A skill is instructions your agent will follow with your credentials and your codebase. Installing one is a supply-chain decision, not a download — treat external skills with the care given to dependencies, plus the care given to prompts.
When to use
- Installing a skill from any source outside the team's own library
- Updating installed skills, or reviewing a repo's installed set
- A client repo arrives with skills nobody remembers installing
Rules
- Read the whole skill before installing — every file in the skill directory, not just the description. You are auditing for: instructions to exfiltrate data, fetch and follow remote content, run opaque scripts, or weaken safety behavior. A skill that tells the agent to obey text it downloads is malware with frontmatter.
- Pin what you install. Install by commit SHA where the tooling supports it
(the
skillsCLI does), so an upstream edit can't silently change your agent's instructions tomorrow. - Commit the lockfile alongside the skills so every machine and teammate runs the same versions, and restores are reproducible.
- Updates are re-reviews. Diff the skill body on every update before accepting — the risk profile of an update equals a fresh install, and a popular skill is a popular target.
- One source of truth per repo. Skills come from the team library or a pinned external source — not ad-hoc pastes that bypass both review and updates.
- Prune on a cadence: uninstall skills nothing has used; every installed skill is standing instructions competing for the agent's attention.
Client repos
- Install only skills the client's workspace approved; record source and SHA in the repo (the lockfile does this) so the client can audit what instructs their agents.
- Never install a skill that phones home to a third party from a client repo without the client's explicit sign-off — their data flows are theirs to approve.
Examples
Good: "Installed review-checklist from <source> @ 4f2a9c1 (read: clean), lockfile
committed; update diffs reviewed before accepting."
Bad: npx skills add <whatever-the-leaderboard-shows> -y — unread instructions now
run with repo access on every machine that clones.