Dev & Engineering

cmux Socket Policy Skill

Gives AI coding agents the threading and focus rules for cmux socket/CLI work, so telemetry stays off the main thread and automation never steals your app focus.

58/ 100
Recommended

Generally reliable with disclosed limitations; trial as directed and keep a rollback path.

See how it was scored ↓
Works as-is in
ChatGPT · Codex · Claude Code · Claude.ai
Stars
★ 28k
Last updated
1d ago
License
NOASSERTION
cmuxmacossocket-apiconcurrency
+4grand-central-dispatchfocus-policycli-developmentappkit

What does this skill do, and when should you use it?

This is one of 25 skills bundled in the manaflow-ai/cmux repository, located at skills/cmux-socket-policy/SKILL.md. It is not an executable tool but a policy document written for AI coding agents, covering three areas: socket command threading (telemetry hot paths must stay off the main thread), focus policy (non-focus commands must never activate the app or raise windows), and remote relay authorization (v2 methods are denied by default and require security analysis to allowlist). The skill targets agents working directly on the cmux native macOS app (Swift/AppKit/Ghostty). It is an internal contribution standard for the repository, not a general-purpose tool for end users.

  • Forbids DispatchQueue.main.sync for high-frequency telemetry commands such as report_*, ports_kick, status/progress updates, and log metadata updates; parsing, validation, dedup, and coalescing must happen off-main
  • Requires new socket commands to default to off-main handling, with an explicit reason in code comments when main-thread execution is necessary
  • Enumerates the only commands with explicit focus intent (window.focus, workspace.select/next/previous/last, surface.focus, pane.focus/last, browser focus commands); all other commands must preserve the current user focus context
  • Makes open commands (vm/cloud shell, tui, open, new, workspace new/open, agent, surface open/new-terminal, cmux open, cmux ssh) focus only when run interactively and stay in the background when run by an agent or script, with --focus / --no-focus overrides and focus defaulting to false on socket methods
  • Enforces default-deny remote relay authorization via RemoteRelayCommandPolicy, requiring the security analysis and policy tests documented in references/remote-relay-authorization.md before allowlisting any v2 method
Good fit
  • A developer contributing to the cmux repository loads this skill before having an agent add or modify socket/CLI commands, preventing main-thread blocking or focus-stealing defects
  • An agent implementing telemetry hot paths like report_*, ports_kick, or status/progress updates follows the policy to parse, dedupe, and coalesce off-main
  • Someone writing automation that calls the cmux CLI or socket verifies that open commands stay in the background and do not steal the current window focus
  • A maintainer wants to allowlist a v2 method for remote cmux ssh relay and follows the skill's default-deny workflow with security analysis
  • A code reviewer uses the skill as a checklist to judge whether a command's execution context and focus changes comply with repository conventions
Not a fit
  • Everyday cmux terminal users — this is an internal contribution standard and says nothing about daily use, theming, or notification settings
  • Developers hoping to reuse it in other projects — the rules are hard-bound to cmux-specific command names (ports_kick, workspace.select, etc.) and are nearly meaningless outside that codebase
  • Teams not on the macOS/Swift/AppKit stack — the policy revolves around the AppKit main thread and the macOS app focus model and cannot be ported

How do you install this skill?

Before you use it
  • This skill applies only when developing socket/CLI/focus features inside the cmux repository; do not invoke it in other projects or terminal environments.
  • The skill files do not state their own license; the repo mixes GPL-3.0 and BUSL-1.1 (web/ and other directories) — verify licensing scope before reusing the policy text.
  • The relay authorization policy is security-critical (deny-by-default, allowlist review); when touching related methods, verify the actual test files the references point to rather than acting on the skill text alone.
  • This is a static source review with no execution; all scores are low confidence.
Before you start
Your agent needs
  • Local filesystem

The skill is a file under the skills/ directory of the manaflow-ai/cmux repository; the source material documents no standalone install commands. To use it, clone the repository and place the skills/cmux-socket-policy/ directory into your Agent Skills-compatible client's skills directory, or simply ask the agent to read SKILL.md and the two reference documents under references/. Exact installation steps are not documented in the source.

