Agent skill

Extension Upload

by agenvoy in agenvoy/Agenvoy

Package a script tool under ~/.config/agenvoy/tools/script/ into a tar.gz and publish to pkg.agenvoy.com registry.

AGPL-3.0Auto-check passedAgent Workflows

Install Extension Upload

skills CLI
$ npx skills add agenvoy/Agenvoy --skill extension-upload -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install agenvoy/Agenvoy extension-upload --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/agenvoy/Agenvoy.git skills-src && mkdir -p .claude/skills && cp -r skills-src/extensions/skills/extension-upload .claude/skills/extension-upload && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
extension-upload
GitHub stars
439
Token cost
~6.1k tokens
SKILL.md length
2,235 words
Files
1
Skills in repo
4
Repo updated
First seen
Licence
AGPL-3.0

At a glance

Package a script tool under ~/.config/agenvoy/tools/script/ into a tar.gz and publish to pkg.agenvoy.com registry.

  • Works in 10 steps: Select extension_dir (picker) → Read the directory → Infer type → …
  • Agent Workflows work in your project
  • SKILL.md covers Input, Flow and Forbidden
  • Calls node, git and python3; reaches pkg.agenvoy.com

What it does

Extension Upload is an agent skill from agenvoy/Agenvoy. Package a script tool under ~/.config/agenvoy/tools/script/ into a tar.gz and publish to pkg.agenvoy.com registry. Keyword picker, dep/key detection, config-stored email (ask + lowercase + persist), ask version, email verification gate, multipart upload with downgrade/unique guards.

Its SKILL.md is about 6.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Agent Workflows. It works with Model Context Protocol. The repository describes itself as: Self-hosted 24/7 personal AI agent that runs on your own machine — memory, schedules, tools and credentials stay local. Single Go binary with MCP. The licence is AGPL-3.0.

When your agent uses it

  • Agent Workflows work in your project

Example prompts

  • “/extension-upload”

Requirements

  • Python 3

Workflow steps

10 steps, taken from the step headings in SKILL.md.

  1. Select extension_dir (picker)
  2. Read the directory
  3. Infer type
  4. Detect dependence and api_key_name
  5. Take name and summary from tool.json
  6. Get registry email (from config; ask if missing)
  7. Fill in any missing manifest fields
  8. Write manifest.json and package
  9. Upload to pkg.agenvoy.com (registry)
  10. Final report

What it can do on your machine

Read from SKILL.md and the folder at commit c7ba3b0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • node
    • git
    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • pkg.agenvoy.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Extension Upload loads about 6.1k tokens when it runs. Until then it costs about 75 tokens; SKILL.md has 2,235 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~75
When it runs · the whole SKILL.md, loaded when a task matches
~6.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from agenvoy/Agenvoy at commit c7ba3b0, republished under its AGPL-3.0 licence (© agenvoy). 2,235 words, ~6,085 tokens.

Download SKILL.mdSave it as .claude/skills/extension-upload/SKILL.md (or your agent's skills folder).
name
extension-upload
description
Package a script tool under ~/.config/agenvoy/tools/script/ into a tar.gz and publish to pkg.agenvoy.com registry. Keyword picker, dep/key detection, config-stored email (ask + lowercase + persist), ask version, email verification gate, multipart upload with downgrade/unique guards.

本 Skill 為 Agenvoy 內部最佳化版本,依 Agenvoy 的執行環境撰寫(run_command 的 CWD、~/.config/agenvoy/skills/.system/ 安裝位置、edit_skill/schedules/find_edit_tool 等工具、subagent 與排程的觸發路徑),不保證適配其他 AI harness。

Extension Uploader

Packages an Agenvoy script tool directory into a marketplace tarball and uploads it to pkg.agenvoy.com. The source root is fixed at ~/.config/agenvoy/tools/script/. If the user provides a keyword (e.g. yt), only matching subdirectories are listed.

Input

keyword (optional): substring filter (case-insensitive) over subdirectories under ~/.config/agenvoy/tools/script/. Examples: yt, dlp, tts.

