riffpad

Prüfen · 65
Im Registry indexiert

Control AI coding agents (Claude Code, Codex, Kimi) from your phone via Riffpad. Use when the user wants to watch, approve, or steer a coding agent remotely / set up Riffpad / pair their phone / keep a long-running agent session going while away from the computer.

Verified installs0
Stars126
Version1.0.0
Qualität68/100 · Vielversprechend
Vertrauen65/100 · Nur Sandbox
Audit78/100 · Riskant

Asset-Profil

Coding- und Entwickler-Agents

Code review, repo analysis, testing, CI, GitHub, DevOps, and developer workflow skills.

Bereich ansehen

Szenario

Coding-Agents

I need a coding agent that can understand a repository, edit code, and review pull requests.

Agent-Fit

Claude Code + OpenAI Agents + Browser agents

Geeignet für Codex, Claude Code, Cursor, CLI oder benutzerdefinierte Agents.

Installieren

Bereit

npx skills add riffpad/riffpad --skill riffpad

Wartung

Aktuell

Heute gepusht

Risiko

Riskant

Dependency or permission surface needs review

GitHub-Qualität

126

68/100 Qualität · 73/100 Vertrauen

Abdeckungs-Tags

CodingCoding-AgentsCoding-Agentsagent-skill

Review-Notizen

Dependency or permission surface needs review · Permission surface may require sandboxing

Agent-Adoptionskarte

Vertrauen, Audit und Installationsbereitschaft auf einen Blick

Diese Werte kombinieren öffentliche Repository-Metadaten, OpenAgentSkill-Reviewsignale, Wartungsaktualität und Installationsbereitschaft. Sie helfen bei der Vorauswahl, ersetzen aber keine menschliche Prüfung.

Qualität

Vielversprechend
68

Useful candidate, but compare it with alternatives before adopting.

Vertrauen

Nur Sandbox
65

Nützlicher Kandidat mit fehlenden oder gemischten Vertrauenssignalen. Bis der Ergebniszyklus die Passung belegt, in einem isolierten Arbeitsbereich verwenden.

Audit

Riskant
78

Maschinenlesbare Prüfung von Installationsbereitschaft, Sicherheitsmetadaten, Wartung und Akzeptanzrisiko.

OpenAgentSkill Trust Score v5

Nur Sandbox

Nur in einer Sandbox ausführen und nahe Alternativen vergleichen, bevor sie produktiv eingesetzt wird.

CodexClaude CodeCursorOpenAgentSkill CLI

Stars

126 GitHub-Stars

Repository-Aktivität

126 Stars und 31 Forks

Wartung

Heute gepusht

Lizenz

Apache-2.0

Installieren

npx skills add riffpad/riffpad --skill riffpad

Installationssicherheit

Standard-Paket- oder Laufzeit-Installationspfad

Berechtigungsfläche

secrets or environment access, shell or command execution

Agent-Ergebnisse

Noch keine Agent-Ergebnisdaten

Dokumentation

Starker README/SKILL.md-Kontext

Risikoübersicht

Vor Produktion prüfen

  • Financial research output is not financial advice; require human review before any live investment decision.
  • This skill may touch real-money trading, broker, wallet, or exchange operations; use only in a sandbox with explicit approval.
  • Quality score needs review
  • Permission surface needs review: secrets or environment access, shell or command execution

Installationsbereitschaft

Installationspfad verfügbar

  • Installationspfad ist verfügbar
  • Repository-Belege sind verfügbar
  • Lizenz ist angegeben
  • Noch keine Agent-Proven-Ergebnisbelege

Agent-lesbare Metadaten

Maschinenlesbare Entscheidungsdaten für diesen Skill.

Nutze diesen Block oder das eingebettete JSON, um zu entscheiden, ob ein Agent diesen Skill installieren, eine Alternative wählen oder zuerst menschliche Prüfung anfordern soll.

