Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsCommunityBlog
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

Back to skills

Hq Cowork Files

ASecurity

Browse or read HQ vault files from Cowork without a full sync.

85 stars
0 votes
0 copies
1 views
Added 9/19/2026
tools

Works with

climcp

Security Analysis

A100/100

Scanned 9/19/2026

Install to Claude Code

$npx -y skills add indigoai-us/hq-core --skill hq-cowork-files --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Hq Cowork Files?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Hq Cowork Files
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/indigoai-us-hq-cowork-files/badge)](https://www.skillsdirectory.com/skills/indigoai-us-hq-cowork-files)

More formats (shields.io, HTML) on the badges page.

Download Zip
Files
SKILL.md
---
name: hq-cowork-files
description: Browse or read HQ vault files from Cowork without a full sync.
allowed-tools: mcp__hq__hq_files
---

# /hq-cowork-files — Inspect HQ vault objects from a sandboxed agent

Reads vault objects on demand from inside Cowork, where the `hq` CLI and the
local sync index aren't reachable. Routes through the host-side MCP server.

**Args:** `$ARGUMENTS` — an action plus its target. Infer the action from
intent if not explicit.

| Action | Purpose | Needs |
|---|---|---|
| `browse` | List objects under a vault path | `path` optional (defaults to root) |
| `cat` | Stream one object to text | `path` required |
| `acl` | Show the access-control list for a prefix | `path` required |
| `search` | Match vault object keys by path/name (NOT content) | `query` (or `path`) required |
| `shared-with-me` | List grants made to you | — |
| `get` | Materialize a file/prefix into local HQ on the host | `path` required; `into` optional |

## Call the tool

```json
{
  "action": "cat",
  "path": "companies/foo/knowledge/x.md",
  "company": "<slug>",     // omit to parse from path
  "personal": false,
  "into": "<dir>"          // action=get only
}
```

Call `mcp__hq__hq_files`. For `search`, pass the query as `query` (or `path`).

## Notes

- **`search` matches keys, not content.** It's a path/name match over vault
  object keys — not full-text search. For content search use `/hq-cowork-search`
  (qmd), which is a different index.
- **`get` writes to the host's local HQ**, not into the sandbox. The
  sandboxed agent won't see the materialized files unless the mounted HQ
  folder is shared. Prefer `cat` to read content directly into the session.
- **Cross-company isolation.** `company` defaults to the slug parsed from the
  path; pass it explicitly when that's ambiguous. Never operate across a
  company boundary you weren't asked to.

## When to use this instead of `/hq-files`

Only inside Cowork or another sandboxed plugin host. On a host-side session,
prefer the unprefixed `/hq-files` (or `hq files`).

## Why this skill exists

`hq files` authenticates with the user's Cognito session under `~/.hq` and
reads the cloud vault — neither is visible from Cowork's Linux VM. The
host-side MCP server runs the real `hq files <action>` and returns output to
the sandboxed agent.

Attribution

indigoai-usindigoai-us
View sourceMore from indigoai-us →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

ucoz-landing-skill

Playbook for creating and editing uCoz landing pages via MCP tools (`templates_tool`, `ftp_tool`, `modules_tool`). Use for tasks such as: "build a landing page", "update the homepage as a landing page", "create a promo page on the homepage", "add a lead form / menu / SEO to the homepage". Homepage: `page_list`, `page_get`; first publish — `page_update` with full `page_tmpl`; HTML edits after generation — `patch_template` (module_id=2, template_id=1), not `update_template`. Activate the mail f...

107 votes

Paperclip

Interact with the Paperclip control plane API for task coordination and governance. Use when checking assignments, updating issue status, posting comments, delegating work, managing routines, or calling Paperclip API endpoints.

805541 votes

Daw Music

Digital Audio Workstation usage, music composition, interactive music systems, and game audio implementation for immersive soundscapes.

761 votes

Instantly Rdsthomas Mission Control

Instantly.ai cold email outreach API - manage campaigns, leads, accounts, and analytics. Use for cold email automation, lead management, campaign creation/monitoring, and email account warmup.

761 votes

Caveman Compress

Compress natural language memory files (CLAUDE.md, todos, preferences) into caveman format to save input tokens. Preserves all technical substance, code, URLs, and structure. Compressed version overwrites the original file. Human-readable backup saved as FILE.original.md. Trigger: /caveman-compress FILEPATH or "compress memory file"

1066600 votes
View all in tools →