What does this skill do, and when should you use it?
Defined at skills/cmux-dev-workflow/SKILL.md in the manaflow-ai/cmux repository, this skill guides contributors through native cmux development and verification. It enforces tagged builds (reload.sh --tag) that isolate bundle IDs, sockets, and build output between sessions, runs setup and scoped verification scripts, and covers Xcode project normalization plus sidebar-extension tagging. It draws a hard safety boundary: only run repository commands from a trusted checkout, and never touch the user's running cmux. It is useful exclusively to cmux contributors; end users and non-macOS developers gain nothing from it.
- Runs ./scripts/setup.sh to initialize submodules, build GhosttyKit, and install the project-normalization pre-commit hook
- Builds tagged dev bundles without launching via ./scripts/reload.sh --tag <short-tag>; add --launch for live verification
- Verifies tagged builds with CMUX_TAG=<tag> scripts/cmux-debug-cli.sh list-workspaces
- Runs python3 scripts/verify-local.py and scoped checks like --only project
- Builds sidebar extensions with scripts/reload-extension.sh --tag <tag> against the matching host
- Normalizes project.pbxproj via the pre-commit hook and registers new Python tests in tests/test-execution.toml
- A cmux contributor changes native app or build-input code and needs a tagged local build for verification without disturbing the user's running cmux instance
- A contributor edits only documentation or portable tooling and wants fast scoped checks from verify-local.py without an unrelated app build
- A contributor edits the Xcode project (e.g. toolchain pins) and must run the normalization hook plus the --only project check
- A developer builds and verifies a sidebar extension for a specific tag, keeping extension-point ID, bundle-ID suffix, and display-name suffix consistent
- End users who want to run AI coding agents inside cmux — this skill only serves cmux's own development
- Non-macOS developers or anyone not working on the cmux codebase; building requires Xcode, the GhosttyKit submodule, and a local checkout
How do you install this skill?
- Static review executed nothing; the actual behavior and failure feedback of referenced scripts (reload.sh, reload-extension.sh, cmux-debug-cli.sh) are unverified.
- Repository license metadata is NOASSERTION while the effective license is a GPL-3.0 / BUSL-1.1 mix; confirm applicable scope before use.
- The skill's hard constraints (e.g., never replacing the running app) are implemented in scripts; spot-check the guard logic in those scripts before relying on them.
- Narrow audience: macOS/Xcode contributors only; no Chinese documentation; default commands load repository code, so run only from a trusted checkout.
- Tagged builds outside this repository require the shared dev backend from a cmuxterm-hq checkout; external contributors should read the CONTRIBUTING restrictions first.
- Shell / CLI
- Local filesystem
macOSXcode (pinned via .xcode-version)Python 3cmux repository checkout
This skill is part of the skill collection bundled in the manaflow-ai/cmux repository (25 skills total). Installation means cloning the repo and pointing your Agent Skills client at skills/cmux-dev-workflow/. The source documents no one-command install for Claude Code, Codex, or other specific clients:
git clone https://github.com/manaflow-ai/cmux.git
cd cmux
# Install skills/cmux-dev-workflow/ into your Agent Skills client (exact command not documented in source)How do you use this skill?
Once installed, send your agent any of these to trigger it:
- I changed a native build input — reload a tagged dev build and verify the workspace list
- I only touched docs — run the scoped verify-local.py checks without an app build
- I changed the toolchain pin in project.pbxproj — run the project normalization check
- Build the sidebar extension for tag dev-42 and verify its extension-point ID, bundle-ID suffix, and display-name suffix
The skill is triggered when a task involves native build inputs, setup, or tagged app verification, per its SKILL.md description. Core flow: run only from a trusted checkout (even --help loads repository code); start fast feedback with python3 scripts/verify-local.py; use tagged builds only for native changes:
./scripts/setup.sh
./scripts/reload.sh --tag <short-tag>
CMUX_TAG=<short-tag> scripts/cmux-debug-cli.sh list-workspacesreload.sh builds without launching by default; add --launch for live verification. Never use bare xcodebuild, open an untagged cmux DEV.app, use /tmp/cmux-cli, or quit/kill/relaunch/xctrace --launch the user's running com.cmuxterm.app. After project edits, run python3 scripts/verify-local.py --only project.
