Nasiko CLI Lifecycle Bridge

SkillDev tools

nasiko-control-plane is a skill that manages the Nasiko CLI lifecycle through ECC. It lets an agent check whether the CLI is present, install a pinned qualified version after user consent and a dry-run preview, and remove it if ECC owns the installed copy. It enforces checksum verification, refuses unapproved versions, and keeps secrets and telemetry under explicit boundarie

Available today. Use it from your connected AI after setup.

Have ECC available so the skill can run its ecc nasiko commands.

Then ask your AI: use the Nasiko CLI Lifecycle Bridge skill

What your AI can do with it

  • Run a read-only status check with ecc nasiko status --json
  • Preview an install with ecc nasiko install --version v0.1.0 --dry-run --json
  • Install the pinned qualified version v0.1.0 only after explicit user consent and --yes
  • Preview and perform ownership-checked uninstall of an ECC-managed binary
  • Verify pinned SHA-256 digests for artifacts and extracted binaries
  • Keep secrets out of arguments, logs, and state; treat telemetry as opt-in

Getting started

  1. Have ECC available so the skill can run its ecc nasiko commands.
  2. Add the nasiko-control-plane skill to your agent's skill set.
  3. Ask the agent to check Nasiko CLI status; this read-only call reports whether it is present.
  4. Review the dry-run preview showing version, registry origin, digest, and destination before approving an install.
  5. Confirm explicitly with --yes to install or uninstall; the agent will refuse unapproved versions or ambiguous states.

What this skill tells your AI

The instructions your AI receives, as published by affaan-m/ecc in skills/nasiko-control-plane/SKILL.md and read by ahel’s review.

Use this skill when a user explicitly asks ECC to install, inspect, or remove the qualified Nasiko CLI. This skill does not operate a Nasiko control plane.

Safety contract

  • Begin with ecc nasiko status --json. Status is read-only.
  • Installation always requires explicit user consent and --yes.
  • Install only an ECC-qualified pinned version, currently v0.1.0.
  • Preview first with ecc nasiko install --version v0.1.0 --dry-run --json.
  • Install with ecc nasiko install --version v0.1.0 --yes --json only after the user reviews the version, registry origin, digest, and destination.
  • Remove only a still-qualified ECC-managed binary with ecc nasiko uninstall --version v0.1.0 --yes --json. Preview removal with --dry-run first.
  • The qualified source is https://github.com/Nasiko-Labs/nasiko, licensed under Apache-2.0; artifact and extracted-binary SHA-256 values are pinned.
  • Never replace the qualified command with a downloaded shell or PowerShell bootstrap script.
  • Never put secrets or credentials in command arguments, logs, skill output, install metadata, or ECC state.
  • Nasiko telemetry and any sharing with Nasiko or Ito must be opt-in and separately disclosed. Installation is not telemetry consent.

Lifecycle boundary

The initial ECC bridge supports qualified installation, read-only status, and ownership-checked uninstall. Use the canonical Nasiko CLI directly for connection, authentication, launch, deployment, or shutdown until those verbs have their own verified ECC contracts. Do not guess CLI verbs.

Installing the CLI does not prove that a control-plane server is running, an agent is governed, routing or ACLs work, observability is complete, telemetry was enabled, or Ito compute is connected. Report each state separately.

Failure behavior

  • If the platform, architecture, version, manifest, digest, archive, binary, or destination fails validation, stop without executing the artifact.
  • Do not fall back to latest.
  • Do not search arbitrary PATH entries. Use ECC's qualified location or an explicit absolute ECC_NASIKO_CLI_EXECUTABLE for development verification.
  • Do not treat a partial or ambiguous installation as success.

Signals

GitHub stars
268k
Forks
40k
Last commit
Sep 2026

Questions

Does installing the CLI mean the control plane is running?
No. Installing does not prove a control-plane server is running, an agent is governed, routing or ACLs work, observability is complete, telemetry was enabled, or Ito compute is connected. Each state is reported separately.
Can it install other versions of the Nasiko CLI?
No. It installs only the ECC-qualified pinned version, currently v0.1.0, and never falls back to latest or replaces the qualified command with a downloaded bootstrap script.
Advanced
Item type
skill
Key
nasiko-control-plane
Source
github.com/affaan-m/ecc