Agent skill

Skill Publisher

by apigee in apigee/devrel

Publishes a local skill directory to the API hub catalog and the GCS bundle store.

Apache-2.0Auto-check passed

Install Skill Publisher

skills CLI
$ npx skills add apigee/devrel --skill skill-publisher -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install apigee/devrel skill-publisher --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/apigee/devrel.git skills-src && mkdir -p .claude/skills && cp -r skills-src/references/apigee-skills-serving/skills/skill-publisher .claude/skills/skill-publisher && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
skill-publisher
GitHub stars
221
Token cost
~4k tokens
SKILL.md length
1,959 words
Files
3 (incl. scripts)
Skills in repo
5
Repo updated
First seen
Licence
Apache-2.0

At a glance

Publishes a local skill directory to the API hub catalog and the GCS bundle store.

  • Works in 6 steps: Resolve the source path. Take the value… → Validate the inputs before invoking… → Reject shell metacharacters in… → …
  • SKILL.md covers ⚠️ Runtime requirements (read…, What this skill does NOT do, Inputs and Runtime dispatch, plus 7 more sections
  • Runs Shell scripts from its folder; calls python3, bash and gcloud; needs SIGNING_PRIV_KEY

What it does

Skill Publisher is an agent skill from apigee/devrel. Publishes a local skill directory to the API hub catalog and the GCS bundle store. Runs the four-step author pipeline end to end, packing the source tree into a deterministic .skill zip, signing the manifest with an ed25519 private key, uploading the zip to GCS, and registering the signed manifest with API hub as an API plus Version plus Spec triple along with its four attribute values. Idempotent by design; re-running with identical inputs produces byte-identical output. Includes a bootstrap mode for first-time…

Its SKILL.md is about 4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including scripts (for example `manifest.yaml` and `scripts/publish.sh`). Compatibility notes: opencode, antigravity, gemini-cli

It works with Python. The repository describes itself as: Common solutions and tools developed for Apigee. The licence is Apache-2.0.

Example prompts

  • “Use the skill-publisher skill to publish a local skill directory to the API hub catalog and the GCS bundle store”
  • “/skill-publisher”

Requirements

  • Python 3
  • A Bash shell
  • A credential in SIGNING_PRIV_KEY
  • Compatibility (from SKILL.md): opencode, antigravity, gemini-cli

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Resolve the source path. Take the value from SKILL_SRC
  2. Validate the inputs before invoking bash. Verify that the
  3. Reject shell metacharacters in SKILL_SRC. The path is
  4. **Invoke the publish script using the runtime path from the
  5. Surface the script's stdout verbatim. The script prints
  6. On non-zero exit, stop. Surface the failing step's stderr

What it can do on your machine

Read from SKILL.md and the folder at commit 5a8ba69. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • python3
    • bash
    • gcloud

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gcloud, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • SIGNING_PRIV_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    opencode, antigravity, gemini-cli

    From compatibility in the SKILL.md frontmatter.

Context cost

Skill Publisher loads about 4k tokens when it runs. Until then it costs about 138 tokens; SKILL.md has 1,959 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~138
When it runs · the whole SKILL.md, loaded when a task matches
~4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from apigee/devrel at commit 5a8ba69, republished under its Apache-2.0 licence (© apigee). 1,959 words, ~4,004 tokens.

Download SKILL.mdSave it as .claude/skills/skill-publisher/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
skill-publisher
description
Publishes a local skill directory to the API hub catalog and the GCS bundle store. Runs the four-step author pipeline end to end, packing the source tree into a deterministic .skill zip, signing the manifest with an ed25519 private key, uploading the zip to GCS, and registering the signed manifest with API hub as an API plus Version plus Spec triple along with its four attribute values. Idempotent by design; re-running with identical inputs produces byte-identical output. Includes a bootstrap mode for first-time self-publication.
compatibility
opencode, antigravity, gemini-cli
license
Apache-2.0
metadata.pipeline_scripts
scripts.pack_skill, scripts.sign_skill, scripts.upload_skill, scripts.register_skill

skill-publisher

⚠️ Runtime requirements (read this first)

This skill requires its bundled venv wrapper. publish.sh internally invokes the four scripts/* Python modules (pack_skill, sign_skill, upload_skill, register_skill), which depend on cryptography, google-auth, requests, and pyyaml. Those are installed into a per-user venv by the installer (bin/install-skill-publisher.sh). They are not available to the system python3.

