83pt1p\",\n  \"slug\": \"agent-skills-setup\",\n  \"version\": \"0.10.1\",\n  \"publishedAt\": 1791004965373\n}\n\nFile v0.10.1:references/bundle-workflow.md\n\n# Portable bundle, restore, and signing workflow\n\nRead for computer switching, portable backups, ACB restore, dependency checks,\nor signing. Commands below use `migrator=/path/to/agent-skills-setup/scripts/smart-ide-migration.sh`;\nsubstitute the installed Skill path and requested source, target, workspace,\nscopes, and artifact paths. Run each command independently and inspect its result.\nUse [migration-safety.md](migration-safety.md) for authorization and conflict rules.\n\n## Capture and inspect\n\n`snapshot` writes an ACB **directory**, not a compressed archive. Name the source\nand output explicitly; the CLI's fallback product selectors are examples, not\npermission to inspect or restore those products.\n\n```bash\nbash \"$migrator\" snapshot --source cursor/ide --target cursor/ide \\\n    --workspace /path/to/project --scope project \\\n    --objects skills,instructions,mcp --output /path/to/project.acb --json\nbash \"$migrator\" bundle-verify /path/to/project.acb --json\nbash \"$migrator\" doctor /path/to/project.acb --json\n```\n\nReview `manifest.json`, the collection summary, `rebuild.json`, and\n`secrets.required.json`. ACB contains portable object bytes, sanitized inventory,\ncompatibility evidence, requirements, reauthentication actions, and checksums\nbinding every declared file. Failed, excluded, or manual objects are not\nautomatically backed up; report them. Credential values and private runtime\nstate must remain outside the bundle.\n\n`objects_captured` counts captured product/profile/scope object surfaces;\n`files_captured` counts their payload files. Compare these with the manifest's\nfile bindings and collection exclusions rather than treating file count as\nthe number of Skills or servers. ACB payload limits are 5,000 files, 10 MiB per\nfile, 100 MiB total, and 16 directory levels. Known image/font assets are\nallowed; executable or unallowlisted binary files fail collection instead of\nsilently disappearing. The exact extensions are `SAFE_BINARY_EXTENSIONS` in\n[acb/bundle.py](../scripts/acb/bundle.py).\n\nNew snapshots record optional integer `files[].mode` permission bits (`0..0o777`)\nin the checksummed manifest. On POSIX, restore and opt-in extraction apply these\nbits to copied files, preserving text helper scripts' executable bits while\ndropping setuid, setgid, and sticky flags. Payload storage permissions need not\nmatch the source. Older mode-less bundles remain readable but cannot establish\noriginal executable permissions; Windows applies only permissions supported by\nits filesystem. Verify required target file modes separately from content\nhashes; directory permissions and script execution are outside this guarantee.\nRecorded modes apply to copied Skill/plugin files and extracted payloads.\nGenerated instruction, MCP, and handoff files use their target writer's\npermissions; for example, generated MCP configuration is private (`0600`).\n\nFor a requested device-wide backup, run `detect` and review eligible profiles,\nthen use `snapshot --all-installed --scope user,project --output ...`.\n`--include-configured` and `--include-compatibility` broaden eligibility to those\ndetection states only when the user wants them. Do not equate shared context\ndirectories with installation proof. Prefer explicitly selected profiles when\ndevice detection cannot establish the requested scope.\n\nPlugins and handoff are opt-in objects, with both the object selector and flag:\n`--objects plugins --include-plugins` or `--objects handoff --include-session`.\nPackage copying requires compatible registry surfaces and performs no install\nor activation. Handoff transports only reviewed summary, branch, selected\nrelative files, and an explicit patch; raw session logs and state are excluded.\nApply the same opt-in flags during restore or saved-plan apply.\n\n## Restore on the destination device\n\nInspect bundle integrity and run `doctor` before execution. Resolve source\nselectors from the manifest and choose concrete destination profiles. Missing\ntools or packages are manual installation work; this skill installs nothing.\n\n`doctor` reports the complete recorded `requirements` and per-executable\n`executable_checks` with `found_on_path`. It checks only executable presence;\n`unresolved_requirements` retains missing executables plus the recorded\npackages, extensions, `manual_installs` (including local script paths), and\nplatform notes. These other requirements are unverified and remain manual\nwork, alongside `reauth_actions` and `rebuild_actions`. Script paths and\nplatform notes are reported as recorded, without resolving new target paths\nor probing product installation. No dependency is executed, imported,\ninstalled, or contacted.\n\n`ok: true` and exit 0 mean bundle integrity and executable-presence checks\npassed; unresolved manual requirements do not change that result. Missing\nexecutables produce `ok: false` and exit 1 while retaining the requirement\nreport. An invalid bundle produces exit 1 at `stage: verify` before its\nrequirements are reported. This status does not establish dependency or\nproduct readiness.\n\n```bash\nbash \"$migrator\" restore /path/to/project.acb \\\n    --source cursor/ide --target cline/ide \\\n    --workspace /path/to/new-project --scope project \\\n    --objects skills,instructions,mcp --plan-only \\\n    --plan-out /path/to/restore-plan.json --json\nbash \"$migrator\" restore /path/to/project.acb \\\n    --source cursor/ide --target cline/ide \\\n    --workspace /path/to/new-project --scope project \\\n    --objects skills,instructions,mcp --plan-in /path/to/restore-plan.json \\\n    --manifest-out /path/to/restore-manifest.json --yes --json\nbash \"$migrator\" verify --manifest /path/to/restore-manifest.json --json\n```\n\nCheck target paths, source content bindings, existing-target diffs, losses, and\nrebuild actions in the saved plan before replay. Restore uses bundle sources and\ndestination-side states; local source installations do not replace the backup.\nBundle or destination drift requires a fresh plan. Saved-plan execution can\nalso use `apply <plan> --bundle <bundle> --yes`; trusted-signature verification\nshould be performed before that path. Use `restore --trusted-key` when signer\nauthentication must be enforced during restore itself.\n\nNew named restore plans record `bundle_source` (bundle ID and manifest SHA256)\nand an `acb_uri` such as `acb://<bundle-id>#<object-id>` for each captured source,\nalongside its temporary execution path. Named replay checks the verified\nmanifest's product, profile, scope, and object identity before target writes;\nmoving the bundle does not change that identity. Saved plan bytes and\n`plan_sha256` stay unchanged during replay. Generic `apply` requires `--bundle`\nfor these plans. Older named plans without this metadata retain their existing\nsource-content and destination-state validation when supplied with a bundle.\n\nFor requested multi-product restore, use `--all-installed` in both planning and\nreplay, review per-target conflicts and failures, and retain the same scopes and\nopt-ins. Apply writes only eligible targets. A bundle resolving no eligible\nobjects fails by default; `--allow-noop` is for an intentional review/no-op,\nnot evidence of restoration.\n\n`--plan-only` avoids product writes but can save `--plan-out`. `--dry-run`\navoids persistent output writes. `--restore-root <dir>` explicitly extracts a\nreview tree and is unnecessary for ordinary restore; extraction is distinct\nfrom installation into destination product surfaces.\n\n## Sign and authenticate\n\nEd25519 key generation, signing, and signature checks need an already installed\nPython `cryptography` package. If unavailable, report the missing dependency;\nchecksum verification and unsigned backup remain usable offline. Use fresh,\ndistinct key paths outside bundles and migration surfaces. Keep the private\n32-byte raw key owner-only; distribute only the public key. Key generation uses\nPOSIX mode `0600` or a protected Windows ACL granting access only to the current\nuser. Signing checks those permissions before reading the private key and\nrejects keys with broader access. Windows key storage must support file ACLs.\n\nIf generation fails after creating an output, inspect `outputs_requiring_review`\nbefore retrying with fresh paths. POSIX outputs are preserved because a pathname\nmay have been replaced concurrently; never delete a listed path without checking\nits current contents and ownership. Windows removes only files still bound to\nthe original held creation handles. Do not use a keypair from a failed operation.\n\n```bash\nbash \"$migrator\" bundle-keygen --out-private /path/to/private.key \\\n    --out-public /path/to/public.key --json\nbash \"$migrator\" bundle-sign /path/to/project.acb \\\n    --key /path/to/private.key --signer local-operator --json\nbash \"$migrator\" bundle-verify /path/to/project.acb \\\n    --trusted-key /path/to/public.key --json\n```\n\nObtain the trusted public key independently of the bundle. `signature.json`\ncontains an embedded public key, which by itself does not establish trust.\nSigning verifies bundle integrity before attestation; report signature\nverification separately from checksums and dependency readiness. Preserve\nexisting keys and signed bundles unless the user authorizes replacing them.\n\nFile v0.10.1:references/cli-workflow.md\n\n# Public CLI workflow\n\nRead for detection, inventory, comparison, profile-aware migration, and command\nselection. `smart-ide-migration.sh` is the public wrapper. Set its path to the\ninstalled Skill directory, independent of the project working directory:\n\n```bash\nmigrator=/path/to/agent-skills-setup/scripts/smart-ide-migration.sh\n```\n\nUse concrete `<product>/<profile>` selectors from [Registry v2](registry-v2.json).\nProfile aliases, supported surfaces, platforms, and manual boundaries come from\n[ide-registry.md](ide-registry.md). Do not substitute paths from another product\nor a different profile. Paths can use documented environment/platform overrides;\nremote-host surfaces remain experimental.