
Security News
RubyGems Adds Cooldown Feature to Bundler for Newly Published Gems
RubyGems and Bundler 4.0.13 introduced an opt-in cooldown feature that delays newly published gems during dependency resolution.
@sysmanager/ai-skills
Advanced tools
Agent Skills Framework - Easy setup for AI agent capabilities and integrations (Claude, Gemini, Codex, GitHub Copilot)
Skills para turbinar seus agentes de codigo
AI Skills sao capacidades modulares que voce instala no seu projeto para estender AI agents (Claude, Gemini, Codex, GitHub Copilot). Cada skill adiciona integracoes, workflows e contexto que o agent pode usar.
npx @sysmanager/ai-skills install --skill ado-workflow --target claude
Pronto. Sem configuracao manual, sem copiar arquivos.
Instala skills no seu projeto.
# Direto, sem perguntas
npx @sysmanager/ai-skills install --skill ado-workflow --target claude
# Escolhe a skill interativamente
npx @sysmanager/ai-skills install --target claude
# Escolhe tudo interativamente (fallback)
npx @sysmanager/ai-skills install
Targets disponiveis: claude | codex | gemini | copilot
Lista todas as skills disponiveis no catalogo.
npx @sysmanager/ai-skills list
Remove todas as configuracoes de AI do projeto.
npx @sysmanager/ai-skills --clear
| Skill | Descricao | MCP |
|---|---|---|
ado-workflow | Workflow de desenvolvimento integrando work items do Azure DevOps com commits Git e gestao de estados | azure-devops |
git-cli | Operacoes Git universais — status, commits inteligentes, push seguro e sync completo | — |
skills/ e os templates MCP de mcps/.env com as variaveis necessarias| Target | Skills | Config MCP |
|---|---|---|
claude | .claude/skills/{id}/prompts/ | .mcp.json |
gemini | .gemini/skills/{id}/references/ | .gemini/settings.json |
codex | .codex/skills/{id}/references/ | .codex/config.toml |
copilot | .github/skills/{id}/references/ | .vscode/mcp.json |
skills/ # Fonte de verdade das skills
ado-workflow/
SKILL.md # Frontmatter + instrucoes
prompts/ # Templates de operacoes
git-cli/
SKILL.md
prompts/
mcps/ # Templates de servidores MCP
azure-devops.mcp.json
schemas/ # JSON Schema para validacao
src/ # TypeScript source
index.ts # Entry point do CLI
core/
frontmatter.ts # Parser de YAML frontmatter
registry.ts # Descoberta de skills
skill.ts # Carregamento + template rendering
mcp.ts # Strategy: gera config por target
render.ts # Engine de {{variaveis}}
mkdir skills/minha-skill
---
id: minha-skill
name: Minha Skill
version: 1.0.0
description: What this skill does.
description_pt: O que essa skill faz.
category: productivity
language: en
requires:
mcp: [nome-do-mcp]
env: [API_KEY]
tags: [tag1, tag2]
---
# Instrucoes da skill aqui...
# mcps/nome-do-mcp.mcp.json
{
"name": "nome-do-mcp",
"description": "Descricao do MCP.",
"transport": "stdio",
"command": "npx",
"args": ["-y", "@org/mcp-server"],
"env": { "API_KEY": "${API_KEY}" }
}
npm run build
node dist/index.js list
node dist/index.js install --skill minha-skill --target claude
O projeto usa Azure Pipelines com publicacao automatica no NPM a cada merge na main.
| Stage | Trigger | O que faz |
|---|---|---|
| CI | push em main ou feature/*, PRs para main | Instala dependencias, compila TypeScript, publica artefato dist/ |
| CD | merge na main (apos CI passar) | Bumpa a versao patch, publica no NPM, commita package.json atualizado com tag git |
O bump de versao so ocorre se a versao ainda nao estiver publicada no registry — evitando duplicatas em runs paralelos.
.env (ja esta no .gitignore)${VAR}, nunca hardcoded.env, nunca sobrescreveMCP nao funciona:
.env e preenchidasnpx @azure-devops/mcp --helpSkill nao aparece no list:
skills/{id}/SKILL.md com frontmatter validoFAQs
Agent Skills Framework - Easy setup for AI agent capabilities and integrations (Claude, Gemini, Codex, GitHub Copilot)
We found that @sysmanager/ai-skills demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
RubyGems and Bundler 4.0.13 introduced an opt-in cooldown feature that delays newly published gems during dependency resolution.

Security News
pnpm 11.5 now recognizes npm staged publish approvals in release metadata, preventing those releases from being mistaken for lower-trust package publishes.

Security News
Federal audit finds NIST lacked a plan to clear the NVD backlog, wasted funds on duplicate work, and delayed use of CISA data.