Best for
- Use this CLI when you are administering an Admin By Request tenant from a terminal or AI agent: triaging pending requests in bulk, pulling audit data into a SIEM you have not yet wired up, generating offline PINs withou…
mvanhorn/printing-press-library/cli-skills/pp-adminbyrequest/SKILL.md
Every Admin By Request portal action, plus a local SQLite mirror of audit, events, inventory and requests for ad-hoc... Trigger phrases: `list pending admin by request elevations`, `approve adminbyrequest request`, `deny adminbyrequest request`, `generate offline elevation PIN`, `check who keeps requesting admin elevation`, `sync admin by request audit log`, `use adminbyrequest`, `run adminbyrequest`.
Decision brief
Every Admin By Request portal action, plus a local SQLite mirror of audit, events, inventory and requests for ad-hoc... Trigger phrases: `list pending admin by request elevations`, `approve adminbyrequest request`, `deny adminbyrequest request`, `generate offline elevation PIN`, `check who keeps requesting admin elevation`, `sync admin by request audit log`…
Compatibility matrix
| Platform | Status | Evidence | What to check |
|---|---|---|---|
| Codex | Not declared | No explicit evidence | Portability before use |
| Claude Code | Not declared | No explicit evidence | Portability before use |
| Cursor | Not declared | No explicit evidence | Portability before use |
| Gemini CLI | Not declared | No explicit evidence | Portability before use |
Installation
The source command is displayed only when detected. A safe inspection prompt is always available so your agent can explain every action before execution.
npx skills add https://github.com/mvanhorn/printing-press-library --skill "cli-skills/pp-adminbyrequest"Inspect the Agent Skill "pp-adminbyrequest" from https://github.com/mvanhorn/printing-press-library/blob/ea0c3cd89072bf822759f559a7026a33adbf8eae/cli-skills/pp-adminbyrequest/SKILL.md at commit ea0c3cd89072bf822759f559a7026a33adbf8eae. List every install step, command, network request, credential, file read/write, external action, and rollback step. Explain whether it fits my task. Do not install or execute anything until I approve.
Workflow
For compliance review and tone-of-policy checks, surfacing the actual words used is faster than reading each row.
Set ADMINBYREQUESTAPIKEY in your environment. The CLI sends it via the apikey header. AbR enforces a 100,000-call daily quota per tenant; the CLI tracks calls locally and warns you before exhaustion via quota forecast.
This skill drives the adminbyrequest-pp-cli binary. You must verify the CLI is installed before invoking any command from this skill. If it is missing, install it first:
Use this CLI when you are administering an Admin By Request tenant from a terminal or AI agent: triaging pending requests in bulk, pulling audit data into a SIEM you have not yet wired up, generating offline PINs without opening the portal, or answering cross-resource questions…
These capabilities aren't available in any other tool for this API.
Permission review
The documentation asks the agent to run terminal commands or scripts.
npx -y @mvanhorn/printing-press-library install adminbyrequest --cli-onlyThe documentation asks the agent to run terminal commands or scripts.
go install github.com/mvanhorn/printing-press-library/library/devices/adminbyrequest/cmd/adminbyrequest-pp-cli@latestThe documentation includes sending, uploading, or posting data to a remote service.
| `webhook:<url>` | POST the output body to the URL (`application/json` or `application/x-ndjson` when `--compact`) |The documentation includes network, browsing, or remote request actions.