  • With keyword → list filtered matches
  • Without keyword (e.g. plain /extension-upload) → list ALL subdirectories for the user to pick; do not ask for a keyword
0. Select extension_dir (picker)

Fixed source root:

SCRIPT_ROOT=~/.config/agenvoy/tools/script

find_files(mode=list) lists all first-level subdirectories under SCRIPT_ROOT (non-recursive). Skip names starting with . or _.

Branch by input:

Has keyword?Candidate set
NoAll subdirectories
YesSubdirectories whose name (lowercased) contains keyword (lowercased)

Branch by candidate count:

CountAction
0Abort. With keyword: "No directory matching <keyword> under SCRIPT_ROOT". Without keyword: "SCRIPT_ROOT is empty — create a script tool first using edit_tool(mode=write)"
1Use that directory as extension_dir directly; report "auto-selected <basename>"
≥ 2ask_user singleSelect listing all candidates; user picks one as extension_dir

extension_dir is the absolute path <SCRIPT_ROOT>/<basename>, used by every step below.

Note: this skill only packages script tools (fixed type: "script"). Packaging api tools requires a separate skill. The worker does not accept mcp type.

Flow

1. Read the directory

find_files(mode=list, recursive=true) enumerates every file under extension_dir (relative paths).

Collect into raw_files, excluding:

  • .DS_Store, Thumbs.db, .git*
  • *.tar, *.tar.gz, *.tgz, *.zip
  • An existing manifest.json (this skill will regenerate it)

read_files reads (if present):

  • tool.json (required — if missing, abort with "tool.json missing in <extension_dir>, refuse to package")
  • All script.{js,py,sh} / *.js / *.py / *.sh
1.5 Generic structure check (gate)

Check root-level files under extension_dir. Abort immediately on any violation:

RuleCondition
tool.json must existextension_dir/tool.json exists and is a regular file
script mutual exclusionscript.py and script.js must not coexist (both present → abort)

Abort message:

❌ Structure check failed: script.py and script.js cannot coexist (keep only one).
2. Infer type

Fixed type: "script" (this skill only packages tools under ~/.config/agenvoy/tools/script/).

2.5 Type-specific structure check (gate)

For type: script:

RuleCondition
script must existscript.py or script.js must exist (exactly one); both missing → abort

Abort message:

❌ Structure check failed: type:script requires script.py or script.js.
2.7 Health check (gate)

Verify the script can be parsed by its interpreter so consumers don't install something that immediately crashes. Any failure aborts and prints the stderr.

Branch on the script file confirmed in §2.5:

  • script.py:
    bash
    python3 -m py_compile <extension_dir>/script.py
  • script.js:
    bash
    node --check <extension_dir>/script.js

exit code ≠ 0 → abort:

❌ Health check failed: script cannot be parsed by the interpreter.
<first line of stderr>

Note: only syntax-level. Top-level code is not executed; import errors / runtime errors / missing API keys are not checked. The author must test runtime behavior before packaging.

3. Detect dependence and api_key_name
Dependence (system binary names)

Scan every script file for these patterns to extract binaries:

  • JavaScript: spawn("X" / exec("X" / execSync("X" / spawnSync("X"
  • Python: subprocess.run(["X" / subprocess.Popen(["X" / os.system("X " / shell=True + "X "
  • Shell: the first non-reserved-word token

Exclude:

  • Shell builtins: cd, echo, test, [, export, set, shift, pwd, true, false
  • Interpreters themselves: node, python, python3, bash, sh, /usr/bin/env
  • Tools whitelisted by default: ls, cat, head, tail, mkdir, cp, mv, rm, grep, sed, awk, find, jq, which, date, git (almost always present; not counted as a dependence)

What remains (e.g. yt-dlp, ffmpeg, imagemagick, pandoc, tesseract) is the dependence candidate set.