Always invoke publish.sh via the wrapper, never via bare bash:

bash
# CORRECT - the wrapper exports PYTHON to point at the venv:
${SKILL_DIR}/bin/run-with-venv.sh <args>

# WRONG - publish.sh will fall back to system python3 which
# will hit ModuleNotFoundError mid-pipeline:
bash ${SKILL_DIR}/scripts/publish.sh <args>

The Command blocks in this file use the wrapper form. Do not "simplify" them — publish.sh reads $PYTHON from its environment and the wrapper is the only thing that sets it correctly. If you invoke publish.sh directly, the four sub-scripts will fail with ModuleNotFoundError.

If the wrapper at ${SKILL_DIR}/bin/run-with-venv.sh is missing, the skill was installed by a pre-v0.1.4 installer. Re-run bin/install-skill-publisher.sh to regenerate the wrapper.


Use this skill when the user asks to "publish a skill", "ship this skill to API hub", "upload and register my skill", "release the skill", or any close paraphrase. This is the single entry point for author-side distribution; it wraps the four scripts/* CLIs from the upstream source repo into one orchestrated sequence with fail-fast semantics.

What this skill does NOT do

  • It does not create the GCS bucket. The bucket must already exist (see repo README §2).
  • It does not create API hub attribute definitions. Run python3 -m scripts.update_taxonomy once per project first (see repo README §4).
  • It does not generate or rotate signing keys. The ed25519 private key path is an input.
  • It does not install the published skill into any local runtime. That is skill-finder's job.

If any prerequisite is missing the underlying script returns a non-zero exit code and this skill surfaces it verbatim and stops.

Inputs

VariableSourceRequiredNotes
SKILL_SRCUser / agentyesPath to a skills/<name>/ source directory containing manifest.yaml and (at minimum) SKILL.md.
SKILL_OUTOperatornoOutput path for the packed zip. Defaults to /tmp/${name}-${version}.skill derived from the manifest.
GCS_BUCKETOperator (${GCS_BUCKET})yesGCS bucket name (no gs:// prefix). Must match the bucket portion of the manifest's gs_uri.
SIGNING_PRIV_KEYOperator (${SIGNING_PRIV_KEY})yesPath to the raw 32-byte ed25519 private key. See the upstream README's author-flow section for how to generate one.
APIHUB_PROJECTOperator (${APIHUB_PROJECT})yesGCP project hosting the API hub instance.
APIHUB_LOCATIONOperator (${APIHUB_LOCATION})yesAPI hub region (e.g. us-central1).
REPO_ROOTAutonoRoot of the upstream source checkout. Defaults to the current working directory. The four scripts/* modules must be importable from there.
BOOTSTRAPUser / agentnoIf set to 1 or true, runs the bootstrap path that publishes skill-publisher itself. See "Bootstrap mode" below.

Runtime dispatch

This skill ships one orchestration contract that runs on multiple runtimes. Pick the invocation path that matches your runtime; the behaviour and stdout contract are identical.

RuntimeHow you invoke the publish script
OpenCodeUse the !bash`` injection blocks below. OpenCode auto-executes them on SKILL.md load.
Gemini CLIUse your bash tool. Run the matching Command block, substituting ${SKILL_DIR} with the install path (~/.gemini/skills/skill-publisher for global; <project>/.agents/skills/skill-publisher for workspace) and the operator-controlled env vars from the table above.
AntigravitySame as Gemini CLI but ${SKILL_DIR} is ~/.gemini/antigravity/skills/skill-publisher for global installs.
Any other runtimeSame as Antigravity / Gemini CLI: invoke via whatever bash mechanism the runtime provides.