| `webhook:<url>` | POST the output body to the URL (`application/json` or `application/x-ndjson` when `--compact`) |Evidence record
| Signal | Value | Evidence type | Meaning |
|---|---|---|---|
| Quality score | 85/100 | Computed | Documentation, specificity, maintenance, and trust rules |
| Repository stars | 1,883 | Source | Repository attention, not individual Skill quality |
| Compatibility | 0 platforms | Source | Declared in the catalog source record |
| Usage guide | automated source guide | Editorial | Generated or reviewed according to the visible evidence level |
Pinned source
This skill drives the adminbyrequest-pp-cli binary. You must verify the CLI is installed before invoking any command from this skill. If it is missing, install it first:
$HOME/.local/bin on macOS/Linux and %LOCALAPPDATA%\Programs\PrintingPress\bin on Windows:
npx -y @mvanhorn/printing-press-library install adminbyrequest --cli-only
adminbyrequest-pp-cli --version$PATH for the agent/runtime that will invoke this skill.If the npx install fails (no Node, offline, etc.), fall back to a direct Go install (requires Go 1.26.5 or newer):
go install github.com/mvanhorn/printing-press-library/library/devices/adminbyrequest/cmd/adminbyrequest-pp-cli@latest
If --version reports "command not found" after install, the runtime cannot see the binary directory on $PATH. Do not proceed with skill commands until verification succeeds.
Use this CLI when you are administering an Admin By Request tenant from a terminal or AI agent: triaging pending requests in bulk, pulling audit data into a SIEM you have not yet wired up, generating offline PINs without opening the portal, or answering cross-resource questions (repeat requestors, agent-version drift) that the portal does not directly support.
These capabilities aren't available in any other tool for this API.
requests repeat-offenders — Surface the top users by elevation-request count over a configurable window, so admins can spot patterns the portal does not visualize.
When tracing repeated elevation attempts across a fleet, this is the single query that names the people; without it, an agent has to walk every request and aggregate manually.
adminbyrequest-pp-cli requests repeat-offenders --window 30d --json
correlate — Given an audit log entry ID, join it to nearby events on the same computer to reconstruct a full elevation timeline.
Incident response often asks what else happened on this machine when this admin session opened; this is the single command that answers it.
adminbyrequest-pp-cli correlate 50461167 --window 5m --json
inventory drift — List endpoints whose AbR client version is older than a target version, useful for upgrade campaigns.
Before any compliance audit, the agent should know which endpoints are running an old client; this is the one-liner.
adminbyrequest-pp-cli inventory drift --client-version 8.7.2 --json
inventory risk-score — Score each endpoint by elevation frequency, local-admin count, and AbR client version recency.
Lets an admin focus remediation effort on the endpoints most likely to be abused.
adminbyrequest-pp-cli inventory risk-score --top 10 --json
quota forecast — Track local API call count against the 100k-per-day quota and predict whether the current pace will exceed it before midnight.
Reachability mitigation: an agent that calls the API in a loop needs to know before it bricks the tenant for the day.
adminbyrequest-pp-cli quota forecast --json
requests denied-reasons — Tokenize the free-text deniedReason field across all denied requests and emit a top-N word distribution.
For compliance review and tone-of-policy checks, surfacing the actual words used is faster than reading each row.
adminbyrequest-pp-cli requests denied-reasons --top 20 --json
report compliance — Render audit entries for a user or computer over a window in a format suitable for auditors (CSV or markdown).
Auditor evidence requests always want a single artifact; this generates it in one command.
adminbyrequest-pp-cli report compliance --since 2026-01-01 --user CHRISCOOMBES --format md
auditlog — Admin session and elevation audit log entries
adminbyrequest-pp-cli auditlog delta — Delta query for audit log changes (use timeNow/deltaTime ticks for resumable sync)adminbyrequest-pp-cli auditlog list — List audit log entries (admin sessions, app elevations, denied requests). Pagination is by id cursor.events — Security and operational events emitted by AbR clients
adminbyrequest-pp-cli events — List events. Use code filter to narrow to specific event types.inventory — Endpoint inventory: hardware, software, OS, AbR agent version
adminbyrequest-pp-cli inventory list — List inventoried endpoints. Use wantsoftware/wanthardware to expand.adminbyrequest-pp-cli inventory pin — Generate an offline elevation PIN code for a device. Pass --challenge for challenge-response mode.requests — Pending, approved, and denied elevation requests
adminbyrequest-pp-cli requests approve — Approve a pending elevation request.adminbyrequest-pp-cli requests deny — Deny a pending elevation request.adminbyrequest-pp-cli requests list — List elevation requests filtered by status.Hand-written commands
adminbyrequest-pp-cli correlate <auditlog-id> — Join an audit log entry to nearby events on the same computer (window in minutes)adminbyrequest-pp-cli report — Render compliance reports from synced dataadminbyrequest-pp-cli quota — Track local API call count vs AbR's 100k/day quotaWhen you know what you want to do but not which command does it, ask the CLI directly:
adminbyrequest-pp-cli which "<capability in your own words>"
which resolves a natural-language capability query to the best matching command from this CLI's curated feature index. Exit code 0 means at least one match; exit code 2 means no confident match — fall back to --help or use a narrower query.
