# skillpack: a pack ships its own policy, not a server

> A command line tool that assembles AI skills into a runnable local agent, packages the result as a zip, and makes it reachable from Slack or Telegram. The archive is deliberately small: it holds skills, prompts, an optional persona and policy file, and two launcher scripts. The launchers resolve the tool from the package registry at run time, so a downloaded pack is not offline-capable, and one of the two example downloads is hosted in an unrelated organisation's repository.

**CreminiAI/skillpack** — Pack and deploy local AI agents for your team in minutes

- Repository: https://github.com/CreminiAI/skillpack
- Website: https://skillpack.sh
- Stars: 1,200 · Forks: 111
- Language: TypeScript
- License: MIT
- Published: 2026-09-10 · Updated: 2026-09-10 · Language: en
- Canonical page: https://hysenlabs.com/projects/creminiai-skillpack

## The downloaded pack is not self-contained, and the launcher says why

The packaging section states that the archive is intentionally lightweight, and then gives the reason in the same paragraph. The two launcher scripts, one for Unix-like systems and one for Windows, are thin wrappers that invoke the published command against the current directory, so the only prerequisite is a Node runtime at a stated patch level. No server directory is bundled with the pack. That makes a downloaded zip something you cannot run offline: the first launch resolves the package from the registry before any of it executes. Everything the page claims about data staying on your own machine still holds, because the data lives in the pack and the runtime is code rather than content, but the distinction is worth holding onto. A team that assumes a zip is a deployable artefact will find the first run needs the network, and a machine without one needs the package staged beforehand.

## A pack carries its own policy and persona and ignores the host machine's

Two optional files in the archive do something the agent would otherwise take from the machine it runs on. The agent-instructions file is described as pack policy and the second as pack persona, and both are read when a new chat session starts and injected into the runtime system prompt. What makes this a decision rather than a feature is the clause at the end. The page says it happens without depending on the host machine's own agent-instructions file, its own system file under a dot-prefixed directory, or its append-system file. So a pack's behaviour does not inherit from the machine that happens to run it. For a team distributing packs that is the right default, since one person's local customisation cannot quietly change what a colleague's pack does. It also means a pack author cannot tune a pack for a single user without editing the pack itself.

## Scheduled jobs travel inside the archive

One optional file defines scheduled jobs, and the page says those jobs travel with the pack and are loaded by the scheduler at run time. The dependency list confirms the mechanism, since a cron library is among the runtime dependencies. So a pack is more than a bag of skills and prompts: it can carry a schedule with it, which means a distributed pack is also a distributed timer. The page does not discuss what that implies. Nothing explains which key a scheduled job authenticates with, whose configuration it reads, or what happens when two people install the same pack and both schedules fire. Anyone handing a pack containing jobs to a team is distributing recurring work to every machine that installs it, and that is worth finding out about before rather than after the first run.

## Skills are addressed by repository shorthand plus a name

Adding a skill takes one of three source forms and each takes a flag naming which skill inside it:

```bash
# GitHub shorthand
vercel-labs/agent-skills --skill frontend-design

# Full GitHub URL
https://github.com/JimLiu/baoyu-skills/tree/main/skills --skill baoyu-comic

# Local path
./skills/my-local-skill
```

Several names from one source can be listed comma-separated. So the addressing scheme is native to the source host rather than a registry of this project's own: a pack is a list of references to skills other people publish, and the tool's own repository carries a skills directory and a lock file for the same reason. The local path form is the escape hatch and the reason a pack can be forked without a pull request, since you can point at a directory you edited. That is also why the packaging step has a flag for using the skills already present in the directory rather than reinstalling them.

## One of the two example downloads is hosted in another organisation

The instructions for running a pack give two download links, and both are versioned release assets. One comes from this project's own examples repository. The other, the deep research pack that the use-case section also points at, comes from a repository under a completely different organisation, a downloads repository rather than a source one. So the recommended first action for a new user involves fetching a zip from an organisation the reader has no other relationship with, and the page offers no checksum, no signature, and no explanation of who maintains that repository or what else is published in it. On a tool whose pitch is that you can trust what runs on your own machine, that is the detail to check first. The other example is named after a person rather than a task, which suggests it is a demonstration of the format rather than something to do work with.