Api_key_name (keychain key names)

Scan every script file for these patterns to extract key names:

  • find-generic-password -s agenvoy -a ([A-Z][A-Z0-9_]*_API_KEY)
  • secret-tool lookup service agenvoy account ([A-Z][A-Z0-9_]*_API_KEY)
  • process\.env\.([A-Z][A-Z0-9_]*_API_KEY)
  • os\.environ\[["']([A-Z][A-Z0-9_]*_API_KEY)["']\]
  • os\.environ\.get\(["']([A-Z][A-Z0-9_]*_API_KEY)["']
  • \$([A-Z][A-Z0-9_]*_API_KEY) (shell scripts)

Dedupe and sort all hits.

Confirm detection results

Call ask_user. Put the detection list in the detail field (hint-style subtitle); keep question short:

json
{
  "questions": [
    {
      "question": "Are the detections above correct?",
      "detail": "dependence: [yt-dlp, ffmpeg]\napi_key_name: []",
      "options": ["Yes, continue", "No, let me edit dependence", "No, let me edit api_key_name", "No, edit both"]
    }
  ]
}

detail is multi-line hint text; question is the short prompt. The popup renders detail with hint style (subtitle) and question with bold (title). Never stuff detail content into question — they will render together and become unreadable.

4. Take name and summary from tool.json

tool.json is the source of truth for these fields:

  • manifest.name = tool.json::name verbatim
  • manifest.summary = first line of tool.json::description, truncated to 120 chars

If either fails §6 validation (name pattern / summary length), §6 handles it with ask_user.

4.5 Ask version

Pre-read <extension_dir>/manifest.json if it exists and use its version as the default; otherwise default to 1.0.0.

ask_user (single free-text):

Enter version (semver `MAJOR.MINOR.PATCH`, e.g. 1.0.0; blank = use default <default>):
default: <existing manifest version or 1.0.0>

Reply handling:

ReplyAction
Blank / whitespace-only / emptyUse default as manifest.version — not an error, do not re-prompt
Matches ^\d+\.\d+\.\d+$Accept as-is
Anything else (incl. v prefix, pre-release like 1.0.0-beta, build metadata +sha, etc.)Re-prompt; abort after 3 attempts with "version format invalid, upload cancelled"

Never treat blank as an error — a deliberate blank means "use default".

5. Get registry email (from config; ask if missing)

read_files("~/.config/agenvoy/config.json") → parse JSON → check email field:

  • Non-empty string → use directly, do not re-prompt, jump to §6
  • Missing / empty → fall through to §5.1 first-time setup
5.1 First-time setup

ask_user (single free-text):

First publish needs a marketplace registry email (stored in ~/.config/agenvoy/config.json, reused next time):

Validate against ^[^@\s]+@[^@\s]+\.[^@\s]+$:

  • Pass → lowercase first, then read_files → edit_file(mode=patch) to persist "email": "<lowercased>" into config.json (worker normalizes to lowercase, client must match)
  • Fail → re-prompt; abort after 3 attempts with "email format invalid"
  • Blank / cancel → abort with "no email provided, cannot upload"

The entire username / git config user.name chain is gone — marketplace identity uses email only. The manifest uses the email field (not author); its value is the lowercased pure email string.

6. Fill in any missing manifest fields

Assemble the candidate manifest:

json
{
  "name": "<tool.json::name>",
  "type": "script",
  "version": "<from §4.5>",
  "summary": "<first line of tool.json::description, truncated to 120>",
  "email": "<§5.1/5.2 registry email, lowercased>",
  "dependence": <confirmed in §3>,
  "api_key_name": <confirmed in §3>,
  "files": <raw_files from §1>
}

Validate field by field; any failure triggers ask_user to fix that field:

FieldCondition
namenon-empty, matches ^[a-z0-9][a-z0-9_-]*$
type∈ {api, script} (worker rejects mcp)
versionstrict semver ^\d+\.\d+\.\d+$ (no pre-release suffix)
summarynon-empty, ≤ 120 chars
emailnon-empty, matches ^[^@\s]+@[^@\s]+\.[^@\s]+$ (already guaranteed by §5)
dependencearray, elements non-empty (empty array OK)
api_key_namearray, each element matches [A-Z][A-Z0-9_]*_API_KEY (empty array OK)
filesarray, length ≥ 1, must include tool.json

Re-validate after each fix; only proceed once everything passes.

7. Write manifest.json and package

Fixed output directory: ~/.config/agenvoy/tools/.extension/.package/ — not $HOME/Downloads, not ~/.config/agenvoy/download/, not the current work dir, not the source dir.

Fixed filename format: <name>@<version>.tar.gz (e.g. yt-dlp-info@1.0.0.tar.gz).

edit_file(mode=write):

  • Path: <extension_dir>/manifest.json
  • Content: the manifest that passed §6 validation, pretty-printed (2-space indent), trailing newline

run_command:

bash
mkdir -p ~/.config/agenvoy/tools/.extension/.package
bash
tar --no-xattrs -czf ~/.config/agenvoy/tools/.extension/.package/<name>@<version>.tar.gz -C <extension_dir>/.. <basename(extension_dir)>/

Where <basename> is the last segment of extension_dir (e.g. yt_dlp_youtube_downloader).

  • --no-xattrs: mandatory. macOS bsdtar tries to read xattrs (e.g. com.apple.quarantine) by default; the sandbox can't read them and prints "Operation not permitted" warnings. Marketplace packages shouldn't carry OS-local metadata anyway.
  • -C <parent>: points to the parent so the tarball stores <basename>/<file>... rather than absolute paths.
7.5 Disk verify (gate — the only success check)

run_command returns a merged stdout+stderr string to the LLM. The LLM cannot see the exit code by itself, and must not guess from stderr substrings like "not permitted" / "error" / "warning". tar can print xattr/ACL warnings yet still exit 0 with a valid tarball.

The only reliable check:

bash
ls -l ~/.config/agenvoy/tools/.extension/.package/<name>@<version>.tar.gz
ls resultVerdict
File exists, size > 0 bytesPackaging succeeded. Record the size, proceed to §8. Ignore every stderr warning from the tar step.
No such file or directory or size 0Actually failed. Print the tar stderr to the user and abort.

Do not branch on "stderr contains a warning → failure". A tarball on disk = success.

If tar is blocked, tell the user:

⚠️ tar is blocked. Check whether it is listed under denied_command in ~/.agenvoy/config.json.
8. Upload to pkg.agenvoy.com (registry)

Fixed endpoint: https://pkg.agenvoy.com/upload — it is not configurable.

manifest.email is the registration email (pure email string); keep it for the §9 report. read_files <extension_dir>/manifest.json to obtain the full JSON string for fields.manifest below (the worker will JSON.parse(manifest) and re-validate).

8.1 First POST — trigger verification email

Call http_request. All four fields are required (url / method / content_type / body); missing any one of them and the worker returns multipart parse failed:

json
{
  "url": "https://pkg.agenvoy.com/upload",
  "method": "POST",
  "content_type": "multipart",
  "body": {
    "fields": {
      "manifest": "<full JSON string written in §7>"
    },
    "files": [
      {
        "name": "tar",
        "path": "~/.config/agenvoy/tools/.extension/.package/<name>@<version>.tar.gz",
        "content_type": "application/gzip"
      }
    ]
  }
}

Do not simplify the payload:

  • Never omit content_type: "multipart" (defaults to json, worker won't see multipart, fails)
  • Never omit body (must contain both fields and files)
  • Never put the manifest JSON into files[] (manifest is a text field, goes under fields.manifest)
  • Never put tar bytes into fields (tar is binary, goes under files[].path and is read from disk by the handler)

Response is the http_request envelope: {status_code, headers, body}. status_code is the only branching signal — do not guess from the body string.

status_codeExpected bodyAction
202{"ok":false,"error":"verification_sent","email":"...","ttl_seconds":60}Proceed to §8.2
400schema errorAbort, print the error in the body
413tar_too_largeAbort
502email_send_failedAbort
OtherShouldn't happen on first POST without a code (always expect 202)Abort, print the raw body
Show full SKILL.md (905 more words)Show less
8.2 ask_user for the verification code

ask_user (single free-text):

A verification code was sent to <email> (valid 60s). Enter the 6-digit code:

If blank or not 6 digits → re-prompt up to 3 times; abort with "verification code format invalid, upload cancelled".

