Skip to content
AI & Agents
Skill

/fleet-maintenance

Mac fleet inventory and upkeep with full/worker profiles: collect installed apps and packages, compare desired versus observed state, audit local-account escrow references, update Homebrew/global packages, safely sync repos and Xcode, and report disk, service, backup, update,

BOOST
From plugin
agent-scripts
7.1k54 skills
Install
$ npx -y skills add steipete/agent-scripts --skill fleet-maintenance --agent claude-code

How it fires

How this skill gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
  • You can call itInvoke it directly when you want it.
  • Slash command/fleet-maintenance

Context preview

The summary Claude sees to decide when to auto-load this skill.

Mac fleet inventory and upkeep with full/worker profiles: collect installed apps and packages, compare desired versus observed state, audit local-account escrow references, update Homebrew/global packages, safely sync repos and Xcode, and report disk, service, backup, update,

SKILL.md

fleet-maintenance.SKILL.md
name: fleet-maintenance
description: "Mac fleet inventory and upkeep with full/worker profiles: collect installed apps and packages, compare desired versus observed state, audit local-account escrow references, update Homebrew/global packages, safely sync repos and Xcode, and report disk, service, backup, update, and security health."

Fleet Maintenance

Maintain Peter's Macs while protecting ambiguous local work. Package updates are explicitly allowed during active sessions and may disrupt the software being upgraded. Use `$remote-mac` for inventory/SSH and `$xcode-sync` for all Xcode work.

Desired state

  • Read `~/Projects/manager/fleet/inventory.json` for desired software and local-account escrow references. Read `references/fleet-schema.md` before changing its schema or adopting packages.
  • Keep exactly two profiles unless Peter explicitly changes the model:
  • `full`: daily-driver Macs with the complete development, communication, media, and agentic toolset.
  • `worker`: lean remote Macs that mainly run Codex, Claude, OpenClaw nodes, and supporting agent infrastructure.
  • Treat profile policy as `minimum`: install required entries and report extras without removing them. Never silently turn observed software into desired state.
  • Keep topology, SSH routing, and handed-off status in `~/Projects/manager/computers.yaml`. Do not duplicate live topology in this skill.
  • Keep passwords, recovery keys, and private keys in 1Password. The inventory stores opaque item IDs only. Invoke `$one-password` before any `op` command; a `pending` reference is not an error during package maintenance.
  • Require the classic OpenSSH mesh named by `ssh_mesh` on both profiles. The manager fleet setup document owns the canonical peer list and live proof. Use the symmetric Tailscale TCP 22 grant plus per-host `authorized_keys`; macOS GUI Tailscale clients cannot act as Tailscale SSH servers. Distribute public keys only, keep private keys host-local, verify both directions with `BatchMode=yes` and a finite timeout, and leave offline or provider-blocked directions pending.
  • Require the stable 1Password CLI integrity baseline on every fleet Mac. Require the file-backed service-account profile block unless that host has a documented `requirement_exceptions` security boundary in inventory. Audit eligible hosts with `scripts/op-profile-audit.sh`; audit token-exempt hosts with `scripts/op-profile-audit.sh --cli-only`. Repair only after `$one-password` is loaded and the mode-0600 token file is provisioned; never print or store the token in inventory.
  • Require the agent skill mirror on every fleet Mac. Audit it with `scripts/agent-skill-links-audit.sh`; its `--repair` invokes broad canonical sync only when both canonical repos exist. Sync preserves real directories and files, accepting same-directory local ownership and reporting other real destination conflicts. For `reason=nested-self-link`, invoke the reviewed sync owner directly by absolute path with `--repair-nested-self-links --dry-run -- NAME...`, then omit `--dry-run` to remove only validated nested leaves; preserve the real Claude skill directories and Codex backlinks. This narrow loop check is not an exhaustive graph validator. See `references/fleet-schema.md` for scope and `~/Projects/manager/docs/fleet-setup.md` for fleet setup.
  • Require the shared global Git ignore on every fleet Mac. Audit it with `scripts/global-gitignore-audit.sh`; `--repair` creates `~/.config/git/ignore`, preserves unrelated entries, adds the inventory's macOS metadata patterns, and points `core.excludesFile` at it. An already-configured alternate excludes file requires manual review so existing rules are never discarded.
  • Require Claude Code and Claude Desktop coding sessions to omit AI attribution. Audit `~/.claude/settings.json` with `scripts/claude-attribution-audit.sh`; `--repair` preserves unrelated settings while disabling commit trailers, pull-request footers, and remote-session links.
  • Require the official Codex and Claude Code CLIs on both profiles. Package ownership comes from the profile's `codex` and `claude-code` Homebrew casks; the separate `claude` cask is Claude Desktop and does not satisfy the CLI requirement. Audit versions and non-interactive authentication with `scripts/agent-cli-audit.sh`; use `--live` for bounded, tool-free, non-persistent model turns. Never copy normal Claude OAuth credentials between Macs: refresh each host independently through `$anthropic` and leave locked-Keychain, account-selection, or offline cases pending.
  • Require Octopool as the GitHub cache on both profiles with `requirements.github_cache: "octopool"`. Package presence alone is insufficient: `scripts/octopool-audit.sh` must prove that non-interactive and login zsh resolve `gh` through the Octopool shim, the client login has complete identity metadata, and every configured pool identity is healthy. Use `--repair` to log in through the existing authenticated stable-path GitHub CLI, install the zsh shim, and repair macOS login PATH ordering when needed; it never installs packages or prints credentials.

Use the deterministic profile tool:

node skills/fleet-maintenance/scripts/fleet-profile.mjs collect
node skills/fleet-maintenance/scripts/fleet-profile.mjs \
  plan --fleet ~/Projects/manager/fleet/inventory.json \
  --host mac-studio-sf --snapshot /path/to/mac-studio-sf.json
node skills/fleet-maintenance/scripts/fleet-profile.mjs \
  diff --source /path/to/macbook-pro.json --target /path/to/mac-studio-sf.json
node skills/fleet-maintenance/scripts/fleet-profile.mjs \
  brewfile --fleet ~/Projects/manager/fleet/inventory.json --host mac-studio-sf
node skills/fleet-maintenance/scripts/fleet-profile.mjs \
  validate --fleet ~/Projects/manager/fleet/inventory.json
skills/fleet-maintenance/scripts/agent-skill-links-audit.sh
skills/fleet-maintenance/scripts/global-gitignore-audit.sh --host mac-studio-sf
skills/fleet-maintenance/scripts/claude-attribution-audit.sh
Read more
Ships withagent-scripts

Shared agent instructions, skills, and small portable helpers for Peter's local workspaces.

Get the whole plugin
Stats
7,208
Stars
617
Forks
Active
Maintenance
Shell
Language
MIT
License
19h ago
Last commit
10mo ago
Created
3h ago
Added

Repo: steipete/agent-scripts

Other skills on agent-scripts.