Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsCommunityBlog
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

Back to skills

Hq Cowork Cli

ASecurity

Run long-tail HQ CLI commands through guarded host-side Cowork tools.

85 stars
0 votes
0 copies
1 views
Added 9/19/2026
toolsgoshell

Works with

climcp

Security Analysis

A100/100

Scanned 9/19/2026

Install to Claude Code

$npx -y skills add indigoai-us/hq-core --skill hq-cowork-cli --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Hq Cowork Cli?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Hq Cowork Cli
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/indigoai-us-hq-cowork-cli/badge)](https://www.skillsdirectory.com/skills/indigoai-us-hq-cowork-cli)

More formats (shields.io, HTML) on the badges page.

Download Zip
Files
SKILL.md
---
name: hq-cowork-cli
description: Run long-tail HQ CLI commands through guarded host-side Cowork tools.
allowed-tools: mcp__hq__hq_cli, mcp__hq__hq_run, mcp__hq__hq_whoami
---

# /hq-cowork-cli — Long-tail HQ from Cowork

Use this when Cowork needs an HQ capability that does not have a dedicated
`hq-cowork-*` skill yet.

Prefer dedicated tools first:

- Search: `/hq-cowork-search`
- Sync: `/hq-cowork-sync`
- Files/share: `/hq-cowork-files`, `/hq-cowork-share`
- Secrets: `/hq-cowork-secrets`
- Meetings/sources/signals: `/hq-cowork-meetings`

## `mcp__hq__hq_cli`

Runs `hq <args...>` on the host. Pass argv, not a shell string.

```json
{
  "args": ["sync", "status"],
  "cwd": ".",
  "timeoutMs": 60000
}
```

The tool blocks:

- `hq login`, `hq logout`, `hq onboard`
- browser/session auth flows other than `hq auth status` and `hq auth refresh`
- secret-value output (`hq secrets env`, `hq secrets get --reveal`)
- raw `hq secrets set|exec` and `hq run` through the escape hatch

Use `mcp__hq__hq_run` for `hq run`.

## `mcp__hq__hq_run`

Runs schema-driven commands with HQ secrets injected via `.env.schema`.
Secret values stay in the child process env; only command output returns.

```json
{
  "cwd": "repos/private/example-app",
  "company": "indigo",
  "schema": ".env.schema",
  "cmd": ["npm", "test"],
  "timeoutMs": 120000
}
```

For validation only:

```json
{
  "cwd": "repos/private/example-app",
  "check": true
}
```

## Rules

- Never ask the user to paste secrets inline.
- Never use the escape hatch for secret-value retrieval.
- Keep `cwd` inside the HQ root. The MCP server enforces this.
- For destructive or cloud-provisioning commands, explain the concrete effect before calling the tool.

Attribution

indigoai-usindigoai-us
View sourceMore from indigoai-us →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

ucoz-landing-skill

Playbook for creating and editing uCoz landing pages via MCP tools (`templates_tool`, `ftp_tool`, `modules_tool`). Use for tasks such as: "build a landing page", "update the homepage as a landing page", "create a promo page on the homepage", "add a lead form / menu / SEO to the homepage". Homepage: `page_list`, `page_get`; first publish — `page_update` with full `page_tmpl`; HTML edits after generation — `patch_template` (module_id=2, template_id=1), not `update_template`. Activate the mail f...

107 votes

Paperclip

Interact with the Paperclip control plane API for task coordination and governance. Use when checking assignments, updating issue status, posting comments, delegating work, managing routines, or calling Paperclip API endpoints.

805541 votes

Daw Music

Digital Audio Workstation usage, music composition, interactive music systems, and game audio implementation for immersive soundscapes.

761 votes

Instantly Rdsthomas Mission Control

Instantly.ai cold email outreach API - manage campaigns, leads, accounts, and analytics. Use for cold email automation, lead management, campaign creation/monitoring, and email account warmup.

761 votes

Caveman Compress

Compress natural language memory files (CLAUDE.md, todos, preferences) into caveman format to save input tokens. Preserves all technical substance, code, URLs, and structure. Compressed version overwrites the original file. Human-readable backup saved as FILE.original.md. Trigger: /caveman-compress FILEPATH or "compress memory file"

1066600 votes
View all in tools →