adminbyrequest-pp-cli requests list --status pending --agent --select id,user.account,reason
Surface the pending elevation queue in agent-friendly JSON narrowed to the fields needed to decide. Approve or deny individual ids with requests approve <id> --reason ... or requests deny <id> --reason ....
adminbyrequest-pp-cli report compliance --since 2026-01-01 --user CHRISCOOMBES --format md > evidence.md
Render every audit log entry for a user since a date into a markdown report.
adminbyrequest-pp-cli inventory drift --client-version 8.7.2 --json --select name,abrClientVersion
Inventory drift filters the synced inventory snapshot for endpoints below the target client version.
adminbyrequest-pp-cli quota show --agent
Local counter of API calls made today; the CLI tracks them in ~/.cache/adminbyrequest-pp-cli/http/ so this command itself never costs an API call.
adminbyrequest-pp-cli correlate 50461167 --window 5m --agent --select audit.application.name,audit.user.account,events.eventText,events.eventTime
Joins audit entry to nearby events on the same computer; --select narrows the deeply nested response so the agent does not parse the full payload.
Set ADMINBYREQUEST_API_KEY in your environment. The CLI sends it via the apikey header. AbR enforces a 100,000-call daily quota per tenant; the CLI tracks calls locally and warns you before exhaustion via quota forecast.
Run adminbyrequest-pp-cli doctor to verify setup.
Add --agent to any command. Expands to: --json --compact --no-input --no-color --yes.
Pipeable — JSON on stdout, errors on stderr
Filterable — --select keeps a subset of fields. Dotted paths descend into nested structures; arrays traverse element-wise. Critical for keeping context small on verbose APIs:
adminbyrequest-pp-cli auditlog list --agent --select id,name,status
Previewable — --dry-run shows the request without sending
Offline-friendly — sync/search commands can use the local SQLite store when available
Non-interactive — never prompts, every input is a flag
Explicit retries — use --idempotent only when an already-existing create should count as success
Commands that read from the local store or the API wrap output in a provenance envelope:
{
"meta": {"source": "live" | "local", "synced_at": "...", "reason": "..."},
"results": <data>
}
Parse .results for data and .meta.source to know whether it's live or local. A human-readable N results (live) summary is printed to stderr only when stdout is a terminal — piped/agent consumers get pure JSON on stdout.
When you (or the agent) notice something off about this CLI, record it:
adminbyrequest-pp-cli feedback "the --since flag is inclusive but docs say exclusive"
adminbyrequest-pp-cli feedback --stdin < notes.txt
adminbyrequest-pp-cli feedback list --json --limit 10
Entries are stored locally at ~/.adminbyrequest-pp-cli/feedback.jsonl. They are never POSTed unless ADMINBYREQUEST_FEEDBACK_ENDPOINT is set AND either --send is passed or ADMINBYREQUEST_FEEDBACK_AUTO_SEND=true. Default behavior is local-only.
Write what surprised you, not a bug report. Short, specific, one line: that is the part that compounds.
