Cross-platform skill discovery and installation for AI coding agents
Search, score, and install AI agent skills from 9 registries in parallel β works across Claude Code, Cursor, Codex, Gemini CLI, Windsurf, and Amp.
- Install β pick any method from Installation below
- Set up API keys β run
/fetch-skill-config(interactive, recommended) or configure manually - Search & install skills β
/fetch-skill react native animation
- 9 Search Sources β SkillsMP (semantic + keyword), GitHub, Anthropic Skills, ClawSkillHub, skills.sh, PolySkill, SkillHub, Skills Directory
- Cross-Platform β Works on 6+ AI coding agents with automatic tool adaptation
- Multi-Variant AI Search β 3 query variants fired in parallel, improving recall significantly
- Quality Scoring β 0-100 composite score: Relevance (40) + Freshness (25) + Community (20) + Trust (15) + External Bonus (5)
- Security Labels β 5 trust tiers: Official, Verified, Partial, Unverified, Security Concerns
- 6-Category Security Scan β Destructive commands, RCE, data exfiltration, system modification, obfuscation, prompt injection
- Prompt Injection Detection β 5 sub-categories (PI-1~PI-5): direct override, hidden role markers, encoding tricks, indirect injection, social engineering
- Complete Bundle Install β Downloads the whole skill directory (SKILL.md +
references/,scripts/,assets/,templates/,prompts/,data/, etc.), preserving the subtree layout so skills that delegate to sibling files actually work - Integrity Verification β SHA-256 hash recorded for every file in the bundle at install; tamper detection on future loads
- Paginated Results β Browse 5 at a time with
cto continue; install by number from any page - Local/Global Install β Choose project-level or user-level installation (mandatory prompt)
- Deduplication β Same skill across registries is merged; similar descriptions are flagged
- Bundled Scripts β Shell scripts for SkillHub and Skills Directory APIs (no API key exposure in argv) plus
fetch-skill-bundle.shfor full-bundle GitHub installs
Choose the method that fits your setup:
# Add the skill-fetch marketplace
claude plugin marketplace add girofu/skill-fetch
# Install skill-fetch plugin
claude plugin install skill-fetch@skill-fetchProvides auto-updates, /fetch-skill command, and full plugin integration.
npx skills add girofu/skill-fetchWorks with Claude Code, Cursor, and Codex.
curl -fsSL https://raw.githubusercontent.com/girofu/skill-fetch/main/install.sh | bashAuto-detects installed agents and installs for all of them. Specify a single agent:
curl -fsSL https://raw.githubusercontent.com/girofu/skill-fetch/main/install.sh | bash -s -- --agent claudepython3 -c "$(curl -fsSL https://raw.githubusercontent.com/girofu/skill-fetch/main/install.py)"Or download and run:
curl -fsSL https://raw.githubusercontent.com/girofu/skill-fetch/main/install.py -o install.py
python3 install.py --agent cursorgit clone https://github.com/girofu/skill-fetch.git
# Claude Code
cp -r skill-fetch/skills/skill-fetch ~/.claude/skills/skill-fetch
# Cursor
cp -r skill-fetch/skills/skill-fetch ~/.cursor/skills/skill-fetch
# Other agents: replace ~/.cursor/ with ~/.codex/, ~/.gemini/, ~/.windsurf/, or ~/.amp/Important: API keys unlock the full 9-source search. Without them, only Sources 3-8 are available (still useful, but fewer results).
