Agent skill

Skill Installer

by danielwpz in danielwpz/pokoclaw

Install third-party skills for Pokoclaw when the user asks an agent to install a skill, pastes a skill-store prompt, or pastes a skill-store CLI command.

Apache-2.0Auto-check passedAgent Workflows

Install Skill Installer

skills CLI
$ npx skills add danielwpz/pokoclaw --skill skill-installer -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install danielwpz/pokoclaw skill-installer --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/danielwpz/pokoclaw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/skill-installer .claude/skills/skill-installer && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
skill-installer
GitHub stars
142
Token cost
~1.9k tokens
SKILL.md length
1,026 words
Files
4 (incl. references)
Skills in repo
4
Repo updated
First seen
Licence
Apache-2.0

At a glance

Install third-party skills for Pokoclaw when the user asks an agent to install a skill, pastes a skill-store prompt, or pastes a skill-store CLI command.

  • Works in 8 steps: Parse the requested skill identity → Inspect available store metadata before… → If the target directory already exists,… → …
  • Asks an agent to install a skill
  • SKILL.md covers Core Rule, Acceptance Checks, Read References and Decide Intent First, plus 4 more sections
  • Calls npx

What it does

Skill Installer is an agent skill from danielwpz/pokoclaw. Install third-party skills for Pokoclaw when the user asks an agent to install a skill, pastes a skill-store prompt, or pastes a skill-store CLI command. Use this for ClawHub, skills.sh, SkillHub, or unknown skill store installation requests.

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/clawhub.md`, `references/skillhub.md` and `references/skills-sh.md`).

It sits in Agent Workflows, covering Skill management. The repository describes itself as: The claw that actually ships 🚀. The licence is Apache-2.0.

When your agent uses it

  • Asks an agent to install a skill
  • Pastes a skill-store prompt
  • Pastes a skill-store CLI command

Example prompts

  • “/skill-installer”

Requirements

  • Node.js

Workflow steps

8 steps, taken from the first numbered list in SKILL.md.

  1. Parse the requested skill identity
  2. Inspect available store metadata before installing
  3. If the target directory already exists, inspect it before modifying it
  4. Install or materialize the skill into the selected Pokoclaw target
  5. Preserve provenance when available
  6. Inspect after installation
  7. Do not run setup scripts, enable hooks, edit shell profiles, install extra CLIs, or change broader environment state unless the user…
  8. Clean up temporary material

What it can do on your machine

Read from SKILL.md and the folder at commit 6cfb6c1. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npx, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Skill Installer loads about 1.9k tokens when it runs, and up to ~4.2k if it reads all its reference files. Until then it costs about 65 tokens; SKILL.md has 1,026 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~65
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from danielwpz/pokoclaw at commit 6cfb6c1, republished under its Apache-2.0 licence (© danielwpz). 1,026 words, ~1,899 tokens.

Download SKILL.mdSave it as .claude/skills/skill-installer/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
skill-installer
description
Install third-party skills for Pokoclaw when the user asks an agent to install a skill, pastes a skill-store prompt, or pastes a skill-store CLI command. Use this for ClawHub, skills.sh, SkillHub, or unknown skill store installation requests.
skillKey
pokoclaw/skill-installer

Skill Installer

Use this skill when the user asks you to install a skill for Pokoclaw, pastes a skill-store install prompt, or pastes a skill-store CLI command.

This skill does not manage commands the user already ran manually in their own terminal. It handles agent-managed installation.

Core Rule

The task is not complete when an external store says "installed". The task is complete only when the skill is installed in a Pokoclaw-discoverable root and passes the acceptance checks below.

Reason: store CLIs can install into their own roots, active workspaces, or agent-specific locations that Pokoclaw does not read.

Acceptance Checks

Always run these checks yourself at the end of the install.

Do this even when you followed a verified reference exactly. Do this even when the external CLI printed "installed" or "done". Do this even when the skill already appeared to be present.

The install is not complete until all checks pass:

  • The final target directory is under the selected Pokoclaw root:
    • project-local: <repo>/.agents/skills/<skill-dir>
    • global: ~/.pokoclaw/skills/<skill-dir>
  • SKILL.md exists at the final target.
  • SKILL.md frontmatter has non-empty name and description.
  • The actual skill identity is taken from SKILL.md frontmatter, not only from the store slug or display title.
  • Setup-relevant files were inspected but not executed.
  • Store provenance was preserved when available:
    • for global installs, provenance is stored inside the final skill directory;
    • for project-local installs, provenance is either stored inside the final skill directory or in a project lock file that remains with the project.
  • Temporary install or staging files were cleaned up.
  • Any broader environment change was skipped unless the user approved it.

If any acceptance check fails, report the blocker and do not claim the skill is installed for Pokoclaw.

Read References

If the request matches a verified channel, read the matching reference before installing:

  • ClawHub: references/clawhub.md
  • skills.sh / npx skills: references/skills-sh.md
  • SkillHub: references/skillhub.md

If the request uses an unknown channel, investigate that channel first, then still satisfy the same acceptance checks in this file.