What are this skill's strengths and limitations?
- Tags isolate bundle IDs, sockets, and build output so parallel sessions don't interfere
- Explicit safety boundary protecting the user's running cmux and its live agent sessions
- Scoped verify-local.py checks give fast feedback without an unrelated app build
- Normalization hook auto-registers new Python tests in tests/test-execution.toml
- Heavily depends on macOS, a pinned Xcode (16.2/Swift 6.0 for the Intel/macOS 14 fallback), and a full local checkout
- Scoped entirely to cmux development — useless for any other repository
- No test evidence for the skill itself; consequences of mistakes (touching a running instance) are serious and rely on documented rules
- Repo license is NOASSERTION on GitHub metadata; actual terms are GPL-3.0-or-later plus BUSL-1.1 for server components, so verify before commercial use
How does this skill compare with similar options?
Side by side with related skills; every score comes from the same FSRS standard.
| Skill | FS score | Stars | Last updated | License |
|---|---|---|---|---|
| cmux Dev Workflow Skill this page | 53 · Use with care | ★ 28k | 1d ago | NOASSERTION |
| cmux Testing Skill | 60 · Recommended | ★ 28k | 1d ago | NOASSERTION |
| cmux Custom Sidebar | 50 · Use with care | ★ 28k | 1d ago | NOASSERTION |
| cmux Workspace Skill | 64 · Recommended | ★ 28k | 1d ago | NOASSERTION |
| cmux-browser: Browser Automation Skill for cmux | 60 · Recommended | ★ 28k | 1d ago | NOASSERTION |
No direct competitor is named in the source; this is essentially cmux's internal contributor guide made executable, not comparable to terminals like tmux.
How did FollowSkills review this skill?
The skill itself shows good least-privilege and isolation discipline: tagged builds isolate bundle IDs/sockets, explicit prohibitions on killing or replacing the user's running cmux with live agent sessions, an override flag (CMUX_ALLOW_REPLACING_RUNNING_CMUX) explicitly reserved for the user, and a trust-boundary warning that even --help loads repository code. Deductions: these protections live in scripts not reviewed here and cannot be statically verified; repository license metadata is NOASSERTION (actual license is a GPL+BUSL mix); publisher unverified; no explicit rollback mechanism described.
Instructions are self-consistent and cross-references align (tagged-builds.md, sidebar-extension-tagging.md, SKILL.md agree on conventions), with reasonably clear abnormal-path guidance (--build-only cannot combine with --launch; helper refuses without CMUX_TAG). Deductions: static review executes nothing, so key paths are unreproduced; failure-feedback quality and edge-case coverage of the scripts are unverified, capped below 10 by calibration.
Audience and scenarios are clear (cmux native-build contributors), boundaries are declared (an app build does not establish test-target compilation; points to the test guide), and non-fit ranges (portable checks need no setup) are stated. Deductions: trigger conditions are descriptive rather than precise semantic rules; macOS/Xcode only, no Chinese-language support; the shared dev backend requirement limits outside contributors.
Information architecture is well layered (lean SKILL.md, details pushed to references/) with clear progressive disclosure and install/dependency notes. Deductions: NOASSERTION license metadata with the mixed GPL/BUSL reality unexplained inside the skill; no skill-level versioning or changelog; maintenance ownership implied only by repository context.
The task paths (safe local builds, tagged app verification, sidebar extension tagging) are concrete with directly usable commands, and the guidance has clear marginal value over ad-hoc xcodebuild use by protecting the user's running app. Deductions: static review cannot confirm outputs are directly usable; some prerequisites (local backend mode, verified prebuilt GhosttyKit download) are not end-to-end demonstrated.
The repository contains real CI workflows (app-host test rerun, Xcode pin CI guard) and committed tests, giving partial auditable support for the project's claims. Deductions: this evidence does not directly cover the skill's key paths (reload.sh, reload-extension.sh, cmux-debug-cli.sh have no shown tests or third-party execution evidence), and static review caps this dimension at 5, which was not reached.
Open a dimension to read why it scored that way
Evidence confidence:Low — Mostly static review, author material or a limited demo; useful for discovery, not high-risk decisions.
See the full review method →