Skip to content

Repository files navigation

skill-fetch

License: MIT GitHub release GitHub stars CI

Cross-platform skill discovery and installation for AI coding agents

Search, score, and install AI agent skills from 9 registries in parallel β€” works across Claude Code, Cursor, Codex, Gemini CLI, Windsurf, and Amp.

Quick Start

  1. Install β€” pick any method from Installation below
  2. Set up API keys β€” run /fetch-skill-config (interactive, recommended) or configure manually
  3. Search & install skills β€” /fetch-skill react native animation

Features

  • 9 Search Sources β€” SkillsMP (semantic + keyword), GitHub, Anthropic Skills, ClawSkillHub, skills.sh, PolySkill, SkillHub, Skills Directory
  • Cross-Platform β€” Works on 6+ AI coding agents with automatic tool adaptation
  • Multi-Variant AI Search β€” 3 query variants fired in parallel, improving recall significantly
  • Quality Scoring β€” 0-100 composite score: Relevance (40) + Freshness (25) + Community (20) + Trust (15) + External Bonus (5)
  • Security Labels β€” 5 trust tiers: Official, Verified, Partial, Unverified, Security Concerns
  • 6-Category Security Scan β€” Destructive commands, RCE, data exfiltration, system modification, obfuscation, prompt injection
  • Prompt Injection Detection β€” 5 sub-categories (PI-1~PI-5): direct override, hidden role markers, encoding tricks, indirect injection, social engineering
  • Complete Bundle Install β€” Downloads the whole skill directory (SKILL.md + references/, scripts/, assets/, templates/, prompts/, data/, etc.), preserving the subtree layout so skills that delegate to sibling files actually work
  • Integrity Verification β€” SHA-256 hash recorded for every file in the bundle at install; tamper detection on future loads
  • Paginated Results β€” Browse 5 at a time with c to continue; install by number from any page
  • Local/Global Install β€” Choose project-level or user-level installation (mandatory prompt)
  • Deduplication β€” Same skill across registries is merged; similar descriptions are flagged
  • Bundled Scripts β€” Shell scripts for SkillHub and Skills Directory APIs (no API key exposure in argv) plus fetch-skill-bundle.sh for full-bundle GitHub installs

Installation

Choose the method that fits your setup:

Option 1: Plugin (Best experience, Claude Code)

# Add the skill-fetch marketplace
claude plugin marketplace add girofu/skill-fetch

# Install skill-fetch plugin
claude plugin install skill-fetch@skill-fetch

Provides auto-updates, /fetch-skill command, and full plugin integration.

Option 2: npx skills add (Node.js)

npx skills add girofu/skill-fetch

Works with Claude Code, Cursor, and Codex.

Option 3: curl | sh (Universal, zero dependencies)

curl -fsSL https://raw.githubusercontent.com/girofu/skill-fetch/main/install.sh | bash

Auto-detects installed agents and installs for all of them. Specify a single agent:

curl -fsSL https://raw.githubusercontent.com/girofu/skill-fetch/main/install.sh | bash -s -- --agent claude

Option 4: Python installer

python3 -c "$(curl -fsSL https://raw.githubusercontent.com/girofu/skill-fetch/main/install.py)"

Or download and run:

curl -fsSL https://raw.githubusercontent.com/girofu/skill-fetch/main/install.py -o install.py
python3 install.py --agent cursor

Option 5: Manual (git clone)

git clone https://github.com/girofu/skill-fetch.git
# Claude Code
cp -r skill-fetch/skills/skill-fetch ~/.claude/skills/skill-fetch

# Cursor
cp -r skill-fetch/skills/skill-fetch ~/.cursor/skills/skill-fetch

# Other agents: replace ~/.cursor/ with ~/.codex/, ~/.gemini/, ~/.windsurf/, or ~/.amp/

βš™οΈ Setup API Keys

Important: API keys unlock the full 9-source search. Without them, only Sources 3-8 are available (still useful, but fewer results).

