← library
skill☀️ Prompt managementv1 · updated 2026-09-10

Skills Install Hygiene

Keeps third-party agent skills safe and reproducible in a repo — read before install, pin to commit SHAs, commit the lockfile, and re-review on update. Use when installing, updating, or auditing agent skills from any external source in any project.

Run it as a prompt

Paste this into any AI agent, or fetch it: curl -s https://uplift.page/api/v1/prompts/skills-install-hygiene/raw

prompt.md
# Skills Install Hygiene

A skill is instructions your agent will follow with your credentials and your
codebase. Installing one is a supply-chain decision, not a download — treat external
skills with the care given to dependencies, plus the care given to prompts.

## When to use

- Installing a skill from any source outside the team's own library
- Updating installed skills, or reviewing a repo's installed set
- A client repo arrives with skills nobody remembers installing

## Rules

1. **Read the whole skill before installing** — every file in the skill directory,
   not just the description. You are auditing for: instructions to exfiltrate data,
   fetch and follow remote content, run opaque scripts, or weaken safety behavior.
   A skill that tells the agent to obey text it downloads is malware with frontmatter.
2. **Pin what you install.** Install by commit SHA where the tooling supports it
   (the `skills` CLI does), so an upstream edit can't silently change your agent's
   instructions tomorrow.
3. **Commit the lockfile** alongside the skills so every machine and teammate runs
   the same versions, and restores are reproducible.
4. **Updates are re-reviews.** Diff the skill body on every update before accepting —
   the risk profile of an update equals a fresh install, and a popular skill is a
   popular target.
5. **One source of truth per repo.** Skills come from the team library or a pinned
   external source — not ad-hoc pastes that bypass both review and updates.
6. **Prune on a cadence**: uninstall skills nothing has used; every installed skill
   is standing instructions competing for the agent's attention.

## Client repos

- Install only skills the client's workspace approved; record source and SHA in the
  repo (the lockfile does this) so the client can audit what instructs their agents.
- Never install a skill that phones home to a third party from a client repo without
  the client's explicit sign-off — their data flows are theirs to approve.

## Examples

```text
Good: "Installed review-checklist from <source> @ 4f2a9c1 (read: clean), lockfile
       committed; update diffs reviewed before accepting."
Bad:  npx skills add <whatever-the-leaderboard-shows> -y  — unread instructions now
      run with repo access on every machine that clones.
```

Install it as a skill

Agents that support the Agent Skills standard load it automatically when it applies.

download
curl -fsSL https://uplift.page/p/skills-install-hygiene/SKILL.md --create-dirs -o .agents/skills/skills-install-hygiene/SKILL.md
or from any MCP client
MCP server: https://uplift.page/mcp
Tool: pull_skill  {"slug": "skills-install-hygiene"}

The full skill

A skill is instructions your agent will follow with your credentials and your codebase. Installing one is a supply-chain decision, not a download — treat external skills with the care given to dependencies, plus the care given to prompts.

When to use

  • Installing a skill from any source outside the team's own library
  • Updating installed skills, or reviewing a repo's installed set
  • A client repo arrives with skills nobody remembers installing

Rules

  1. Read the whole skill before installing — every file in the skill directory, not just the description. You are auditing for: instructions to exfiltrate data, fetch and follow remote content, run opaque scripts, or weaken safety behavior. A skill that tells the agent to obey text it downloads is malware with frontmatter.
  2. Pin what you install. Install by commit SHA where the tooling supports it (the skills CLI does), so an upstream edit can't silently change your agent's instructions tomorrow.
  3. Commit the lockfile alongside the skills so every machine and teammate runs the same versions, and restores are reproducible.
  4. Updates are re-reviews. Diff the skill body on every update before accepting — the risk profile of an update equals a fresh install, and a popular skill is a popular target.
  5. One source of truth per repo. Skills come from the team library or a pinned external source — not ad-hoc pastes that bypass both review and updates.
  6. Prune on a cadence: uninstall skills nothing has used; every installed skill is standing instructions competing for the agent's attention.

Client repos

  • Install only skills the client's workspace approved; record source and SHA in the repo (the lockfile does this) so the client can audit what instructs their agents.
  • Never install a skill that phones home to a third party from a client repo without the client's explicit sign-off — their data flows are theirs to approve.

Examples

Good: "Installed review-checklist from <source> @ 4f2a9c1 (read: clean), lockfile
       committed; update diffs reviewed before accepting."
Bad:  npx skills add <whatever-the-leaderboard-shows> -y  — unread instructions now
      run with repo access on every machine that clones.

Served from the uplift.page library and refreshed within 5 minutes of every update.