Claude Skill

Skillsmith

Skillsmith is the canonical lifecycle manager for agent skills (SKILL.md format) across any MCP-capable agent runtime — Claude Code, Cursor, Copilot, Codex, Windsurf. Discover, evaluate, install, use, maintain, author, govern, retire skills. Triggers: 'use Skillsmith', 'ask Skill

LLM Mart · 0 points · 14 views 0 listing impressions 0 install-command copies
Virus-scanned Reviewed automatically before listing.

Full trust report

Download smith-horn-skillsmith-packages_mcp-server_src_assets_skills_skillsmith-42c194d.zip · 3 KB
Part of smith-horn/skillsmith — 12 skills

Install

skills CLI npx skills add https://github.com/smith-horn/skillsmith/tree/main/packages/mcp-server/src/assets/skills/skillsmith
Claude Code claude plugin marketplace add https://llmmart.ai/marketplace.json && claude plugin install smith-horn-skillsmith@llmmart
Git git clone https://github.com/smith-horn/skillsmith.git

The skills CLI installs just this skill, for any of its supported agents. Claude Code installs the whole smith-horn/skillsmith collection as a plugin from our marketplace. Git is the plain clone.

Skill manifest

Skillsmith

Skillsmith is your master skill for the full lifecycle of agent skills — across every MCP-capable agent runtime. Use Skillsmith to discover, evaluate, install, use, maintain, author, govern, and retire SKILL.md-format skills without leaving your editor.

Lifecycle Stages

Every Skillsmith operation maps to one of 8 lifecycle stages. Use the stage name when you want to be explicit ("use Skillsmith to discover testing skills"); natural prompts work too.

# Stage What it covers Primary surface
1 Discover Find skills by query, recommendation, or filter MCP search, skill_recommend
2 Evaluate Compare candidates, read trust badges, view diffs MCP get_skill, skill_compare, skill_diff
3 Install Add a skill to the runtime's skills directory MCP install_skill; CLI install
4 Use Invoke the installed skill at the runtime layer runtime-native (e.g. Claude Code skill match)
5 Maintain Update, pin, audit collisions, configure modes CLI update/pin/unpin/audit collisions; MCP skill_updates, skill_outdated
6 Author Init, validate, transform, publish a new skill CLI author init/validate/publish/subagent/transform/mcp-init
7 Govern Audit logs, RBAC, SIEM, compliance (Team+) MCP audit_export, audit_query, siem_export
8 Retire Uninstall, deprecate MCP uninstall_skill; CLI remove

Quick Reference: MCP Tools

Tool Stage Use when Example prompt
search Discover Finding skills by keyword/category/trust tier "Use Skillsmith to search for testing skills"
skill_recommend Discover Contextual recommendations "Ask Skillsmith to recommend skills for my React project"
get_skill Evaluate Full details for a known skill "Use Skillsmith to show details for community/jest-helper"
skill_compare Evaluate Side-by-side comparison "Use Skillsmith to compare jest-helper and vitest-helper"
skill_diff Evaluate Diff two installed versions "Use Skillsmith to diff jest-helper versions"
install_skill Install Add a skill to your runtime "Use Skillsmith to install jest-helper"
skill_validate Install Pre-install validation of SKILL.md "Use Skillsmith to validate ./my-skill"
skill_updates Maintain Check for available updates "Ask Skillsmith for updates to my installed skills"
skill_outdated Maintain List skills behind latest "Use Skillsmith to show outdated skills"
skill_inventory_audit Maintain Namespace-collision audit (Team+) "Use Skillsmith to audit my skills inventory"
audit_export / audit_query / siem_export Govern Compliance + SIEM (Enterprise) "Use Skillsmith to export audit logs for last 30 days"
uninstall_skill Retire Remove an installed skill "Use Skillsmith to uninstall jest-helper"

Triggering tip: prefix natural-language prompts with Use Skillsmith to ... or Ask Skillsmith for .... The product-name anchor binds tool selection reliably across MCP-capable runtimes.

CLI Fallback

If the MCP server is unavailable, use the CLI directly:

# Discover
skillsmith search "testing" --tier verified
skillsmith recommend

# Evaluate
skillsmith info community/jest-helper
skillsmith diff jest-helper

# Install
skillsmith install community/jest-helper
skillsmith validate ./my-skill

# Maintain
skillsmith update --all --dry-run
skillsmith update <skill>
skillsmith audit collisions

# Retire
skillsmith remove jest-helper

See "Routing CLI-only Operations" below for operations that are CLI-only regardless of MCP server availability.