Generic route: install into Claude Code manually (macOS / Linux)
tmp="$(mktemp -d)"
git clone --depth 1 https://github.com/manaflow-ai/cmux.git "$tmp"
mkdir -p ~/.claude/skills
cp -R "$tmp/skills/cmux-socket-policy" ~/.claude/skills/
rm -rf "$tmp"

Generated from the source repository and skill path; it copies only this skill's folder. If the author's install steps above differ, follow those first. To scope it to one project, replace ~/.claude/skills with that project's .claude/skills.

How do you use this skill?

Try saying

Once installed, send your agent any of these to trigger it:

  • I'm adding a new report_metrics socket command to cmux — read the cmux-socket-policy skill first and implement it per the threading policy, with argument parsing and dedup off-main
  • Write a script that opens 10 cmux workspaces; per the focus policy don't steal my current window focus, keep socket calls at the default focus=false
  • I want to allowlist the workspace.rename v2 method for cmux ssh remote relay — read references/remote-relay-authorization.md first, do the security analysis, and add the policy tests
  • Review the new CLI command in this PR: it calls DispatchQueue.main.sync for ports_kick telemetry and activates the app window — flag the violations against cmux-socket-policy

The skill declares its trigger conditions in the SKILL.md description: load it whenever a task involves adding or changing socket commands, CLI commands, telemetry commands, focus/select/open/close/send-key behavior, or automation that could steal app focus. The flow is to read the threading and focus policy bodies in SKILL.md, then consult the two references as needed: references/threading-and-focus.md (when adding a command or changing its execution context) and references/remote-relay-authorization.md (when adding or changing a v2 method or remote CLI command). Note that open commands support --focus / --no-focus flags, socket methods default focus to false, and a pane opened without focus is marked unread.

What are this skill's strengths and limitations?

Pros
  • Rules are concrete down to command names and APIs (DispatchQueue.main.sync, defaultFocusForUserOpen), making them directly actionable rather than vague principles
  • Sensible focus defaults: agent/script-triggered open commands run in the background by default, interactive use gets focus, with explicit opt-in/opt-out flags
  • Remote relay uses a default-deny allowlist model with mandatory security analysis and policy tests — a clear security posture
  • Pure documentation skill with no runtime dependencies; any agent client that can read files can use it directly
Limitations
  • Only useful for developing the cmux repository itself; near-zero transfer value to other projects
  • The source provides no evidence of tests or CI enforcement verifying compliance with the policy
  • Depends on two reference documents; a repo restructuring (e.g., remote-relay-authorization.md being renamed) would break the skill
  • No install or invocation commands are given; adoption depends on the client supporting the Agent Skills directory convention

How does this skill compare with similar options?

Side by side with related skills; every score comes from the same FSRS standard.

Skill FS score Stars Last updated License
cmux Socket Policy Skill this page 58 · Recommended ★ 28k 1d ago NOASSERTION
cmux Workspace Skill 64 · Recommended ★ 28k 1d ago NOASSERTION
cmux-browser: Browser Automation Skill for cmux 60 · Recommended ★ 28k 1d ago NOASSERTION
cmux Diagnostics 51 · Use with care ★ 28k 1d ago NOASSERTION
cmux Shared Behavior Rules 48 · Use with care ★ 28k 1d ago NOASSERTION

The source does not compare this skill to any direct alternative. The cmux application itself is compared to tmux in the README (tmux is a multiplexer running inside any terminal; cmux is a native macOS app with vertical tabs, an embedded browser, and a socket API), but that is a product-level comparison, not relevant to this internal coding-policy skill.

How did FollowSkills review this skill?

FollowSkills review · FSRS-2.0
Recommended
58/ 100 5-point scale 2.9 / 5
1Trust18 / 25 · 3.6/5

The skill contains no executable code; it declares policies only: telemetry off main thread by default, non-focus commands must not steal app focus, remote relay denies by default and requires security analysis plus policy tests (GHSA-9vmv-3hjw-j28c). Data-flow disclosure is clear and least-privilege is explicit. Deducted for: unverified publisher and NOASSERTION repo-level license metadata; the skill itself does not state its license or attribution.