Decide Intent First

If the user pastes a store CLI command, decide whether they want:

  • a Pokoclaw skill install, or
  • the raw external command run against that external tool's own environment.

If the user explicitly asks to operate the external tool itself, ask before running commands that change real global or workspace state.

If the user asks in a Pokoclaw context, or the request is ambiguous, treat it as a Pokoclaw skill install. Do not blindly run the pasted command as the final action.

Reason: users often paste store-provided commands as shorthand for "install this skill for my agent"; those commands may install somewhere Pokoclaw cannot discover.

Select Target

For project-local installs, use:

text
<repo>/.agents/skills/<skill-dir>/SKILL.md

For global Pokoclaw installs, use:

text
~/.pokoclaw/skills/<skill-dir>/SKILL.md

Do not use ~/.agents/skills, ~/.openclaw/workspace-*/skills, or a store-specific global directory as the final target unless Pokoclaw is explicitly configured to read it.

Reason: Pokoclaw currently reads its own global root and repo-local .agents/skills; it does not automatically read every other agent ecosystem's global root.

Show full SKILL.md (539 more words)Show less

Install Procedure

  1. Parse the requested skill identity:

    • extract store, slug, package URL, page URL, display title, owner, and version if present;
    • do not assume slug, display title, and SKILL.md frontmatter name are the same.
  2. Inspect available store metadata before installing:

    • use only metadata you can verify from the store, repository, downloaded package, or installed files;
    • do not invent setup requirements, hooks, environment variables, or dependencies.
  3. If the target directory already exists, inspect it before modifying it:

    • if it already passes the acceptance checks and matches the requested skill identity plus any source/version constraints, report that the skill is already installed;
    • if it passes the acceptance checks but the source or version differs from the request, report the conflict and ask before replacing or updating it;
    • if it is invalid or incomplete, report the failed checks and ask before replacing, updating, or merging it;
    • do not overwrite an existing target directory unless the user explicitly approves.
  4. Install or materialize the skill into the selected Pokoclaw target:

    • use a verified channel-specific direct target option when one exists;
    • otherwise stage or install through the store, then copy or symlink only the requested skill into the selected Pokoclaw target;
    • keep the work scoped to the requested skill only.
  5. Preserve provenance when available:

    • keep store metadata files such as _meta.json, .clawhub/origin.json, lock entries, or source metadata if they are part of the installed skill;
    • if provenance exists only in an external lock or staging file and the final target will not include that file, write a per-skill provenance file inside the final skill directory;
    • do not copy unrelated store caches or registry state into the skill directory.
  6. Inspect after installation:

    • read SKILL.md frontmatter;
    • report the installed skill name, description, source, version if known, and final target path;
    • run the setup inspection checklist below.
  7. Do not run setup scripts, enable hooks, edit shell profiles, install extra CLIs, or change broader environment state unless the user explicitly approves.

  8. Clean up temporary material:

    • remove temporary download/staging directories;
    • for test installs, restore pre-test lock files and remove test-created symlinks or skill directories;
    • do not remove pre-existing user files.

Unknown Channels

For an unverified store or installer:

  1. Read its help/docs or inspect the command output to determine the real install root.
  2. Check whether it supports an explicit target root.
  3. If it supports a target root, direct it to the selected Pokoclaw target root.
  4. If it does not support a target root, install or download in a controlled way, then copy or symlink the requested skill into the selected Pokoclaw target.
  5. Record any verified channel behavior if the user is asking you to improve installer support.

Do not rely on store branding, command names, or current working directory to infer where files landed. Verify the actual files.

Setup Inspection Checklist

Inspect these files and paths when they exist in the installed skill. Do not execute them unless the user explicitly approves.

  • README*
  • package.json
  • setup*
  • install*
  • hooks/
  • hook*
  • scripts/
  • references/
  • assets/
  • *.sh
  • *.js
  • *.ts
  • _meta*
  • metadata*
  • .clawhub/origin.json
  • .skills-sh/origin.json
  • .skillhub/origin.json
  • store-specific lock or provenance files, including copied per-skill lock entries

Reason: setup requirements and executable side effects are often documented in these files, and different stores package them differently.

© danielwpz, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (references) in skills/skill-installer of danielwpz/pokoclaw.

  • SKILL.md
  • references/clawhub.md
  • references/skillhub.md
  • references/skills-sh.md

Open the folder on GitHubat commit 6cfb6c1

Compare with similar skills

Skill Installer next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Skill Installer compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Skill Installer this skilldanielwpz/pokoclaw142—~1.9kAutomated safety check: PassApache-2.0
Darwin Skill Optimizeralchaincyf/darwin-skill6.2k1 repos~4.7kAutomated safety check: PassMIT
Using Agent Skillsaddyosmani/agent-skills103k4 repos~2.4kAutomated safety check: PassMIT
Ponytail Help CardDietrichGebert/ponytail158k—~728Automated safety check: PassMIT
Skill Creatorzhayujie/CowAgent47k—~4.7kAutomated safety check: NotesMIT
Task Observerrebelytics/one-skill-to-rule-them-all3.2k1 repos~12kAutomated safety check: PassCC-BY-4.0

Similar skills

  • Darwin Skill Optimizer

    alchaincyf/darwin-skill

    Scores SKILL.md files on a nine-dimension rubric, then improves them in a keep-or-revert loop with independent judge agents, test prompts, git history and human checkpoints.