Interactive Setup (Recommended)

Run /fetch-skill-config in Claude Code. It will:

  • Show which keys are currently configured
  • Walk you through setting each key with links to get them
  • Automatically install the SkillsMP MCP server if needed
  • Write everything to ~/.claude/skills/.fetch-config.json

Manual Setup

πŸ”‘ SkillsMP API Key (Sources 1-2) β€” Recommended

SkillsMP provides the best semantic search with AI-powered matching. Get your free API key:

  1. Go to skillsmp.com and create an account
  2. Copy your API key
  3. Register the MCP server:
claude mcp add --scope user skillsmp -- npx -y skillsmp-mcp-server --env SKILLSMP_API_KEY=your_key_here
  1. Restart Claude Code β€” SkillsMP tools will be available in the next session

πŸ”‘ SkillHub & Skills Directory (Sources 8-9) β€” Optional

For additional coverage, create ~/.claude/skills/.fetch-config.json:

{
  "SKILLSMP_API_KEY": "your-skillsmp-key",
  "SKILLHUB_API_KEY": "sk-sh-your-key-here",
  "SKILLS_DIRECTORY_API_KEY": "sk_live_your-key-here"
}

Sources 3-8 work without any API keys. Source 9 (Skills Directory) requires a key.


Supported Agents

Agent Plugin npx curl/sh Python Manual
Claude Code βœ… βœ… βœ… βœ… βœ…
Cursor β€” βœ… βœ… βœ… βœ…
Codex β€” βœ… βœ… βœ… βœ…
Gemini CLI β€” β€” βœ… βœ… βœ…
Windsurf β€” βœ… βœ… βœ… βœ…
Amp β€” β€” βœ… βœ… βœ…

Usage

# Search for skills (Claude Code)
/fetch-skill react native animation

# Install from URL
/fetch-skill https://github.com/owner/repo

# Auto-triggered by skill-eval hook
# (no manual invocation needed)

In other agents, the skill activates automatically when referenced in context.

How It Works

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚                   User Query                         β”‚
β”‚              "testing React Native"                  β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                       β”‚
        β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
        β–Ό              β–Ό                  β–Ό
   β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”   β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”      β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
   β”‚SkillsMP β”‚   β”‚SkillsMP  β”‚      β”‚SkillsMP  β”‚
   β”‚AI Var A  β”‚   β”‚AI Var B  β”‚      β”‚AI Var C  β”‚
   β””β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”˜   β””β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”˜      β””β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”˜
        β”‚              β”‚                  β”‚
        β””β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”˜β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”˜
               β–Ό                  β–Ό
   β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”    β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
   β”‚ SkillsMP KW   β”‚    β”‚    GitHub        β”‚
   β”‚ + Anthropic    β”‚    β”‚    + PolySkill   β”‚
   β””β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”˜    β””β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”˜
           β”‚                     β”‚
   β”Œβ”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”    β”Œβ”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”
   β”‚  ClawSkillHub β”‚    β”‚  skills.sh     β”‚
   β””β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”˜    β””β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”˜
           β”‚                     β”‚
   β”Œβ”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”    β”Œβ”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”
   β”‚  SkillHub     β”‚    β”‚ Skills         β”‚
   β”‚  (API script) β”‚    β”‚ Directory      β”‚
   β””β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”˜    β””β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”˜
           β”‚                     β”‚
           β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                      β–Ό
              β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
              β”‚  Deduplicate  β”‚
              β”‚  Score & Rank β”‚
              β”‚  (0-100)      β”‚
              β””β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”˜
                      β–Ό
              β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
              β”‚  Security     β”‚
              β”‚  Scan (A-F)   β”‚
              β””β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”˜
                      β–Ό
              β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
              β”‚  Display 5    β”‚
              β”‚  per page     β”‚
              β””β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”˜
                      β–Ό
              β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
              β”‚  User picks   β”‚
              β”‚  β†’ Install    β”‚
              β”‚  β†’ Hash       β”‚
              β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

Cross-platform note: SkillsMP sources require the MCP server + API key (see API Key Setup). On other platforms, the flow starts from GitHub + supplementary sources.

Search Sources

# Source Method Type Availability
1 SkillsMP (semantic) skillsmp_ai_search MCP Γ— 3 variants Primary Claude Code + MCP
2 SkillsMP (keyword) skillsmp_search MCP Primary Claude Code + MCP
3 GitHub gh search code --filename SKILL.md (primary) + gh search repos (supplementary) Primary All agents
4 Anthropic Skills gh search code in anthropics/skills Official All agents
5 ClawSkillHub npx -y clawhub search Supplementary Agents with npx
6 skills.sh HTTP API / WebFetch Supplementary All agents
7 PolySkill npx -y @polyskill/cli search (single keyword) Supplementary Agents with npx
8 SkillHub Bundled shell script (API) or CLI fallback Supplementary All agents
9 Skills Directory Bundled shell script (API) Supplementary Configured agents

All sources are searched in parallel. Sources fail gracefully β€” if any is unavailable, the search continues with remaining sources.

