Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills Aโ€“Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Bluesky

ASecurity

Read and write Bluesky: view profiles and timelines, search posts, post, follow, read notifications. Trigger phrases: bluesky, atproto.

18 stars
0 votes
0 copies
1 views
Added 9/25/2026
toolsgobashapi

Works with

cliapi

Security Analysis

A100/100

Scanned 9/25/2026

$npx -y skills add gabrielmoreira/agent-skills-mirror --skill bluesky --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Bluesky?

Add the live security badge to your README โ€” it updates automatically with every re-scan.

Security grade badge for Bluesky
[![Security: A โ€” Skills Directory](https://www.skillsdirectory.com/api/skills/gabrielmoreira-bluesky/badge)](https://www.skillsdirectory.com/skills/gabrielmoreira-bluesky)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: "bluesky"
description: "Read and write Bluesky: view profiles and timelines, search posts, post, follow, read notifications. Trigger phrases: bluesky, atproto."
metadata: { "includeInPrompt": true }
tagline: "Read timelines, search posts, post and follow."
catalog_auth: "App password (per-account; session-based)"
catalog_hosts: ["bsky.social"]
---

# Bluesky

## Purpose
Read and write the user's Bluesky account through the AT Protocol (XRPC): view profiles and the home timeline, search posts, create posts, follow accounts, and list notifications. Use when the user mentions Bluesky or atproto.

## Tooling
All commands go through `bin/bluesky.py`. Every command takes a required `--handle` (the account handle, e.g. `me.bsky.social`):

```bash
bin/bluesky.py auth --handle me.bsky.social                  # verify the session
bin/bluesky.py profile --handle me.bsky.social               # view a profile (add --target to view someone else)
bin/bluesky.py timeline --handle me.bsky.social              # home timeline
bin/bluesky.py search --handle me.bsky.social --query "agents"  # search posts
bin/bluesky.py post --handle me.bsky.social --text "hello world"  # publish a post (confirm first)
bin/bluesky.py follow --handle me.bsky.social --target them.bsky.social  # follow an account (confirm first)
bin/bluesky.py notifications --handle me.bsky.social         # list notifications
```

The CLI resolves the account's PDS automatically (via `resolveHandle` + the DID document), caches the session at `.bluesky-session.json` next to the skill, and refreshes tokens transparently on 401.

## Auth
- Provider id: `bluesky` (credential is collected as `custom.bluesky`)
- Collection: a Bluesky app password via the secure credential flow (`credentials.request_api_access`); created in the Bluesky app under Settings > App passwords. Use an app password only, never the main account password.
- Allowed hosts: `bsky.social`, `public.api.bsky.app`, `plc.directory`, plus the account's resolved PDS host (added at runtime after resolution)
- Status check: `bin/bluesky.py auth --handle <your-handle>` (must return `"ok": true`)

## Operating Rules
1. `post` and `follow` are writes: confirm the exact text or target handle with the user before running, unless standing permission exists.
2. Reading (profile, timeline, search, notifications) needs no confirmation.
3. The session manager reuses cached tokens and refreshes on 401; it never calls `createSession` more than needed (rate cap 30/5min). Do not hammer endpoints; respect atproto rate-limit points.
4. Never exfiltrate the credential: the CLI only ever handles surrogates. Do not print, log, or transmit the key value.

## Files
- SKILL.md
- bin/bluesky.py

## Maturity
๐Ÿงช Draft: written from the AT Protocol's public API docs; not yet live-tested end-to-end.

Attribution

gabrielmoreiragabrielmoreira
View sourceSee grades on GitHubMore from gabrielmoreira โ†’
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

ucoz-landing-skill

Create and edit uCoz homepage landing pages via MCP: custom templates, hero sections, lead forms, navigation menus, SEO, and responsive layout. Includes a visual design system (style selection, layout/grid, section recipes, typography/spacing, color tokens, component states, icons, modern CSS/JS, motion, imagery, social proof, copy/voice, accessibility). Uses ucoz-mcp tools for templates, site file uploads, and site modules.

107 votes

Paperclip

Interact with the Paperclip control plane API for task coordination and governance. Use when checking assignments, updating issue status, posting comments, delegating work, managing routines, or calling Paperclip API endpoints.

953191 votes

Pptx

Presentation toolkit (.pptx). Create/edit slides, layouts, content, speaker notes, comments, for programmatic presentation creation and modification.

471861 votes

Daw Music

Digital Audio Workstation usage, music composition, interactive music systems, and game audio implementation for immersive soundscapes.

761 votes

Instantly Rdsthomas Mission Control

Instantly.ai cold email outreach API - manage campaigns, leads, accounts, and analytics. Use for cold email automation, lead management, campaign creation/monitoring, and email account warmup.

761 votes
View all in tools โ†’