Mode 1: Publish a third-party skill

Use this when the user wants to publish any skill other than skill-publisher itself.

Steps
  1. Resolve the source path. Take the value from SKILL_SRC verbatim if provided. Otherwise ask the user once: "Which skill directory do you want to publish?" Expect a path like skills/apigee-policy-top10. Do not paraphrase the answer.

  2. Validate the inputs before invoking bash. Verify that the following are all set and non-empty: SKILL_SRC, GCS_BUCKET, SIGNING_PRIV_KEY, APIHUB_PROJECT, APIHUB_LOCATION. If any is missing, REFUSE to invoke and tell the user which one is missing. Do not guess.

  3. Reject shell metacharacters in SKILL_SRC. The path is interpolated into a bash command via POSIX double quotes, which do not suppress $(...) command substitution or backtick expansion. If SKILL_SRC contains any of ` $ \ " ; & | < > ( ) { } REFUSE to invoke and ask the user to rephrase.

  4. Invoke the publish script using the runtime path from the table above. The exact command is:

    Command (OpenCode auto-runs this; on Antigravity / Gemini CLI run it via your bash tool):

    !bash ${SKILL_DIR}/scripts/publish.sh \ --src "${SKILL_SRC}" \ --bucket "${GCS_BUCKET}" \ --priv-key "${SIGNING_PRIV_KEY}" \ --project "${APIHUB_PROJECT}" \ --location "${APIHUB_LOCATION}"

  5. Surface the script's stdout verbatim. The script prints one [skill-publisher] step N/4 ... line per pipeline step, followed by the GCS URI and the API hub resource path on success. Reproduce every line as-is; do NOT summarize. The lines are a stable contract for log parsing.

  6. On non-zero exit, stop. Surface the failing step's stderr verbatim. Do not retry, do not "fix" the manifest, do not re-sign with a different key. The four underlying scripts have distinct exit codes (see "Exit code mapping" below); use them to give the user an accurate diagnosis.


Mode 2: Bootstrap — publish skill-publisher itself

Use this when the user wants to publish skill-publisher for the first time, or republish it after editing its own source.

The bootstrap problem

skill-publisher cannot use its own installed copy to publish itself: at first run the installed copy does not yet exist in the API hub catalog. Once published, subsequent versions of skill-publisher can be republished by the currently-installed copy — but the very first publish is a chicken-and-egg situation.

Steps
  1. Confirm the user actually means bootstrap. Ask once: "Do you want to publish skill-publisher itself (bootstrap mode)? This is normally only done by repo maintainers." If the user says no, switch to Mode 1.

  2. Validate the inputs exactly as Mode 1 step 2. SKILL_SRC for bootstrap is always the path to the in-repo skills/skill-publisher/ directory; default to that if the user does not specify.

  3. Invoke with --bootstrap. The bootstrap flag tells publish.sh to use the repo-local scripts/publish.sh (this file) directly via the four sibling Python modules in ${REPO_ROOT}/scripts/, rather than relying on any installed copy. The exact command is:

    Command:

    !bash ${SKILL_DIR}/scripts/publish.sh \ --src "${SKILL_SRC:-skills/skill-publisher}" \ --bucket "${GCS_BUCKET}" \ --priv-key "${SIGNING_PRIV_KEY}" \ --project "${APIHUB_PROJECT}" \ --location "${APIHUB_LOCATION}" \ --bootstrap

  4. Surface stdout verbatim (same as Mode 1 step 5).

  5. On success, advise the user to re-run with Mode 1. Tell them: "skill-publisher is now in the catalog. Any future publish — including republishing skill-publisher itself — can use the installed copy via skill-finder + this skill, without --bootstrap."