Collect the code with ask_user; guessing / pre-fill / popupSecret are not substitutes — the code is not a secret, expires in 60s, and plaintext echo helps the user paste it correctly.

8.3 Second POST with the code

Call http_request — same four-field structure as §8.1, only difference is fields now also has code:

json
{
  "url": "https://pkg.agenvoy.com/upload",
  "method": "POST",
  "content_type": "multipart",
  "body": {
    "fields": {
      "manifest": "<same as 8.1>",
      "code": "<6-digit code>"
    },
    "files": [
      {
        "name": "tar",
        "path": "<same as 8.1>",
        "content_type": "application/gzip"
      }
    ]
  }
}
status_codeAction
200Success — parse body for r2_key / sha256 / size_bytes, proceed to §9
401verification_failed (wrong / expired) → loop back to §8.2; abort after 3 retries
409version_already_exists or type_mismatch → abort, print body existing info, ask user to bump version or align type
422downgrade_not_allowed → abort, print body latest, ask user to bump version
413tar_too_large → abort
5xxinternal / email_send_failed → abort, print raw body
OtherAbort, print raw body
9. Final report

Success (§8.3 returned 200):

✅ packaged & published
- manifest: <extension_dir>/manifest.json
- tarball:  ~/.config/agenvoy/tools/.extension/.package/<name>@<version>.tar.gz
- size:     <bytes>
- registry: pkg.agenvoy.com
- r2_key:   <body.r2_key>
- sha256:   <body.sha256>

size was captured by ls in §7.5 — do not re-run.

Upload-stage failure (§8.1 / §8.2 / §8.3) → show ✅ packaged plus ❌ publish failed with the worker error; the local tarball stays in .package/ so the user can fix and retry.

§7.5 disk-verify failure (tarball missing or size 0) → show ❌ packaging failed with the tar stderr; do not proceed to §8.