\n\n| Command | Observable result |\n| --- | --- |\n| `detect` | Offline install/configuration/compatibility detection, with evidence. |\n| `inventory` | Resolved surfaces, policy, precedence, and existence. |\n| `plan` | Destination paths, statuses, diffs, losses, and rebuild actions. |\n| `migrate` | Saved plan, apply manifest, and verification artifact in one flow. |\n| `apply` | Execution of a saved, state-validated plan and transaction manifest. |\n| `verify` | Whether recorded applied files still match their manifest. |\n| `rollback` | Guarded undo using that apply manifest. |\n| `snapshot` | Portable ACB directory and collection/exclusion summary. |\n| `bundle-verify` | Closed-world checksum, binding, and secret checks; optional trusted signature. |\n| `bundle-keygen`, `bundle-sign` | Offline Ed25519 key files or signature artifact. |\n| `restore` | Destination-side plan from bundle bytes, optional apply and verify. |\n| `doctor` | Complete recorded requirements, executable PATH checks, and reauthentication/rebuild actions. |\n| `legacy` | Explicit lookup or zero-write dry-run compatibility only. |\n\n`--json` emits one JSON document on stdout; diagnostics go to stderr. Inspect\nexit status, item statuses, and applied counts, not merely `ok`. Use\n`bash \"$migrator\" <command> --help` for that command's accepted flags.\n\n## Detect and preview the named project\n\n```bash\nbash \"$migrator\" detect --product cursor --profile ide \\\n    --workspace /path/to/project --json\nbash \"$migrator\" inventory --product cursor --profile ide \\\n    --workspace /path/to/project --json\nbash \"$migrator\" plan --source cursor/ide --target claude/code-cli \\\n    --workspace /path/to/project --scope project \\\n    --objects skills,instructions,mcp --json\n```\n\nThe final command emits a preview without saving an artifact. To prepare an\nauthorized execution, add `--output /path/to/plan.json`, read that file's\n`review_preview`, `loss_report`, and `rebuild_manifest`, and apply the same file.\nDo not claim a migration from detection, plan output, or an empty inventory.\nBroad `detect`/`inventory` without a product filter is for a device-wide request.\n\n## Apply and verify a saved plan\n\n```bash\nbash \"$migrator\" plan --source cursor/ide --target claude/code-cli \\\n    --workspace /path/to/project --scope project \\\n    --objects skills,instructions,mcp --output /path/to/plan.json --json\nbash \"$migrator\" apply /path/to/plan.json \\\n    --manifest /path/to/manifest.json --yes --json\nbash \"$migrator\" verify --manifest /path/to/manifest.json --json\n```\n\nFollow [migration-safety.md](migration-safety.md) before execution and\n[verification.md](verification.md) for delivery or rollback. Only use `--yes`\nwithin the user's existing authorization. A saved plan locks source/target\nstates, Registry digest, adapter versions, and Git provenance; drift is a\nfailure requiring a fresh plan. Apply does not accept arbitrary source files\nthrough legacy flags: stage user-supplied fixtures in an isolated workspace's\ndocumented source surface when testing, without overwriting real configuration.\n\n`--apply-safe` is the default. It applies eligible objects, defers lossy ones\nunless accepted, and records manual/forbidden/conflict outcomes. Conflicts block\ntheir target group. `--strict` rejects any non-`ready` item. `--no-apply-safe`\nalso requires every item to be `ready` before any target write.\n`--include lossy` accepts all reviewed lossy items. `--accept-loss` on\n`apply`/`migrate` names item IDs such as `3:instructions`, not bare row numbers.\nExplicit loss acceptance remains necessary when the original request did not\nauthorize those semantics.\n\nInstruction/MCP conversions that drop reported fields or redact credentials\nare `ready-lossy`; `--yes` alone does not accept those losses. Accepted\nconversions still remove unsupported fields and literal credentials. Required\nSkill `.env` exclusions remain enforced without making an otherwise eligible\nSkill copy require loss acceptance.\n\n## Orchestrated migration\n\nFor an authorized scoped migration, `migrate` runs planning, apply, and verify:\n\n```bash\nbash \"$migrator\" migrate --source cursor/ide --target claude/code-cli \\\n    --workspace /path/to/project --scope project \\\n    --objects skills,instructions,mcp --plan-out /path/to/plan.json \\\n    --manifest-out /path/to/manifest.json --verify-out /path/to/verify.json \\\n    --yes --json\n```\n\nUse `--plan-only` when execution should stop at the plan. It still saves the\nplan; use ordinary `plan --json` for a preview with no persistent output writes.\nWithout explicit output paths, orchestration uses `<workspace>/.migration/`;\ntransaction backups and default apply manifests use\n`<workspace>/.agent-context-migration/`.\nChoose fresh manifest and verification output paths for each execution. Existing\ntransaction artifacts are preserved and rejected as outputs; keep them for\nverification and rollback instead of replacing them on a repeated run.\n\n`--objects all-portable` selects `skills,instructions,mcp`. Select narrower\nobjects when requested; `--objects all-inventory` is for inventory/manual/forbidden\nreporting, not permission to write those surfaces. Opt-in `plugins` and `handoff`\nalso require `--include-plugins` or `--include-session`, respectively.\nScopes are `user`, `project`, `local`, or documented unions/all as accepted by\neach command; applying `migrate --scope all` requires `--yes`, while\n`--plan-only` can preview it without that flag. CLI defaults differ, so pass explicit scopes instead of allowing a project request to inspect user files.\n\n## Backup, signing, diagnostics, and recovery\n\nUse [bundle-workflow.md](bundle-workflow.md) for `snapshot`, `bundle-verify`,\n`bundle-keygen`, `bundle-sign`, `doctor`, and bundle-backed `restore`/`apply`.\nUse [object-migration.md](object-migration.md) and\n[mcp-migration.md](mcp-migration.md) for object-specific boundaries. Remote MCP,\ncloud/UI, and unsupported adapters produce reconstruction actions, not silent\nfallback copies.\n\nThe explicit `legacy` subcommand accepts retained lookup/dry-run syntax:\n\n```bash\nbash \"$migrator\" legacy --print-path cursor project-mcp\n```\n\nImplicit legacy flags, direct legacy-engine execution, and every legacy write\nare rejected. Legacy `--source-mcp-file`, `--opencode-version`, or `--strategy`\nexamples cannot authorize a public write; use reviewed profile-aware plans or\nmanual reconstruction when the current Registry has no writable adapter.\n\nFile v0.10.1:references/doc-freshness-checks.json\n\n{\n  \"schema_version\": 1,\n  \"verified_at\": \"2026-08-15\",\n  \"checks\": [\n    {\n      \"id\": \"agent-skills-spec\",\n      \"url\": \"https://raw.githubusercontent.com/agentskills/agentskills/main/docs/specification.mdx\",\n      \"required_terms\": [\n        \"name\",\n        \"description\",\n        \"metadata\"\n      ]\n    },\n    {\n      \"id\": \"cline-config\",\n      \"url\": \"https://docs.cline.bot/getting-started/config\",\n      \"required_terms\": [\n        \"cline\",\n        \"configuration\"\n      ]\n    },\n    {\n      \"id\": \"forgecode-docs\",\n      \"url\": \"https://forgecode.dev/docs/\",\n      \"required_terms\": [\n        \"forge\",\n        \"agent\"\n      ]\n    },\n    {\n      \"id\": \"qoder-docs\",\n      \"url\": \"https://docs.qoder.com/\",\n      \"required_terms\": [\n        \"qoder\"\n      ]\n    },\n    {\n      \"id\": \"codex-docs\",\n      \"url\": \"https://learn.chatgpt.com/docs/llms.txt\",\n      \"required_terms\": [\n        \"codex\"\n      ]\n    },\n    {\n      \"id\": \"openhands-docs\",\n      \"url\": \"https://docs.openhands.dev/overview/introduction\",\n      \"required_terms\": [\n        \"openhands\"\n      ]\n    },\n    {\n      \"id\": \"amp-manual\",\n      \"url\": \"https://ampcode.com/manual\",\n      \"required_terms\": [\n        \"agent skills\",\n        \"mcp\"\n      ]\n    },\n    {\n      \"id\": \"monkeycode-readme\",\n      \"url\": \"https://raw.githubusercontent.com/chaitin/MonkeyCode/main/README.md\",\n      \"required_terms\": [\n        \"monkeycode\",\n        \"development platform\"\n      ]\n    },\n    {\n      \"id\": \"cursor-rules\",\n      \"url\": \"https://docs.cursor.com/context/rules\",\n      \"required_terms\": [\n        \"cursor\",\n        \"rule\"\n      ]\n    },\n    {\n      \"id\": \"claude-code-skills\",\n      \"url\": \"https://code.claude.com/docs/en/skills\",\n      \"required_terms\": [\n        \"skill\"\n      ]\n    },\n    {\n      \"id\": \"github-copilot-cli\",\n      \"url\": \"https://docs.github.com/en/copilot/how-tos/copilot-cli\",\n      \"required_terms\": [\n        \"copilot\",\n        \"cli\"\n      ]\n    },\n    {\n      \"id\": \"vscode-agent-skills\",\n      \"url\": \"https://code.visualstudio.com/docs/agent-customization/agent-skills\",\n      \"required_terms\": [\n        \"skill\"\n      ]\n    },\n    {\n      \"id\": \"gemini-cli-skills\",\n      \"url\": \"https://github.com/google-gemini/gemini-cli/blob/main/docs/skills.md\",\n      \"required_terms\": [\n        \"gemini\",\n        \"skill\"\n      ]\n    },\n    {\n      \"id\": \"kiro-steering\",\n      \"url\": \"https://kiro.dev/docs/steering\",\n      \"required_terms\": [\n        \"kiro\",\n        \"steering\"\n      ]\n    },\n    {\n      \"id\": \"rovodev-cli-skills\",\n      \"url\": \"https://support.atlassian.com/rovo/docs/use-agent-skills-in-rovo-dev-cli/\",\n      \"required_terms\": [\n        \"rovo\",\n        \"skill\"\n      ]\n    },\n    {\n      \"id\": \"ibm-bob-docs\",\n      \"url\": \"https://www.ibm.com/docs/en/bob\",\n      \"required_terms\": [\n        \"bob\",\n        \"agent\"\n      ]\n    },\n    {\n      \"id\": \"warp-drive-prompts\",\n      \"url\": \"https://docs.warp.dev/agents/prompts\",\n      \"required_terms\": [\n        \"warp\",\n        \"prompt\"\n      ]\n    },\n    {\n      \"id\": \"windsurf-rules\",\n      \"url\": \"https://docs.codeium.com/windsurf/rules\",\n      \"required_terms\": [\n        \"windsurf\",\n        \"rule\"\n      ]\n    }\n  ]\n}\n\nFile v0.10.1:references/ide-paths.json\n\n{\n  \"antigravity\": {\n    \"global_skills\": \"~/.gemini/config/skills\",\n    \"project_skills\": \".agents/skills\",\n    \"rules\": \".agents/rules\",\n    \"mcp\": \"~/.gemini/config/mcp_config.json\",\n    \"project_mcp\": \".agents/mcp_config.json\",\n    \"config\": \"\"\n  },\n  \"claude\": {\n    \"global_skills\": \"~/.claude/skills\",\n    \"project_skills\": \".claude/skills\",\n    \"rules\": \"CLAUDE.md\",\n    \"mcp\": \"~/.claude.json\",\n    \"project_mcp\": \".mcp.json\",\n    \"project_config\": \".claude/settings.json\",\n    \"config\": \"~/.claude/settings.json\"\n  },\n  \"codely\": {\n    \"global_skills\": \"~/.codely-cli/skills\",\n    \"project_skills\": \".codely-cli/skills\",\n    \"rules\": \"CODELY.md\",\n    \"mcp\": \"~/.codely-cli/settings.json\",\n    \"project_mcp\": \".codely-cli/settings.json\",\n    \"project_config\": \".codely-cli/settings.json\",\n    \"config\": \"~/.codely-cli/settings.json\"\n  },\n  \"codex\": {\n    \"global_skills\": \"~/.agents/skills\",\n    \"project_skills\": \".agents/skills\",\n    \"rules\": \"AGENTS.md\",\n    \"mcp\": \"~/.codex/config.toml\",\n    \"project_mcp\": \".codex/config.toml\",\n    \"project_config\": \".codex/config.toml\",\n    \"config\": \"~/.codex/config.toml\"\n  },\n  \"copilot\": {\n    \"global_skills\": \"~/.copilot/skills\",\n    \"project_skills\": \".github/skills\",\n    \"rules\": \".github/copilot-instructions.md\",\n    \"mcp\": \"~/.copilot/mcp-config.json\",\n    \"project_mcp\": \".mcp.json\",\n    \"config\": \"\"\n  },\n  \"cursor\": {\n    \"global_skills\": \"~/.cursor/skills\",\n    \"project_skills\": \".cursor/skills\",\n    \"rules\": \".cursor/rules\",\n    \"mcp\": \"~/.cursor/mcp.json\",\n    \"project_mcp\": \".cursor/mcp.json\",\n    \"config\": \"\"\n  },\n  \"windsurf\": {\n    \"global_skills\": \"~/.codeium/windsurf/skills\",\n    \"project_skills\": \".windsurf/skills\",\n    \"rules\": \".windsurf/rules\",\n    \"mcp\": \"~/.codeium/windsurf/mcp_config.json\",\n    \"config\": \"\"\n  },\n  \"jetbrains\": {\n    \"global_skills\": \"~/.junie/skills\",\n    \"project_skills\": \".junie/skills\",\n    \"rules\": \".junie/AGENTS.md\",\n    \"mcp\": \"~/.junie/mcp/mcp.json\",\n    \"project_mcp\": \".junie/mcp/mcp.json\",\n    \"config\": \"\"\n  },\n  \"openclaw\": {\n    \"global_skills\": \"~/.openclaw/skills\",\n    \"project_skills\": \"skills\",\n    \"rules\": \"AGENTS.md\",\n    \"mcp\": \"~/.openclaw/openclaw.json\",\n    \"config\": \"~/.openclaw/openclaw.json\"\n  },\n  \"trae\": {\n    \"global_skills\": \"~/.trae/skills\",\n    \"project_skills\": \".trae/skills\",\n    \"rules\": \".trae/rules\",\n    \"mcp\": \"\",\n    \"project_mcp\": \".trae/mcp.json\",\n    \"config\": \"\"\n  },\n  \"trae-cn\": {\n    \"global_skills\": \"~/.trae-cn/skills\",\n    \"project_skills\": \".trae/skills\",\n    \"rules\": \".trae/rules\",\n    \"mcp\": \"\",\n    \"project_mcp\": \".trae/mcp.json\",\n    \"config\": \"\"\n  },\n  \"vscode\": {\n    \"global_skills\": \"~/.copilot/skills\",\n    \"project_skills\": \".github/skills\",\n    \"rules\": \".github/copilot-instructions.md\",\n    \"mcp\": \"\",\n    \"project_mcp\": \".vscode/mcp.json\",\n    \"config\": \"\"\n  },\n  \"visual-studio\": {\n    \"global_skills\": \"~/.copilot/skills\",\n    \"project_skills\": \".github/skills\",\n    \"rules\": \".github/copilot-instructions.md\",\n    \"mcp\": {\n      \"darwin\": \"\",\n      \"linux\": \"\",\n      \"windows\": \"%USERPROFILE%\\\\.mcp.json\"\n    },\n    \"project_mcp\": \".mcp.json\",\n    \"config\": \"\"\n  },\n  \"jetbrains-ai\": {\n    \"global_skills\": \"\",\n    \"project_skills\": \".agents/skills\",\n    \"rules\": \"\",\n    \"mcp\": \"\",\n    \"project_mcp\": \"\",\n    \"config\": \"\"\n  },\n  \"firebase-studio\": {\n    \"global_skills\": \"\",\n    \"project_skills\": \"\",\n    \"rules\": \".idx/airules.md\",\n    \"mcp\": \"\",\n    \"project_mcp\": \".idx/mcp.json\",\n    \"config\": \"\"\n  },\n  \"android-studio\": {\n    \"global_skills\": \"~/.agents/skills\",\n    \"project_skills\": \".agents/skills\",\n    \"rules\": \"AGENTS.md\",\n    \"mcp\": \"\",\n    \"project_mcp\": \"\",\n    \"config\": \"\"\n  },\n  \"zed\": {\n    \"global_skills\": \"~/.agents/skills\",\n    \"project_skills\": \".agents/skills\",\n    \"rules\": \"AGENTS.md\",\n    \"mcp\": \"~/.config/zed/settings.json\",\n    \"project_mcp\": \".zed/settings.json\",\n    \"config\": \"\"\n  },\n  \"neovim\": {\n    \"global_skills\": \"\",\n    \"project_skills\": \"\",\n    \"rules\": \"\",\n    \"mcp\": \"\",\n    \"config\": \"~/.config/nvim/init.lua\"\n  },\n  \"emacs\": {\n    \"global_skills\": \"\",\n    \"project_skills\": \"\",\n    \"rules\": \"\",\n    \"mcp\": \"\",\n    \"config\": \"\"\n  },\n  \"continue\": {\n    \"global_skills\": \"\",\n    \"project_skills\": \"\",\n    \"rules\": \".continue/rules\",\n    \"mcp\": \"~/.continue/config.yaml\",\n    \"project_mcp\": \".continue/mcpServers\",\n    \"config\": \"~/.continue/config.yaml\"\n  },\n  \"aider\": {\n    \"global_skills\": \"\",\n    \"project_skills\": \"\",\n    \"rules\": \"CONVENTIONS.md\",\n    \"mcp\": \"\",\n    \"config\": \"~/.aider.conf.yml\"\n  },\n  \"roo-code\": {\n    \"global_skills\": \"~/.roo/skills\",\n    \"project_skills\": \".roo/skills\",\n    \"rules\": \".roorules\",\n    \"project_mcp\": \".roo/mcp.json\",\n    \"mcp\": \"\",\n    \"config\": \"\"\n  },\n  \"cline\": {\n    \"project\": \"\",\n    \"global_skills\": \"~/.cline/skills\",\n    \"project_skills\": \".cline/skills\",\n    \"rules\": \".cline/rules\",\n    \"mcp\": \"~/.cline/data/settings/cline_mcp_settings.json\",\n    \"project_mcp\": \".cline/mcp.json\",\n    \"config\": \"\"\n  },\n  \"amazon-q\": {\n    \"global_skills\": \"\",\n    \"project_skills\": \"\",\n    \"rules\": \".amazonq/rules\",\n    \"mcp\": \"~/.aws/amazonq/default.json\",\n    \"project_mcp\": \".amazonq/default.json\",\n    \"config\": \"\"\n  },\n  \"cody\": {\n    \"global_skills\": \"\",\n    \"project_skills\": \"\",\n    \"rules\": \"\",\n    \"mcp\": \"\",\n    \"config\": \"\"\n  },\n  \"codeium\": {\n    \"global_skills\": \"\",\n    \"project_skills\": \"\",\n    \"rules\": \"\",\n    \"mcp\": \"\",\n    \"config\": \"\"\n  },\n  \"tabnine\": {\n    \"global_skills\": \"\",\n    \"project_skills\": \"\",\n    \"rules\": \".tabnine/guidelines\",\n    \"mcp\": \"~/.tabnine/mcp_servers.json\",\n    \"project_mcp\": \".tabnine/mcp_servers.json\",\n    \"config\": \"\"\n  },\n  \"replit\": {\n    \"global_skills\": \"\",\n    \"project_skills\": \".agents/skills\",\n    \"rules\": \"replit.md\",\n    \"mcp\": \"\",\n    \"project_config\": \".replit\",\n    \"config\": \"\"\n  },\n  \"pearai\": {\n    \"global_skills\": \"\",\n    \"project_skills\": \"\",\n    \"rules\": \"\",\n    \"mcp\": \"\",\n    \"config\": \"\"\n  },\n  \"supermaven\": {\n    \"global_skills\": \"\",\n    \"project_skills\": \"\",\n    \"rules\": \"\",\n    \"mcp\": \"\",\n    \"config\": \"\"\n  },\n  \"pieces\": {\n    \"global_skills\": \"\",\n    \"project_skills\": \"\",\n    \"rules\": \"\",\n    \"mcp\": \"\",\n    \"project_mcp\": \"\",\n    \"project_config\": \"\",\n    \"config\": \"\"\n  },\n  \"blackbox\": {\n    \"global_skills\": \"\",\n    \"project_skills\": \".blackbox/skills\",\n    \"rules\": \"\",\n    \"mcp\": \"\",\n    \"config\": \"\"\n  },\n  \"gemini-cli\": {\n    \"global_skills\": \"~/.gemini/skills\",\n    \"project_skills\": \".gemini/skills\",\n    \"rules\": \"GEMINI.md\",\n    \"mcp\": \"~/.gemini/settings.json\",\n    \"project_mcp\": \".gemini/settings.json\",\n    \"project_config\": \".gemini/settings.json\",\n    \"config\": \"~/.gemini/settings.json\"\n  },\n  \"goose-cli\": {\n    \"global_skills\": \"~/.agents/skills\",\n    \"project_skills\": \".agents/skills\",\n    \"rules\": \".goosehints\",\n    \"mcp\": \"~/.config/goose/config.yaml\",\n    \"config\": \"~/.config/goose/config.yaml\"\n  },\n  \"opencode\": {\n    \"global_skills\": \"~/.config/opencode/skills\",\n    \"project_skills\": \".opencode/skills\",\n    \"rules\": \"AGENTS.md\",\n    \"mcp\": \"~/.config/opencode/opencode.json\",\n    \"project_mcp\": \"opencode.json\",\n    \"project_config\": \"opencode.json\",\n    \"config\": \"~/.config/opencode/opencode.json\"\n  },\n  \"kilocode\": {\n    \"project\": \".kilo\",\n    \"global_skills\": \"~/.kilo/skills\",\n    \"project_skills\": \".kilo/skills\",\n    \"rules\": \"AGENTS.md\",\n    \"mcp\": \"~/.config/kilo/kilo.jsonc\",\n    \"project_mcp\": \".kilo/kilo.jsonc\",\n    \"project_config\": \".kilo/kilo.jsonc\",\n    \"config\": \"~/.config/kilo/kilo.jsonc\"\n  },\n  \"kimiai\": {\n    \"global_skills\": \"~/.kimi-code/skills\",\n    \"project_skills\": \".kimi-code/skills\",\n    \"rules\": \"AGENTS.md\",\n    \"mcp\": \"~/.kimi-code/mcp.json\",\n    \"project_mcp\": \".kimi-code/mcp.json\",\n    \"config\": \"~/.kimi-code/config.toml\"\n  },\n  \"workbuddy\": {\n    \"global_skills\": \"\",\n    \"project_skills\": \"\",\n    \"rules\": \"\",\n    \"mcp\": \"~/.workbuddy/mcp.json\",\n    \"project_mcp\": \".workbuddy/mcp.json\",\n    \"config\": \"\"\n  },\n  \"claude-desktop\": {\n    \"global_skills\": \"\",\n    \"project_skills\": \"\",\n    \"rules\": \"\",\n    \"mcp\": {\n      \"darwin\": \"~/Library/Application Support/Claude/claude_desktop_config.json\",\n      \"linux\": \"\",\n      \"windows\": \"%APPDATA%\\\\Claude\\\\claude_desktop_config.json\"\n    },\n    \"config\": \"\"\n  },\n  \"kiro\": {\n    \"global_skills\": \"~/.kiro/skills\",\n    \"project_skills\": \".kiro/skills\",\n    \"rules\": \".kiro/steering\",\n    \"mcp\": \"~/.kiro/settings/mcp.json\",\n    \"project_mcp\": \".kiro/settings/mcp.json\",\n    \"config\": \"\"\n  },\n  \"augment-code\": {\n    \"global_skills\": \"~/.augment/skills\",\n    \"project_skills\": \".augment/skills\",\n    \"rules\": \".augment/rules\",\n    \"mcp\": \"~/.augment/settings.json\",\n    \"project_mcp\": \".augment/settings.json\",\n    \"project_config\": \".augment/settings.json\",\n    \"config\": \"~/.augment/settings.json\"\n  },\n  \"void-editor\": {\n    \"global_skills\": \"\",\n    \"project_skills\": \"\",\n    \"rules\": \".voidrules\",\n    \"mcp\": \"~/.void-editor/mcp.json\",\n    \"project_mcp\": \".vscode/mcp.json\",\n    \"config\": \"\"\n  },\n  \"baidu-comate\": {\n    \"global_skills\": \"~/.comate/skills\",\n    \"project_skills\": \".comate/skills\",\n    \"rules\": \"\",\n    \"mcp\": \"~/.comate/mcp.json\",\n    \"project_mcp\": \".comate/mcp.json\",\n    \"config\": \"\"\n  },\n  \"tencent-codebuddy\": {\n    \"global_skills\": \"~/.codebuddy/skills\",\n    \"project_skills\": \".codebuddy/skills\",\n    \"rules\": \"CODEBUDDY.md\",\n    \"mcp\": \"~/.codebuddy/.mcp.json\",\n    \"project_mcp\": \".mcp.json\",\n    \"project_config\": \".codebuddy/settings.json\",\n    \"config\": \"~/.codebuddy/settings.json\"\n  },\n  \"zcode\": {\n    \"global_skills\": \"~/.zcode/skills\",\n    \"project_skills\": \"\",\n    \"rules\": \"AGENTS.md\",\n    \"mcp\": \"~/.zcode/cli/config.json\",\n    \"project_mcp\": \".zcode/config.json\",\n    \"project_config\": \".zcode/config.json\",\n    \"config\": \"~/.zcode/cli/config.json\"\n  }\n}\n\nFile v0.10.1:references/ide-registry.md\n\n# IDE Reference Index\n\nRead only the selected source and target entries. Each link records documented\npaths, supported migration surfaces, and manual boundaries; a few UI-only\nclients intentionally share one reference. `ide-paths.json` remains the\nlegacy compatibility mapping. [Registry v2](registry-v2.json) is authoritative\nfor product profiles, lifecycle, storage type, scope, migration policy, source,\nversion range, and freshness.