agentsclimarketplace

Skillsmith

Skill smith-horn/skillsmith/packages/mcp-server/src/assets/skills/skillsmith

Lifecycle Management for Agent Skills

Install
npx -y skills add smith-horn/skillsmith --skill skillsmith

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

One thing to look at

  • no licenseNo license file was found in the repository. Code published without one is not open source by default, so using it at work is a question for whoever answers licensing questions where you are.

What its author says it does

Copied from the file, not written here

Skillsmith is the canonical lifecycle manager for agent skills (SKILL.md format) across any MCP-capable agent runtime — Claude Code, Cursor, Copilot, Codex, Windsurf. Discover, evaluate, install, use, maintain, author, govern, retire skills. Triggers: 'use Skillsmith', 'ask Skillsmith', 'search Skillsmith', 'find a Skillsmith skill', 'install with Skillsmith', 'Skillsmith trust tier', 'Skillsmith audit', 'create a skill with Skillsmith', 'publish to Skillsmith', 'Skillsmith quota', 'pin a Skillsmith skill', 'compare Skillsmith skills'. Routes natural-language requests to Skillsmith MCP tools and CLI commands.

SKILL.md

8.1 KB, as published. Nobody here has run it

Skillsmith

Skillsmith is your master skill for the full lifecycle of agent skills — across every MCP-capable agent runtime. Use Skillsmith to discover, evaluate, install, use, maintain, author, govern, and retire SKILL.md-format skills without leaving your editor.

Lifecycle Stages

Every Skillsmith operation maps to one of 8 lifecycle stages. Use the stage name when you want to be explicit ("use Skillsmith to discover testing skills"); natural prompts work too.

#StageWhat it coversPrimary surface
1DiscoverFind skills by query, recommendation, or filterMCP search, skill_recommend
2EvaluateCompare candidates, read trust badges, view diffsMCP get_skill, skill_compare, skill_diff
3InstallAdd a skill to the runtime's skills directoryMCP install_skill; CLI install
4UseInvoke the installed skill at the runtime layerruntime-native (e.g. Claude Code skill match)
5MaintainUpdate, pin, audit collisions, configure modesCLI update/pin/unpin/audit collisions; MCP skill_updates, skill_outdated
6AuthorInit, validate, transform, publish a new skillCLI author init/validate/publish/subagent/transform/mcp-init
7GovernAudit logs, RBAC, SIEM, compliance (Team+)MCP audit_export, audit_query, siem_export
8RetireUninstall, deprecateMCP uninstall_skill; CLI remove

Quick Reference: MCP Tools

ToolStageUse whenExample prompt
searchDiscoverFinding skills by keyword/category/trust tier"Use Skillsmith to search for testing skills"
skill_recommendDiscoverContextual recommendations"Ask Skillsmith to recommend skills for my React project"
get_skillEvaluateFull details for a known skill"Use Skillsmith to show details for community/jest-helper"
skill_compareEvaluateSide-by-side comparison"Use Skillsmith to compare jest-helper and vitest-helper"
skill_diffEvaluateDiff two installed versions"Use Skillsmith to diff jest-helper versions"
install_skillInstallAdd a skill to your runtime"Use Skillsmith to install jest-helper"
skill_validateInstallPre-install validation of SKILL.md"Use Skillsmith to validate ./my-skill"
skill_updatesMaintainCheck for available updates"Ask Skillsmith for updates to my installed skills"
skill_outdatedMaintainList skills behind latest"Use Skillsmith to show outdated skills"
skill_inventory_auditMaintainNamespace-collision audit (Team+)"Use Skillsmith to audit my skills inventory"
audit_export / audit_query / siem_exportGovernCompliance + SIEM (Enterprise)"Use Skillsmith to export audit logs for last 30 days"
uninstall_skillRetireRemove an installed skill"Use Skillsmith to uninstall jest-helper"

Triggering tip: prefix natural-language prompts with Use Skillsmith to ... or Ask Skillsmith for .... The product-name anchor binds tool selection reliably across MCP-capable runtimes.