## The dependency list ships a chat platform SDK with no documented integration

Fourteen runtime dependencies, and two of them name a chat platform directly: a framework for Slack and a Telegram bot library, both of which have setup pages on the documentation site that state how long getting the two tokens should take. A third dependency is an SDK for a different collaboration platform, and no integration page for it appears anywhere on the page. The rest of the list is generic infrastructure, and it maps cleanly onto what the tool does. A schema validator and a type definition library together are how a pack configuration gets checked. A zip archiver is the packaging step. A terminal styling library and an argument parser are the command line. A web framework and a websocket library are the local server the browser interface runs on. An interactive prompt library is the create command. A cron library is the scheduler. So a platform integration exists in the shipped code that the documentation does not describe.

## A patch-level Node floor, and the examples are not in the published package

The manifest states an exact Node patch level as its engine requirement, and the pack documentation repeats the same number rather than naming a major version. That is unusually strict for a tool whose audience wants it working today, and the consequence is that a machine on an earlier patch of the same major version fails the check. The published file list is four entries plus the two documents: the build output, a web directory, a templates directory, the readme and the licence. The examples directory is not among them, which is why the documentation points at one example configuration by its raw URL on the main branch rather than expecting it inside the installed package. Two build details are worth knowing as well. The prepare script runs the build, and three of the named scripts each rebuild before running, so the tool is expected to be run from source or through a freshly built copy.

## Conclusion

Skillpack fits a team that wants agents running on machines it controls rather than on someone else's servers, and that wants to hand colleagues a single file. The pack format is the interesting part: a pack carries its own policy and persona rather than inheriting the host machine's, which is the right default for something you distribute. Three things to check before you hand packs around. A downloaded zip is not self-contained, because the launcher resolves the tool from the package registry on first run, so plan for network access or stage the package yourself. One of the two example downloads comes from a repository under an unrelated organisation, with no checksum and no signature. And a pack can carry scheduled jobs, which means a distributed pack is also a distributed timer whose authentication and key usage the documentation does not explain.

## FAQ

### What is SkillPack and what does it do?

It is a command line tool that packages AI skills into runnable local agents. A pack bundles skills plus prompts telling the agent how to orchestrate them, runs on your own machine rather than a hosted service, and can be reached from Slack or Telegram. The tool's own framing is that skills are the parts and a pack is the assembled product.

### Can I run a downloaded SkillPack offline?

Not on the first run. The archive is described as intentionally lightweight, and the two launcher scripts invoke the published package against the current directory rather than bundling a server directory. Node.js 22.19.0 or newer is the only stated prerequisite, which means the tool itself is resolved from the package registry when the launcher runs.

### What files does a packaged SkillPack contain?

A pack configuration file, an installed skills directory, and the two launcher scripts, plus three optional files. An optional jobs file defines scheduled tasks that travel with the pack and load at run time. An optional policy file and an optional persona file are read when a chat session starts and injected into the system prompt, independently of the host machine's own instruction files.

### How do I add skills to a SkillPack?

Three source forms are accepted: an owner and repository shorthand, a full repository URL pointing at a subdirectory, or a local path. Each takes a skill flag naming which skill in that source, and several names from one source can be given comma-separated. There is also a packaging flag for reusing skills already present in the directory instead of reinstalling them.

### Which chat platforms does SkillPack integrate with?

Slack and Telegram are the two documented integrations, each with a setup page covering obtaining the required tokens. The dependency list also includes an SDK for a third collaboration platform with no integration page on the site, so the shipped code appears to cover more than the documentation describes.

## Sources

- [CreminiAI/skillpack on GitHub](https://github.com/CreminiAI/skillpack)
- [Issues](https://github.com/CreminiAI/skillpack/issues)
- [License: MIT](https://github.com/CreminiAI/skillpack/blob/main/LICENSE)
- [Project website](https://skillpack.sh)
- [README](https://github.com/CreminiAI/skillpack/blob/main/README.md)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/creminiai-skillpack
