Skillsmith

平台与服务

by smith-horn

面向Claude Code的MCP server,用于技能发现、安装与日常管理。

什么是 Skillsmith

面向Claude Code的MCP server,用于技能发现、安装与日常管理。

README

Skillsmith

Shared skills, safe for production.

Once more than one team is publishing agent skills, the problem stops being finding them and starts being managing them. Which team is this scoped to? Which version is installed where? Has it been flagged by a security scan? What happens to the ones nobody maintains anymore?

Skillsmith is a registry for sharing, scanning, and tracking agent skills across teams. Skills are published to a registry scoped to your team and versioned immutably, so drift across installs is visible instead of silent. Flagged or suspicious skills are quarantined pending security review. Skills that go stale can be deprecated instead of quietly rotting in someone's repo.

Installation

Quick Setup (MCP)

Skillsmith is MCP-compatible — pick the snippet for your agent. SMI-4580: snippets sourced from packages/cli/src/templates/mcp-server.template.snippets.ts so this README and the website docs cannot drift.

<details> <summary><strong>Claude Code</strong> — <code>~/.claude/settings.json</code></summary>
json
{
  "mcpServers": {
    "@skillsmith/mcp-server": {
      "command": "npx",
      "args": ["-y", "@skillsmith/mcp-server"],
      "env": {
        "SKILLSMITH_API_KEY": "sk_live_..."
      }
    }
  }
}

Restart Claude Code after editing settings.json.

</details> <details> <summary><strong>Cursor</strong> — <code>~/.cursor/mcp.json</code></summary>
json
{
  "mcpServers": {
    "@skillsmith/mcp-server": {
      "command": "<paste output of: which skillsmith-mcp (macOS/Linux) or where skillsmith-mcp (Windows)>",
      "env": {
        "SKILLSMITH_API_KEY": "sk_live_...",
        "SKILLSMITH_CLIENT": "cursor"
      }
    }
  }
}

Cursor 2.4+ required, Node >=22.22 (Cursor's own bundled Node meets this). SKILLSMITH_CLIENT routes installs to ~/.cursor/skills instead of the default ~/.claude/skills.

Setup: run npm install -g @skillsmith/mcp-server, then run which skillsmith-mcp (macOS/Linux) or where skillsmith-mcp (Windows) and paste that path into command above — Cursor's bundled Node cannot resolve packages via npx (a real ENOENT on a missing Resources/app/resources/lib directory), so pointing directly at the installed binary is the only form confirmed to work inside Cursor. Prefer to try npx first anyway? Replace command with "npx" and add "args": ["-y", "@skillsmith/mcp-server"] — simpler, but may hit the same ENOENT, plus EBADENGINE or ENOTEMPTY on repeated installs. After saving: enable the server in Cursor's Settings → MCP panel and start a new chat — a correctly-configured entry still shows disconnected until toggled on there — then reload the window.

</details> <details> <summary><strong>GitHub Copilot (VS Code)</strong> — <code>.vscode/mcp.json</code> (workspace)</summary>
json
{
  "mcpServers": {
    "@skillsmith/mcp-server": {
      "command": "npx",
      "args": ["-y", "@skillsmith/mcp-server"],
      "env": {
        "SKILLSMITH_API_KEY": "sk_live_..."
      }
    }
  }
}

VS Code 1.108+ required. Workspace-scoped (commit to repo if team-shared, or use user settings.json instead).

</details> <details> <summary><strong>Windsurf</strong> — <code>~/.codeium/windsurf/mcp_config.json</code></summary>
json
{
  "mcpServers": {
    "@skillsmith/mcp-server": {
      "command": "npx",
      "args": ["-y", "@skillsmith/mcp-server"],
      "env": {
        "SKILLSMITH_API_KEY": "${env:SKILLSMITH_API_KEY}"
      }
    }
  }
}

Supports ${env:VAR} interpolation; export SKILLSMITH_API_KEY in your shell instead of inlining the secret.