2Reliability9 / 20 · 2.3/5

SKILL.md and both references are internally consistent, with concrete trigger conditions, an explicit focus-intent allowlist, and named defaults (defaultFocusForUserOpen, --focus/--no-focus) and test paths. Static review cannot execute anything; whether the cited test suites actually cover key paths was not reproduced — deducted.

3Adaptability10 / 15 · 3.3/5

Audience (developers/agents adding or changing cmux socket, CLI, telemetry, or focus behavior) and invocation timing are precisely described; the boundary (cmux-repo contribution only) is clear. Deducted for: extremely narrow scope, no explicit non-fit statement for other projects, English-only documentation.

4Convention9 / 15 · 3.0/5

Good layering: SKILL.md as main layer, references for progressive disclosure, agents/openai.yaml interface metadata, and a CI review-bot rule enforcing the relay policy. Deducted for: no version or changelog in the skill, NOASSERTION license metadata, and maintenance/update responsibility resting on repo-level context rather than the skill itself.

5Effectiveness7 / 15 · 2.3/5

As a coding-policy guide it directly constrains agent behavior, preventing focus stealing and main-thread deadlocks — clear marginal value over letting an agent guess. Deducted for: static review cannot verify actual agent compliance, output is behavioral constraint rather than a directly usable artifact, and comparative-benefit evidence is limited.

6Verifiability5 / 10 · 2.5/5

Citations are auditable: a concrete GHSA id, concrete source and test paths (RemoteCLIRelayPolicyTests, CmuxRemoteWorkspace/Relay/), and a review-bot rule file. All are author claims; static review could not independently reproduce the policy implementation or test coverage — deducted.

1 2 3 4 5 6

Open a dimension to read why it scored that way

Reviewed Oct 10, 2026 Reviewed revision 3dd1fe78859f Review evidence[1][2][3][4][5][6][7][8][9][10][11][12][13]

Evidence confidence:Low — Mostly static review, author material or a limited demo; useful for discovery, not high-risk decisions.

See the full review method →

FAQ

Does this skill help me use the cmux terminal day to day?
No. It is a coding policy for agents and contributors modifying the cmux codebase. For daily use, see the cmux CLI docs and the other skills in the cmux-skills collection.
Why do open commands sometimes take focus and sometimes not?
Per this policy, open commands focus when run interactively and stay in the background when run by an agent or script (defaultFocusForUserOpen). Use --focus to force focus, --no-focus to force background; socket methods default focus to false.
Can I allowlist a v2 method for remote relay?
Yes, but RemoteRelayCommandPolicy denies all methods by default. Allowlisting requires the security analysis and policy tests described in references/remote-relay-authorization.md.
Why can't telemetry commands run synchronously on the main thread?
report_*, ports_kick, and status/progress/log-metadata updates are high-frequency hot paths; DispatchQueue.main.sync would block the AppKit main thread and cause stalls. The policy requires parsing, validation, dedup, and coalescing off-main, with only minimal UI/model mutation via DispatchQueue.main.async when needed.

More skills from this repository

All from manaflow-ai/cmux

Dev & Engineering

cmux Workspace Skill

Lets an AI coding agent work safely inside the cmux workspace that invoked it, without disturbing the workspace or window the user is actually looking at.

★ 28k FS 64 Recommended 1d ago
Dev & Engineering

cmux-browser: Browser Automation Skill for cmux

Open sites, inspect browser surfaces, wait for page state, and extract data through the cmux CLI without stealing focus — built for parallel AI coding agent workflows.

★ 28k FS 60 Recommended 1d ago
Dev & Engineering

cmux Diagnostics

Collects support-safe, read-only diagnostics for cmux so you can pinpoint failing hooks, notifications, session restore, and CLI control without leaking secrets.

★ 28k FS 51 Use with care 1d ago
Dev & Engineering

cmux Shared Behavior Rules

Codifies one shared implementation and verification path for cmux behaviors exposed through multiple entrypoints, so fixes never land on one surface and leave others stale.