JSON öffnen

Geeignete Aufgaben

  • Local desktop-Workflows
  • Claude-Code-Teams
  • builders willing to evaluate younger projects
  • Navigate local resources

Geeignete Agents

CodexClaude CodeCursorOpenAgentSkill CLIOpenAI AgentsBrowser agentsCLI

Installationsentscheidung

Befehl
npx skills add riffpad/riffpad --skill riffpad
Richtlinie
Blockieren
Menschliche Prüfung
Ja

Vertrauen und Risiko

Vertrauen
65/100
Audit
78/100
Risikoebene
Riskant

Ergebnis-Loop

Endpoint
/api/agent/outcome
Event-ID
resolve
Ergebnisse
5

Installationsbefehl

npx skills add riffpad/riffpad --skill riffpad

Nicht verwenden, wenn

  • Teams, die ein vom Anbieter unterstütztes SLA benötigen
  • Hochregulierte Umgebungen ohne interne Sicherheitsprüfung
  • No OpenAgentSkill engagement data yet
  • Audit risk risky exceeds max_risk=medium
  • Hinweise auf Hochrisiko-Berechtigungen: Shell or command execution, Secrets or environment access

Agent-Sicherheit v2

34/100 · Automatische Installation vermeiden

Blocked for auto-installBlockieren

This skill should not be selected by an agent without explicit human security review.

Do not auto-install. Inspect the source, dependencies, and permission surface first.

Per API auflösen

Hoch

Shell- oder Befehlsausführung

Die Skill-Metadaten verweisen auf Terminal-, CLI-, Shell-, Subprozess- oder Befehlsausführungs-Workflows.

Mittel

Browser automation

Skill may drive a browser or interact with web pages.

Mittel

Netzwerkzugriff

Die Skill ruft wahrscheinlich Remote-Seiten, APIs, Repositories oder externe Dienste ab.

Mittel

Dateisystemzugriff

Die Skill kann Projektdateien, Dokumente, generierte Artefakte oder den lokalen Arbeitsbereich lesen oder schreiben.

  • Audit risk risky exceeds max_risk=medium
  • Hinweise auf Hochrisiko-Berechtigungen: Shell or command execution, Secrets or environment access
  • Dependency or permission surface needs review

Installationsziele

Diesen Skill im Agent-Workflow installieren

Über den öffentlichen Endpunkt erhältst du Befehl, Sicherheitscheckliste, Ziel-Prompts und kanonische Links.

skill install

OpenAgentSkill CLI

Resolve policy, run the source installer safely, and report a verified install receipt.

$ npx --yes https://github.com/Leon-Drq/openagentskill/releases/download/cli-v0.2.1/openagentskill-0.2.1.tgz install riffpad-riffpad

Agent-Auflösungsplan

Lass einen Agent die Eignung vor der Installation prüfen.

Die Resolve API liefert die beste Skill, Alternativen, Sicherheitsrichtlinien, Auditnotizen, Installationsziel und einen direkt nutzbaren Prompt.

Textplan öffnen

Agent sollte prüfen

  • Task fit and alternatives from Resolve API.
  • Audit score, trust score, and safety policy warnings.
  • Install target compatibility for Codex, Claude Code, Cursor, or CLI.

Prompt kopieren

Task: Use riffpad in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20riffpad%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/riffpad-riffpad/install
Install command: npx skills add riffpad/riffpad --skill riffpad
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.

Agent-Übergabe

Gib dem Agent den Installationspfad, nicht noch ein Verzeichnis.

Über den öffentlichen Endpunkt erhältst du Befehl, Sicherheitscheckliste, Ziel-Prompts und kanonische Links.

Installations-API öffnen

Agent-Prompt

Use riffpad for this task. Review https://www.openagentskill.com/api/skills/riffpad-riffpad/install, then install with: npx skills add riffpad/riffpad --skill riffpad

Registry-Metadaten

Agent-lesbares Profil für die automatische Skill-Auswahl.

Die Registry API stellt Entscheidungs-, Vertrauens-, Audit-, Use-Case- und Installationssignale ohne UI-Scraping bereit.

Manifest öffnen

Agent-Fit

67/100

Local desktop

Plattformen

Claude Code, OpenAI Agents, Browser agents

Audit-Bericht

Riskant · 78/100

Maschinenlesbare Prüfung von Installationsbereitschaft, Sicherheitsmetadaten, Wartung und Akzeptanzrisiko.

Audit-Bericht ansehenEval-Bericht ansehen

Agent-Entscheidungspanel

Fallback candidate for Local desktop

Prototype with this skill first; keep a fallback candidate ready.