</details> <details> <summary><strong>Codex CLI</strong> — <code>~/.codex/config.toml</code> (TOML, not JSON)</summary>
toml
[mcp_servers.@skillsmith/mcp-server]
command = "npx"
args = ["-y", "@skillsmith/mcp-server"]

[mcp_servers.@skillsmith/mcp-server.env]
SKILLSMITH_API_KEY = "sk_live_..."

Codex reads ~/.agents/skills. When installing via CLI, pass --client agents.

</details> <details> <summary><strong>Cross-agent (open standard)</strong> — <code>~/.agents/mcp.json</code></summary>
json
{
  "mcpServers": {
    "@skillsmith/mcp-server": {
      "command": "npx",
      "args": ["-y", "@skillsmith/mcp-server"],
      "env": {
        "SKILLSMITH_API_KEY": "sk_live_..."
      }
    }
  }
}

Read by any agent honouring the cross-agent skill convention.

</details>

After adding to your MCP client settings and restarting, you can search for skills immediately.

API Key Configuration (Optional)

For higher rate limits and usage tracking, authenticate with your API key.

Easiest — CLI login (interactive):

bash
npm install -g @skillsmith/cli
skillsmith login

This opens skillsmith.app/account/cli-token in your browser. Generate a key, copy it, and paste it when prompted. The key is stored securely in your OS keyring.

MCP server config — add the key to your settings:

The per-client snippets above already include the env.SKILLSMITH_API_KEY slot — replace the sk_live_... placeholder with the value from skillsmith login.

Get your API key at skillsmith.app/account/cli-token.

TierRate LimitCost
Trial10 totalFree
Community30/minFree
Individual60/min$9.99/mo
Team120/min$25/user/mo
Enterprise300/minCustom

Note: Never paste API keys in chat. Configure via settings.json only.

CLI Installation (Development)

The CLI is available for local development:

bash
# From the repository root
npm run build
node packages/cli/dist/index.js search "testing"

The four questions

Once more than one team is publishing skills, these are the questions that matter:

  1. Which team is this scoped to? Every skill in the registry is scoped to a team.
  2. Which version is installed here? Versions are immutable; skill_diff and skill_outdated report drift for what's installed on the machine you run them from.
  3. Has it been flagged by the security scan? Skills pulled from the public index are scored automatically; flagged or suspicious ones are quarantined pending review — unflagged means it wasn't flagged, not that it was formally approved. Skills carry one of five trust tiers, from Official to Unverified (Security Guide).
  4. What happens to the ones nobody maintains? Stale skills can be deprecated instead of quietly rotting in someone's repo.

How it works

  • Publish — skills are published to a registry scoped to your team, versioned immutably.
  • Version — every publish creates a new immutable version; nothing is overwritten in place.
  • Drift detectionskill_diff and skill_outdated show what's installed and where it has fallen behind, at the point you check.
  • Deprecate — skills that go stale can be deprecated instead of quietly rotting in someone's repo.

Scopes and permissions

Skills are scoped to your team's registry. Team owners and admins control who can publish and manage skills; members install and search.

Start solo

Search, install, and manage skills for yourself, free. When your team needs the same skill, the registry is already there.

MCP Tools

ToolDescription
searchSearch skills with filters (query, category, trust tier, min score)
get_skillGet detailed skill information including install command
install_skillInstall a skill to your local environment
uninstall_skillRemove an installed skill
recommendGet contextual skill recommendations
validateValidate a skill's structure and quality
compareCompare multiple skills side-by-side

Local-first by design. Skillsmith caches the registry in a local SQLite database at ~/.skillsmith/skills.db, shared across the MCP server, the CLI, and the VS Code extension. Search is FTS5 (SQLite's built-in keyword search) by default; semantic search is opt-in (SKILLSMITH_USE_HNSW=true) and runs over local ONNX embeddings (an open ML model format that runs on CPU — no API call). Inside the Local Skill Database walks through the schema, the FTS5 / HNSW search paths, and how sync (a Team+ tier feature) keeps the cache fresh.

