
Security News
upm Launches as a Fast, Tiny Package Manager Written in TypeScript
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.
@cleocode/skills
Advanced tools
CLEO skill definitions - bundled capabilities for AI agents.
This package contains pre-built skills and capabilities that extend CLEO agents with specialized functionality. Skills define what an agent can do and how it should do it.
Skills are modular capability packages that:
npm install @cleocode/skills
pnpm add @cleocode/skills
yarn add @cleocode/skills
Tiers and install behaviour come from each SKILL.md's metadata (owner decision
D11157). packages/skills/skills/manifest.json is generated from them by
node scripts/skills/generate-manifest.mjs; gates 29-31 keep the manifest,
installability and every documented cleo command honest.
| Skill | Purpose |
|---|---|
| ct-cleo | CLEO task management protocol - session, task, and workflow guidance. |
| ct-dev-workflow | Development workflow orchestration for task-driven development with atomic commits, conventional commit messag… |
| ct-documentor | Documentation coordinator with CLEO style guide compliance. |
| ct-lead | Phase Lead orchestration playbook for spawning and supervising a parallel worker swarm in one wave. |
| ct-orchestrator | Pipeline-aware orchestration skill for managing complex workflows through subagent delegation. |
| ct-task-executor | General implementation task execution for completing assigned CLEO tasks by following instructions and produci… |
| Skill | Purpose |
|---|---|
| ct-adr-recorder | Records Architecture Decision Records from accepted consensus verdicts. |
| ct-artifact-publisher | Builds and publishes artifacts to registries (npm, PyPI, cargo, docker, GitHub releases, generic tarballs) fol… |
| ct-codebase-mapper | Orient in an unfamiliar or large codebase with CLEO's code-intelligence graph (cleo nexus) and project map (cl… |
| ct-consensus-voter | Runs structured multi-agent voting for decision tasks with confidence scores, conflict detection, and HITL esc… |
| ct-contribution | Guided workflow for multi-agent consensus contributions. |
| ct-council | Convene "The Council" — a 5-advisor, shuffled gate-based peer-review, chairman-synthesis workflow for reviewin… |
| ct-epic-architect | Epic planning and task decomposition for breaking down large initiatives into atomic, executable tasks. |
| ct-ivt-looper | Runs a project-agnostic autonomous Implement-then-Validate-then-Test compliance loop on any git worktree. |
| ct-provenance-keeper | Generates in-toto v1 attestations, SLSA-level provenance records, SBOMs (CycloneDX or SPDX), and sigstore/cosi… |
| ct-release-orchestrator | Orchestrates the canonical 4-verb release pipeline introduced by SPEC-T9345: cleo release plan, then cleo rele… |
| ct-research-agent | Multi-source research and investigation combining web search, documentation lookup via Context7, and codebase … |
| ct-spec-writer | Technical specification writing using RFC 2119 language for clear, unambiguous requirements. |
| ct-validator | Compliance validation for verifying systems, documents, or code against requirements, schemas, or standards. |
| Skill | Purpose |
|---|---|
| ct-grade | CLEO session grading and A/B behavioral analysis with token tracking. |
| ct-skill-author | Create, improve and validate CLEO skills. |
Merged or retired in T12649: ct-docs-write and ct-docs-review are references of ct-documentor; ct-memory and ct-stickynote are references of ct-cleo; ct-skill-creator and ct-skill-validator became ct-skill-author; ct-docs-lookup (use the Context7 MCP) and ct-master-tac were retired; signaldock-connect moved to the SignalDock repository.
Each skill follows a standardized structure:
skills/
├── <skill-name>/
│ ├── SKILL.md # Main skill definition (required)
│ ├── README.md # User documentation (optional)
│ ├── INSTALL.md # Installation guide (optional)
│ ├── agents/ # Specialized agent definitions
│ │ ├── analyzer.md
│ │ └── executor.md
│ ├── references/ # Reference documentation
│ │ ├── patterns.md
│ │ └── examples.md
│ └── assets/ # Assets and templates
│ └── template.md
# Load a skill
cleo skills load ct-research-agent
# Use skill with a task
cleo skills apply ct-research-agent --task T1234
# List available skills
cleo skills list
# Show skill details
cleo skills show ct-research-agent
import { skills } from '@cleocode/core';
// Load a skill
const skill = await skills.load('ct-research-agent');
// Apply skill to a task
await skills.apply({
skill: 'ct-research-agent',
taskId: 'T1234',
context: { topic: 'API design patterns' }
});
// Get skill information
const info = await skills.get('ct-codebase-mapper');
console.log(info.description);
console.log(info.capabilities);
Skills are automatically injected when spawning agents:
import { orchestration } from '@cleocode/core';
// Skill is injected based on task context
await orchestration.spawn({
agent: 'cleo-subagent',
taskId: 'T1234',
skill: 'ct-implementation' // Injected at spawn
});
Skills are defined in SKILL.md files with YAML frontmatter:
---
id: ct-example-skill
name: Example Skill
description: |
Multi-line description of what this skill does
and when to use it.
version: 1.0.0
author: CLEO Team
tags:
- development
- example
dependencies:
- ct-cleo
allowed_tools:
- Read
- Write
- Bash
- Glob
- Grep
- WebFetch
- WebSearch
---
# Example Skill
## Overview
Detailed explanation of the skill's purpose and usage.
## Capabilities
- **Capability 1**: Description
- **Capability 2**: Description
## Workflow
1. **Step 1**: Description
2. **Step 2**: Description
3. **Step 3**: Description
## Constraints
| ID | Rule | Enforcement |
|----|------|-------------|
| EX-001 | **MUST** follow constraint | Required |
| EX-002 | **SHOULD** consider guideline | Recommended |
## Examples
### Example 1: Basic Usage
```bash
# Command example
# Advanced command example
## Creating Custom Skills
### 1. Create Skill Directory
```bash
mkdir -p skills/my-custom-skill
---
id: my-custom-skill
name: My Custom Skill
description: |
Description of what this skill does.
version: 1.0.0
author: Your Name
tags:
- custom
- specialized
allowed_tools:
- Read
- Write
- Bash
---
# My Custom Skill
## Purpose
Explain what this skill does and when to use it.
## Workflow
1. Analyze the task
2. Execute the work
3. Validate the output
## Output Format
Describe expected output format.
import { skills } from '@cleocode/core';
skills.register({
id: 'my-custom-skill',
path: './skills/my-custom-skill',
version: '1.0.0'
});
Validate skills before distribution:
# Validate a skill
cleo skills validate my-custom-skill
# Or programmatically
import { skills } from '@cleocode/core';
const result = await skills.validate('my-custom-skill');
if (result.valid) {
console.log('Skill is valid ✓');
} else {
console.log('Issues:', result.issues);
}
Skills are organized by category:
Skills can depend on other skills:
# In SKILL.md frontmatter
dependencies:
- ct-cleo # Base CLEO operations
- ct-research-agent # Research capabilities
- ct-validator # Validation support
Dependencies are automatically loaded when a skill is applied.
Skills can be chained together:
import { skills } from '@cleocode/core';
// Chain multiple skills
await skills.chain([
{ skill: 'ct-research-agent', taskId: 'T1234' },
{ skill: 'ct-spec-writer', taskId: 'T1235' },
{ skill: 'ct-epic-architect', taskId: 'T1236' }
]);
Group skills into profiles for different roles:
# profiles/backend-developer.yaml
name: Backend Developer
skills:
- ct-codebase-mapper
- ct-research-agent
- ct-spec-writer
- drizzle-orm
- ct-dev-workflow
Use profiles:
cleo skills apply-profile backend-developer --task T1234
Common patterns and utilities in skills/_shared/:
manifest-operations.md - Working with pipeline_manifest via cleo manifest CLIsubagent-protocol-base.md - Base subagent protocolsskill-chaining-patterns.md - Chaining best practicestesting-framework-config.md - Test configurationtask-system-integration.md - Task system integrationcleo-style-guide.md - CLEO documentation styleSkills and agents work together:
Example:
Task: "Research authentication patterns"
↓
Orchestrator selects: ct-research-agent skill
↓
Spawns: cleo-subagent with ct-research-agent injected
↓
Agent follows LOOM protocol
↓
Skill guides research methodology
↓
Output: Research report written to file
This package has no runtime dependencies. It contains:
MIT License - see LICENSE for details.
FAQs
CLEO skill definitions - bundled with CLEO monorepo
The npm package @cleocode/skills receives a total of 1,595 weekly downloads. As such, @cleocode/skills popularity was classified as popular.
We found that @cleocode/skills demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.