Model or dataset
tech-leads-club/agent-skills avatar
tech-leads-club/agent-skills

agent-skills: A Security-Vetted Skill Registry for AI Coding Agents

The secure, validated skill registry for professional AI coding agents. Extend Antigravity, Claude Code, Cursor, Copilot and more with absolute confidence.

7,014 stars558 forksTypeScriptNOASSERTION

At a glance

What is it?
agent-skills is an open-source registry that packages vetted, tested capabilities for AI coding tools including Claude Code, Cursor, and GitHub Copilot, addressing the security gap in an ecosystem where unreviewed third-party instructions are common.
Who is it for?
Teams using AI coding agents who cannot review every third-party skill file individually should use agent-skills. Projects that need custom, proprietary capabilities not in the catalog should evaluate whether the MCP server integration meets their needs before adopting the full package.
Can I use it commercially?
Check first. The repository uses a licence we do not classify automatically, so read its LICENSE file before any commercial use.
Is it still maintained?
Yes. The repository last received commits 10 days ago.
What is it written in?
Mainly TypeScript, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 29, 2026, and from our analysis. They are not legal advice.

Editorial analysis

The security problem agent-skills is designed to solve

AI coding agents accept instructions from skill files, and those files run with the permissions of your editor or shell session. The README cites an independent analysis finding that over 13% of marketplace skills contain critical vulnerabilities. A skill that tells an agent to execute a post-install script, read from an unexpected path, or modify a configuration file can cause real damage without any obvious sign.

agent-skills takes a different approach: every skill in the catalog goes through static analysis in CI/CD, is scanned with Snyk Agent Scan (formerly mcp-scan) before publishing, and uses an atomic lockfile and content hashing to make the published catalog immutable. The CLI itself applies defense-in-depth: input sanitization, path isolation, symlink guards, and an audit trail on every installation. No binaries ship; all skill files are plain text and open source, so the entire trust chain is inspectable.

How skills are structured inside the repository

Each skill lives under a category folder inside the packages/skills-catalog directory. The layout the README documents is:

code
packages/skills-catalog/skills/
  (category-name)/
    skill/
      SKILL.md
      templates/
      references/

SKILL.md contains the main instructions the agent reads at invocation time. The templates/ folder holds file templates the skill may emit, and references/ holds on-demand documentation the agent can load when it needs deeper context on a topic. This separation lets an agent fetch only what it needs rather than loading everything into context at once.

The catalog is versioned: the most recent release at the time of this review was skills-catalog-v0.17.9, published on 2026-09-18. The monorepo itself last pushed on 2026-09-20.

Installing agent-skills and adding skills to your project

The CLI requires Node.js 24 or newer, a hard constraint the engine field in package.json enforces. To start, run the interactive installer in your project directory:

bash
npx @tech-leads-club/agent-skills

This command presents a menu of available skills and writes the selected skill files into your project. The CLI's path isolation ensures that files land only in the expected directories and that symlinks are resolved before any write. Once a skill is installed, your AI agent picks it up on the next invocation according to that agent's own loading mechanism.

For Claude Code specifically, installed skills appear as slash commands or context files depending on the skill type. The README lists Claude Code in the Tier 1 (Popular) category alongside Cursor, Cline, GitHub Copilot, and Windsurf.

The MCP server for programmatic skill access

Beyond the CLI, agent-skills provides an MCP server that exposes the skill catalog through the Model Context Protocol. This lets an agent query available skills and fetch their content at runtime rather than having them pre-installed on disk. The development server starts with:

bash
npm run start:dev:mcp

The MCP server option is useful in environments where you cannot modify the project directory or where multiple projects share one skill catalog. The trade-off is that skill content arrives at inference time over a local connection rather than being available offline, which adds latency and a dependency on the server process being up.