Routing CLI-only Operations

Some lifecycle operations live in the CLI and have no MCP equivalent (yet). When the user asks for these, surface the exact terminal command:

Operation CLI command
Pin a skill to a version skillsmith pin <skill> <version>
Unpin a skill skillsmith unpin <skill>
Preview updates to all installed skills skillsmith update --all --dry-run
Audit advisories (Team+) skillsmith audit advisories
Audit collisions skillsmith audit collisions
Configure audit mode skillsmith config set audit_mode <preventative\|power_user\|governance\|off>
Author a new skill skillsmith author init <name>
Publish a skill skillsmith author publish
Login skillsmith login

Always show the command verbatim with a one-line note: "Run this in your terminal."

Cross-Runtime Behavior

Skillsmith's MCP server works in any MCP-capable agent runtime:

  • Claude Code — default runtime. Skills install to ~/.claude/skills/.
  • Cursor / Copilot / Windsurf — set SKILLSMITH_CLIENT=<runtime> in your MCP server env config to install to the runtime-equivalent path. See Getting Started.
  • Custom MCP routers — universal MCP tool calls work; skill-file install paths configurable via SKILLSMITH_CLIENT.

Trust Tiers

Skills are categorized by verification level:

Tier Badge Meaning When to Trust
Verified Green checkmark Official Skillsmith / Anthropic Always safe
Curated Blue badge Vendor-org publisher, ≥0.80 quality Generally safe
Community Yellow Security scan + required metadata Review before install
Experimental Orange Beta / new Use cautiously
Unknown Red warning No verification Only if you trust the author

For criteria detail, see https://skillsmith.app/docs/trust-tiers.

Pricing & Quotas

Tier API calls/month Price
Community 100 Free
Individual 1,000 $9.99/mo
Team 10,000 $25/user/mo
Enterprise Unlimited Custom (Contact Sales)

Usage warnings at 80% and 90%. Upgrade at https://skillsmith.app/upgrade.

Security Model

Skillsmith is the security boundary between untrusted skill sources and your runtime.

What Skillsmith validates before install:

  • SKILL.md frontmatter and required fields
  • Security scan: jailbreak patterns, suspicious URLs, sensitive file access
  • Typosquatting check against known skills
  • Blocklist of known-malicious skills

What Skillsmith cannot prevent:

  • Novel attack patterns not in detection database
  • Social engineering in legitimate-looking instructions
  • Runtime behavior (skills execute with your permissions)

Recommendation: review skill content before installation, especially for unverified skills.

Creating Skills

Skill authoring lives in the CLI:

skillsmith author init my-new-skill
skillsmith author validate
skillsmith author publish

For an end-to-end walkthrough, see https://skillsmith.app/docs/tutorials/author.

The companion skill-builder skill guides you through frontmatter, progressive disclosure structure, and directory organization. Install it with skillsmith install skill-builder (it's not bundled by default).

Common Workflows

Discover then install

"Use Skillsmith to recommend skills for my Next.js project"
"Use Skillsmith to install community/next-helper"

Evaluate before installing

"Use Skillsmith to compare jest-helper and vitest-helper"
"Use Skillsmith to show details for community/vitest-helper"
"Use Skillsmith to install community/vitest-helper"

Maintain installed skills

"Ask Skillsmith for updates to my installed skills"
# Then run in terminal — preview first, then update skills one at a time:
skillsmith update --all --dry-run
skillsmith update <skill>

Audit before sharing your skill folder

"Use Skillsmith to audit my skills inventory"
# Or in terminal:
skillsmith audit collisions

License

Skillsmith uses Elastic License 2.0:

  • Self-host for internal use ✓
  • Modify for your own use ✓
  • Offer Skillsmith as a managed service to others ✗
  • Circumvent license key functionality ✗

Getting Help

Files (skillsmith)
  • SKILL.md 8.8 KB
    ---
    name: "Skillsmith"
    description: "Skillsmith is a registry for sharing, scanning, and tracking agent skills (SKILL.md format) across any MCP-capable agent runtime — Claude Code, Cursor, Copilot, Codex, Windsurf. Discover, evaluate, install, use, maintain, author, govern, retire skills. Triggers: 'use Skillsmith', 'ask Skillsmith', 'search Skillsmith', 'find a Skillsmith skill', 'install with Skillsmith', 'Skillsmith trust tier', 'Skillsmith audit', 'create a skill with Skillsmith', 'publish to Skillsmith', 'Skillsmith quota', 'pin a Skillsmith skill', 'compare Skillsmith skills'. Routes natural-language requests to Skillsmith MCP tools and CLI commands."
    ---
    
    # Skillsmith
    
    Skillsmith is your master skill for the full lifecycle of agent skills — across every MCP-capable agent runtime. Use Skillsmith to discover, evaluate, install, use, maintain, author, govern, and retire SKILL.md-format skills without leaving your editor.
    