\n\nRegistry support levels are evidence contracts, not marketing labels. No\nprofile is currently `full`: reviewed automatic subsets are `partial`; disputed\nor undocumented products remain `manual`, `source-only`, `provider`, `legacy`,\nor `unverified`. Product templates cannot authorize a legacy write. Promotion\nrequires current official sources, a versioned surface contract, an adapter,\nfixtures, secret/rollback coverage, and a fresh documentation check.\n\n## Lifecycle and target eligibility\n\n| Classification | Products | Default behavior |\n| --- | --- | --- |\n| Legacy/source-only | Roo Code, Void, Supermaven, Firebase Studio | Inventory and export only; never target. |\n| Brand alias | Codeium, Tongyi Lingma | Resolve to the named current profile; do not invent paths. |\n| Provider | Pieces | Configure the consuming MCP client. |\n| Editor host | Emacs, Neovim, Helix | Select a concrete plugin profile first. |\n| Cloud/UI | Devin, v0, Lovable, Bolt, TRAE Work, Cody | Use official API/UI or a rebuild checklist. |\n| Profiled local client | Cline, Amazon Q, Codex, ForgeCode, Augment, Windsurf, Qoder and the new CLI entries | Enforce per-surface policy and loss reporting. |\n\n## IDE references\n\n- [`claude-desktop`](ides/claude-desktop.md) — claude-desktop (Claude Desktop app)\n- [`codely`](ides/codely.md) — codely (Tuanjie Codely / Tuanjie Cowork; Unity 中国 AI Agent)\n- [`claude`](ides/claude.md) — claude (Claude Code)\n- [`cursor`](ides/cursor.md) — cursor\n- [`cline`](ides/cline.md) — cline\n- [`roo-code`](ides/roo-code.md) — roo-code (archived 2026-05)\n- [`vscode`](ides/vscode.md) — vscode (VS Code + GitHub Copilot IDE; not cloud agent or the `copilot` script target)\n- [`visual-studio`](ides/visual-studio.md) — visual-studio (Visual Studio 2026/2022 + GitHub Copilot; Windows only)\n- [`firebase-studio`](ides/firebase-studio.md) — firebase-studio (sunsetting 2027-03-22; existing-workspace rules source)\n- [`android-studio`](ides/android-studio.md) — android-studio (Gemini in Android Studio, Quail 1+)\n- [`copilot`](ides/copilot.md) — copilot-cli\n- [`windsurf`](ides/windsurf.md) — windsurf\n- [`codeium`](ides/codeium.md) — codeium (Codeium → Windsurf)\n- [`continue`](ides/continue.md) — continue\n- [`emacs`](ides/emacs.md) — emacs (GNU Emacs)\n- [`augment-code`](ides/augment-code.md) — augment-code\n- [`kilocode`](ides/kilocode.md) — kilocode\n- [`zed`](ides/zed.md) — zed\n- [`trae`](ides/trae.md) — trae\n- [`trae-work`](ides/trae-work.md) — trae-work (separate product; not a supported mapper target)\n- [`trae-cn`](ides/trae-cn.md) — trae-cn\n- [`jetbrains`](ides/jetbrains.md) — jetbrains (Junie in JetBrains IDEs; not JetBrains AI Assistant)\n- [`jetbrains-ai`](ides/jetbrains-ai.md) — jetbrains-ai (JetBrains AI Assistant; distinct from Junie)\n- [`kiro`](ides/kiro.md) — kiro\n- [`codex`](ides/codex.md) — codex\n- [`gemini-cli`](ides/gemini-cli.md) — gemini-cli\n- [`antigravity`](ides/antigravity.md) — antigravity (Antigravity IDE / shared 2.0 surface)\n- [`amazon-q`](ides/amazon-q.md) — amazon-q\n- [`opencode`](ides/opencode.md) — opencode\n- [`goose-cli`](ides/goose-cli.md) — goose-cli (Goose CLI)\n- [`openclaw`](ides/openclaw.md) — openclaw (OpenClaw)\n- [`aider`](ides/aider.md) — aider\n- [`openhands`](ides/openhands.md) — openhands\n- [`replit`](ides/replit.md) — replit (Replit AI)\n- [`sourcegraph-amp`](ides/sourcegraph-amp.md) — sourcegraph-amp\n- [`cody`](ides/cody.md) — sourcegraph-cody\n- [`forge`](ides/forge.md) — forge\n- [`pearai`](ides/pearai.md) — pearai\n- [`void-editor`](ides/void-editor.md) — void-editor\n- [`tabnine`](ides/tabnine.md) — tabnine\n- [`supermaven`](ides/supermaven.md) — supermaven\n- [`blackbox`](ides/blackbox.md) — blackbox (Blackbox AI)\n- [`pieces`](ides/pieces.md) — pieces (Pieces for Developers)\n- [`helix`](ides/helix.md) — helix\n- [`neovim`](ides/neovim.md) — neovim\n- [`mcphub-nvim`](ides/mcphub-nvim.md) — mcphub-nvim\n- [`codecompanion-nvim`](ides/codecompanion-nvim.md) — codecompanion-nvim\n- [`tongyi-lingma`](ides/tongyi-lingma.md) — tongyi-lingma (DEPRECATED — renamed to Qoder CN on 2026-05-20, see `qoder-cn`)\n- [`baidu-comate`](ides/baidu-comate.md) — baidu-comate\n- [`tencent-codebuddy`](ides/tencent-codebuddy.md) — tencent-codebuddy\n- [`kimiai`](ides/kimiai.md) — kimi-code (Moonshot AI)\n- [`workbuddy`](ides/workbuddy.md) — workbuddy (WorkBuddy)\n- [`zcode`](ides/zcode.md) — zcode (Zhipu AI)\n- [`minimax-code`](ides/minimax-code.md) — minimax-code (MiniMax)\n- [`mmx-cli`](ides/mmx-cli.md) — mmx-cli (MiniMax CLI)\n- [`qoder-cn`](ides/qoder-cn.md) — qoder-cn (Alibaba — formerly Tongyi Lingma, renamed 2026-05-20)\n- [`baidu-comate-ide`](ides/baidu-comate-ide.md) — baidu-comate-ide (Baidu — standalone IDE, distinct from plugin)\n- [`tencent-codebuddy-ide`](ides/tencent-codebuddy-ide.md) — tencent-codebuddy-ide (Tencent — standalone IDE, distinct from plugin)\n- [`iflycode`](ides/ui-only-mcp.md) — iflycode (iFlytek; shared UI-only reference)\n- [`raccoon-ai`](ides/ui-only-mcp.md) — raccoon-ai (SenseTime; shared UI-only reference)\n- [`monkeycode`](ides/monkeycode.md) — monkeycode (Chaitin Tech)\n- [`vecli`](ides/vecli.md) — vecli (Volcano Engine)\n- [`bolt-new`](ides/bolt-new.md) — bolt-new (StackBlitz)\n- [`qodo`](ides/qodo.md) — qodo (formerly CodiumAI)\n- [`devin`](ides/devin.md) — devin (Cognition)\n- [`v0`](ides/v0.md) — v0 (Vercel)\n- [`lovable`](ides/lovable.md) — lovable\n- [`xcode`](ides/xcode.md) — xcode (Xcode 26.3+/27 coding agents; manual configuration boundary)\n- [`gptel-mcp-el`](ides/gptel-mcp-el.md) — gptel-mcp-el (third-party Emacs packages)\n- [`qoder`](ides/qoder.md) — Qoder International CLI / IDE profiles\n- [`qwen-code`](ides/qwen-code.md) — Qwen Code\n- [`mistral-vibe`](ides/mistral-vibe.md) — Mistral Vibe Code\n- [`factory-droid`](ides/factory-droid.md) — Factory Droid\n- [`warp-oz`](ides/warp-oz.md) — Warp Oz local/cloud agent CLI\n- [`pi`](ides/pi.md) — Pi coding agent\n- [`crush`](ides/crush.md) — Crush terminal coding agent\n- [`gemini-code-assist`](ides/gemini-code-assist.md) — Gemini Code Assist\n- [`gitlab-duo`](ides/gitlab-duo.md) — GitLab Duo Agent Platform\n- [`hermes`](ides/hermes.md) — Hermes Agent\n- [`ibm-bob`](ides/ibm-bob.md) — IBM Bob\n- [`jules`](ides/jules.md) — Google Jules\n- [`letta`](ides/letta.md) — Letta\n- [`letta-code`](ides/letta-code.md) — Letta Code\n- [`rovodev`](ides/rovodev.md) — Atlassian Rovo Dev\n- [`warp`](ides/warp.md) — Warp\n- [`zencoder`](ides/zencoder.md) — Zencoder\n- [`zenflow`](ides/zenflow.md) — Zenflow\n\nFile v0.10.1:references/ide-tier-overrides.json\n\n{\n  \"_comment\": \"Per-profile tier overrides for the generated compatibility matrix. Each key is a '<product>/<profile>' selector. The value is a per-object-type tier (E2E Verified, Adapter-Compatible, Manual / Rebuild, Not Applicable) or a per-(scope, object_type) override keyed by '<scope>:<object_type>'. Higher priority than registry policy + E2E detection; lower than direct edits to registry-v2.json.\",\n  \"tiers\": {},\n  \"examples\": {\n    \"<product>/<profile>\": {\n      \"skills\": \"E2E Verified\",\n      \"instructions\": \"Adapter-Compatible\",\n      \"mcp\": \"Not Applicable\",\n      \"user:skills\": \"E2E Verified\",\n      \"project:mcp\": \"Manual / Rebuild\"\n    }\n  }\n}\n\nFile v0.10.1:references/ides/aider.md\n\n# aider\n\n<!-- GENERATED: ide-paths.json summary; do not edit this block -->\n\n| Object | Documented path |\n| --- | --- |\n| Global skills | Not mapped |\n| Project skills | Not mapped |\n| Rules | `CONVENTIONS.md` |\n| MCP | Not mapped |\n| Project MCP | Not mapped |\n| Project config | Not mapped |\n| Config | `~/.aider.conf.yml` |\n\n<!-- END GENERATED: ide-paths.json summary -->\n- Aider config is YAML and layered; an explicit `--config` can select another file. It is diagnostic/manual, never a conversion target.\n- `CONVENTIONS.md` is read-only context (`--read` or YAML `read:`).\n- `.env`, `AIDER_*`, CLI flags, `/load`, prompts, Skills, and MCP lack a portable generic migration contract. Never copy credentials or rewrite another IDE's config into Aider YAML.\n\nSources: [configuration](https://aider.chat/docs/config.html), [YAML config](https://aider.chat/docs/config/aider_conf.html), [conventions](https://aider.chat/docs/usage/conventions.html).\n\nFile v0.10.1:references/ides/amazon-q.md\n\n# amazon-q\n\n<!-- GENERATED: ide-paths.json summary; do not edit this block -->\n\n| Object | Documented path |\n| --- | --- |\n| Global skills | Not mapped |\n| Project skills | Not mapped |\n| Rules | `.amazonq/rules` |\n| MCP | `~/.aws/amazonq/default.json` |\n| Project MCP | `.amazonq/default.json` |\n| Project config | Not mapped |\n| Config | Not mapped |\n\n<!-- END GENERATED: ide-paths.json summary -->\n- Resolve a profile before acting. Q in the IDE documents user `~/.aws/amazonq/default.json`, project `.amazonq/default.json`, and legacy `mcp.json` compatibility. `~/.aws/amazonq/agents/` belongs to custom-agent definitions and is not an alternative IDE MCP destination.\n- Q CLI and custom agents have their own agent/profile directories. Their prompts, tools, permissions, hooks, and MCP state are not interchangeable with the narrow IDE `mcpServers` subobject.\n- `.amazonq/` and `~/.aws/amazonq/` are mixed namespaces. Only the selected profile's explicit surface may be read or written; never flatten the whole tree.\n- The v2 profiles are `amazon-q/ide`, `amazon-q/cli`, and `amazon-q/custom-agent`.\n\nSources: [IDE MCP](https://docs.aws.amazon.com/amazonq/latest/qdeveloper-ug/mcp-ide.html), [project rules](https://docs.aws.amazon.com/amazonq/latest/qdeveloper-ug/context-project-rules.html), [MCP scopes](https://docs.aws.amazon.com/amazonq/latest/qdeveloper-ug/qdev-mcp.html).\n\nFile v0.10.1:references/ides/android-studio.md\n\n# android-studio (Gemini in Android Studio)\n\n<!-- GENERATED: ide-paths.json summary; do not edit this block -->\n\n| Object | Documented path |\n| --- | --- |\n| Global skills | `~/.agents/skills` |\n| Project skills | `.agents/skills` |\n| Rules | `AGENTS.md` |\n| MCP | Not mapped |\n| Project MCP | Not mapped |\n| Project config | Not mapped |\n| Config | Not mapped |\n\n<!