Exit code mapping

publish.sh exits with the exit code of the first failing step. The mapping below is the union of the four underlying scripts' exit codes (see each script's docstring for detail):

Exit codeMeaningWhere it comes from
0All four steps succeeded.n/a
1User error: bad CLI args, missing file, invalid YAML, ADC unavailable, or empty required env var.any step
2System error: filesystem write failure, GCS network error, GCS 404 (bucket not found), or API hub network error.pack / upload / register
3Either (a) cryptographic error during sign (priv key unreadable / wrong length) OR (b) GCS IAM denial (403) during upload OR (c) API hub IAM denial (403) during register. The failing-step log line in stdout disambiguates.sign / upload / register
4API hub rejected the registration because the four attribute definitions are not initialised. Run python3 -m scripts.update_taxonomy once and retry.register only
5Packaging policy violation: scripts/common/ has the wrong file set (missing or extra files), or the source dir is missing SKILL.md.pack only (originally exit 3 in pack_skill; remapped here to disambiguate from sign/IAM).

The [skill-publisher] step N/4 FAILED line printed by publish.sh immediately before exit tells the user which step failed and what the underlying script's raw exit code was, so the remap above is auditable, not opaque.


Show full SKILL.md (697 more words)Show less

Idempotency

All four underlying scripts are idempotent by design:

  • pack_skill.py writes the zip with sorted entry order, so sha256(zip) is stable across builds.
  • sign_skill.py produces byte-identical output for identical inputs (ed25519 is deterministic per RFC 8032; YAML is dumped with sort_keys=True).
  • upload_skill.py overwrites the object at the same name — re-running uploads the same bytes to the same key.
  • register_skill.py reads first, only POSTs/PATCHes on diff; re-running with no changes makes only GET calls.

Therefore re-running publish.sh with the same inputs is safe and observable as zero mutating API calls after the first successful publish. The skill does NOT need a "dry-run" mode of its own; pass --dry-run through to register_skill if you want to skip the registration step entirely (currently not wired — file an issue if needed).


Security notes

  • The ed25519 private key path is the only secret this skill touches. It is read by sign_skill.py, never logged, never uploaded. The key file should have mode 0600.
  • The signature is computed over the canonical manifest bytes (see scripts/common/canonical.py). Any post-signing edit to the manifest invalidates the signature; skill-finder will refuse to install the skill.
  • The signing_key_id field is the sha256 of the public key, not the private key. It is safe to publish. skill-finder cross-checks it against installed trust roots (keys/*.pem); a manifest signed by a key not in the trust root is rejected client-side. Multiple keys can be installed side-by-side to support multi-publisher orgs and zero-downtime key rotation.
  • GCS uploads use ADC. The operator must have storage.objects.create on the target bucket. The skill does not run a permission pre-flight; it relies on the upload itself to surface 403 as exit code 3.

Common rationalizations

RationalizationWhy it fails here
"I'll skip the pack step — the zip already exists on disk."sign_skill.py writes zip_sha256 from a fresh sha256 of the zip bytes. If the zip on disk is stale (e.g. a SKILL.md edit hasn't been re-packed), the manifest commits to a hash that does not match the bytes skill-finder will fetch from GCS, and every install fails signature verification. Always run pack-then-sign in one sequence.
"I'll re-sign without re-packing — only the manifest changed."Same trap. If the manifest text changed but the zip bytes also changed (because pack_skill would have noticed a source-tree edit), zip_sha256 is wrong. The pipeline is a unit; do not split it.
"I'll upload before signing — saves a round trip."If signing fails (bad key, invalid manifest), the GCS object now points at a zip whose manifest is unsigned. Any client that fetches it gets a manifest that fails schema validation. Sign first, upload second, register third — this order is enforced by publish.sh.
"I'll register before uploading — the catalog can wait for the zip."skill-finder fetches the zip immediately after the manifest passes signature check. A registered manifest pointing at a non-existent gs_uri returns 404 to every install attempt. Upload before register.
"I'll use gcloud storage cp instead of upload_skill.py."The script uses ADC + the GCS JSON API directly (the runtime tree is capped at four packages, so no google-cloud-storage dependency). It also has structured exit codes that this skill remaps. Using gcloud breaks the exit-code contract and the offline test suite.
"I'll skip update_taxonomy.py — the attributes will auto-create."They will not. register_skill.py PATCHes attribute values by reference to attribute definitions that must already exist. Without update_taxonomy.py having run once, the PATCH returns 400 and this skill exits 4. The first publish in a new project always needs update_taxonomy.py first.
"I'll catch the failure of step 2 and retry step 2 only."Don't. If sign fails after pack succeeded, the zip on disk is fine but the manifest is broken — re-running the whole pipeline is safe (pack is deterministic) and avoids the "stale zip" trap above. Always retry the whole pipeline, never a single step.