Architecture

Skillsmith uses the Model Context Protocol (MCP):

text
┌─────────────────────────────────────────────────────┐
│  MCP Client (Claude Code, Cursor, etc.)               │
│  ┌─────────────────────────────────────────────────┐│
│  │  Skillsmith MCP Server                          ││
│  │  └── @skillsmith/mcp-server                     ││
│  │      ├── search, get_skill, compare             ││
│  │      ├── install_skill, uninstall_skill         ││
│  │      └── recommend, validate                    ││
│  └─────────────────────────────────────────────────┘│
│                          │                           │
│                          ▼                           │
│  ┌─────────────────────────────────────────────────┐│
│  │  ~/.skillsmith/skills.db (SQLite + FTS5)        ││
│  │  ~/.claude/skills/ (installed skills)           ││
│  └─────────────────────────────────────────────────┘│
└─────────────────────────────────────────────────────┘

Usage

Once configured, your MCP client can use Skillsmith tools:

text
"Search for testing skills"
→ Uses search tool to find testing-related skills

"Show me details for community/jest-helper"
→ Uses get_skill tool to retrieve full skill information

"Install the jest-helper skill"
→ Uses install_skill tool to add it to ~/.claude/skills

"Compare jest-helper and vitest-helper"
→ Uses compare tool to show side-by-side comparison

CLI Usage (Development)

bash
# From the repository, after building
node packages/cli/dist/index.js search "testing" --tier verified --min-score 80
node packages/cli/dist/index.js get community/jest-helper
node packages/cli/dist/index.js install community/jest-helper

Documentation

Public

Internal

Internal documentation is in a private submodule at docs/internal/. Access requires repository membership. Run git submodule update --init after cloning.

Development

Skillsmith uses Docker-first development. All commands run inside Docker to ensure consistent native module support across all platforms.

Prerequisites

  • Docker Desktop (v24+) or Docker Engine with Docker Compose
  • Git (for cloning the repository)
  • Node.js (optional, only for local tooling outside Docker)

Quick Start

bash
# 1. Clone the repository
git clone https://github.com/smith-horn/skillsmith.git
cd skillsmith

# 2. Create your local environment file
cp .env.example .env

# 3. Start the development container
docker compose --profile dev up -d

# 4. Install dependencies (first time only)
docker exec skillsmith-dev-1 npm install

# 5. Build and test
docker exec skillsmith-dev-1 npm run build
docker exec skillsmith-dev-1 npm test

Running Commands in Docker

All npm commands should be run inside the Docker container:

CommandDocker Command
Builddocker exec skillsmith-dev-1 npm run build
Testdocker exec skillsmith-dev-1 npm test
Lintdocker exec skillsmith-dev-1 npm run lint
Typecheckdocker exec skillsmith-dev-1 npm run typecheck
Auditdocker exec skillsmith-dev-1 npm run audit:standards

Container Management

bash
# Start development container
docker compose --profile dev up -d

# Check container status
docker ps | grep skillsmith

# View container logs
docker logs skillsmith-dev-1

# Stop container
docker compose --profile dev down

# Restart after Dockerfile changes
docker compose --profile dev down
docker compose --profile dev build --no-cache
docker compose --profile dev up -d

After Pulling Changes

When you pull changes that modify package.json or package-lock.json:

bash
docker exec skillsmith-dev-1 npm install
docker exec skillsmith-dev-1 npm run build

Troubleshooting

Container won't start

bash
docker compose --profile dev down
docker volume rm skillsmith_node_modules
docker compose --profile dev up -d
docker exec skillsmith-dev-1 npm install

Native module errors (ERR_DLOPEN_FAILED)

Native modules like better-sqlite3 and onnxruntime-node may need rebuilding:

bash
docker exec skillsmith-dev-1 npm rebuild

Tests fail with shared library errors

If you see errors about ld-linux-aarch64.so.1 or similar, ensure you're running inside Docker (not locally):

bash
# Wrong - don't run locally
npm test

# Correct - run in Docker
docker exec skillsmith-dev-1 npm test

Why Docker?