-- END GENERATED: ide-paths.json summary -->\n- Agent Skills require Android Studio Quail 1+. Project and personal skills support `.agents/skills/` and `.android-studio/skills/`; the mapper chooses portable `.agents/skills/`. Legacy `.skills/` and `agent/skills/` are deprecated migration sources and remain manual.\n- Agent files use hierarchical `AGENTS.md`; `GEMINI.md` takes precedence in the same directory. IDE-native rules in `.idea/project.prompts.xml` are not portable and remain manual.\n- MCP is configured through **Settings → Tools → AI → MCP Servers** and stored in a product/version-managed `mcp.json` with `mcpServers`. Do not guess its path or copy UI trust state. Current support excludes stdio, MCP resources, and MCP prompt templates.\n\nSources: [Skills](https://developer.android.com/studio/gemini/skills), [agent files](https://developer.android.com/studio/gemini/agent-files), [MCP](https://developer.android.com/studio/gemini/add-mcp-server).\n\nFile v0.10.1:references/ides/antigravity.md\n\n# antigravity (Antigravity IDE / shared 2.0 surface)\n\n<!-- GENERATED: ide-paths.json summary; do not edit this block -->\n\n| Object | Documented path |\n| --- | --- |\n| Global skills | `~/.gemini/config/skills` |\n| Project skills | `.agents/skills` |\n| Rules | `.agents/rules` |\n| MCP | `~/.gemini/config/mcp_config.json` |\n| Project MCP | `.agents/mcp_config.json` |\n| Project config | Not mapped |\n| Config | Not mapped |\n\n<!-- END GENERATED: ide-paths.json summary -->\n\n**Registry status:** `unverified/manual-reference`. These paths are discovery\nevidence only; Antigravity is not an automatic source or target until its\nIDE/CLI and version-specific schemas have independent adapters and fixtures.\n\n- MCP uses JSON `mcpServers`; remote endpoints use `serverUrl`, not `url`. The global file is shared by Antigravity surfaces; workspace MCP remains manual.\n- Global Skills default to the generated path. `ANTIGRAVITY_SKILLS_DIR` overrides it; otherwise preserve a legacy-only tree and never merge legacy/current trees implicitly. `.agent/` remains legacy compatibility.\n- Workspace rules use `.agents/rules/`; do not invent `.agents/AGENTS.md`. No official installation-detection or stable workflow path exists.\n- Hooks use `.agents/hooks.json` and `~/.gemini/config/hooks.json`; plugins use `.agents/plugins/<name>` and `~/.gemini/config/plugins/<name>`. They are supported but schema/trust-sensitive, so reconstruct manually. Workflows remain UI-managed. Antigravity CLI is separate.\n\nSources: [IDE Skills](https://antigravity.google/docs/ide/skills), [shared Skills](https://antigravity.google/docs/skills?app=antigravity-ide), [MCP](https://antigravity.google/docs/mcp), [plugins](https://antigravity.google/docs/ide/plugins), [hooks](https://antigravity.google/docs/hooks).\n\nArchive v0.10.0: 122 files, 254010 bytes\n\nFiles: assets/demo.gif (83653b), assets/LICENSE.clawhub (926b), LICENSE (926b), references/bundle-workflow.md (8811b), references/cli-workflow.md (7136b), references/doc-freshness-checks.json (3183b), references/ide-paths.json (9771b), references/ide-paths.tsv (7509b), references/ide-registry.md (7072b), references/ide-tier-overrides.json (665b), references/ides/aider.md (951b), references/ides/amazon-q.md (1385b), references/ides/android-studio.md (1335b), references/ides/antigravity.md (1779b), references/ides/augment-code.md (1205b), references/ides/baidu-comate-ide.md (339b), references/ides/baidu-comate.md (989b), references/ides/blackbox.md (1047b), references/ides/bolt-new.md (176b), references/ides/claude-desktop.md (1978b), references/ides/claude.md (1596b), references/ides/cline.md (1554b), references/ides/codecompanion-nvim.md (183b), references/ides/codeium.md (600b), references/ides/codely.md (1900b), references/ides/codex.md (1921b), references/ides/cody.md (800b), references/ides/continue.md (1072b), references/ides/copilot.md (1207b), references/ides/crush.md (807b), references/ides/cursor.md (1310b), references/ides/devin.md (166b), references/ides/emacs.md (605b), references/ides/factory-droid.md (772b), references/ides/firebase-studio.md (1582b), references/ides/forge.md (703b), references/ides/gemini-cli.md (1449b), references/ides/gemini-code-assist.md (341b), references/ides/gitlab-duo.md (345b), references/ides/goose-cli.md (1294b), references/ides/gptel-mcp-el.md (221b), references/ides/helix.md (166b), references/ides/hermes.md (309b), references/ides/ibm-bob.md (351b), references/ides/jetbrains-ai.md (1342b), references/ides/jetbrains.md (1468b), references/ides/jules.md (280b), references/ides/kilocode.md (1214b), references/ides/kimiai.md (948b), references/ides/kiro.md (1152b), references/ides/letta-code.md (243b), references/ides/letta.md (183b), references/ides/lovable.md (188b), references/ides/mcphub-nvim.md (192b), references/ides/minimax-code.md (213b), references/ides/mistral-vibe.md (585b), references/ides/mmx-cli.md (238b), references/ides/monkeycode.md (666b), references/ides/neovim.md (746b), references/ides/openclaw.md (1310b), references/ides/opencode.md (1409b), references/ides/openhands.md (458b), references/ides/pearai.md (545b), references/ides/pi.md (759b), references/ides/pieces.md (780b), references/ides/qoder-cn.md (425b), references/ides/qoder.md (785b), references/ides/qodo.md (348b), references/ides/qwen-code.md (583b), references/ides/replit.md (1121b), references/ides/roo-code.md (1213b), references/ides/rovodev.md (448b), references/ides/sourcegraph-amp.md (421b), references/ides/supermaven.md (651b), references/ides/tabnine.md (715b), references/ides/tencent-codebuddy-ide.md (696b), references/ides/tencent-codebuddy.md (1068b), references/ides/tongyi-lingma.md (281b), references/ides/trae-cn.md (1417b), references/ides/trae-work.md (198b)\n\nFile v0.10.0:SKILL.md\n\n---\nname: agent-skills-setup\nversion: \"0.10.0\"\ncompatibility: Requires local Bash, Python 3, environment lookup, and filesystem access; optional signing needs installed cryptography; no network access.\ndescription: >-\n  Use when a user wants to migrate, back up, restore, compare, or move\n  AI-coding-agent context across Cursor, Claude Code, Codex, Cline,\n  Copilot, Windsurf, Gemini CLI, or another registered profile, including\n  switching computers. Handles Skills, instructions/rules, and MCP with\n  secret redaction, preview, verification, rollback, and portable bundles.\nmetadata:\n  openclaw:\n    requires:\n      bins:\n        - bash\n        - python3\n---\n# Agent Skills Setup\n\n## Permissions\n\n- Run bundled local Bash/Python helpers and offline discovery only; network access is forbidden. No downloads, installations, or MCP connections.\n- Read selected products, requested scopes, workspace, bundles, and named keys. Broad discovery needs a device-wide request; environment lookup resolves paths without exposing credentials.\n- Write authorized targets, named plan/bundle/key outputs, and transaction state. `--yes` records existing user authorization for apply/restore/rollback; it does not grant authorization.\n\n## Choose the workflow\n\n- Infer products, objects, workspace, and scope from the request and established context. Project migration uses project scope; include user surfaces only when requested. Ask only for material information or authorization that cannot be inferred.\n- An explicit move/apply/restore/rollback request authorizes that scoped action. Preserve prior authorization; preview-only requests stop after preview. Review exact destinations and losses before writing; ask for unresolved conflicts, unapproved losses, or broader scope.\n- Save the plan, review its diff/rebuild manifest, and apply that exact file for execution. Changed inputs require a fresh plan and review.\n\n| Request | Entry point and guidance |\n| --- | --- |\n| Detect or inventory context | `detect`, `inventory`; [registry](references/ide-registry.md) and [CLI guide](references/cli-workflow.md). |\n| Compare or preview migration | `plan --json`; [migration safety](references/migration-safety.md). Saving `--output` writes a plan artifact. |\n| Migrate context | Saved `plan` → `apply --yes` → `verify`; `migrate` orchestrates the same stages. [CLI guide](references/cli-workflow.md). |\n| Back up or switch computers | `snapshot`, `bundle-verify`, `doctor`, `restore`; [bundle workflow](references/bundle-workflow.md). |\n| Sign or authenticate a bundle | `bundle-keygen`, `bundle-sign`, `bundle-verify --trusted-key`; [bundle workflow](references/bundle-workflow.md). |\n| Verify or undo applied changes | `verify`, `rollback --yes`; [verification](references/verification.md). |\n\nResolve both product profiles through [ide-registry.md](references/ide-registry.md) / [registry-v2.json](references/registry-v2.json) for migration; use bundle manifest selectors for restore.\n\n1. Read the selected profiles' references only: [references/ides/<source>.md](references/ides/) and [references/ides/<target>.md](references/ides/). Follow registry reference/alias routing; filenames need not match selectors.\n2. Before preview or apply, read [migration-safety.md](references/migration-safety.md).\n3. For MCP, read [mcp-migration.md](references/mcp-migration.md); for other objects, [object-migration.md](references/object-migration.md). Load [verification.md](references/verification.md) for delivery evidence.\n\n## Supported boundaries\n\n- Automatic writers cover `skills`, `instructions`, and reviewed local stdio `mcp`. `plugins` needs `--include-plugins` and compatible package surfaces; `handoff` needs `--include-session` and whitelisted reviewed context.\n- Prompts, commands, agents, hooks, workflows, and unsupported formats produce review/rebuild actions. Never auto-activate executable content or migrate credentials, trust, approvals, raw history, or generated memory.\n- Shared config migration extracts only the authorized subobject and preserves unrelated settings. Cloud/UI and remote MCP remain manual; support is determined per surface, not by product name.\n- Use the explicit `legacy` subcommand for lookup/dry-run compatibility only; legacy writes are disabled.\n- Deliver artifact paths, applied/deferred counts, verification, backups, and remaining manual work. Parsing proves file validity; runtime and connectivity need their own evidence.\n\nFile v0.10.0:_meta.json\n\n{\n  \"ownerId\": \"kn73ym4c6fp5b2vaa22t84v5fn83pt1p\",\n  \"slug\": \"agent-skills-setup\",\n  \"version\": \"0.10.0\",\n  \"publishedAt\": 1790960754129\n}\n\nFile v0.10.0:references/bundle-workflow.md\n\n# Portable bundle, restore, and signing workflow\n\nRead for computer switching, portable backups, ACB restore, dependency checks,\nor signing. Commands below use `migrator=/path/to/agent-skills-setup/scripts/smart-ide-migration.sh`;\nsubstitute the installed Skill path and requested source, target, workspace,\nscopes, and artifact paths. Run each command independently and inspect its result.