    ## Lifecycle Stages
    
    Every Skillsmith operation maps to one of 8 lifecycle stages. Use the stage name when you want to be explicit ("use Skillsmith to **discover** testing skills"); natural prompts work too.
    
    | # | Stage | What it covers | Primary surface |
    |---|---|---|---|
    | 1 | **Discover** | Find skills by query, recommendation, or filter | MCP `search`, `skill_recommend` |
    | 2 | **Evaluate** | Compare candidates, read trust badges, view diffs | MCP `get_skill`, `skill_compare`, `skill_diff` |
    | 3 | **Install** | Add a skill to the runtime's skills directory | MCP `install_skill`; CLI `install` |
    | 4 | **Use** | Invoke the installed skill at the runtime layer | runtime-native (e.g. Claude Code skill match) |
    | 5 | **Maintain** | Update, pin, audit collisions, configure modes | CLI `update`/`pin`/`unpin`/`audit collisions`; MCP `skill_updates`, `skill_outdated` |
    | 6 | **Author** | Init, validate, transform, publish a new skill | CLI `author init/validate/publish/subagent/transform/mcp-init` |
    | 7 | **Govern** | Audit logs, RBAC, SIEM, compliance (Team+) | MCP `audit_export`, `audit_query`, `siem_export` |
    | 8 | **Retire** | Uninstall, deprecate | MCP `uninstall_skill`; CLI `remove` |
    
    ## Quick Reference: MCP Tools
    
    | Tool | Stage | Use when | Example prompt |
    |---|---|---|---|
    | `search` | Discover | Finding skills by keyword/category/trust tier | "Use Skillsmith to search for testing skills" |
    | `skill_recommend` | Discover | Contextual recommendations | "Ask Skillsmith to recommend skills for my React project" |
    | `get_skill` | Evaluate | Full details for a known skill | "Use Skillsmith to show details for community/jest-helper" |
    | `skill_compare` | Evaluate | Side-by-side comparison | "Use Skillsmith to compare jest-helper and vitest-helper" |
    | `skill_diff` | Evaluate | Diff two installed versions | "Use Skillsmith to diff jest-helper versions" |
    | `install_skill` | Install | Add a skill to your runtime | "Use Skillsmith to install jest-helper" |
    | `skill_validate` | Install | Pre-install validation of SKILL.md | "Use Skillsmith to validate ./my-skill" |
    | `skill_updates` | Maintain | Check for available updates | "Ask Skillsmith for updates to my installed skills" |
    | `skill_outdated` | Maintain | List skills behind latest | "Use Skillsmith to show outdated skills" |
    | `skill_inventory_audit` | Maintain | Namespace-collision audit (Team+) | "Use Skillsmith to audit my skills inventory" |
    | `audit_export` / `audit_query` / `siem_export` | Govern | Compliance + SIEM (Enterprise) | "Use Skillsmith to export audit logs for last 30 days" |
    | `uninstall_skill` | Retire | Remove an installed skill | "Use Skillsmith to uninstall jest-helper" |
    
    **Triggering tip**: prefix natural-language prompts with `Use Skillsmith to ...` or `Ask Skillsmith for ...`. The product-name anchor binds tool selection reliably across MCP-capable runtimes.
    
    ## CLI Fallback
    
    If the MCP server is unavailable, use the CLI directly:
    
    ```bash
    # Discover
    skillsmith search "testing" --tier verified
    skillsmith recommend
    
    # Evaluate
    skillsmith info community/jest-helper
    skillsmith diff jest-helper
    
    # Install
    skillsmith install community/jest-helper
    skillsmith validate ./my-skill
    
    # Maintain
    skillsmith update --all --dry-run
    skillsmith update <skill>
    skillsmith audit collisions
    
    # Retire
    skillsmith remove jest-helper
    ```
    
    See "Routing CLI-only Operations" below for operations that are CLI-only regardless of MCP
    server availability.
    
    ## Routing CLI-only Operations
    
    Some lifecycle operations live in the CLI and have no MCP equivalent (yet). When the user asks for these, surface the exact terminal command:
    
    | Operation | CLI command |
    |---|---|
    | Pin a skill to a version | `skillsmith pin <skill> <version>` |
    | Unpin a skill | `skillsmith unpin <skill>` |
    | Preview updates to all installed skills | `skillsmith update --all --dry-run` |
    | Audit advisories (Team+) | `skillsmith audit advisories` |
    | Audit collisions | `skillsmith audit collisions` |
    | Configure audit mode | `skillsmith config set audit_mode <preventative\|power_user\|governance\|off>` |
    | Author a new skill | `skillsmith author init <name>` |
    | Publish a skill | `skillsmith author publish` |
    | Login | `skillsmith login` |
    
    Always show the command verbatim with a one-line note: "Run this in your terminal."
    