Featured skills in the current catalog

The README highlights five skills as representative of what the catalog covers. tlc-spec-driven structures project planning into four phases: Specify, Design, Tasks, and Implement. It creates atomic tasks with verification criteria and maintains memory across sessions. aws-advisor provides architecture and security guidance backed by AWS MCP documentation. playwright-skill handles browser automation including form filling, screenshot capture, and UX validation. figma connects to Figma via MCP and translates design nodes into production code. security-best-practices performs language-specific vulnerability scans and proposes secure-by-default fixes.

These five come from four different categories: development, cloud, web-automation, and design. The full catalog spans additional categories not detailed in the README, accessible through the CLI menu or the documentation site at tech-leads-club.github.io/agent-skills.

All catalog skills go through the same Snyk Agent Scan gate before shipping, regardless of category. A skill that passes the scan is published with a content hash that the CLI verifies on install, so a compromised registry mirror cannot substitute a different file without the hash check catching it.

Where agent-skills is the wrong tool

The catalog does not include skills that require binary execution or that call external services with stored credentials. If your use case needs a skill that runs a compiled tool, makes authenticated API calls on behalf of the user, or interacts with a proprietary internal system, you will need to write that skill yourself outside the catalog.

The Node.js 24 requirement is a real barrier in enterprise environments that standardize on older runtimes. There is no downgrade path documented in the README. Projects running Node.js 20 or 22 cannot use the CLI without upgrading their environment first.

The registry is also opinionated about what counts as a safe skill. Skills that perform file operations outside the project directory, spawn subprocesses with elevated permissions, or prompt-inject through template expansion would fail the Snyk Agent Scan gate. Teams that need those capabilities will find the catalog's security model incompatible with their requirements.

Maintenance and license implications

The repository publishes under the MIT license, as the package.json declares. That permits commercial use, modification, and redistribution with attribution. The monorepo includes a SECURITY.md with a documented threat model and a vulnerability reporting channel.

Release cadence has been active: three catalog releases shipped in September 2026 alone (v0.17.7, v0.17.8, v0.17.9). The most recent commit was on 2026-09-20. Compared to ad-hoc skill marketplaces where individual contributors maintain skills independently, agent-skills centralizes security review, which means a discovered vulnerability in the scan tooling could temporarily block all catalog updates until the scanner is updated.

Editorial conclusion

Teams using AI coding agents who cannot review every third-party skill file individually should use agent-skills. Projects that need custom, proprietary capabilities not in the catalog should evaluate whether the MCP server integration meets their needs before adopting the full package. Verify that your environment runs Node.js 24 or newer before installing, since the CLI enforces that requirement at startup.

Frequently asked questions

How do I install agent-skills in Claude Code?

Run `npx @tech-leads-club/agent-skills` in your project directory. The CLI presents a menu of available skills and writes the selected files into your project, where Claude Code picks them up on the next invocation. Node.js 24 or newer is required.

How do I use agent-skills in Cursor?

Run the interactive CLI with `npx @tech-leads-club/agent-skills`, select the skills you want, and the installer writes them into your project directory. Cursor is listed as a Tier 1 supported agent, so installed skills are available immediately in the Cursor session.

How do I use agent-skills in GitHub Copilot?

The same `npx @tech-leads-club/agent-skills` command installs skills for GitHub Copilot. The CLI handles writing files to the correct locations; the README lists GitHub Copilot as a Tier 1 supported agent.

How do I install agent-skills?

Install using `npx @tech-leads-club/agent-skills` from your project directory. The command requires Node.js 24 or newer. The CLI guides you through skill selection and writes the chosen skill files into your project.

How do I use agent-skills in Antigravity?

The `npx @tech-leads-club/agent-skills` CLI supports Antigravity as a Tier 2 rising agent. Run it in your project directory, select the skills you need, and the installer places the files where Antigravity expects them.

Official sources

  1. Issues
  2. Project website
  3. README
  4. Releases
  5. tech-leads-club/agent-skills on GitHub
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/tech-leads-club-agent-skills.svg)](https://hysenlabs.com/projects/tech-leads-club-agent-skills)