\nUse [migration-safety.md](migration-safety.md) for authorization and conflict rules.\n\n## Capture and inspect\n\n`snapshot` writes an ACB **directory**, not a compressed archive. Name the source\nand output explicitly; the CLI's fallback product selectors are examples, not\npermission to inspect or restore those products.\n\n```bash\nbash \"$migrator\" snapshot --source cursor/ide --target cursor/ide \\\n    --workspace /path/to/project --scope project \\\n    --objects skills,instructions,mcp --output /path/to/project.acb --json\nbash \"$migrator\" bundle-verify /path/to/project.acb --json\nbash \"$migrator\" doctor /path/to/project.acb --json\n```\n\nReview `manifest.json`, the collection summary, `rebuild.json`, and\n`secrets.required.json`. ACB contains portable object bytes, sanitized inventory,\ncompatibility evidence, requirements, reauthentication actions, and checksums\nbinding every declared file. Failed, excluded, or manual objects are not\nautomatically backed up; report them. Credential values and private runtime\nstate must remain outside the bundle.\n\n`objects_captured` counts captured product/profile/scope object surfaces;\n`files_captured` counts their payload files. Compare these with the manifest's\nfile bindings and collection exclusions rather than treating file count as\nthe number of Skills or servers. ACB payload limits are 5,000 files, 10 MiB per\nfile, 100 MiB total, and 16 directory levels. Known image/font assets are\nallowed; executable or unallowlisted binary files fail collection instead of\nsilently disappearing. The exact extensions are `SAFE_BINARY_EXTENSIONS` in\n[acb/bundle.py](../scripts/acb/bundle.py).\n\nNew snapshots record optional integer `files[].mode` permission bits (`0..0o777`)\nin the checksummed manifest. On POSIX, restore and opt-in extraction apply these\nbits to copied files, preserving text helper scripts' executable bits while\ndropping setuid, setgid, and sticky flags. Payload storage permissions need not\nmatch the source. Older mode-less bundles remain readable but cannot establish\noriginal executable permissions; Windows applies only permissions supported by\nits filesystem. Verify required target file modes separately from content\nhashes; directory permissions and script execution are outside this guarantee.\nRecorded modes apply to copied Skill/plugin files and extracted payloads.\nGenerated instruction, MCP, and handoff files use their target writer's\npermissions; for example, generated MCP configuration is private (`0600`).\n\nFor a requested device-wide backup, run `detect` and review eligible profiles,\nthen use `snapshot --all-installed --scope user,project --output ...`.\n`--include-configured` and `--include-compatibility` broaden eligibility to those\ndetection states only when the user wants them. Do not equate shared context\ndirectories with installation proof. Prefer explicitly selected profiles when\ndevice detection cannot establish the requested scope.\n\nPlugins and handoff are opt-in objects, with both the object selector and flag:\n`--objects plugins --include-plugins` or `--objects handoff --include-session`.\nPackage copying requires compatible registry surfaces and performs no install\nor activation. Handoff transports only reviewed summary, branch, selected\nrelative files, and an explicit patch; raw session logs and state are excluded.\nApply the same opt-in flags during restore or saved-plan apply.\n\n## Restore on the destination device\n\nInspect bundle integrity and run `doctor` before execution. Resolve source\nselectors from the manifest and choose concrete destination profiles. Missing\ntools or packages are manual installation work; this skill installs nothing.\n\n`doctor` reports the complete recorded `requirements` and per-executable\n`executable_checks` with `found_on_path`. It checks only executable presence;\n`unresolved_requirements` retains missing executables plus the recorded\npackages, extensions, `manual_installs` (including local script paths), and\nplatform notes. These other requirements are unverified and remain manual\nwork, alongside `reauth_actions` and `rebuild_actions`. Script paths and\nplatform notes are reported as recorded, without resolving new target paths\nor probing product installation. No dependency is executed, imported,\ninstalled, or contacted.\n\n`ok: true` and exit 0 mean bundle integrity and executable-presence checks\npassed; unresolved manual requirements do not change that result. Missing\nexecutables produce `ok: false` and exit 1 while retaining the requirement\nreport. An invalid bundle produces exit 1 at `stage: verify` before its\nrequirements are reported. This status does not establish dependency or\nproduct readiness.\n\n```bash\nbash \"$migrator\" restore /path/to/project.acb \\\n    --source cursor/ide --target cline/ide \\\n    --workspace /path/to/new-project --scope project \\\n    --objects skills,instructions,mcp --plan-only \\\n    --plan-out /path/to/restore-plan.json --json\nbash \"$migrator\" restore /path/to/project.acb \\\n    --source cursor/ide --target cline/ide \\\n    --workspace /path/to/new-project --scope project \\\n    --objects skills,instructions,mcp --plan-in /path/to/restore-plan.json \\\n    --manifest-out /path/to/restore-manifest.json --yes --json\nbash \"$migrator\" verify --manifest /path/to/restore-manifest.json --json\n```\n\nCheck target paths, source content bindings, existing-target diffs, losses, and\nrebuild actions in the saved plan before replay. Restore uses bundle sources and\ndestination-side states; local source installations do not replace the backup.\nBundle or destination drift requires a fresh plan. Saved-plan execution can\nalso use `apply <plan> --bundle <bundle> --yes`; trusted-signature verification\nshould be performed before that path. Use `restore --trusted-key` when signer\nauthentication must be enforced during restore itself.\n\nNew named restore plans record `bundle_source` (bundle ID and manifest SHA256)\nand an `acb_uri` such as `acb://<bundle-id>#<object-id>` for each captured source,\nalongside its temporary execution path. Named replay checks the verified\nmanifest's product, profile, scope, and object identity before target writes;\nmoving the bundle does not change that identity. Saved plan bytes and\n`plan_sha256` stay unchanged during replay. Generic `apply` requires `--bundle`\nfor these plans. Older named plans without this metadata retain their existing\nsource-content and destination-state validation when supplied with a bundle.\n\nFor requested multi-product restore, use `--all-installed` in both planning and\nreplay, review per-target conflicts and failures, and retain the same scopes and\nopt-ins. Apply writes only eligible targets. A bundle resolving no eligible\nobjects fails by default; `--allow-noop` is for an intentional review/no-op,\nnot evidence of restoration.\n\n`--plan-only` avoids product writes but can save `--plan-out`. `--dry-run`\navoids persistent output writes. `--restore-root <dir>` explicitly extracts a\nreview tree and is unnecessary for ordinary restore; extraction is distinct\nfrom installation into destination product surfaces.\n\n## Sign and authenticate\n\nEd25519 key generation, signing, and signature checks need an already installed\nPython `cryptography` package. If unavailable, report the missing dependency;\nchecksum verification and unsigned backup remain usable offline. Use fresh,\ndistinct key paths outside bundles and migration surfaces. Keep the private\n32-byte raw key owner-only; distribute only the public key. Key generation uses\nPOSIX mode `0600` or a protected Windows ACL granting access only to the current\nuser. Signing checks those permissions before reading the private key and\nrejects keys with broader access. Windows key storage must support file ACLs.\n\n```bash\nbash \"$migrator\" bundle-keygen --out-private /path/to/private.key \\\n    --out-public /path/to/public.key --json\nbash \"$migrator\" bundle-sign /path/to/project.acb \\\n    --key /path/to/private.key --signer local-operator --json\nbash \"$migrator\" bundle-verify /path/to/project.acb \\\n    --trusted-key /path/to/public.key --json\n```\n\nObtain the trusted public key independently of the bundle. `signature.json`\ncontains an embedded public key, which by itself does not establish trust.\nSigning verifies bundle integrity before attestation; report signature\nverification separately from checksums and dependency readiness. Preserve\nexisting keys and signed bundles unless the user authorizes replacing them.\n\nFile v0.10.0:references/cli-workflow.md\n\n# Public CLI workflow\n\nRead for detection, inventory, comparison, profile-aware migration, and command\nselection. `smart-ide-migration.sh` is the public wrapper. Set its path to the\ninstalled Skill directory, independent of the project working directory:\n\n```bash\nmigrator=/path/to/agent-skills-setup/scripts/smart-ide-migration.sh\n```\n\nUse concrete `<product>/<profile>` selectors from [Registry v2](registry-v2.json).\nProfile aliases, supported surfaces, platforms, and manual boundaries come from\n[ide-registry.md](ide-registry.md). Do not substitute paths from another product\nor a different profile. Paths can use documented environment/platform overrides;\nremote-host surfaces remain experimental.\n\n| Command | Observable result |\n| --- | --- |\n| `detect` | Offline install/configuration/compatibility detection, with evidence. |\n| `inventory` | Resolved surfaces, policy, precedence, and existence. |\n| `plan` | Destination paths, statuses, diffs, losses, and rebuild actions. |\n| `migrate` | Saved plan, apply manifest, and verification artifact in one flow. |\n| `apply` | Execution of a saved, state-validated plan and transaction manifest. |\n| `verify` | Whether recorded applied files still match their manifest. |\n| `rollback` | Guarded undo using that apply manifest. |\n| `snapshot` | Portable ACB directory and collection/exclusion summary. |\n| `bundle-verify` | Closed-world checksum, binding, and secret checks; optional trusted signature. |\n| `bundle-keygen`, `bundle-sign` | Offline Ed25519 key files or signature artifact. |\n| `restore` | Destination-side plan from bundle bytes, optional apply and verify. |\n| `doctor` | Complete recorded requirements, executable PATH checks, and reauthentication/rebuild actions. |\n| `legacy` | Explicit lookup or zero-write dry-run compatibility only. |\n\n`--json` emits one JSON document on stdout; diagnostics go to stderr. Inspect\nexit status, item statuses, and applied counts, not merely `ok`. Use\n`bash \"$migrator\" <command> --help` for that command's accepted flags.