treeseed
Operate a TreeSeed control plane through its current MCP capabilities for project, knowledge, governance, and execution work. Use when a task targets TreeSeed records or governed project-agent chat; do not use it as authority to run agents or mutate repositories.
How do I install this agent skill?
npx skills add https://github.com/treeseed-ai/skill --skill treeseedIs this agent skill safe to install?
- Gen Agent Trust Hubpass
The skill provides comprehensive instructions for operating the TreeSeed control plane with a strong emphasis on governance and credential safety. It includes a verification script that fetches vendor manifests from GitHub to ensure catalog integrity and is subject to low-severity indirect prompt injection via project records and agent chats.
- Socketpass
No alerts
- Snykwarn
Risk: MEDIUM · 1 issue
What does this agent skill do?
TreeSeed
Treat the connected TreeSeed server as the authority for identity, access, governance, scheduling, and receipts. Discover its current MCP tools, resources, templates, prompts, schemas, and capability annotations before choosing an operation. Do not rely on a remembered tool list or construct REST paths.
Operating boundary
- Act as the authenticated external principal. Do not claim project-agent identity unless an explicit, authorized project-agent chat operation returns that delegation.
- Read current state before a consequential mutation. Follow returned blockers, concurrency tokens, confirmation requests, resource links, and next actions.
- Use server-provided structured input and output schemas. Never place credentials, session material, private keys, or bearer tokens in tool arguments or model-visible content.
- Treat
input_requiredas a signed, exact-argument confirmation checkpoint. Ask the human when required; never alter, reuse, or synthesize confirmation state. - Follow durable
treeseed://resource links for asynchronous work. Use progress, cancellation, completion, and subscriptions when advertised instead of polling invented endpoints. - Do not invoke or emulate
save,stage, orreleaseuntil the server advertises their accepted governed operations. - For repository-backed project knowledge, use the
trsd libraryworkflow inreferences/knowledge.md; never assume an unbound virtual repository or asrc/contentlibrary root.
Choose the relevant guidance
- For questions, research, knowledge, or TreeDX projections, read references/knowledge.md.
- For proposals, decisions, estimates, reviews, or discussions, read references/governance.md.
- For teams, projects, repositories, or provider bindings, read references/projects.md.
- For agents, providers, capacity, plans, workdays, assignments, or explicit project-agent chat, read references/execution.md.
- For connection discovery, protocol behavior, errors, subscriptions, or confirmations, read references/mcp.md.
Distribution
Install and update the project-scoped skill with the pinned Vercel Labs Skills CLI version recorded by the consuming project:
npx skills@1.5.23 add treeseed-ai/skill --skill treeseed --agent codex --yes
npx skills@1.5.23 update treeseed --project --yes
The receipt pins published SDK and API evidence for this copy. Runtime discovery remains authoritative when a connected server advertises a newer compatible catalog. Installed files and skills-lock.json belong to the consuming project; this repository remains the source of releases.
How can the creator link this skill?
Add the canonical catalog link to the repository README so users can inspect current installs and available audits. The publishing guide covers the complete discovery path.
<a href="https://skillzs.dev/skills/treeseed-ai/skill/treeseed">View treeseed on skillZs</a>