Forbidden

  • Never hardcode email; it must come from config.json (and §5.1 ask_user + edit_file(mode=patch) if missing)
  • Never touch git config user.name / git config user.email; marketplace identity uses only the config registry email
  • Never use an author field in the manifest; the worker expects email (a pure email string, not <name> (<email>))
  • Never skip the §5.2 lowercase normalize; the worker normalizes email to lowercase — mismatched case breaks both KV verification lookup and D1 lookup
  • Never re-ask the user for email; once §5.1 returns a non-empty value, use it
  • Never run username sanitization in §5, never derive a <safe-author> / <email-local> prefix; the filename is just <name>@<version>.tar.gz with no prefix
  • Never add items to dependence / api_key_name that weren't detected in the scripts; the user can add them in §3, but the LLM must not embellish
  • Never list manifest.json itself in the files array (the marketplace client fetches the manifest separately)
  • Never omit -C <parent> in §7 — the tarball would contain absolute paths otherwise
  • Never omit --no-xattrs in §7 — macOS sandbox can't read xattrs and would flood warnings
  • Never skip §7.5 disk verify; ls -l <tarball> is the only success check
  • Never infer failure from stderr substrings ("not permitted" / "error" / "warning" / "Operation not permitted"); run_command returns merged stdout+stderr and the LLM has no exit code — disk state is the source of truth
  • Never claim ✅ packaged and ❌ publish failed while stopping at the packaging step — that's a contradiction; once §7.5 passes, packaging succeeded and §8 must run
  • Never drop the tarball in the current work dir, ~/Downloads, ~/.config/agenvoy/download/, the source dir, tmp, or any path from ask_user; the output location is fixed at ~/.config/agenvoy/tools/.extension/.package/
  • Never add prefixes like <safe-author>- / <email-local>- to the filename; fixed <name>@<version>.tar.gz
  • Never substitute zip for tar.gz (the marketplace only accepts tar.gz)
  • Never lower §6 standards by accepting 1.0, v1.0.0, 1.0.0-beta etc.
  • Never skip §1.5 or §2.5 structure checks (tool.json must exist, script.py and script.js are mutually exclusive, type:script requires a script)
  • Never bypass the §0 picker by guessing extension_dir; the source root is fixed at ~/.config/agenvoy/tools/script/ — do not scan .extension/ / api/ / anywhere else
  • Invoked without a keyword → skip ask_user — list all subdirectories directly (the user explicitly wants to browse everything)
  • Never fall back to "list everything" when a provided keyword yields zero hits — abort and ask for a more precise keyword
  • This skill only packages type:script; §2 type is fixed
  • Never skip §2.7 health check; a syntax failure means the tool is broken — shipping it would crash on install
  • Never replace py_compile / node --check in §2.7 with "run the whole script" — top-level reads on stdin would hang
  • name and summary in §4 come from tool.json; §6 handles the validation fallback
  • Never skip §4.5; the user must confirm version in the main flow — do not hardcode 1.0.0 or rely on §6 fallback
  • Never accept v prefix, pre-release suffix, or build metadata (+sha) in §4.5; strict ^\d+\.\d+\.\d+$
  • Never treat a blank reply as an error in §4.5; blank = "use default", accept directly and do not re-prompt
  • The §8 endpoint is fixed at https://pkg.agenvoy.com/upload; staging / custom domains are not options
  • Never skip the first §8.1 POST (the one that triggers the email) and jump to §8.3 with a guessed code; the code must come from the worker email and be entered by the user
  • Never use popupSecret to collect the code in §8.2; the code is not a secret, expires in 60s, plaintext echo helps the user paste it
  • Never use run_command with curl / wget; uploads must use http_request with content_type=multipart, binary read from files[].path
  • Never simplify the §8 http_request payload — all four fields (url/method/content_type/body) are required, and body must contain both fields and files
  • Never omit content_type: "multipart" (defaults to json, worker won't see multipart)
  • Never put manifest JSON into files[] (it's a text field, goes under fields.manifest); never put tar bytes into fields (binary goes under files[].path and the handler reads from disk)
  • Never guess status_code; use the http_request envelope status_code as the only branch signal
  • Never auto-bump version and re-POST after 409 / 422; both codes signal "user-side mistake" — user bumps the version manually, then re-run the whole skill
  • Never upload tarball + manifest to any endpoint other than §8 (raw GitHub / S3 / any other worker variant)
    </content>
</invoke>

© agenvoy, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in extensions/skills/extension-upload of agenvoy/Agenvoy.

Open the folder on GitHubat commit c7ba3b0

Compare with similar skills

Extension Upload next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Extension Upload compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Extension Upload this skillagenvoy/Agenvoy439—~6.1kAutomated safety check: PassAGPL-3.0
MCP Server Builderanthropics/skills180k63 repos~2.3kAutomated safety check: PassApache-2.0
MCP Server BuildershareAI-lab/learn-claude-code78k4 repos~1.2kAutomated safety check: PassMIT
MCP Integration for Pluginsanthropics/claude-plugins-official38k11 repos~3.1kAutomated safety check: PassApache-2.0
MemPalace Memory SearchMemPalace/mempalace60k—~1.4kAutomated safety check: PassMIT
Crush Configurationcharmbracelet/crush29k—~3.7kAutomated safety check: PassCustom licence

Similar skills

  • MCP Server Builder

    anthropics/skills

    Official

    Guides the design and implementation of Model Context Protocol servers in TypeScript or Python, from tool naming and error messages to evaluation.

    180k GitHub starsUsed in 63 repos~2.3k tokens
    Agent WorkflowsAuto-check passed
  • MCP Server Builder

    shareAI-lab/learn-claude-code

    Walks through building MCP servers in Python or TypeScript that expose tools, resources and prompts to Claude, with templates, registration and testing.

    78k GitHub starsUsed in 4 repos~1.2k tokens
    Agent WorkflowsAuto-check passed
  • MCP Integration for Plugins

    anthropics/claude-plugins-official

    Official

    Explains how to bundle Model Context Protocol servers in a Claude Code plugin, covering config files, stdio, SSE, HTTP and WebSocket server types, and authentication.

