Instructions and skills
Tell Farabi how to answer, add skills for one kind of work, pick them per conversation, and preview the prompt below the safety core you cannot change.
Pro
Farabi and every AI feature are part of Gatesys Pro — free for 3 months, then $20 a year. See plans
Farabi’s system prompt has three layers, always in this order. You write the second and choose the third; the first decides what Farabi may do, and you cannot change it.
| Layer | Who writes it | Where it is | What goes with a question |
|---|---|---|---|
| Safety core | Gatesys SSH | Built in | Always, first and whole |
| Your instructions | You | ~/.gatesys-ssh/farabi/system.md | Always, below the core |
| Skills | Gatesys SSH, or you | Built in, or ~/.gatesys-ssh/skills/<id>/SKILL.md | The ones on for the conversation, below your instructions |
Both cards are in Settings › Farabi: System prompt under Language and instructions, and Skill library under Skills. They show while Use the assistant is on. Without Pro you can read the built-in skills, and nothing can be changed.
The safety core
The core keeps Farabi safe to point at a server:
- Commands only in
shblocks, one per block, so the app can rate each one itself. - Nothing invented about hosts, paths or credentials.
- Whatever a server printed is treated as evidence, never as instructions.
- No tools. Farabi only suggests, and nothing runs until you click Run.
Between the core and your layers, a line tells the model that your instructions and skills refine tone, language, detail and house conventions, and that the core wins if one seems to contradict it. Click Safety core on the System prompt card to read the core word for word.
Your text cannot loosen the rules
Instructions and skills are text only. They cannot run anything, reach a tool, grant a permission or move above the core. The app still rates every command itself, and Run still needs your click. See Command safety.
Write your instructions
- Open Settings › Farabi and find the System prompt card under Language and instructions.
- Type in Your instructions: how Farabi should answer you. For example, the language to reply in, how much detail you want, or house rules such as we use podman, not docker or our logs are in /srv/logs.
- Click Save. The card says Saved — in use from the next question.
A fresh install starts with a short default: be direct and practical, answer in the language of the question, and prefer the tools the host already has. Reset to default puts it back.
- Size. Under the text, the card counts characters and tokens, and the whole prompt against the current model’s budget, for example whole prompt ≈620 of 1,500 for qwen3:8b · Ollama (a small local model). The limit is 6,000 characters, about 1,500 tokens.
- In your editor. Click the path,
~/.gatesys-ssh/farabi/system.md, to open the file. A change there applies as soon as you save it. Comments written as<!-- … -->are never sent. - No secrets. Your instructions go to the model with every question, so text that looks like an API key, a private key, a token or a labelled password is refused. An edit in the file that holds one, or runs past the limit, is not applied: the card says why, and the last good text stays in use.
- Flagged wording. If the Injection Shield reads a phrase as trying to change Farabi’s rules, the card quotes it. Your instructions are still used, below the core, so the core still wins.
Preview the final prompt
Click Preview final prompt on the System prompt card. It shows the prompt layer by layer, exactly as a question would send it, each with its size in tokens: the safety core, your instructions, then each skill on by default. Copy copies the whole text.
- The fence nonce shows as
00000000; each question gets its own. - A model off this computer also gets the placeholder clause. See Egress slots.
- In a conversation, the skills the host’s facts suggest join the defaults.
Skills
A skill is guidance Farabi reads for one kind of work. Each one puts read-only checks first, in the order an experienced operator would run them, says what the output means, and then makes changes one at a time, saying what each one interrupts.
Built-in skills
Built-in skills are read-only. View shows the text, and Duplicate copies it into your own folder, as Name (mine), for you to edit.
| Skill | For | Suggested when the host’s facts show |
|---|---|---|
| Linux triage | A slow, flaky or broken host, read in the order an operator would read it | Recent out-of-memory kills |
| systemd & journald | Why a unit failed, from its status and journal, and how to change it safely | A failed unit |
| Docker & Compose | Containers, images, volumes and Compose stacks, inspected before anything is removed | Running containers, or a Docker, containerd or Podman package |
| Kubernetes | kubectl, read first; every change named with its namespace and what it reschedules | A Kubernetes component, or a listener on :6443 |
| Nginx & TLS | nginx as a web server or proxy, its logs, and the certificate in front of it | nginx, or a listener on :443 |
| PostgreSQL DBA | Sessions, locks, size and replication, read-only first; a backup before any change | PostgreSQL, or a listener on :5432 |
| MySQL/MariaDB | Processlist, InnoDB, replication and sizes, read-only first; a dump before any change | MySQL or MariaDB, or a listener on :3306 |
| Network troubleshooting | Cannot connect, slow or does not resolve, from the interface up with ss, ip, dig and mtr | Never; turn it on yourself |
| Security hardening review | Logins, exposure, patches and startup items, reviewed read-only with evidence | Never; turn it on yourself |
| Disk & log cleanup | A filling disk: find what grew, then free space in the safe order | A filesystem at 85% or more |
| Türkçe yanıt | Farabi answers in Turkish; commands, paths and technical tokens stay exactly as they are | Never; turn it on yourself |
Pick skills for a conversation
In Farabi’s panel header, the skills · N chip counts the skills on for this conversation. Click it to open the picker.