API Key Setup

See βš™οΈ Setup API Keys above for detailed instructions.

Quality Scoring

Each result receives a composite score (0-100):

Dimension Weight How
Relevance 0-40 LLM judges description-to-task semantic match
Freshness 0-25 Time since last GitHub push
Community 0-20 Star count (log scale)
Trust 0-15 Source credibility tier
External Bonus 0-5 Security/quality signals from PolySkill, SkillHub, Skills Directory

Grade labels:

Score Label
85+ 🟒 Strongly Recommended
70-84 🟒 Recommended
55-69 🟑 Worth Considering
40-54 🟑 Marginal
<40 πŸ”΄ Not Recommended

Security

Security Labels

Label Criteria
πŸ”’ Official From anthropics/skills repo
πŸ”’ Verified SkillsMP stars β‰₯ 50 + securityGrade A/B + scan clean
⚠️ Partial Lower stars but scan clean, or standard frontmatter present
⚠️ Unverified Direct URL or no external signals
⚠️ Security Concerns Scan found issues or securityGrade D/F

6-Category Security Scan

All skills are scanned before (or immediately after) installation:

Category Name Severity
A Destructive Commands Critical
B Remote Code Execution Critical
C Data Exfiltration High
D System Modification High
E Obfuscation Medium
F Prompt Injection (5 sub-types) High

Integrity Verification

After installation, SHA-256 hashes are recorded for all skill files. On future loads, hashes are compared to detect tampering.

Permissions Declaration (Advisory)

Skills may optionally declare their required permissions (network, filesystem-write, shell-commands, external-urls) in SKILL.md frontmatter. The scanner flags mismatches between declared and actual behavior.

File Structure

skill-fetch/
β”œβ”€β”€ .claude-plugin/
β”‚   └── plugin.json                   # Claude Code plugin manifest
β”œβ”€β”€ commands/
β”‚   β”œβ”€β”€ fetch-skill.md               # /fetch-skill slash command
β”‚   └── fetch-skill-config.md        # /fetch-skill-config API key setup
β”œβ”€β”€ skills/
β”‚   └── skill-fetch/
β”‚       β”œβ”€β”€ SKILL.md                  # Main skill (cross-platform)
β”‚       β”œβ”€β”€ references/
β”‚       β”‚   β”œβ”€β”€ search-sources.md     # Source-specific commands & dedup rules
β”‚       β”‚   β”œβ”€β”€ quality-signals.md    # Scoring algorithm + security labels
β”‚       β”‚   β”œβ”€β”€ interaction-patterns.md # Output templates, security scan, prompt injection
β”‚       β”‚   β”œβ”€β”€ platform-adapters.md  # Cross-platform tool mapping
β”‚       β”‚   β”œβ”€β”€ installation-guide.md # Complete Step 3 install workflow
β”‚       β”‚   └── local-index.md        # Local skill/plugin scan for pre-search dedup
β”‚       └── scripts/
β”‚           β”œβ”€β”€ fetch-skill-bundle.sh    # Download a complete skill bundle from GitHub (SKILL.md + all siblings)
β”‚           β”œβ”€β”€ fetch-skillhub.sh        # SkillHub API search (reads key from config)
β”‚           └── fetch-skills-directory.sh # Skills Directory API search
β”œβ”€β”€ .github/
β”‚   └── maintainer/                   # Per-repo state for open-source-maintainer workflow
β”œβ”€β”€ install.sh                        # Universal bash installer
β”œβ”€β”€ install.py                        # Python installer
β”œβ”€β”€ CHANGELOG.md                      # Version history
β”œβ”€β”€ README.md                         # This file
└── LICENSE                           # MIT

Requirements

Minimum (any agent):

  • Shell with curl or WebFetch for HTTP-based searches

Full experience (Claude Code):

  • SkillsMP MCP server + API key from skillsmp.com (see API Key Setup)
  • GitHub CLI (gh) for GitHub and Anthropic Skills search
  • Node.js for npx-based searches (ClawSkillHub, PolySkill, SkillHub CLI)
  • ~/.claude/skills/.fetch-config.json for SkillHub and Skills Directory APIs (optional)

Author

Built by girofu β€” AI engineering portfolio at github.com/girofu.

For private portfolio walkthroughs or contracting inquiries: girofu@gmail.com

License

MIT

About

Multi-registry skill discovery and installation for AI coding agents β€” search 9 sources, score, paginate, and install agent skills with security labels

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

30 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages