Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsCommunityBlog
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

Back to skills

Hq Cowork Share

ASecurity

Share HQ vault paths from Cowork through links or direct grants.

85 stars
0 votes
0 copies
1 views
Added 9/19/2026
toolsshell

Works with

claude codeclimcp

Security Analysis

A100/100

Scanned 9/19/2026

Install to Claude Code

$npx -y skills add indigoai-us/hq-core --skill hq-cowork-share --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Hq Cowork Share?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Hq Cowork Share
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/indigoai-us-hq-cowork-share/badge)](https://www.skillsdirectory.com/skills/indigoai-us-hq-cowork-share)

More formats (shields.io, HTML) on the badges page.

Download Zip
Files
SKILL.md
---
name: hq-cowork-share
description: Share HQ vault paths from Cowork through links or direct grants.
allowed-tools: mcp__hq__hq_share
---

# /hq-cowork-share — Share an HQ vault path from a sandboxed agent

Mints share-session URLs and grants ACLs on HQ vault paths from inside
Cowork (or any sandboxed Claude Code plugin host). Equivalent to the
unprefixed `/hq-share` skill, but routed through the host-side MCP server
because the sandboxed agent cannot run the `hq` CLI directly.

**Args:** `$ARGUMENTS` — required path + optional flags.

| Arg | Meaning |
|---|---|
| `<path>` (positional) | Vault path or prefix to share (e.g. `companies/foo/knowledge/x.md`). Required. |
| `--with <principal>` | Email, group id, or `@all`. Omit to mint a share-session URL instead. |
| `--permission read\|write` | Permission level (only meaningful with `--with`). |
| `--expires 15m\|1h\|24h` | Token expiry for share-session URL (default 15m, max 24h). |

## When to use this instead of `/hq-share`

- **You're in Cowork or another sandboxed plugin host** — the regular
  `/hq-share` skill shells out to `hq files share` on the host, which isn't
  reachable from the sandbox.
- **You want the MCP tool-call surface** — observable in the host's tool log.

On a normal host-side Claude Code session, prefer the unprefixed `/hq-share`.

## What you do

### Step 1 — Parse args

Extract the positional `<path>` and any optional flags. Without a path,
ask the user which vault prefix to share.

### Step 2 — Call the tool

Call `mcp__hq__hq_share` with:

```json
{
  "path": "<path>",
  "with": "<principal>",          // omit if not set
  "permission": "read|write",     // omit if not set
  "expires": "15m|1h|24h"         // omit to use default 15m
}
```

### Step 3 — Surface output

The minting turn is the ONE surface where the unredacted share-session URL
is permitted in chat. Print it as a clickable markdown link so the user can
copy it.

**Hard rule (carried over from `core/policies/hq-share-session-urls-are-capabilities.md`):**
After this turn, NEVER paste the URL back into later turns, summaries,
journals, handoffs, commits, PRs, Slack/email, or any persisted context.
Refer to it as `https://hq.{co}.com/share-session/<TOKEN_REDACTED>` from
then on. The token IS a capability — anyone who holds it can use the share.

If `--with` was used (direct grant, not URL), there's no token to print —
just confirm the grant landed and surface any error from the tool.

## Why this skill exists

`hq files share` runs on the host with the user's Cognito session and the
local sync index — neither of which is visible from inside Cowork's Linux
VM. The host-side MCP server in `hq-pack-cowork` runs the real `hq files
share`, then returns its output back to the sandboxed agent. This skill is
the in-session adapter.

Attribution

indigoai-usindigoai-us
View sourceMore from indigoai-us →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

ucoz-landing-skill

Playbook for creating and editing uCoz landing pages via MCP tools (`templates_tool`, `ftp_tool`, `modules_tool`). Use for tasks such as: "build a landing page", "update the homepage as a landing page", "create a promo page on the homepage", "add a lead form / menu / SEO to the homepage". Homepage: `page_list`, `page_get`; first publish — `page_update` with full `page_tmpl`; HTML edits after generation — `patch_template` (module_id=2, template_id=1), not `update_template`. Activate the mail f...

107 votes

Paperclip

Interact with the Paperclip control plane API for task coordination and governance. Use when checking assignments, updating issue status, posting comments, delegating work, managing routines, or calling Paperclip API endpoints.

805541 votes

Daw Music

Digital Audio Workstation usage, music composition, interactive music systems, and game audio implementation for immersive soundscapes.

761 votes

Instantly Rdsthomas Mission Control

Instantly.ai cold email outreach API - manage campaigns, leads, accounts, and analytics. Use for cold email automation, lead management, campaign creation/monitoring, and email account warmup.

761 votes

Caveman Compress

Compress natural language memory files (CLAUDE.md, todos, preferences) into caveman format to save input tokens. Preserves all technical substance, code, URLs, and structure. Compressed version overwrites the original file. Human-readable backup saved as FILE.original.md. Trigger: /caveman-compress FILEPATH or "compress memory file"

1066600 votes
View all in tools →