Layout

skills/skill-publisher/
  SKILL.md                # this file
  manifest.yaml           # unsigned template; sign-step rewrites
                          # zip_sha256, signing_key_id, signature
                          # in place
  scripts/
    publish.sh            # the bash orchestrator that runs the
                          # four scripts/* modules in order

publish.sh is the entire runtime surface of this skill. It shells out to:

  • python3 -m scripts.pack_skill --src <SKILL_SRC> --out <SKILL_OUT>
  • python3 -m scripts.sign_skill --manifest <SKILL_SRC>/manifest.yaml --zip <SKILL_OUT> --priv-key <SIGNING_PRIV_KEY> --in-place
  • python3 -m scripts.upload_skill --zip <SKILL_OUT> --bucket <GCS_BUCKET> --object-name <name>-<version>.skill
  • python3 -m scripts.register_skill --manifest <SKILL_SRC>/manifest.yaml --project <APIHUB_PROJECT> --location <APIHUB_LOCATION>

The four module paths are stable; if the repo ever renames them, update publish.sh and bump the skill version.

© apigee, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (scripts) in references/apigee-skills-serving/skills/skill-publisher of apigee/devrel.

  • SKILL.md
  • manifest.yaml
  • scripts/publish.sh

Open the folder on GitHubat commit 5a8ba69

Compare with similar skills

Skill Publisher next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Skill Publisher compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Skill Publisher this skillapigee/devrel221—~4kAutomated safety check: PassApache-2.0
MCP Server Builderanthropics/skills180k63 repos~2.3kAutomated safety check: PassApache-2.0
PDF Processinganthropics/skills180k47 repos~2kAutomated safety check: PassProprietary
NotebookLM Research AssistantPleasePrompto/notebooklm-skill7.8k14 repos~2.4kAutomated safety check: NotesMIT
Manim Video Productionbrowser-use/video-use29k6 repos~3kAutomated safety check: PassMIT
PPT Masterhugohe3/ppt-master59k1 repos~2.5kAutomated safety check: PassMIT

Similar skills

  • MCP Server Builder

    anthropics/skills

    Official

    Guides the design and implementation of Model Context Protocol servers in TypeScript or Python, from tool naming and error messages to evaluation.

    180k GitHub starsUsed in 63 repos~2.3k tokens
    Agent WorkflowsAuto-check passed
  • PDF Processing

    anthropics/skills

    Official

    Handles everyday PDF jobs in Python and on the command line: extract text and tables, merge, split, rotate, watermark, fill forms, encrypt and OCR.

    180k GitHub starsUsed in 47 repos~2k tokens
    Documents & OfficeAuto-check passed
  • NotebookLM Research Assistant

    PleasePrompto/notebooklm-skill

    Lets Claude Code ask questions of your Google NotebookLM notebooks through browser automation and return answers grounded in your uploaded sources.

