
Security News
Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.
skillkit-cli
Advanced tools
The toolbox for AI agent skills: scaffold, lint, pack, install, and serve SKILL.md skills with a built-in MCP server
The toolbox for AI agent skills. Scaffold, lint, pack, and install SKILL.md skills — and serve your whole skill library to Claude Code, Cursor, and any MCP client with a built-in Model Context Protocol server.

Community audits found that the overwhelming majority of published SKILL.md files carry at least one "skill smell" — and a large share leak secrets. skillkit catches those before you ship.
📖 Deep docs: Usage guide — lint rules reference, MCP patterns, CI usage · Architecture · Contributing · Changelog · Security
new — scaffold a spec-compliant skill folder in one commandlint — validate against the Agent Skills spec plus security smells:
leaked API keys, vague descriptions, oversized bodies, folder typos, and more
(scored 0–100 with a grade)pack — zip a skill for upload to skill-capable platformsinstall — install from a folder or any git URL into
~/.claude/skills (or your own directory)list / remove — manage your installed skill librarymcp — a zero-dependency MCP server (stdio, JSON-RPC 2.0) that
exposes list_skills, read_skill, and lint_skill tools to any client# install from PyPI (installs the `skillkit` command)
pipx install skillkit-cli
# ...or from source
git clone https://github.com/furkan708/skillkit.git
cd skillkit && pip install .
# 1. create a skill
skillkit new commit-writer -d "Writes conventional commit messages from staged diffs. Use when the user asks to commit changes."
# 2. lint it (spec + security + quality)
skillkit lint commit-writer
# ✓ no issues found
# score: 100/100 (grade A) · 0 errors · 0 warnings · 0 notes
# 3. pack it for upload
skillkit pack commit-writer # → commit-writer.zip
# 4. install it for Claude Code
skillkit install ./commit-writer # → ~/.claude/skills/commit-writer
Add skillkit to any MCP client config — Claude Code, Cursor, Windsurf, and every other MCP-compatible agent:
{
"mcpServers": {
"skillkit": { "command": "skillkit", "args": ["mcp"] }
}
}
Your agent can now discover and read every installed skill on demand:
| Tool | What it does |
|---|---|
list_skills | Discover installed skills with names + descriptions |
read_skill | Load the full SKILL.md instructions of one skill |
lint_skill | Validate a skill and get its quality score |
| Rule | Severity | Check |
|---|---|---|
| SEC001 | ✗ error | Leaked secrets: GitHub/AWS/OpenAI/Slack tokens, private keys, hardcoded credentials |
| SKILL001 | ✗ error | Invalid name: charset, length ≤ 64, reserved words (anthropic, claude) |
| SKILL002 | ✗ error | name does not match the folder name |
| SKILL003 | ✗ error | description longer than 1,024 characters |
| SKILL009 | ✗ error | metadata is not a string→string map |
| SKILL004 | ⚠ warn | Vague description (won't trigger — describe what and when) |
| SKILL005 | ⚠ warn | Body over ~500 lines (move detail into references/) |
| SKILL007 | ⚠ warn | Folder typos: script/, reference/, docs/… |
| SKILL006 | · info | Very thin body — add steps and examples |
| SKILL008 | · info | Unknown frontmatter fields |
Every run ends with a 0–100 score and a letter grade, so you know when a skill is ready to publish.
skillkit new <name> -d <description> [--dir DIR] scaffold a skill
skillkit lint <path> [--json] [--strict] validate a skill
skillkit pack <path> [-o FILE.zip] zip for upload
skillkit install <path|git-url> [--agent claude|project] [--dir DIR]
skillkit list [--agent ...] [--dir DIR] [--json] show installed skills
skillkit remove <name> [--dir DIR] uninstall a skill
skillkit mcp [--dir DIR] serve skills over MCP
Built on the open Agent Skills specification — the same format supported by 40+ platforms including Claude, OpenAI Codex, and GitHub Copilot.
pip install pytest
pytest -v
skillkit/
├── skillkit/
│ ├── frontmatter.py # minimal YAML frontmatter parser
│ ├── model.py # skill loading (Agent Skills spec)
│ ├── linter.py # rules, security smells, 0-100 score
│ ├── scaffold.py # new + pack
│ ├── installer.py # install / list / remove (folder or git)
│ ├── mcp_server.py # zero-dependency MCP stdio server
│ └── cli.py # command-line interface
└── tests/
skillkit search — search community skill registriesskillkit doctor — prompt-injection heuristics (planned, not implemented yet)MIT — see the LICENSE file for details.
FAQs
The toolbox for AI agent skills: scaffold, lint, pack, install, and serve SKILL.md skills with a built-in MCP server
We found that skillkit-cli demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.

Research
/Security News
The compromise affects MemTensor's MemOS, an open source memory framework for large language models (LLMs) and AI agents. Both npm package @memtensor/memos-cloud-openclaw-plugin and the PyPI package MemoryOS are compromised. They drop cross-platform Go binaries that exfiltrate developer secrets.