@skillsafe-team/publish-to-skillsafe

Save and share an AI skill on the SkillSafe registry, including writing a scannable SKILL.md and passing the publisher security scan.

View in AI SkillSafe app
Scanned · no findings
1 downloads
0 stars
0 demos
SKILL.md
namepublish-to-skillsafe
descriptionSave and share an AI skill on the SkillSafe registry, including writing a scannable SKILL.md and passing the publisher security scan. Use when the user wants to publish, share, or distribute a skill they have written.

Publish a skill to SkillSafe

SkillSafe is save-first: saving stores the skill privately; sharing makes it available to others and requires a clean publisher scan.

Authoring checklist (before publishing)

A skill that scans clean follows these rules:

  • Document every capability. If a bundled script makes network calls, reads environment variables, runs subprocesses, or writes files, say so explicitly in SKILL.md. Undocumented capabilities are flagged as surplus functionality (undoc_network, undoc_env_read, undoc_subprocess, undoc_file_write).
  • No secrets in files. API keys, tokens, and private keys are detected and the share will carry critical findings.
  • No writes to agent config. Never write to CLAUDE.md, MEMORY.md, SOUL.md, .cursorrules, or anything inside the agent's hidden config directory in the user's home — these are treated as agent-poisoning patterns.
  • No encoded payloads. Base64 blobs are decoded and re-scanned; piping decoded content into a shell is an automatic critical finding.

Publishing steps

  1. Authenticate — create an account and API key at https://skillsafe.ai/ (browser sign-in) or via the CLI device flow.

  2. Save the skill (private by default):

    # The web UI and desktop app handle this form for you; programmatically:
    curl -s -X POST https://api.skillsafe.ai/v1/skills/@YOUR_NS/your-skill \
      -H "Authorization: Bearer $SKILLSAFE_API_KEY" \
      -F '[email protected]' \
      -F 'metadata={"version":"1.0.0","description":"...","file_manifest":[...]}'
    
  3. Share it once the publisher scan on the version is clean:

    curl -s -X POST \
      https://api.skillsafe.ai/v1/skills/@YOUR_NS/your-skill/versions/1.0.0/share \
      -H "Authorization: Bearer $SKILLSAFE_API_KEY" \
      -H "content-type: application/json" \
      -d '{"visibility": "public", "expires_in": "never"}'
    
  4. Verify the listing at https://skillsafe.ai/skill/@YOUR_NS/your-skill/ and embed the verification badge in your README:

    [![SkillSafe verified](https://api.skillsafe.ai/v1/badge/@YOUR_NS/your-skill/verified)](https://skillsafe.ai/skill/@YOUR_NS/your-skill/)
    

Notes

  • Consumers re-scan on install and the server compares both reports — if your published content is modified in transit, installs fail closed.
  • Organizations can serve their registry to Claude Code directly: /plugin marketplace add https://api.skillsafe.ai/orgs/{org}/marketplace.json

Published by the SkillSafe team as a reference skill. Source: https://github.com/skillsafe/skillsafe.ai-website/tree/main/examples/skills/

Embed badges

Add these to your README to show the skill's verification status.

SkillSafe verified badge
Verified badge
[![SkillSafe verified badge](https://api.skillsafe.ai/v1/badge/@skillsafe-team/publish-to-skillsafe/verified)](https://skillsafe.ai/skill/@skillsafe-team/publish-to-skillsafe/)
Installs badge
Installs badge
[![Installs badge](https://api.skillsafe.ai/v1/badge/@skillsafe-team/publish-to-skillsafe/installs)](https://skillsafe.ai/skill/@skillsafe-team/publish-to-skillsafe/)
Scan badge
Scan badge
[![Scan badge](https://api.skillsafe.ai/v1/badge/@skillsafe-team/publish-to-skillsafe/scan)](https://skillsafe.ai/skill/@skillsafe-team/publish-to-skillsafe/)
Eval pass rate badge
Eval pass rate
[![Eval pass rate badge](https://api.skillsafe.ai/v1/badge/@skillsafe-team/publish-to-skillsafe/eval)](https://skillsafe.ai/skill/@skillsafe-team/publish-to-skillsafe/)