67
Bereitschaft
Prototyp
Phase

Rolle im Stack

Fallback-Kandidat

Primäre Eignung

Local desktop

Vertrauenslabel

Zuerst prototypisieren

Installationspfad

Befehl bereit

Verwenden wenn

  • Local desktop-Workflows
  • Claude-Code-Teams
  • builders willing to evaluate younger projects

Evidenz

  • recent repository activity
  • install command or GitHub repo available
  • Qualitätsprofil 68/100

zuerst prüfen

  • No OpenAgentSkill engagement data yet

Implementierungspfad

  1. 1Installieren Sie es in einem Sandbox-Agent und führen Sie eine Local desktop-Aufgabe vollständig aus.
  2. 2Compare output quality, latency, and failure behavior against at least one alternative.
  3. 3Promote it into production only after reviewing repository permissions, license, and maintenance signals.

Vertrauensprofil

Nur Sandbox

Nützlicher Kandidat mit fehlenden oder gemischten Vertrauenssignalen. Bis der Ergebniszyklus die Passung belegt, in einem isolierten Arbeitsbereich verwenden.

65
OpenAgentSkill Trust Score

GitHub-Akzeptanz

Info

126 GitHub-Stars

Star-/Fork-Aktivität

Prüfen

126 Stars und 31 Forks; Issue-Aktivität ist in den aktuellen Metadaten nicht verfügbar

Aktuelle Wartung

Bestanden

Heute gepusht

Lizenzklarheit

Bestanden

Apache-2.0

Positive Signale

  • KI-Prüfung genehmigt
  • Installationspfad ist verfügbar
  • Repository-Belege sind verfügbar
  • Kürzlich gewartetes Repository
  • Der Installationsbefehl weist kein offensichtliches Hochrisikomuster auf
  • Ergebniszyklus ist bereit, benötigt aber den ersten echten Agent-Lauf

Vor Installation prüfen

  • Financial research output is not financial advice; require human review before any live investment decision.
  • This skill may touch real-money trading, broker, wallet, or exchange operations; use only in a sandbox with explicit approval.
  • Quality score needs review
  • Permission surface needs review: secrets or environment access, shell or command execution
  • Stars/forks activity: 126 stars, 31 forks; issue activity unavailable in current metadata
  • Dependency/runtime risk: command execution surface, credential or environment access
  • Permission surface: secrets or environment access, shell or command execution
  • Noch keine echten Agent-Ergebnisberichte
  • Vor unbeaufsichtigter Installation ist menschliche Prüfung erforderlich

Empfohlene Aktion

Nur in einer Sandbox ausführen und nahe Alternativen vergleichen, bevor sie produktiv eingesetzt wird.

Qualitätsprofil

Vielversprechend Kandidat für Agent-Workflows

Useful candidate, but compare it with alternatives before adopting.

68
GitHub-Stars
126
Aktualität
Heute
Installationsbereit
Ja
Lizenz
Apache-2.0

Workflow-Eignung

Diese Skill in diesen Szenarien nutzen

Workflow-Eignung

Zum vollständigen Workflow hinzufügen

Alternativen-Shortlist

Vor Installation vergleichen

Similar skills that may fit this task.

Alle vergleichen

Übersicht

--- name: riffpad description: Control AI coding agents (Claude Code, Codex, Kimi) from your phone via Riffpad. Use when the user wants to watch, approve, or steer a coding agent remotely / set up Riffpad / pair their phone / keep a long-running agent session going while away from the computer. ---

# riffpad

Watch, approve, and steer AI coding agents (Claude Code, Codex, Kimi) from your phone. A local daemon bridges the CLI agents running on the user's own machine to their phone, end-to-end encrypted through a zero-knowledge relay. **Not a cloud IDE** — agents keep running on the user's machine with their own API keys and repos; the phone is just a mirror + remote control.