Run /fetch-skill-config in Claude Code. It will:
- Show which keys are currently configured
- Walk you through setting each key with links to get them
- Automatically install the SkillsMP MCP server if needed
- Write everything to
~/.claude/skills/.fetch-config.json
SkillsMP provides the best semantic search with AI-powered matching. Get your free API key:
- Go to skillsmp.com and create an account
- Copy your API key
- Register the MCP server:
claude mcp add --scope user skillsmp -- npx -y skillsmp-mcp-server --env SKILLSMP_API_KEY=your_key_here- Restart Claude Code β SkillsMP tools will be available in the next session
For additional coverage, create ~/.claude/skills/.fetch-config.json:
{
"SKILLSMP_API_KEY": "your-skillsmp-key",
"SKILLHUB_API_KEY": "sk-sh-your-key-here",
"SKILLS_DIRECTORY_API_KEY": "sk_live_your-key-here"
}Sources 3-8 work without any API keys. Source 9 (Skills Directory) requires a key.
| Agent | Plugin | npx | curl/sh | Python | Manual |
|---|---|---|---|---|---|
| Claude Code | β | β | β | β | β |
| Cursor | β | β | β | β | β |
| Codex | β | β | β | β | β |
| Gemini CLI | β | β | β | β | β |
| Windsurf | β | β | β | β | β |
| Amp | β | β | β | β | β |
# Search for skills (Claude Code)
/fetch-skill react native animation
# Install from URL
/fetch-skill https://github.com/owner/repo
# Auto-triggered by skill-eval hook
# (no manual invocation needed)
In other agents, the skill activates automatically when referenced in context.
βββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β User Query β
β "testing React Native" β
ββββββββββββββββββββββββ¬βββββββββββββββββββββββββββββββ
β
ββββββββββββββββΌβββββββββββββββββββ
βΌ βΌ βΌ
βββββββββββ ββββββββββββ ββββββββββββ
βSkillsMP β βSkillsMP β βSkillsMP β
βAI Var A β βAI Var B β βAI Var C β
ββββββ¬ββββββ ββββββ¬ββββββ ββββββ¬ββββββ
β β β
ββββββββ¬βββββββββββββββββββ¬ββββββββ
βΌ βΌ
βββββββββββββββββ βββββββββββββββββββ
β SkillsMP KW β β GitHub β
β + Anthropic β β + PolySkill β
βββββββββ¬ββββββββ ββββββββββ¬βββββββββ
β β
βββββββββ΄ββββββββ βββββββββ΄βββββββββ
β ClawSkillHub β β skills.sh β
βββββββββ¬ββββββββ βββββββββ¬βββββββββ
β β
βββββββββ΄ββββββββ βββββββββ΄βββββββββ
β SkillHub β β Skills β
β (API script) β β Directory β
βββββββββ¬ββββββββ βββββββββ¬βββββββββ
β β
ββββββββββββ¬βββββββββββ
βΌ
βββββββββββββββββ
β Deduplicate β
β Score & Rank β
β (0-100) β
βββββββββ¬ββββββββ
βΌ
βββββββββββββββββ
β Security β
β Scan (A-F) β
βββββββββ¬ββββββββ
βΌ
βββββββββββββββββ
β Display 5 β
β per page β
βββββββββ¬ββββββββ
βΌ
βββββββββββββββββ
β User picks β
β β Install β
β β Hash β
βββββββββββββββββ
Cross-platform note: SkillsMP sources require the MCP server + API key (see API Key Setup). On other platforms, the flow starts from GitHub + supplementary sources.
| # | Source | Method | Type | Availability |
|---|---|---|---|---|
| 1 | SkillsMP (semantic) | skillsmp_ai_search MCP Γ 3 variants |
Primary | Claude Code + MCP |
| 2 | SkillsMP (keyword) | skillsmp_search MCP |
Primary | Claude Code + MCP |
| 3 | GitHub | gh search code --filename SKILL.md (primary) + gh search repos (supplementary) |
Primary | All agents |
| 4 | Anthropic Skills | gh search code in anthropics/skills |
Official | All agents |
| 5 | ClawSkillHub | npx -y clawhub search |
Supplementary | Agents with npx |
| 6 | skills.sh | HTTP API / WebFetch | Supplementary | All agents |
| 7 | PolySkill | npx -y @polyskill/cli search (single keyword) |
Supplementary | Agents with npx |
| 8 | SkillHub | Bundled shell script (API) or CLI fallback | Supplementary | All agents |
| 9 | Skills Directory | Bundled shell script (API) | Supplementary | Configured agents |
All sources are searched in parallel. Sources fail gracefully β if any is unavailable, the search continues with remaining sources.