    6.2k GitHub starsUsed in 1 repo~4.7k tokens
    Agent WorkflowsAuto-check passed
  • Using Agent Skills

    addyosmani/agent-skills

    Meta-skill for choosing which workflow skill fits the task at hand, plus always-on habits: surface assumptions, stop on confusion, push back, keep it simple and stay in scope.

    103k GitHub starsUsed in 4 repos~2.4k tokens
    Agent WorkflowsAuto-check passed
  • Ponytail Help Card

    DietrichGebert/ponytail

    Shows a one-shot quick-reference card for the ponytail skills: intensity levels, the six commands, and how to turn it off, set a default mode and update.

    158k GitHub stars~728 tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Skill Creator

    zhayujie/CowAgent

    Guides creating, installing and updating agent skills in a workspace: SKILL.md frontmatter, bundled scripts and references, with scripts to scaffold, validate and package.

    47k GitHub stars~4.7k tokensUpdated today
    Agent WorkflowsAuto-check: notes
  • Task Observer

    rebelytics/one-skill-to-rule-them-all

    Monitors task execution for skill improvement opportunities.

    3.2k GitHub starsUsed in 1 repo~12k tokens
    Agent WorkflowsAuto-check passed
  • Open-Science Skill Creator

    aipoch/open-science

    Creates, revises, evaluates and publishes skills in the Open-Science app through its native host.skills composer, with optional test prompts and benchmarks.

    5.5k GitHub stars~1.7k tokensUpdated today
    Agent WorkflowsAuto-check passed

More from danielwpz/pokoclaw

  • A2ui Author

    danielwpz/pokoclaw

    Generate, validate, and interpret static A2UI v0.8 JSON for interactive UI surfaces.

    142 GitHub stars~330 tokensUpdated 19 days ago
    Auto-check passed
  • Claude Session Observe

    danielwpz/pokoclaw

    A skill your agent uses to inspect Claude Code session history under ~/.claude, recover what sessions exist, and manually determine what a session was doing from transcript evidence.

    142 GitHub stars~1.8k tokensUpdated 19 days ago
    Auto-check passed
  • System Observe

    danielwpz/pokoclaw

    Use this skill before calling querysystemdb or when diagnosing pokoclaw.

    142 GitHub stars~1.5k tokensUpdated 19 days ago
    Auto-check passed

Categories

Questions about Skill Installer

What does Skill Installer do?

Install third-party skills for Pokoclaw when the user asks an agent to install a skill, pastes a skill-store prompt, or pastes a skill-store CLI command. Skill Installer is an agent skill from danielwpz/pokoclaw. Install third-party skills for Pokoclaw when the user asks an agent to install a skill, pastes a skill-store prompt, or pastes a skill-store CLI command.

When should I use Skill Installer?

Skill Installer fits situations like: asks an agent to install a skill; pastes a skill-store prompt; pastes a skill-store CLI command.

How do I install Skill Installer in Claude Code?

Run `npx skills add danielwpz/pokoclaw --skill skill-installer -a claude-code`. Or copy the skill folder (skills/skill-installer in danielwpz/pokoclaw) into .claude/skills/skill-installer in your project. Claude Code loads it when a task matches its description.

How do I install Skill Installer in Codex?

Run `npx skills add danielwpz/pokoclaw --skill skill-installer -a codex`. Or copy the skill folder (skills/skill-installer in danielwpz/pokoclaw) into .agents/skills/skill-installer in your project. Codex loads it when a task matches its description.

Can I use Skill Installer in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add danielwpz/pokoclaw --skill skill-installer -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/skill-installer, .gemini/skills/skill-installer, .github/skills/skill-installer and .opencode/skills/skill-installer in your project.

What does Skill Installer need to run?

Going by SKILL.md and its folder, Skill Installer needs the command-line tools its instructions call (npx). Our summary lists: Node.js.

Does Skill Installer access the network?

SKILL.md contains no URLs. Its commands use npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Skill Installer safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Skill Installer use?

Skill Installer is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Skill Installer use?

About 1.9k tokens (SKILL.md is roughly 7.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.3k tokens, read only when the agent opens those files.

What are the alternatives to Skill Installer?

Skills that share tags, products or a category with Skill Installer: Darwin Skill Optimizer (alchaincyf/darwin-skill, 6.2k stars), Using Agent Skills (addyosmani/agent-skills, 103k stars), Ponytail Help Card (DietrichGebert/ponytail, 158k stars) and Skill Creator (zhayujie/CowAgent, 47k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Skill Installer?

danielwpz (a GitHub user) maintains it in danielwpz/pokoclaw, which has 142 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on September 19, 2026.

Source: danielwpz/pokoclaw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.