## Install

If `riffpad` is not installed:

```bash # macOS / Linux curl -fsSL https://riffpad.ai/install.sh | sh

# Windows (PowerShell) irm https://riffpad.ai/install.ps1 | iex ```

Verify with `riffpad version`. If still not found after install, open a new terminal.

---

## Onboarding flow (run these in order)

1. **Install** the daemon (above), then `riffpad version` to confirm. 2. **Sign in on the computer**: `riffpad login` - Opens a browser for GitHub authorization (like `gh auth login`). The **user** completes it in the browser; the daemon registers this machine and restarts automatically. - Non-GitHub / password login: set `RIFFPAD_RELAY_USER` + `RIFFPAD_RELAY_PASSWORD`, then `riffpad login --username`. 3. **Pair the phone**: `riffpad pair` - Prints a 6-char code + QR. **The user** must open https://app.riffpad.ai on their phone, sign in with the same account, and enter the code (or scan the QR). You can't complete this step for them — tell them what to do. 4. **Start a session**: `riffpad run codex` (or `claude` / `kimi`) - The terminal stays visible and interactive. The session mirrors to the phone immediately; the user can watch progress, approve permission prompts, and send new instructions from the phone.

> To capture a Claude session the user **already started themselves** (instead of launching a new one), use `riffpad attach` (injects Claude hooks) — not `run`.

---

## CLI reference

| Command | Description | |---|---| | `riffpad login [--url wss://…]` | GitHub device sign-in (default); `--username` for password login | | `riffpad logout` | Sign out and revoke the relay token | | `riffpad auth` | Show the current account (live validation) | | `riffpad pair` | Print a 6-char pairing code and QR | | `riffpad run [claude\|codex\|kimi] [--name N] [--prompt P] [--cwd D]` | Create a hosted session; terminal stays visible/interactive | | `riffpad attach` / `detach` | Inject/remove Claude hooks to capture the user's own running session | | `riffpad sessions` | List sessions | | `riffpad status` | Daemon status | | `riffpad setup [--remove]` | Install/remove the Linux systemd autostart | | `riffpad kill` | Kill switch — stop all sessions + revoke all paired devices | | `riffpad update` | Replace with the latest version (SHA256 + atomic swap) | | `riffpad logs` | Show daemon logs | | `riffpad version` | Print the version |

### `run` options - `--name N` — label the session - `--prompt P` — start with an initial prompt - `--cwd D` — set the working directory

### Languages Output defaults to English. Use `--lang zh` to switch to Chinese; `--lang en` explicitly selects English.

### Environment variables | Variable | Default | Purpose | |---|---|---| | `RIFFPAD_RELAY_URL` | `wss://api.riffpad.ai` | Relay address (change to self-host) | | `RIFFPAD_RELAY_USER` / `RIFFPAD_RELAY_PASSWORD` | — | Password-login credentials | | `RIFFPAD_URL` | `http://127.0.0.1:8787` | Local daemon address | | `RIFFPAD_DIR` | `~/.config/riffpad` | Data directory |

---

## Self-host the relay (optional) The relay is the only server component, and it's zero-knowledge — it forwards ciphertext and stores nothing. To point Riffpad at your own relay, set `RIFFPAD_RELAY_URL` before `login`. Relay source + self-host notes: https://github.com/riffpad/riffpad (`apps/relay`).

---

## Common pitfalls

| Pitfall | Correct approach | |---|---| | Treating it like a cloud IDE | Agents run on the user's machine with their own keys; the phone only mirrors + sends approvals/instructions. Don't try to move the session to the cloud. | | Skipping pairing | `riffpad pair` must run, and the user must complete pairing on their phone at app.riffpad.ai. Without it, nothing reaches the phone. | | Using `run` for a session the user already started | Use `riffpad attach` (injects Claude hooks into an existing session), not `run` (which starts a new one). | | Approvals not showing on the phone | Confirm `riffpad status` is healthy and the phone is paired; check `riffpad logs`. | | `login` can't open a browser (headless) | Use `--username` with `RIFFPAD_RELAY_USER` / `RIFFPAD_RELAY_PASSWORD`. | | Need to stop everything immediately | `riffpad kill` — stops all sessions + revokes all paired devices (kill switch). |

---