Routing CLI-only Operations

Some lifecycle operations live in the CLI and have no MCP equivalent (yet). When the user asks for these, surface the exact terminal command:

OperationCLI command
Pin a skill to a versionskillsmith pin <skill> <version>
Unpin a skillskillsmith unpin <skill>
Update all installed skillsskillsmith update --all
Audit advisories (Team+)skillsmith audit advisories
Audit collisionsskillsmith audit collisions
Configure audit modeskillsmith config set audit_mode <preventative|power_user|governance|off>
Author a new skillskillsmith author init <name>
Publish a skillskillsmith author publish
Loginskillsmith login

Always show the command verbatim with a one-line note: "Run this in your terminal."

Cross-Runtime Behavior

Skillsmith's MCP server works in any MCP-capable agent runtime:

  • Claude Code — default runtime. Skills install to ~/.claude/skills/.
  • Cursor / Copilot / Windsurf — set SKILLSMITH_CLIENT=<runtime> in your MCP server env config to install to the runtime-equivalent path. See Getting Started.
  • Custom MCP routers — universal MCP tool calls work; skill-file install paths configurable via SKILLSMITH_CLIENT.

Trust Tiers

Skills are categorized by verification level:

TierBadgeMeaningWhen to Trust
VerifiedGreen checkmarkOfficial Skillsmith / AnthropicAlways safe
CuratedBlue badgeVendor-org publisher, ≥0.80 qualityGenerally safe
CommunityYellowSecurity scan + required metadataReview before install
ExperimentalOrangeBeta / newUse cautiously
UnknownRed warningNo verificationOnly if you trust the author

For criteria detail, see https://skillsmith.app/docs/trust-tiers.

Pricing & Quotas

TierAPI calls/monthPrice
Community1,000Free
Individual10,000$9.99/mo
Team100,000$25/user/mo
EnterpriseUnlimited$55/user/mo

Usage warnings at 80% and 90%. Upgrade at https://skillsmith.app/upgrade.

Security Model

Skillsmith is the security boundary between untrusted skill sources and your runtime.

What Skillsmith validates before install:

  • SKILL.md frontmatter and required fields
  • Security scan: jailbreak patterns, suspicious URLs, sensitive file access
  • Typosquatting check against known skills
  • Blocklist of known-malicious skills

What Skillsmith cannot prevent:

  • Novel attack patterns not in detection database
  • Social engineering in legitimate-looking instructions
  • Runtime behavior (skills execute with your permissions)

Recommendation: review skill content before installation, especially for unverified skills.

Creating Skills

Skill authoring lives in the CLI:

skillsmith author init my-new-skill
skillsmith author validate
skillsmith author publish

For an end-to-end walkthrough, see https://skillsmith.app/docs/tutorials/author.

The companion skill-builder skill guides you through frontmatter, progressive disclosure structure, and directory organization. Install it with skillsmith install skill-builder (it's not bundled by default).

Common Workflows

Discover then install

"Use Skillsmith to recommend skills for my Next.js project"
"Use Skillsmith to install community/next-helper"

Evaluate before installing

"Use Skillsmith to compare jest-helper and vitest-helper"
"Use Skillsmith to show details for community/vitest-helper"
"Use Skillsmith to install community/vitest-helper"

Maintain installed skills

"Ask Skillsmith for updates to my installed skills"
# Then run in terminal:
skillsmith update --all

Audit before sharing your skill folder

"Use Skillsmith to audit my skills inventory"
# Or in terminal:
skillsmith audit collisions

License

Skillsmith uses Elastic License 2.0:

  • Self-host for internal use ✓
  • Modify for your own use ✓
  • Offer Skillsmith as a managed service to others ✗
  • Circumvent license key functionality ✗

Getting Help

Keep looking

Skills are one crate of 328,083. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.