@skillsafe-team/publish-to-skillsafe
Save and share an AI skill on the SkillSafe registry, including writing a scannable SKILL.md and passing the publisher security scan.
| name | publish-to-skillsafe |
| description | Save and share an AI skill on the SkillSafe registry, including writing a scannable SKILL.md and passing the publisher security scan. Use when the user wants to publish, share, or distribute a skill they have written. |
Publish a skill to SkillSafe
SkillSafe is save-first: saving stores the skill privately; sharing makes it available to others and requires a clean publisher scan.
Authoring checklist (before publishing)
A skill that scans clean follows these rules:
- Document every capability. If a bundled script makes network calls,
reads environment variables, runs subprocesses, or writes files, say so
explicitly in SKILL.md. Undocumented capabilities are flagged as surplus
functionality (
undoc_network,undoc_env_read,undoc_subprocess,undoc_file_write). - No secrets in files. API keys, tokens, and private keys are detected and the share will carry critical findings.
- No writes to agent config. Never write to
CLAUDE.md,MEMORY.md,SOUL.md,.cursorrules, or anything inside the agent's hidden config directory in the user's home — these are treated as agent-poisoning patterns. - No encoded payloads. Base64 blobs are decoded and re-scanned; piping decoded content into a shell is an automatic critical finding.
Publishing steps
Authenticate — create an account and API key at https://skillsafe.ai/ (browser sign-in) or via the CLI device flow.
Save the skill (private by default):
# The web UI and desktop app handle this form for you; programmatically: curl -s -X POST https://api.skillsafe.ai/v1/skills/@YOUR_NS/your-skill \ -H "Authorization: Bearer $SKILLSAFE_API_KEY" \ -F 'file_SKILL.md=@SKILL.md' \ -F 'metadata={"version":"1.0.0","description":"...","file_manifest":[...]}'Share it once the publisher scan on the version is clean:
curl -s -X POST \ https://api.skillsafe.ai/v1/skills/@YOUR_NS/your-skill/versions/1.0.0/share \ -H "Authorization: Bearer $SKILLSAFE_API_KEY" \ -H "content-type: application/json" \ -d '{"visibility": "public", "expires_in": "never"}'Verify the listing at
https://skillsafe.ai/skill/@YOUR_NS/your-skill/and embed the verification badge in your README:[](https://skillsafe.ai/skill/@YOUR_NS/your-skill/)
Notes
- Consumers re-scan on install and the server compares both reports — if your published content is modified in transit, installs fail closed.
- Organizations can serve their registry to Claude Code directly:
/plugin marketplace add https://api.skillsafe.ai/orgs/{org}/marketplace.json
Published by the SkillSafe team as a reference skill. Source: https://github.com/skillsafe/skillsafe.ai-website/tree/main/examples/skills/
Loading...
Select a file to preview
Analyzing security...
Checking scan reports and verification data.
Bill of Materials
Everything this skill can do — files, network, commands, and more.