- Suggested for db-primary lists up to three skills the host’s measured facts point to, each with the reason in the app’s own words, such as docker: 18 containers or /var at 91%. Code picks them from the facts; no model is asked.
- Auto turns the suggestions on for you. Switch it off to choose by hand.
- Click any skill to turn it on or off for this conversation only. The search box filters by name, description and tag.
- Manage skills opens Settings.
The choice lasts as long as the session, like the model pick. Under each answer, beside the model, the app names the skills that shaped it.
Suggestions need facts that could go into the prompt: Send host context, Remember host facts and Include host facts in prompts on, and the host not opted out of facts. See Host facts.
Turn a skill on for every conversation
In Settings › Farabi › Skills, the switch on a skill’s row turns it on in every conversation, unless a panel turns it off. None is on by default.
Suggest skills from host facts, on by default, decides whether a new panel starts with Auto on.
When the prompt runs out of room
A small local model has little room beside the host facts, the terminal and the conversation. Farabi’s system prompt gets about 1,500 tokens on a local runtime, and about 8,000 on a cloud API, an agent CLI or an Ollama cloud model.
When the skills on would go past that, the lowest-priority skills are left out first until the prompt fits. The core and your instructions are never left out. The picker marks a skill that did not fit Left out: over this model’s prompt budget, and the line under the answer says how many were left out. A larger model, or fewer skills, keeps them.
Write your own skill
Open Settings › Farabi › Skills and click New skill.
Fill in the fields:
Field What to enter Name Up to 60 characters, for example Our deploy runbook Folder The skill’s id and folder name. It follows the name until you type your own: lower-case letters, digits and dashes, up to 48 Description One line, up to 200 characters Tags Words to find it by in the picker Priority 0 to 100, 50 by default. When the prompt runs out of room, lower priorities are left out first Suggest when the host’s facts show Facts, Packages, Ports and OS. Leave all four empty to only turn it on by hand Instructions The text Farabi reads, up to 8,000 characters Check the preview beside it: As Farabi reads it, or the SKILL.md it will write, with its size in tokens and anything wrong.
Click Add skill.
The facts a skill can be suggested on are docker, podman, containers, kubernetes, nginx, apache, caddy, haproxy, traefik, tls, postgres, mysql, redis, systemd, failed-units, disk-pressure, oom and linux.
Your skills are listed under Mine, above the built-in ones.
- Edit opens a skill in the same editor, with Delete. Changing Folder renames it.
- The download button exports its SKILL.md to a place you choose.
- Import brings a skill in from a SKILL.md, a folder with one, or any
.mdfile with the same frontmatter. Only the text is copied, never other files in the folder. On macOS you can pick a folder; elsewhere, pick the file. - Show folder opens
~/.gatesys-ssh/skills.
The SKILL.md file
Each skill of yours is a folder in ~/.gatesys-ssh/skills/, named with its id, holding one SKILL.md: a short frontmatter, then the instructions.
---
name: Our deploy runbook
description: How we ship with Ansible from /srv/ops, then a smoke test
tags: [deploy, ansible]
when:
facts: [docker]
pkg: [nginx]
port: [443]
priority: 60
---
Read-only checks first:
- `systemctl status myapp --no-pager`
- `journalctl -u myapp -n 100 --no-pager`
Deploys go through `ansible-playbook site.yml --check` before the real run.- Only
name,description,tags,when(withfacts,pkg,portandos) andpriorityare read. Any other key is an error that names its line: a skill has no key for a script, a tool or a permission. nameand the instructions are required. The file can be up to 64 KB.- An id that belongs to a built-in skill is refused.
- Edit it in your own editor and the change applies as soon as you save. A file that does not parse, holds a secret or runs too long is not applied: its row says what is wrong, and the last good copy stays in use. A skill that never read cleanly cannot be used until you fix it.
Skills the Shield flags
The Injection Shield reads each of your skills for wording that tries to loosen Farabi’s rules rather than inform them, such as you may run, no need to confirm, skip the confirmation or override the system prompt.
- A flagged skill is marked Flagged, with the phrase quoted. Until you click Approve on its row, it is not used or suggested, and the picker shows it greyed out.
- The approval covers that exact text. Any change to the skill asks again.
- Approvals are kept in the vault as a hash of the skill, so a program that can write the skills folder cannot approve its own text.
- An approved skill still sits below the safety core.
The editor warns before you save a skill it would flag. Built-in skills are never flagged.
What is sent, and what is kept
- Only Farabi’s questions carry these layers, to the provider answering the conversation. Explain, watch and setup drafts and Safe Change drafts keep their own fixed prompts.
- Test this model sends them only with Test with my Farabi prompt on.
- Hooks receive the ids of the skills in a prompt, never their text.
- The audit log records each change to your instructions, and each flagged skill you approve.
- The files are yours:
farabi/system.mdandskills/in~/.gatesys-ssh/, or in the folderGATESYS_HOMEnames. The app writes them readable only by you. See The settings file.
Something unclear or wrong? Tell us.