Start
Getting started
Install the plugin, generate a project policy, and watch the authorization protocol take over. About five minutes.
Requirements#
Claude Code with the /plugin command. If you don't see it, update Claude Code to the latest version. Keel Skills is a single-plugin marketplace — nothing else to install.
1 · Install the plugin#
Inside Claude Code, add the marketplace and install:
/plugin marketplace add https://github.com/quitohooded/keel-skills
/plugin install keel-skills@keel-skillsOnce it's approved in the community marketplace you'll also be able to install it the shorter way:
/plugin marketplace add anthropics/claude-plugins-community
/plugin install keel-skills@claude-communityThis adds five skills, six commands, and two hooks. The skills are model-invoked: they trigger themselves when the situation calls for it, so there's nothing to remember to run.
2 · Run the onboarding#
In the project you want to govern, run:
/keel-skills:onboardIt assumes nothing. First it looks at what is actually there — whether this is a repo, one project or several, the stack, any agent instructions you already have, where state seems to live, or whether the folder is empty. Then it tells you what it found and what it could not tell, and asks about the rest rather than guessing.
Then it offers three sizes and builds only the one you pick:
| Level | Time | What you get |
|---|---|---|
| 1 · The brake | ~5 min | An AGENT_POLICY.md with your real hot zones, enforced by the hook |
| 2 · + session loop | ~15 min | A state/history pair, so work survives across sessions |
| 3 · + maintenance loop | ~30 min | Mechanical checks, an improvement backlog, a scheduled sweep |
Note
If you only want the policy file and none of the interview around it, /keel-skills:policy-init does that one step on its own.
Why a separate file
3 · Let the hooks do their jobs#
From then on the SessionStart hook injects your AGENT_POLICY.md into context at the start of every session, so the policy no longer depends on the agent remembering to read it. If a project has no policy, it prints a two-line nudge instead.
The PreToolUse hook is the hard half: it inspects each tool call before it runs and stops a hot one for explicit approval — and denies it outright in a non-interactive run, since nobody is there to approve. Every decision is appended to .keel/audit.jsonl.
4 · See it work#
Ask the agent to do something that touches a hot zone — for example, “clean this up and push.” Instead of executing, the authorization-protocol skill recognizes the push as a hot zone, returns a clearly-marked proposal with the exact scope, and waits for your explicit approval. If it doesn't stop itself, the hook stops it anyway.
Note
5 · The daily loop (optional)#
If you took level 2 or 3, the rhythm is: /keel-skills:session-start to load state and run the checks before working, /keel-skills:session-close to write state back and leave a handoff, /keel-skills:hygiene weekly, and /keel-skills:harvest whenever there's spare capacity.
Where to go next#
- Permission model — the core: goal / method / green light, the four-step check, hot zones.
- The operating loop — sessions, documents that don't age, checks, and turning repetition into tools.
- Model & delegation — pick the cheapest capable model; keep delegation shallow.
- Context discipline — keep sessions grounded in files, not chat.