\n\n## Detect and preview the named project\n\n```bash\nbash \"$migrator\" detect --product cursor --profile ide \\\n    --workspace /path/to/project --json\nbash \"$migrator\" inventory --product cursor --profile ide \\\n    --workspace /path/to/project --json\nbash \"$migrator\" plan --source cursor/ide --target claude/code-cli \\\n    --workspace /path/to/project --scope project \\\n    --objects skills,instructions,mcp --json\n```\n\nThe final command emits a preview without saving an artifact. To prepare an\nauthorized execution, add `--output /path/to/plan.json`, read that file's\n`review_preview`, `loss_report`, and `rebuild_manifest`, and apply the same file.\nDo not claim a migration from detection, plan output, or an empty inventory.\nBroad `detect`/`inventory` without a product filter is for a device-wide request.\n\n## Apply and verify a saved plan\n\n```bash\nbash \"$migrator\" plan --source cursor/ide --target claude/code-cli \\\n    --workspace /path/to/project --scope project \\\n    --objects skills,instructions,mcp --output /path/to/plan.json --json\nbash \"$migrator\" apply /path/to/plan.json \\\n    --manifest /path/to/manifest.json --yes --json\nbash \"$migrator\" verify --manifest /path/to/manifest.json --json\n```\n\nFollow [migration-safety.md](migration-safety.md) before execution and\n[verification.md](verification.md) for delivery or rollback. Only use `--yes`\nwithin the user's existing authorization. A saved plan locks source/target\nstates, Registry digest, adapter versions, and Git provenance; drift is a\nfailure requiring a fresh plan. Apply does not accept arbitrary source files\nthrough legacy flags: stage user-supplied fixtures in an isolated workspace's\ndocumented source surface when testing, without overwriting real configuration.\n\n`--apply-safe` is the default. It applies eligible objects, defers lossy ones\nunless accepted, and records manual/forbidden/conflict outcomes. Conflicts block\ntheir target group. `--strict` rejects any non-`ready` item. `--no-apply-safe`\nalso requires every item to be `ready` before any target write.\n`--include lossy` accepts all reviewed lossy items. `--accept-loss` on\n`apply`/`migrate` names item IDs such as `3:instructions`, not bare row numbers.\nExplicit loss acceptance remains necessary when the original request did not\nauthorize those semantics.\n\nInstruction/MCP conversions that drop reported fields or redact credentials\nare `ready-lossy`; `--yes` alone does not accept those losses. Accepted\nconversions still remove unsupported fields and literal credentials. Required\nSkill `.env` exclusions remain enforced without making an otherwise eligible\nSkill copy require loss acceptance.\n\n## Orchestrated migration\n\nFor an authorized scoped migration, `migrate` runs planning, apply, and verify:\n\n```bash\nbash \"$migrator\" migrate --source cursor/ide --target claude/code-cli \\\n    --workspace /path/to/project --scope project \\\n    --objects skills,instructions,mcp --plan-out /path/to/plan.json \\\n    --manifest-out /path/to/manifest.json --verify-out /path/to/verify.json \\\n    --yes --json\n```\n\nUse `--plan-only` when execution should stop at the plan. It still saves the\nplan; use ordinary `plan --json` for a preview with no persistent output writes.\nWithout explicit output paths, orchestration uses `<workspace>/.migration/`;\ntransaction backups and default apply manifests use\n`<workspace>/.agent-context-migration/`.\nChoose fresh manifest and verification output paths for each execution. Existing\ntransaction artifacts are preserved and rejected as outputs; keep them for\nverification and rollback instead of replacing them on a repeated run.\n\n`--objects all-portable` selects `skills,instructions,mcp`. Select narrower\nobjects when requested; `--objects all-inventory` is for inventory/manual/forbidden\nreporting, not permission to write those surfaces. Opt-in `plugins` and `handoff`\nalso require `--include-plugins` or `--include-session`, respectively.\nScopes are `user`, `project`, `local`, or documented unions/all as accepted by\neach command; applying `migrate --scope all` requires `--yes`, while\n`--plan-only` can preview it without that flag. CLI defaults differ, so pass explicit scopes instead of allowing a project request to inspect user files.\n\n## Backup, signing, diagnostics, and recovery\n\nUse [bundle-workflow.md](bundle-workflow.md) for `snapshot`, `bundle-verify`,\n`bundle-keygen`, `bundle-sign`, `doctor`, and bundle-backed `restore`/`apply`.\nUse [object-migration.md](object-migration.md) and\n[mcp-migration.md](mcp-migration.md) for object-specific boundaries. Remote MCP,\ncloud/UI, and unsupported adapters produce reconstruction actions, not silent\nfallback copies.\n\nThe explicit `legacy` subcommand accepts retained lookup/dry-run syntax:\n\n``...","readmeExcerpt":"Skill: agent-skills-setup Owner: luckycat133 Summary: Use when a user wants to migrate, back up, restore, compare, or move AI-coding-agent context across Cursor, Claude Code, Codex, Cline, Copilot, Windsurf, Gemini CLI, or another registered profile, including switching computers. Handles Skills, instructions/rules, and MCP with secret redaction, preview, verification, rollback, and portable bundles; compatible plugi","codeSnippets":[],"executableExamples":[{"language":"bash","snippet":"bash \"$migrator\" snapshot --source cursor/ide --target cursor/ide \\\n    --workspace /path/to/project --scope project \\\n    --objects skills,instructions,mcp --output /path/to/project.acb --json\nbash \"$migrator\" bundle-verify /path/to/project.acb --json\nbash \"$migrator\" doctor /path/to/project.acb --json"},{"language":"bash","snippet":"bash \"$migrator\" restore /path/to/project.acb \\\n    --source cursor/ide --target cline/ide \\\n    --workspace /path/to/new-project --scope project \\\n    --objects skills,instructions,mcp --plan-only \\\n    --plan-out /path/to/restore-plan.json --json\nbash \"$migrator\" restore /path/to/project.acb \\\n    --source cursor/ide --target cline/ide \\\n    --workspace /path/to/new-project --scope project \\\n    --objects skills,instructions,mcp --plan-in /path/to/restore-plan.json \\\n    --manifest-out /path/to/restore-manifest.json --yes --json\nbash \"$migrator\" verify --manifest /path/to/restore-manifest.json --json"},{"language":"bash","snippet":"bash \"$migrator\" bundle-keygen --out-private /path/to/private.key \\\n    --out-public /path/to/public.key --json\nbash \"$migrator\" bundle-sign /path/to/project.acb \\\n    --key /path/to/private.key --signer local-operator --json\nbash \"$migrator\" bundle-verify /path/to/project.acb \\\n    --trusted-key /path/to/public.key --json"},{"language":"bash","snippet":"migrator=/path/to/agent-skills-setup/scripts/smart-ide-migration.sh"},{"language":"bash","snippet":"bash \"$migrator\" detect --product cursor --profile ide \\\n    --workspace /path/to/project --json\nbash \"$migrator\" inventory --product cursor --profile ide \\\n    --workspace /path/to/project --json\nbash \"$migrator\" plan --source cursor/ide --target claude/code-cli \\\n    --workspace /path/to/project --scope project \\\n    --objects skills,instructions,mcp --json"},{"language":"bash","snippet":"bash \"$migrator\" plan --source cursor/ide --target claude/code-cli \\\n    --workspace /path/to/project --scope project \\\n    --objects skills,instructions,mcp --output /path/to/plan.json --json\nbash \"$migrator\" apply /path/to/plan.json \\\n    --manifest /path/to/manifest.json --yes --json\nbash \"$migrator\" verify --manifest /path/to/manifest.json --json"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: agent-skills-setup\nversion: \"0.10.2\"\ncompatibility: Requires local Bash, Python 3, environment lookup, and filesystem access; optional signing needs installed cryptography; no network access.\ndescription: >-\n  Use when a user wants to migrate, back up, restore, compare, or move\n  AI-coding-agent context across Cursor, Claude Code, Codex, Cline,\n  Copilot, Windsurf, Gemini CLI, or another registered profile, including\n  switching computers. Handles Skills, instructions/rules, and MCP with\n  secret redaction, preview, verification, rollback, and portable bundles;\n  compatible plugin packages and reviewed handoff are available by explicit opt-in.\nmetadata:\n  openclaw:\n    requires:\n      bins:\n        - bash\n        - python3\n---\n# Agent Skills Setup\n\n## Permissions\n\n- Run bundled local Bash/Python helpers and offline discovery only; network access is forbidden. No downloads, installations, or MCP connections.\n- Read selected products, requested scopes, workspace, bundles, and named keys. Broad discovery needs a device-wide request; environment lookup resolves paths without exposing credentials.\n- Write authorized targets, named plan/bundle/key outputs, and transaction state. `--yes` records existing user authorization for apply/restore/rollback; it does not grant authorization.\n\n## Choose the workflow\n\n- Infer products, objects, workspace, and scope from the request and established context. Project migration uses project scope; include user surfaces only when requested. Ask only for material information or authorization that cannot be inferred.\n- An explicit move/apply/restore/rollback request authorizes that scoped action. Preserve prior authorization; preview-only requests stop after preview. Review exact destinations and losses before writing; ask for unresolved conflicts, unapproved losses, or broader scope.\n- Save the plan, review its diff/rebuild manifest, and apply that exact file for execution. Changed inputs require a fresh plan and review.