Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsCommunityBlog
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Update Global Dotlas Skills

ASecurity

Sync the globally-installed dotlas/skills catalog and prune stale remnants. Runs the documented global install command, then detects skills that were installed from dotlas/skills but no longer exist in the catalog and removes them (with confirmation). Use when the user wants to update, refresh, or clean up their global Dotlas skills, or invokes /update-global-dotlas-skills.

2 stars
0 votes
0 copies
0 views
Added 9/22/2026
ai-agentspythongogit

Works with

cli

Security Analysis

A100/100

Scanned 9/22/2026

Install to Claude Code

$npx -y skills add dotlas/skills --skill update-global-dotlas-skills --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Update Global Dotlas Skills?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Update Global Dotlas Skills
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/dotlas-update-global-dotlas-skills/badge)](https://www.skillsdirectory.com/skills/dotlas-update-global-dotlas-skills)

More formats (shields.io, HTML) on the badges page.

Download with Pro
Files
SKILL.md
---
name: update-global-dotlas-skills
description: Sync the globally-installed dotlas/skills catalog and prune stale remnants. Runs the documented global install command, then detects skills that were installed from dotlas/skills but no longer exist in the catalog and removes them (with confirmation). Use when the user wants to update, refresh, or clean up their global Dotlas skills, or invokes /update-global-dotlas-skills.
---
# Update the global Dotlas skills

Bring the machine’s **global** skill install back in line with the current
[`dotlas/skills`](https://github.com/dotlas/skills) catalog: install/refresh everything
in the catalog, then remove **remnants** — skills that were installed from
`dotlas/skills` but have since been renamed or dropped from the catalog.
`npx skills add` never prunes, so remnants accumulate silently.

Run one **spine**: **locate lock → sync → build catalog truth-set → diff for stale →
confirm → remove → report**.

Two hard rules, both from [INTERNAL.md](../../../../INTERNAL.md):

- **Agent scope is always `-a claude-code`.** Never `-a '*'` — not for install, not for
  removal.
- **Only ever touch skills whose lock `source` is `dotlas/skills`.** Skills installed
  from any other owner (`mattpocock/skills`, `LottieFiles/...`, etc.)
  are out of scope and must never be removed, even if they look unfamiliar.

## 1. Locate the global lock file

The global manifest is **`~/.agents/.skill-lock.json`** (note the leading dot; version 3
schema). This is *not* the per-project `skills-lock.json`. If it is missing, the machine
has no global skills installed — report that and stop; there is nothing to sync or
prune.

```sh
LOCK="$HOME/.agents/.skill-lock.json"
test -f "$LOCK" || echo "No global lock at $LOCK — nothing to do."
```

Each entry looks like:
`{"source": "dotlas/skills", "skillPath": "...", "updatedAt": "...", ...}` keyed by the
skill’s frontmatter `name:`.

## 2. Sync the catalog globally

Run the documented global install.
`-s '*'` installs every current catalog skill (picking up newly-added ones and
refreshing existing ones):

```sh
npx skills add dotlas/skills -s '*' -a claude-code -g -y
```

## 3. Build the catalog truth-set

The lock is the record of what is *installed*; it does not know what the catalog *now
contains*. Get the authoritative current list by shallow-cloning the catalog into
scratch and reading every skill’s frontmatter `name:` (this is the identity the lock
keys on — folder names can differ):

```sh
git clone --depth 1 https://github.com/dotlas/skills "$SCRATCH/catalog"
```

## 4. Diff the lock against the catalog for stale skills

**Stale** = a lock entry whose `source` is `dotlas/skills` **and** whose key is absent
from the catalog truth-set.
Use this snippet (edit `$SCRATCH` to the real path):

```sh
python3 - "$HOME/.agents/.skill-lock.json" "$SCRATCH/catalog" <<'PY'
import json, os, re, sys
lock_path, catalog_root = sys.argv[1], sys.argv[2]

# catalog truth-set = frontmatter name: of every SKILL.md in the fresh clone
catalog = set()
for root, _, files in os.walk(os.path.join(catalog_root, "skills")):
    if "SKILL.md" in files:
        with open(os.path.join(root, "SKILL.md")) as f:
            m = re.search(r"^name:\s*(.+)$", f.read(), re.M)
            if m:
                catalog.add(m.group(1).strip())

lock = json.load(open(lock_path))["skills"]
dotlas = {k for k, v in lock.items() if v.get("source") == "dotlas/skills"}
stale = sorted(dotlas - catalog)

print(f"catalog skills: {len(catalog)}")
print(f"dotlas-sourced global skills: {len(dotlas)}")
print("STALE (dotlas-sourced, no longer in catalog):")
for s in stale:
    print("  -", s)
PY
```

**Guard against false positives.** If the clone failed, the catalog set is tiny/empty,
or the stale list contains *most* of the dotlas-sourced skills, something went wrong
(bad clone, layout change) — **do not delete**. Report the anomaly and stop.

## 5. Confirm, then remove

Show the user the exact stale list.
**Wait for explicit confirmation before removing anything.** On approval, remove each
stale skill — one call per skill, scoped to `claude-code`:

```sh
npx skills remove -g -a claude-code -s <name> -y
```

The skill name **must** go behind `-s` — passed positionally the CLI mis-reads it as an
agent name and fails.

If the list is empty, say so and skip this step.

## 6. Report

Summarise: catalog skills synced, and each stale skill removed (or “none — global
install already matched the catalog”). Leave non-`dotlas/skills` skills untouched and
unmentioned.

Attribution

dotlasdotlas
View sourceMore from dotlas →
SSkills DirectorySkills Directory

Your tool, in front of Claude Code builders.

3 founder slots · $299/mo · GSC-verified traffic · sponsors can never buy grades.

See placements

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Your tool, in front of Claude Code builders.

3 founder slots · $299/mo · GSC-verified traffic · sponsors can never buy grades.

See placements

Related Skills

Caveman

Ultra-compressed communication mode that cuts output tokens while keeping technical accuracy. Levels: lite, full, ultra and the wenyan variants. Use for /caveman, "caveman mode", "talk like caveman", "be brief" or "less tokens".

1074701 votes

Hyperplan

Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...

693621 votes

Mcp Code Execution

Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.

3351 votes

catchup

Recovers the conversation and failed tool calls of a previous Codex, Claude Code, Antigravity, Cline, Copilot CLI, Cursor, DeepSeek Harness, Kimi, OpenCode, Pi Agent, or ZCode session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", asks to recover/summarize a previous session before continuing, or asks to diagnose or report a catchup failure. Do NOT use for the current conversation, git history, or any non-agent log.

691 votes

math-skill

A comprehensive mathematical reasoning skill for AI assistants — handles arithmetic to research-level problems with rigorous step-by-step reasoning, systematic verification, and transparent uncertainty handling

381 votes
View all in ai-agents →