    7.8k GitHub starsUsed in 14 repos~2.4k tokens
    Knowledge ManagementAuto-check: notes
  • Manim Video Production

    browser-use/video-use

    Produces math and technical explainer videos with Manim Community Edition: concept animations, equation derivations, algorithm walkthroughs and data stories.

    29k GitHub starsUsed in 6 repos~3k tokens
    Media & CreativeAuto-check passed
  • PPT Master

    hugohe3/ppt-master

    Generates editable PowerPoint decks, rebuilds slides from images, fills .pptx templates and polishes existing presentations through routed workflows.

    59k GitHub starsUsed in 1 repo~2.5k tokens
    Documents & OfficeAuto-check passed
  • Scikit Learn

    zLanqing/codex-claude-academic-skills

    Machine learning in Python with scikit-learn. An agent skill from zLanqing/codex-claude-academic-skills.

    4.7k GitHub starsUsed in 16 repos~3.9k tokens
    Data & AnalyticsAuto-check passed

More from apigee/devrel

  • Skill Finder

    apigee/devrel

    Discovers and installs agentic skills from the customer API hub.

    221 GitHub stars~1.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Apigee Policy Top10

    apigee/devrel

    Reports the top 10 Apigee policy types currently in use across deployed proxy revisions in the caller's Apigee org.

    221 GitHub stars~651 tokensUpdated 1 mo ago
    Auto-check passed
  • Currency Converter

    apigee/devrel

    Converts monetary amounts between fiat currencies using a stub exchange-rate table.

    221 GitHub stars~287 tokensUpdated 1 mo ago
    Auto-check passed
  • Weather Lookup

    apigee/devrel

    Returns a stub weather forecast for a given location. An agent skill from apigee/devrel.

    221 GitHub stars~270 tokensUpdated 1 mo ago
    Auto-check passed

Works with

Questions about Skill Publisher

What does Skill Publisher do?

Publishes a local skill directory to the API hub catalog and the GCS bundle store. Skill Publisher is an agent skill from apigee/devrel. Publishes a local skill directory to the API hub catalog and the GCS bundle store.

How do I install Skill Publisher in Claude Code?

Run `npx skills add apigee/devrel --skill skill-publisher -a claude-code`. Or copy the skill folder (references/apigee-skills-serving/skills/skill-publisher in apigee/devrel) into .claude/skills/skill-publisher in your project. Claude Code loads it when a task matches its description.

How do I install Skill Publisher in Codex?

Run `npx skills add apigee/devrel --skill skill-publisher -a codex`. Or copy the skill folder (references/apigee-skills-serving/skills/skill-publisher in apigee/devrel) into .agents/skills/skill-publisher in your project. Codex loads it when a task matches its description.

Can I use Skill Publisher in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add apigee/devrel --skill skill-publisher -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/skill-publisher, .gemini/skills/skill-publisher, .github/skills/skill-publisher and .opencode/skills/skill-publisher in your project.

What does Skill Publisher need to run?

Going by SKILL.md and its folder, Skill Publisher needs a shell for the scripts in its folder, the command-line tools its instructions call (python3, bash and gcloud) and credentials named SIGNING_PRIV_KEY. Our summary lists: Python 3; A Bash shell; A credential in SIGNING_PRIV_KEY. Compatibility (from SKILL.md): opencode, antigravity, gemini-cli.

Does Skill Publisher access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Skill Publisher safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Skill Publisher use?

Skill Publisher is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Skill Publisher use?

About 4k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Skill Publisher?

Skills that share tags, products or a category with Skill Publisher: MCP Server Builder (anthropics/skills, 180k stars), PDF Processing (anthropics/skills, 180k stars), NotebookLM Research Assistant (PleasePrompto/notebooklm-skill, 7.8k stars) and Manim Video Production (browser-use/video-use, 29k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Skill Publisher?

apigee (a GitHub organization) maintains it in apigee/devrel, which has 221 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on August 13, 2026.

Source: apigee/devrel on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.