★ 28k FS 48 Use with care 1d ago
Dev & Engineering

cmux Testing Skill

Pick the right scoped local/CI verification for the cmux repo, add behavior-grounded tests, and keep Swift test targets correctly wired in the Xcode project.

★ 28k FS 60 Recommended 1d ago
Dev & Engineering

cmux Keyboard Shortcuts

Turns your key preferences into working cmux shortcut bindings, with templates, snapshots, and rollback instead of blind JSON edits.

★ 28k FS 58 Recommended 1d ago
Dev & Engineering

cmux Settings Management Skill (cmux-settings)

Safely view, edit, and roll back cmux's cmux. configuration with hot reload — changes apply on save, no app restart.

★ 28k FS 58 Recommended 1d ago
Dev & Engineering

cmux Customization

A skill for safely customizing the cmux terminal: edit cmux., Dock config and Ghostty preferences to tailor actions, layouts, shortcuts and notifications without breaking existing config.

★ 28k FS 55 Use with care 1d ago
Dev & Engineering

cmux Dev Workflow Skill

A standardized contributor workflow for cmux: tagged native builds, Xcode project normalization, and sidebar extensions — without disturbing a running cmux instance.

★ 28k FS 53 Use with care 1d ago
Productivity & Collaboration

cmux Markdown Viewer

Opens .md files in a formatted panel beside your cmux terminal with live reload, keeping plans, docs, and notes visible as they change.

★ 28k FS 52 Use with care 1d ago
Automation & Ops

cmux Computer Use Skill

Lets AI coding agents inside cmux drive real macOS apps through a local computer-use engine, strictly on explicit user request.

★ 28k FS 50 Use with care 1d ago
Dev & Engineering

cmux Custom Sidebar

Turn a plain-language request into a hot-reloading custom cmux sidebar — no Xcode, no build step, no signing.

★ 28k FS 50 Use with care 1d ago
Automation & Ops

cmux Cloud VM Skill

Lets an AI agent operate cmux Cloud machines through the cmux CLI: run durable remote commands and coding agents on persistent terminals, then present verified results to the user.

★ 28k FS 56 Use with care 1d ago
Dev & Engineering

cmux Architecture Skill

Load cmux's package architecture, layering, dependency inversion, and Swift 6 concurrency rules before adding or heavily rewriting Swift files, packages, coordinators, services, or public APIs in the cmux repository.

★ 28k FS 63 Recommended 1d ago
Dev & Engineering

cmux-capture: Screenshot and Record cmux Windows

Capture screenshots or recordings of a cmux window from the CLI to supply real evidence for PRs, bug reports, and visual verification — with no screen recording permission required.

★ 28k FS 55 Use with care 1d ago
Dev & Engineering

cmux Core Control

Deterministically control cmux terminal topology — windows, workspaces, panes, surfaces, focus, and attention cues — via the cmux CLI, built for AI coding agent automation.

★ 28k FS 47 Use with care 1d ago
Dev & Engineering

cmux Debugging Skill

Gives AI agents the project-specific debugging conventions for cmux — a Ghostty-based macOS terminal — so probes, profiling, and UI changes never break typing latency or live agent sessions.

★ 28k FS 56 Use with care 1d ago
Dev & Engineering

cmux Localization Rules & Audit Skill

Enforces localization rules and a verifiable audit workflow for every cmux user-facing string change, so no hardcoded English text ever lands.

★ 28k FS 56 Use with care 1d ago
Dev & Engineering

cmux Ghostty Submodule Workflow Skill

Standardizes Ghostty submodule commits, GhosttyKit.xcframework rebuilds, and parent pointer updates for cmux contributors, preventing dangling submodule pointers that break CI and checkouts.

★ 28k FS 54 Use with care 1d ago
Dev & Engineering

cmux Release Skill

A release-workflow skill for cmux maintainers covering version bumps, changelog assembly, pretag guard, tagging, and release asset verification.

★ 28k FS 53 Use with care 1d ago

Related skills