    38k GitHub starsUsed in 11 repos~3.1k tokens
    Agent WorkflowsAuto-check passed
  • MemPalace Memory Search

    MemPalace/mempalace

    Mines project files and conversation exports into a local, searchable memory palace and recalls past work by semantic search through the mempalace CLI.

    60k GitHub stars~1.4k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Crush Configuration

    charmbracelet/crush

    Explains how to configure the Crush coding agent with crushrc or crush.json, covering providers, models, LSPs, MCP servers, hooks, permissions and config precedence.

    29k GitHub stars~3.7k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Context Mode Output Sandbox

    mksglu/context-mode

    Routes large command, file, API and browser output through context-mode tools so only the needed result enters the agent's context, instead of dumping it via Bash.

    26k GitHub stars~4.1k tokensUpdated today
    Agent WorkflowsAuto-check passed

More from agenvoy/Agenvoy

  • 建立並排程定時觸發的 skill。所有新增定時/週期任務、提醒、排程通知的請求必須走此 skill,禁止直接呼叫 schedules(mode=write)(那是 skill 已存在時的時間綁定工具,不該作為新建排程的入口)。

    439 GitHub stars~3k tokensUpdated today
    Auto-check passed
  • Skill Creator

    agenvoy/Agenvoy

    Create, edit, improve, or audit AgentSkills. An agent skill from agenvoy/Agenvoy.

    439 GitHub stars~3k tokensUpdated today
    Auto-check passed
  • Extension Install

    agenvoy/Agenvoy

    Install an Agenvoy extension from pkg.agenvoy.com registry (browse/pick) or local tarball into ~/.config/agenvoy/tools/.extension/<type/<name@<version/.

    439 GitHub stars~2.9k tokensUpdated today
    Auto-check: notes

Categories

Questions about Extension Upload

What does Extension Upload do?

Package a script tool under ~/.config/agenvoy/tools/script/ into a tar.gz and publish to pkg.agenvoy.com registry. Extension Upload is an agent skill from agenvoy/Agenvoy.com registry.

When should I use Extension Upload?

Extension Upload fits situations like: agent Workflows work in your project.

How do I install Extension Upload in Claude Code?

Run `npx skills add agenvoy/Agenvoy --skill extension-upload -a claude-code`. Or copy the skill folder (extensions/skills/extension-upload in agenvoy/Agenvoy) into .claude/skills/extension-upload in your project. Claude Code loads it when a task matches its description.

How do I install Extension Upload in Codex?

Run `npx skills add agenvoy/Agenvoy --skill extension-upload -a codex`. Or copy the skill folder (extensions/skills/extension-upload in agenvoy/Agenvoy) into .agents/skills/extension-upload in your project. Codex loads it when a task matches its description.

Can I use Extension Upload in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add agenvoy/Agenvoy --skill extension-upload -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/extension-upload, .gemini/skills/extension-upload, .github/skills/extension-upload and .opencode/skills/extension-upload in your project.

What does Extension Upload need to run?

Going by SKILL.md and its folder, Extension Upload needs the command-line tools its instructions call (node, git and python3). Our summary lists: Python 3.

Does Extension Upload access the network?

SKILL.md names 1 domain. In commands or code: pkg.agenvoy.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Extension Upload safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Extension Upload use?

Extension Upload is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Extension Upload use?

About 6.1k tokens (SKILL.md is roughly 24k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Extension Upload?

Skills that share tags, products or a category with Extension Upload: MCP Server Builder (anthropics/skills, 180k stars), MCP Server Builder (shareAI-lab/learn-claude-code, 78k stars), MCP Integration for Plugins (anthropics/claude-plugins-official, 38k stars) and MemPalace Memory Search (MemPalace/mempalace, 60k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Extension Upload?

agenvoy (a GitHub organization) maintains it in agenvoy/Agenvoy, which has 439 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on October 10, 2026.

Source: agenvoy/Agenvoy on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.