See βοΈ Setup API Keys above for detailed instructions.
Each result receives a composite score (0-100):
| Dimension | Weight | How |
|---|---|---|
| Relevance | 0-40 | LLM judges description-to-task semantic match |
| Freshness | 0-25 | Time since last GitHub push |
| Community | 0-20 | Star count (log scale) |
| Trust | 0-15 | Source credibility tier |
| External Bonus | 0-5 | Security/quality signals from PolySkill, SkillHub, Skills Directory |
Grade labels:
| Score | Label |
|---|---|
| 85+ | π’ Strongly Recommended |
| 70-84 | π’ Recommended |
| 55-69 | π‘ Worth Considering |
| 40-54 | π‘ Marginal |
| <40 | π΄ Not Recommended |
| Label | Criteria |
|---|---|
| π Official | From anthropics/skills repo |
| π Verified | SkillsMP stars β₯ 50 + securityGrade A/B + scan clean |
| Lower stars but scan clean, or standard frontmatter present | |
| Direct URL or no external signals | |
| Scan found issues or securityGrade D/F |
All skills are scanned before (or immediately after) installation:
| Category | Name | Severity |
|---|---|---|
| A | Destructive Commands | Critical |
| B | Remote Code Execution | Critical |
| C | Data Exfiltration | High |
| D | System Modification | High |
| E | Obfuscation | Medium |
| F | Prompt Injection (5 sub-types) | High |
After installation, SHA-256 hashes are recorded for all skill files. On future loads, hashes are compared to detect tampering.
Skills may optionally declare their required permissions (network, filesystem-write, shell-commands, external-urls) in SKILL.md frontmatter. The scanner flags mismatches between declared and actual behavior.
skill-fetch/
βββ .claude-plugin/
β βββ plugin.json # Claude Code plugin manifest
βββ commands/
β βββ fetch-skill.md # /fetch-skill slash command
β βββ fetch-skill-config.md # /fetch-skill-config API key setup
βββ skills/
β βββ skill-fetch/
β βββ SKILL.md # Main skill (cross-platform)
β βββ references/
β β βββ search-sources.md # Source-specific commands & dedup rules
β β βββ quality-signals.md # Scoring algorithm + security labels
β β βββ interaction-patterns.md # Output templates, security scan, prompt injection
β β βββ platform-adapters.md # Cross-platform tool mapping
β β βββ installation-guide.md # Complete Step 3 install workflow
β β βββ local-index.md # Local skill/plugin scan for pre-search dedup
β βββ scripts/
β βββ fetch-skill-bundle.sh # Download a complete skill bundle from GitHub (SKILL.md + all siblings)
β βββ fetch-skillhub.sh # SkillHub API search (reads key from config)
β βββ fetch-skills-directory.sh # Skills Directory API search
βββ .github/
β βββ maintainer/ # Per-repo state for open-source-maintainer workflow
βββ install.sh # Universal bash installer
βββ install.py # Python installer
βββ CHANGELOG.md # Version history
βββ README.md # This file
βββ LICENSE # MIT
Minimum (any agent):
- Shell with
curlorWebFetchfor HTTP-based searches
Full experience (Claude Code):
- SkillsMP MCP server + API key from skillsmp.com (see API Key Setup)
- GitHub CLI (
gh) for GitHub and Anthropic Skills search - Node.js for npx-based searches (ClawSkillHub, PolySkill, SkillHub CLI)
~/.claude/skills/.fetch-config.jsonfor SkillHub and Skills Directory APIs (optional)
Built by girofu β AI engineering portfolio at github.com/girofu.
For private portfolio walkthroughs or contracting inquiries: girofu@gmail.com
MIT