## Notes - **Local-first**: code, repos, and API keys never leave the user's machine. - **End-to-end encrypted** (X25519 + AES-256-GCM); the relay is zero-knowledge. - **Read-only by default** on the phone — every approve/reject/prompt is an explicit tap. - Docs: https://www.riffpad.ai/docs/guide/quickstart · Repo: https://github.com/riffpad/riffpad · App: https://app.riffpad.ai

Technische Details

Version
1.0.0
Lizenz
Apache-2.0
Letzte Aktualisierung
23. Aug. 2026
Veröffentlicht
23. Aug. 2026

Entscheidungsübersicht

Fallback-Kandidat

67
Bereit
Prototyp
Phase

recent repository activity

Audit

Installationsprüfung

Installations- und Adoptionsprüfung

78
Riskant
Sicherheit
76/100
Wartung
100/100
Installieren
92/100
Vollständiges Audit öffnenEval-Bericht ansehen

Von Agent belegte Evidenz

Von Agent belegte Evidenz

Ergebnisberichte nach Resolve, Prüfung, Installation und einem begrenzten Lauf.

0
Belegt
Needs first agent runAuto-Installation: zuerst prüfenLetzter: Unbekannt
Erfolgsrate
Letzter Fehler
Ergebnisse
0
Ausgabequalität
Fehlgeschlagen
0
Nicht relevant
0
Installationen
0
Durch Risiko blockiert
0
Einrichtung erforderlich
0
Produktion
0

Noch keine Agent-Ergebnisdaten. Der erste Lauf kann Erfolg, Einrichtungsbedarf, Risikoblockaden, Fehler oder Irrelevanz über /api/agent/outcome melden.

Installieren

Zum Agent-Workflow hinzufügen

Kostenlos und Open Source. Bericht vor der Installation in Produktions-Agents prüfen.

Wachstums-Loop

Share-Kit

X

Szenariobasierter Entwurf für riffpad, bereit für einen manuellen X-Post.

Kuratorenhinweis
riffpad: Control AI coding agents (Claude Code, Codex, Kimi) from your phone via Riffpad. Use when the...

126 stars

https://www.openagentskill.com/skills/riffpad-riffpad?ref=x
X-Entwurf öffnen
Optionale Antwort mit Installationsbefehl
Listing + install path for riffpad:
https://www.openagentskill.com/skills/riffpad-riffpad?ref=x

Install: npx skills add riffpad/riffpad --skill riffpad
Antwortentwurf öffnen

Quelle des Eintrags

Registry-indexiert

Beanspruchbar

Dieser Eintrag wurde aus öffentlichen Quellen indexiert und ist erst nach Genehmigung eines Maintainer-Anspruchs offiziell.

Ersteller
riffpad
Indexiert von
OpenAgentSkill Community-Index

Die Zuordnung verlinkt auf das öffentliche Repository oder Creator-Profil. Creator können den Eintrag beanspruchen, um Eigentümersignale zu aktualisieren.

Diesen Skill beanspruchen

Eigentümeranspruch

Diesen Skill-Eintrag beanspruchen

Dieser Registry-indexiert-Eintrag wird riffpad zugeschrieben, ist aber noch nicht offiziell markiert. Beanspruche ihn, um ein verifiziertes Eigentümersignal hinzuzufügen und künftige Launch-, Installations- und Audit-Updates vertrauenswürdiger zu machen.

Creator-Backlink-Kit

Evidenz-Badges in deine README einfügen

Zeige den kanonischen Eintrag, aktuelle Vertrauens- und Audit-Signale sowie echte Agent-Proven-Evidenz dort, wo Entwickler das Repository bewerten.

[![Listed on OpenAgentSkill](https://www.openagentskill.com/api/badge/riffpad-riffpad?metric=listed&label=Listed)](https://www.openagentskill.com/skills/riffpad-riffpad)
[![OpenAgentSkill Trust](https://www.openagentskill.com/api/badge/riffpad-riffpad?metric=trust&label=Trust)](https://www.openagentskill.com/skills/riffpad-riffpad)
[![OpenAgentSkill Audit](https://www.openagentskill.com/api/badge/riffpad-riffpad?metric=audit&label=Audit)](https://www.openagentskill.com/skills/riffpad-riffpad/audit)
[![Agent Proven](https://www.openagentskill.com/api/badge/riffpad-riffpad?metric=proven&label=Agent%20Proven)](https://www.openagentskill.com/skills/riffpad-riffpad)

Autor

R

riffpad

@riffpad

Gesundheitssignale

GitHub-Stars
126
Qualitätswert
38/100
Letzter GitHub-Push
23. Aug. 2026
Framework-Hinweise
Unbekannt
OpenAgentSkill-Aufrufe
0
Installationskopien
0
Externe Klicks
0

Community-Signal

Teile mit, ob dieser Skill für deinen Agent-Workflow nützlich ist. Zusammengefasstes Feedback verbessert das Ranking im Laufe der Zeit.

Vertrauen & Sicherheit

Nur Sandbox

65
  • GitHub-Akzeptanz126 GitHub-StarsInfo
  • Star-/Fork-Aktivität126 Stars und 31 Forks; Issue-Aktivität ist in den aktuellen Metadaten nicht verfügbarPrüfen
  • Aktuelle WartungHeute gepushtBestanden
  • LizenzklarheitApache-2.0Bestanden
  • README/SKILL.md-VollständigkeitMetadaten enthalten ausreichend Nutzungs- und Workflow-KontextBestanden
  • Abhängigkeits-/Laufzeitrisikocommand execution surface, credential or environment accessPrüfen