agent-activity
Streams what the agent is doing into the room, as rows the desktop client renders in an **events drawer** above the composer (collapsed: avatar, pulsing dots,…
Hardened loopback static server for local presentation drafts — capability-URL, read-only GET/HEAD, Host-header gate, nosniff + sandbox CSP. Use instead of a plain http.server when the Presentation panel's dev mode loads a local deck.
$ npx -y skills add sonichi/sutando --skill local-workspace-server --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/local-workspace-serverContext preview
The summary Claude sees to decide when to auto-load this skill.
Hardened loopback static server for local presentation drafts — capability-URL, read-only GET/HEAD, Host-header gate, nosniff + sandbox CSP. Use instead of a plain http.server when the Presentation panel's dev mode loads a local deck.
name: local-workspace-server description: Hardened loopback static server for local presentation drafts — capability-URL, read-only GET/HEAD, Host-header gate, nosniff + sandbox CSP. Use instead of a plain http.server when the Presentation panel's dev mode loads a local deck.
Serves ONE directory, read-only, to the trusted Presentation panel's dev mode. Loopback binding is not treated as trust: the owner's hardening checklist (2026-08-26) is the spec, and every guard is pinned in `tests/local-workspace-server.test.py` over real HTTP.
python3 skills/local-workspace-server/scripts/serve.py --root <deck-dir> [--port 8899] [--ttl 3600]
Prints a capability URL (`http://127.0.0.1:<port>/<token>/`). Paste it into the panel's device-local dev override — it never goes into room state (logical `local_workspace` descriptors only; see the Presentation protocol thread).
Guards: 127.0.0.1 bind only · random capability path segment (constant-time compare) · TTL expiry → 403 · GET/HEAD only, anything else 405 · no directory listing · traversal-safe resolve containment · explicit MIME + nosniff · `sandbox allow-scripts` CSP on HTML · Host header must be loopback (DNS- rebinding defense, computed from the BOUND port) · no-store caching · stdout logging only.
My AI Stand — Realtime by Day, Rewriting Itself by Night. Summon my AI superpower. Voice, vision, screen, meetings, calls when I'm engaged. Learns my patterns, ships its own code when I'm not. Runs across my Macs, interacts with people & their Stands.
Repo: sonichi/sutando
Streams what the agent is doing into the room, as rows the desktop client renders in an **events drawer** above the composer (collapsed: avatar, pulsing dots,…
Local Agent Registry — a standalone, dependency-free service that tracks running Claude Code (and other) agent instances. Agents self-register on startup and…
**Prefer the `ag2-space` MCP tools when they are connected and the room exposes them** — availability is per-room and per-actor, so check…
Deterministic final-answer normalizer — a last-step pass for any task that ends in a *precise* answer (a number, a short string, a comma-list). Applies the…
Transcribes audio files and voice notes to text via Gemini 2.5-flash. Integrates with Slack, Discord, and Telegram bridges so voice clips surface as readable…
Act back on the owner's Bee wearable — the TOOL half of the Bee integration (channels-vs-tools split). The Bee CHANNEL (ag2-sparrow's `sources/bee.py` watcher)…