Skillsmith uses native Node.js modules (better-sqlite3, onnxruntime-node) that require glibc. Docker provides a consistent Debian-based environment with glibc, avoiding compatibility issues on systems using musl libc (like Alpine Linux).

For the full technical decision, see ADR-002: Docker with glibc for Native Module Compatibility.

See CLAUDE.md for full development workflow and skill configuration.

Tech Stack

  • Runtime: Node.js >=22.22 (Docker with glibc)
  • Protocol: MCP (Model Context Protocol)
  • Database: SQLite with FTS5
  • Embeddings: all-MiniLM-L6-v2 via onnxruntime-node
  • Testing: Vitest
  • CI/CD: GitHub Actions

License

Skillsmith is source-available under the Elastic License 2.0.

You CAN:

  • Use Skillsmith for personal or internal business purposes
  • Modify the source code for your own use
  • Self-host for your team
  • Contribute bug fixes and improvements

You CANNOT:

  • Offer Skillsmith as a managed service to third parties
  • Circumvent license key enforcement features

For the full license text, see the LICENSE file.

Author

Smith Horn Group Ltd


Skillsmith is not affiliated with Anthropic. Claude and Claude Code are trademarks of Anthropic.

常见问题

Skillsmith 是什么?

面向Claude Code的MCP server,用于技能发现、安装与日常管理。

相关 Skills

MCP构建

by anthropics

Universal
热门

聚焦高质量 MCP Server 开发,覆盖协议研究、工具设计、错误处理与传输选型,适合用 FastMCP 或 MCP SDK 对接外部 API、封装服务能力。

想让 LLM 稳定调用外部 API,就用 MCP构建:从 Python 到 Node 都有成熟指引,帮你更快做出高质量 MCP 服务器。

平台与服务
未扫描175.1k

Slack动图

by anthropics

Universal
热门

面向Slack的动图制作Skill,内置emoji/消息GIF的尺寸、帧率和色彩约束、校验与优化流程,适合把创意或上传图片快速做成可直接发送的Slack动画。

帮你快速做出适配 Slack 的动图,内置约束规则和校验工具,少踩上传与播放坑,做表情包和演示都更省心。

平台与服务
未扫描175.1k

接口测试套件

by alirezarezvani

Universal
热门

扫描 Next.js、Express、FastAPI、Django REST 的 API 路由,自动生成覆盖鉴权、参数校验、错误码、分页、上传与限流场景的 Vitest 或 Pytest 测试套件。

帮你把API与集成测试自动化跑顺,减少回归漏测;能力全面,尤其适合复杂接口场景的QA团队。

平台与服务
未扫描25.7k

相关 MCP Server

Slack 消息

编辑精选

by Anthropic

热门

Slack 是让 AI 助手直接读写你的 Slack 频道和消息的 MCP 服务器。

这个服务器解决了团队协作中需要 AI 实时获取 Slack 信息的痛点,特别适合开发团队让 Claude 帮忙汇总频道讨论或发送通知。不过,它目前只是参考实现,文档有限,不建议在生产环境直接使用——更适合开发者学习 MCP 如何集成第三方服务。

平台与服务
89.7k

by netdata

热门

io.github.netdata/mcp-server 是让 AI 助手实时监控服务器指标和日志的 MCP 服务器。

这个工具解决了运维人员需要手动检查系统状态的痛点,最适合 DevOps 团队让 Claude 自动分析性能数据。不过,它依赖 NetData 的现有部署,如果你没用过这个监控平台,得先花时间配置。

平台与服务
80.0k

by d4vinci

热门

Scrapling MCP Server 是专为现代网页设计的智能爬虫工具,支持绕过 Cloudflare 等反爬机制。

这个工具解决了爬取动态网页和反爬网站时的头疼问题,特别适合需要批量采集电商价格或新闻数据的开发者。不过,它依赖外部浏览器引擎,资源消耗较大,不适合轻量级任务。

平台与服务
72.9k

评论