Every command accepts --deliver <sink>. The output goes to the named sink in addition to (or instead of) stdout, so agents can route command results without hand-piping. Three sinks are supported:
| Sink | Effect |
|---|---|
stdout | Default; write to stdout only |
file:<path> | Atomically write output to <path> (tmp + rename) |
webhook:<url> | POST the output body to the URL (application/json or application/x-ndjson when --compact) |
Unknown schemes are refused with a structured error naming the supported set. Webhook failures return non-zero and log the URL + HTTP status on stderr.
A profile is a saved set of flag values, reused across invocations. Use it when a scheduled agent calls the same command every run with the same configuration - HeyGen's "Beacon" pattern.
adminbyrequest-pp-cli profile save briefing --json
adminbyrequest-pp-cli --profile briefing auditlog list
adminbyrequest-pp-cli profile list --json
adminbyrequest-pp-cli profile show briefing
adminbyrequest-pp-cli profile delete briefing --yes
Explicit flags always win over profile values; profile values win over defaults. agent-context lists all available profiles under available_profiles so introspecting agents discover them at runtime.
| Code | Meaning |
|---|---|
| 0 | Success |
| 2 | Usage error (wrong arguments) |
| 3 | Resource not found |
| 4 | Authentication required |
| 5 | API error (upstream issue) |
| 7 | Rate limited (wait and retry) |
| 10 | Config error |
Parse $ARGUMENTS:
help, or --help → show adminbyrequest-pp-cli --help outputinstall → ends with mcp → MCP installation; otherwise → see Prerequisites above--agent)Install the MCP binary from this CLI's published public-library entry or pre-built release, then register it:
claude mcp add adminbyrequest-pp-mcp -- adminbyrequest-pp-mcp
Verify: claude mcp list
which adminbyrequest-pp-cli
If not found, offer to install (see Prerequisites at the top of this skill).--agent flag:
adminbyrequest-pp-cli <command> [subcommand] [args] --agent
adminbyrequest-pp-cli <command> --help.Alternatives
mvanhorn/printing-press-library
Every Admin By Request portal action, plus a local SQLite mirror of audit, events, inventory and requests for ad-hoc... Trigger phrases: `list pending admin by request elevations`, `approve adminbyrequest request`, `deny adminbyrequest request`, `generate offline elevation PIN`, `check who keeps requesting admin elevation`, `sync admin by request audit log`, `use adminbyrequest`, `run adminbyrequest`.
coreyhaines31/marketingskills
When the user wants to plan, design, or implement an A/B test or experiment, or build a growth experimentation program. Also use when the user mentions "A/B test," "split test," "experiment," "test this change," "variant copy," "multivariate test," "hypothesis," "should I test this," "which version is better," "test two versions," "statistical significance," "how long should I run this test," "growth experiments," "experiment velocity," "experiment backlog," "ICE score," "experimentation program
alirezarezvani/claude-skills
App Store Optimization (ASO) toolkit for researching keywords, analyzing competitor rankings, generating metadata suggestions, and improving app visibility on Apple App Store and Google Play Store. Use when the user asks about ASO, app store rankings, app metadata, app titles and descriptions, app store listings, app visibility, or mobile app marketing on iOS or Android. Supports keyword research and scoring, competitor keyword analysis, metadata optimization, A/B test planning, launch checklist
dotnet/skills
Migrates .NET test projects from VSTest to Microsoft.Testing.Platform (MTP). Use when user asks to "migrate to MTP", "switch from VSTest", "enable Microsoft.Testing.Platform", "use MTP runner", set OutputType=Exe only for test projects in Directory.Build.props, or mentions EnableMSTestRunner, EnableNUnitRunner, or UseMicrosoftTestingPlatformRunner. USE FOR: MTP behavioral differences vs VSTest (exit code 8, zero tests discovered, --ignore-exit-code, TESTINGPLATFORM_EXITCODE_IGNORE); centralizing