    ## Cross-Runtime Behavior
    
    Skillsmith's MCP server works in **any MCP-capable agent runtime**:
    
    - **Claude Code** — default runtime. Skills install to `~/.claude/skills/`.
    - **Cursor / Copilot / Windsurf** — set `SKILLSMITH_CLIENT=<runtime>` in your MCP server env config to install to the runtime-equivalent path. See [Getting Started](https://skillsmith.app/docs/getting-started).
    - **Custom MCP routers** — universal MCP tool calls work; skill-file install paths configurable via `SKILLSMITH_CLIENT`.
    
    ## Trust Tiers
    
    Skills are categorized by verification level:
    
    | Tier | Badge | Meaning | When to Trust |
    |------|-------|---------|---------------|
    | **Verified** | Green checkmark | Official Skillsmith / Anthropic | Always safe |
    | **Curated** | Blue badge | Vendor-org publisher, ≥0.80 quality | Generally safe |
    | **Community** | Yellow | Security scan + required metadata | Review before install |
    | **Experimental** | Orange | Beta / new | Use cautiously |
    | **Unknown** | Red warning | No verification | Only if you trust the author |
    
    For criteria detail, see https://skillsmith.app/docs/trust-tiers.
    
    ## Pricing & Quotas
    
    | Tier | API calls/month | Price |
    |---|---|---|
    | **Community** | 100 | Free |
    | **Individual** | 1,000 | $9.99/mo |
    | **Team** | 10,000 | $25/user/mo |
    | **Enterprise** | Unlimited | Custom (Contact Sales) |
    
    Usage warnings at 80% and 90%. Upgrade at https://skillsmith.app/upgrade.
    
    ## Security Model
    
    Skillsmith is the security boundary between untrusted skill sources and your runtime.
    
    **What Skillsmith validates before install**:
    
    - SKILL.md frontmatter and required fields
    - Security scan: jailbreak patterns, suspicious URLs, sensitive file access
    - Typosquatting check against known skills
    - Blocklist of known-malicious skills
    
    **What Skillsmith cannot prevent**:
    
    - Novel attack patterns not in detection database
    - Social engineering in legitimate-looking instructions
    - Runtime behavior (skills execute with your permissions)
    
    **Recommendation**: review skill content before installation, especially for unverified skills.
    
    ## Creating Skills
    
    Skill authoring lives in the CLI:
    
    ```
    skillsmith author init my-new-skill
    skillsmith author validate
    skillsmith author publish
    ```
    
    For an end-to-end walkthrough, see https://skillsmith.app/docs/tutorials/author.
    
    The companion **skill-builder** skill guides you through frontmatter, progressive disclosure structure, and directory organization. Install it with `skillsmith install skill-builder` (it's not bundled by default).
    
    ## Common Workflows
    
    ### Discover then install
    
    ```
    "Use Skillsmith to recommend skills for my Next.js project"
    "Use Skillsmith to install community/next-helper"
    ```
    
    ### Evaluate before installing
    
    ```
    "Use Skillsmith to compare jest-helper and vitest-helper"
    "Use Skillsmith to show details for community/vitest-helper"
    "Use Skillsmith to install community/vitest-helper"
    ```
    
    ### Maintain installed skills
    
    ```
    "Ask Skillsmith for updates to my installed skills"
    # Then run in terminal — preview first, then update skills one at a time:
    skillsmith update --all --dry-run
    skillsmith update <skill>
    ```
    
    ### Audit before sharing your skill folder
    
    ```
    "Use Skillsmith to audit my skills inventory"
    # Or in terminal:
    skillsmith audit collisions
    ```
    
    ## License
    
    Skillsmith uses **Elastic License 2.0**:
    
    - Self-host for internal use ✓
    - Modify for your own use ✓
    - Offer Skillsmith as a managed service to others ✗
    - Circumvent license key functionality ✗
    
    ## Getting Help
    
    - Docs: https://skillsmith.app/docs
    - Tutorials (lifecycle walkthroughs): https://skillsmith.app/docs/tutorials
    - CLI: `skillsmith --help`
    - Issues: https://github.com/smith-horn/skillsmith/issues
    - Email: support@skillsmith.app
    

Comments (0)

Sign in to join the conversation.

No comments yet.

Reviews (0)

No reviews yet.

Related