Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Skill Authoring

ASecurity

Use when creating or editing any skill: frontmatter rules (name/description), folder structure, script bundling, quality checklist — including converting the current session/procedure/URL into a new reusable skill ("learn", "/learn", "turn this session into a skill", "make a skill from this workflow", "сделай скилл из этой процедуры", "навык из"). Per the Agent Skills specification (Hermes-compatible).

3 stars
0 votes
0 copies
1 views
Added 9/22/2026
ai-agentsgo

Security Analysis

A100/100

Pro scans all 2 files and shows the line behind each finding

Scanned 10/6/2026

$npx -y skills add oleg494/coding-kit --skill skill-authoring --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Skill Authoring?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Skill Authoring
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/oleg494-skill-authoring/badge)](https://www.skillsdirectory.com/skills/oleg494-skill-authoring)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: skill-authoring
description: 'Use when creating or editing any skill: frontmatter rules (name/description), folder structure, script bundling, quality checklist — including converting the current session/procedure/URL into a new reusable skill ("learn", "/learn", "turn this session into a skill", "make a skill from this workflow", "сделай скилл из этой процедуры", "навык из"). Per the Agent Skills specification (Hermes-compatible).'
license: MIT
compatibility: applies to skills/ in this set, ~/.hermes/skills, .claude/skills
metadata:
  version: "4.7.0"
---

# How to author skills correctly

A set of rules based on the Agent Skills specification + practice. Verified against real skills.

## 1. Frontmatter (required fields)

```markdown
---
name: my-skill
description: Use when [triggers/symptoms/contexts]. [what it does + when to apply]
---
```

| Field | Rule |
|---|---|
| `name` | REQUIRED. 1–64 characters, `a-z0-9` + hyphens. **Must match the skill's folder name** |
| `description` | REQUIRED. 1–1024 characters. «What it does + when to use»; include the keywords the agent searches by. NOT a workflow summary |
| `license` | optional |
| `compatibility` | 1–500 characters, only if there are environment requirements |

## 2. Directory structure

```
skill-name/
├── SKILL.md            # required
├── scripts/            # optional: executable scripts
├── references/         # optional: details, «read when X»
├── assets/             # optional
└── any other files/folders — allowed
```

- From SKILL.md reference files with **relative paths from the skill root**.
- Progressive disclosure: SKILL.md < ~500 lines; details go into `references/` with a pointer «read this when X happens».

## 3. Script bundling (scripts/)

1. **First check for an existing tool**: `npx`, `uvx`, `pipx`, `bunx` — take an existing one, write your own only when none exists.
2. If you bundle a script, it must be **self-contained**: document dependencies in SKILL.md or `compatibility`.
3. **Agent-safe design:**
   - NO interactive prompts — the agent will hang on a TTY. Input only via arguments.
   - `--help` with usage; clear error messages.
   - Structured output: result to stdout, diagnostics to stderr.
   - Idempotency; `--dry-run` for destructive operations.
   - Predictable output size (agents truncate ~10–30K characters).

## 4. Best practices and antipatterns

**Do:**
- Small, composable, like a function: one coherent task.
- Description in the imperative: «Use when …», list the triggers. Agents under-trigger.
- Add what the agent does not know; drop what it already can do.
- `Gotchas` sections — the most valuable content; checklists for multi-step processes; output templates.
- Defaults, not menus; procedures, not declarations; explain «why».
- Calibrate detail to fragility: for fragile operations — prescriptively.

**Do not:**
- Do not stuff code into SKILL.md — move it to `scripts/`.
- Do not describe the workflow in `description`.
- Do not give many equal options without a default.
- Do not generate generic content without subject knowledge.

## 5. New skill template

```markdown
---
name: my-skill
description: Use when [symptoms/contexts]. [what it does + when to apply, 1–1024 chars.]
license: MIT               # optional
compatibility: Requires X  # optional
---
# What it does (1–2 sentences)

## When to use / when NOT to use
## Workflow (numbered, imperative)
## Gotchas
## Available scripts (relative paths from the skill root)
## References (pointers «read when X»)
```

## 6. Turning a session into a skill (the former /learn flow)

The raw material is what happened in this chat (or a named directory/procedure/URL) — not a skill-format question, and not a conclusion to remember (that is dev-wiki/findings).

1. **Isolate the repeatable procedure.** What did you actually do that a fresh session would have to rediscover? Steps in order, with the "why" behind non-obvious decisions. One-off facts are NOT skills → memory instead; general knowledge the agent already has is NOT a skill (YAGNI).
2. **Trigger test before writing.** In a fresh session, would the description fire for the natural phrase a user would say? No plausible trigger → stop, don't write it. The description is the only thing a future session sees.
3. **Draft SKILL.md** by the rules above: numbered imperative procedure, defaults (not menus), gotchas — the most valuable section.
4. **Choose the location.** Portable (any machine/project) → kit `skills/<slug>/`, subject to English, file-size and review checks. Machine/user-specific → the harness's user skills dir (e.g. `~/.claude/skills/`), which does not propagate. Creating a skill does not itself authorize a commit or deployment to installed harnesses; apply AGENTS.md action authorization.
5. **Verify and candidate state before broad promotion.** Frontmatter delimiters, `name` == folder, description within limits; trigger test against the natural phrase. A newly distilled procedure starts as a candidate:
   - **Promotion criteria:** promotion to default or mandatory policy requires replaying the originating case, at least one nearby negative case (where the procedure must NOT fire or alter behavior), and at least one held-out case.
   - **Retirement criteria:** skills are evaluated and retired by post-install opportunity/use and measurable contribution to correct outcomes, not raw read counts.
Gotchas: don't over-generalize — encode the procedure that exists, not the class of procedures; Russian belongs only in trigger words; scripts stay in `scripts/`, never inline; a skill that was wrong once is fixed like code — edit + verify against the same case.

Attribution

oleg494oleg494
View sourceSee grades on GitHubMore from oleg494 →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Caveman

Terse caveman voice: answer first, fluff gone, every technical fact kept. Use for /caveman, "caveman mode", "talk like caveman", "be brief", "less tokens". Stays on until "stop caveman" or "normal mode".

1100021 votes

Hyperplan

Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...

698431 votes

Writing Skills

Create and manage Claude Code skills in HASH repository following Anthropic best practices. Use when creating new skills, modifying skill-rules.json, understanding trigger patterns, working with hooks, debugging skill activation, or implementing progressive disclosure. Covers skill structure, YAML frontmatter, trigger types (keywords, intent patterns), UserPromptSubmit hook, and the 500-line rule. Includes validation and debugging with SKILL_DEBUG. Examples include rust-error-stack, cargo-dep...

3931 votes

Mcp Code Execution

Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.

3421 votes

catchup

Recovers the conversation and failed tool calls of a previous Codex, Amp, Claude Code, Antigravity, Cline, Copilot CLI, Cursor, DeepSeek Harness, Grok Build, Kimi, OpenCode, Pi Agent, or ZCode session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", asks to recover/summarize a previous session before continuing, or asks to diagnose or report a catchup failure. Do NOT use for the current conversation, git history, or any non-agent log.

741 votes
View all in ai-agents →