\n\n| Request | Entry point and guidance |\n| --- | --- |\n| Detect or inventory context | `detect`, `inventory`; [registry](references/ide-registry.md) and [CLI guide](references/cli-workflow.md). |\n| Compare or preview migration | `plan --json`; [migration safety](references/migration-safety.md). Saving `--output` writes a plan artifact. |\n| Migrate context | Saved `plan` → `apply --yes` → `verify`; `migrate` orchestrates the same stages. [CLI guide](references/cli-workflow.md). |\n| Back up or switch computers | `snapshot`, `bundle-verify`, `doctor`, `restore`; [bundle workflow](references/bundle-workflow.md). |\n| Sign or authenticate a bundle | `bundle-keygen`, `bundle-sign`, `bundle-verify --trusted-key`; [bundle workflow](references/bundle-workflow.md). |\n| Verify or undo applied changes | `verify`, `rollback --yes`; [verification](references/verification.md). |\n\nResolve both product profiles through [ide-registry.md](references/ide-registry.md) / [registry-v2.json](references/registry-v2.json"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn73ym4c6fp5b2vaa22t84v5fn83pt1p\",\n  \"slug\": \"agent-skills-setup\",\n  \"version\": \"0.10.2\",\n  \"publishedAt\": 1791015266890\n}"},{"path":"references/bundle-workflow.md","content":"# Portable bundle, restore, and signing workflow\n\nRead for computer switching, portable backups, ACB restore, dependency checks,\nor signing. Commands below use `migrator=/path/to/agent-skills-setup/scripts/smart-ide-migration.sh`;\nsubstitute the installed Skill path and requested source, target, workspace,\nscopes, and artifact paths. Run each command independently and inspect its result.\nUse [migration-safety.md](migration-safety.md) for authorization and conflict rules.\n\n## Capture and inspect\n\n`snapshot` writes an ACB **directory**, not a compressed archive. Name the source\nand output explicitly; the CLI's fallback product selectors are examples, not\npermission to inspect or restore those products.\n\n```bash\nbash \"$migrator\" snapshot --source cursor/ide --target cursor/ide \\\n    --workspace /path/to/project --scope project \\\n    --objects skills,instructions,mcp --output /path/to/project.acb --json\nbash \"$migrator\" bundle-verify /path/to/project.acb --json\nbash \"$migrator\" doctor /path/to/project.acb --json\n```\n\nReview `manifest.json`, the collection summary, `rebuild.json`, and\n`secrets.required.json`. ACB contains portable object bytes, sanitized inventory,\ncompatibility evidence, requirements, reauthentication actions, and checksums\nbinding every declared file. Failed, excluded, or manual objects are not\nautomatically backed up; report them. Credential values and private runtime\nstate must remain outside the bundle.\n\n`objects_captured` counts captured product/profile/scope object surfaces;\n`files_captured` counts their payload files. Compare these with the manifest's\nfile bindings and collection exclusions rather than treating file count as\nthe number of Skills or servers. ACB payload limits are 5,000 files, 10 MiB per\nfile, 100 MiB total, and 16 directory levels. Known image/font assets are\nallowed; executable or unallowlisted binary files fail collection instead of\nsilently disappearing. The exact extensions are `SAFE_BINARY_EXTENSIONS` in\n[acb/bundle.py](../scripts/acb/bundle.py).\n\nNew snapshots record optional integer `files[].mode` permission bits (`0..0o777`)\nin the checksummed manifest. On POSIX, restore and opt-in extraction apply these\nbits to copied files, preserving text helper scripts' executable bits while\ndropping setuid, setgid, and sticky flags. Payload storage permissions need not\nmatch the source. Older mode-less bundles remain readable but cannot establish\noriginal executable permissions; Windows applies only permissions supported by\nits filesystem. Verify required target file modes separately from content\nhashes; directory permissions and script execution are outside this guarantee.\nRecorded modes apply to copied Skill/plugin files and extracted payloads.\nGenerated instruction, MCP, and handoff files use their target writer's\npermissions; for example, generated MCP configuration is private (`0600`).\n\nFor a requested device-wide backup, run `detect` and review eligible profiles,\nthen use `snapshot --all-installed --scope us"},{"path":"references/cli-workflow.md","content":"# Public CLI workflow\n\nRead for detection, inventory, comparison, profile-aware migration, and command\nselection. `smart-ide-migration.sh` is the public wrapper. Set its path to the\ninstalled Skill directory, independent of the project working directory:\n\n```bash\nmigrator=/path/to/agent-skills-setup/scripts/smart-ide-migration.sh\n```\n\nUse concrete `<product>/<profile>` selectors from [Registry v2](registry-v2.json).\nProfile aliases, supported surfaces, platforms, and manual boundaries come from\n[ide-registry.md](ide-registry.md). Do not substitute paths from another product\nor a different profile. Paths can use documented environment/platform overrides;\nremote-host surfaces remain experimental.\n\n| Command | Observable result |\n| --- | --- |\n| `detect` | Offline install/configuration/compatibility detection, with evidence. |\n| `inventory` | Resolved surfaces, policy, precedence, and existence. |\n| `plan` | Destination paths, statuses, diffs, losses, and rebuild actions. |\n| `migrate` | Saved plan, apply manifest, and verification artifact in one flow. |\n| `apply` | Execution of a saved, state-validated plan and transaction manifest. |\n| `verify` | Whether recorded applied files still match their manifest. |\n| `rollback` | Guarded undo using that apply manifest. |\n| `snapshot` | Portable ACB directory and collection/exclusion summary. |\n| `bundle-verify` | Closed-world checksum, binding, and secret checks; optional trusted signature. |\n| `bundle-keygen`, `bundle-sign` | Offline Ed25519 key files or signature artifact. |\n| `restore` | Destination-side plan from bundle bytes, optional apply and verify. |\n| `doctor` | Complete recorded requirements, executable PATH checks, and reauthentication/rebuild actions. |\n| `legacy` | Explicit lookup or zero-write dry-run compatibility only. |\n\nLegacy preview reports stay on stdout, including when `--report` is supplied;\nthe named file is neither created nor changed. Use `plan --output` to save a\nprofile-aware plan for review and execution.\n\n`--json` emits one JSON document on stdout; diagnostics go to stderr. Inspect\nexit status, item statuses, and applied counts, not merely `ok`. Use\n`bash \"$migrator\" <command> --help` for that command's accepted flags.\n\n## Detect and preview the named project\n\n```bash\nbash \"$migrator\" detect --product cursor --profile ide \\\n    --workspace /path/to/project --json\nbash \"$migrator\" inventory --product cursor --profile ide \\\n    --workspace /path/to/project --json\nbash \"$migrator\" plan --source cursor/ide --target claude/code-cli \\\n    --workspace /path/to/project --scope project \\\n    --objects skills,instructions,mcp --json\n```\n\nThe final command emits a preview without saving an artifact. To prepare an\nauthorized execution, add `--output /path/to/plan.json`, read that file's\n`review_preview`, `loss_report`, and `rebuild_manifest`, and apply the same file.\nDo not claim a migration from detection, plan output, or an empty inventory.\nBroad `detect`/`inventory` without a product"},{"path":"references/doc-freshness-checks.json","content":"{\n  \"schema_version\": 1,\n  \"verified_at\": \"2026-08-15\",\n  \"checks\": [\n    {\n      \"id\": \"agent-skills-spec\",\n      \"url\": \"https://raw.githubusercontent.com/agentskills/agentskills/main/docs/specification.mdx\",\n      \"required_terms\": [\n        \"name\",\n        \"description\",\n        \"metadata\"\n      ]\n    },\n    {\n      \"id\": \"cline-config\",\n      \"url\": \"https://docs.cline.bot/getting-started/config\",\n      \"required_terms\": [\n        \"cline\",\n        \"configuration\"\n      ]\n    },\n    {\n      \"id\": \"forgecode-docs\",\n      \"url\": \"https://forgecode.dev/docs/\",\n      \"required_terms\": [\n        \"forge\",\n        \"agent\"\n      ]\n    },\n    {\n      \"id\": \"qoder-docs\",\n      \"url\": \"https://docs.qoder.com/\",\n      \"required_terms\": [\n        \"qoder\"\n      ]\n    },\n    {\n      \"id\": \"codex-docs\",\n      \"url\": \"https://learn.chatgpt.com/docs/llms.txt\",\n      \"required_terms\": [\n        \"codex\"\n      ]\n    },\n    {\n      \"id\": \"openhands-docs\",\n      \"url\": \"https://docs.openhands.dev/overview/introduction\",\n      \"required_terms\": [\n        \"openhands\"\n      ]\n    },\n    {\n      \"id\": \"amp-manual\",\n      \"url\": \"https://ampcode.com/manual\",\n      \"required_terms\": [\n        \"agent skills\",\n        \"mcp\"\n      ]\n    },\n    {\n      \"id\": \"monkeycode-readme\",\n      \"url\": \"https://raw.githubusercontent.com/chaitin/MonkeyCode/main/README.md\",\n      \"required_terms\": [\n        \"monkeycode\",\n        \"development platform\"\n      ]\n    },\n    {\n      \"id\": \"cursor-rules\",\n      \"url\": \"https://docs.cursor.com/context/rules\",\n      \"required_terms\": [\n        \"cursor\",\n        \"rule\"\n      ]\n    },\n    {\n      \"id\": \"claude-code-skills\",\n      \"url\": \"https://code.claude.com/docs/en/skills\",\n      \"required_terms\": [\n        \"skill\"\n      ]\n    },\n    {\n      \"id\": \"github-copilot-cli\",\n      \"url\": \"https://docs.github.com/en/copilot/how-tos/copilot-cli\",\n      \"required_terms\": [\n        \"copilot\",\n        \"cli\"\n      ]\n    },\n    {\n      \"id\": \"vscode-agent-skills\",\n      \"url\": \"https://code.visualstudio.com/docs/agent-customization/agent-skills\",\n      \"required_terms\": [\n        \"skill\"\n      ]\n    },\n    {\n      \"id\": \"gemini-cli-skills\",\n      \"url\": \"https://github.com/google-gemini/gemini-cli/blob/main/docs/skills.md\",\n      \"required_terms\": [\n        \"gemini\",\n        \"skill\"\n      ]\n    },\n    {\n      \"id\": \"kiro-steering\",\n      \"url\": \"https://kiro.dev/docs/steering\",\n      \"required_terms\": [\n        \"kiro\",\n        \"steering\"\n      ]\n    },\n    {\n      \"id\": \"rovodev-cli-skills\",\n      \"url\": \"https://support.atlassian.com/rovo/docs/use-agent-skills-in-rovo-dev-cli/\",\n      \"required_terms\": [\n        \"rovo\",\n        \"skill\"\n      ]\n    },\n    {\n      \"id\": \"ibm-bob-docs\",\n      \"url\": \"https://www.ibm.com/docs/en/bob\",\n      \"required_terms\": [\n        \"bob\",\n        \"agent\"\n      ]\n    },\n    {\n      \"id\": \"warp-drive-prompts\",\n      \"url\": \"https://docs.warp.dev/agents/prompts\",\n      \"required_terms\": [\n        \"warp\",\n        \"prompt\"\n    "}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":null,"editorialQuality":{"score":100,"threshold":65,"status":"thin","wordCount":2840,"uniquenessScore":40,"reasons":["uniqueness-below-45"]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-09T09:23:58.739Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-09T09:23:58.739Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-09T20:27:46.312Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}