Skip to main content

Architecture

Repository layout

Data flow

Principles

  1. Skills are the product. Everything else validates, packages or distributes them.
  2. One source of truth. Manifests, catalog, notices, README tables, llms.txt and docs pages are generated from skills/ and third_party/, and CI fails if any is stale (tools/build_catalog.py --check).
  3. Spec-first portability. Only Agent Skills spec fields at the top level of frontmatter, so every harness can load every skill.
  4. Deterministic code for deterministic work. Parsing, validation and conversion live in tested scripts, not in prose.
  5. Defense in depth. Validation, injection lint, third-party scanner, code scanning, a network allowlist, signed releases and install-time hashes.
  6. Measured quality. Static rubric → trigger routing → task outcomes (see Benchmarks).

CI pipelines

Adapted vs original skills

Adapted skills come from MIT-licensed upstream projects at pinned revisions (third_party/sources.yaml) and are normalized by tools/import_upstream.py + tools/rebrand.py. Fixes live in third_party/patches/, so re-imports keep them. Original skills are written in this repository. The catalog marks each skill’s origin, and notices are generated in THIRD_PARTY_NOTICES.md.