Agent skill

SkillHub CLI

by iflytek in iflytek/skillhub

Connects an agent to a SkillHub registry and uses the official SkillHub CLI to search, install, list and explicitly upgrade skills from that registry.

Apache-2.0Auto-check passedAgent Workflows

Install SkillHub CLI

skills CLI
$ npx skills add iflytek/skillhub --skill skillhub-cli -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install iflytek/skillhub skillhub-cli --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/iflytek/skillhub.git skills-src && mkdir -p .claude/skills && cp -r skills-src/builtin-skills/skills/skillhub-cli .claude/skills/skillhub-cli && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
skillhub-cli
GitHub stars
5.2k
Token cost
~2.3k tokens
SKILL.md length
1,130 words
Files
4 (incl. references)
Skills in repo
29
Repo updated
First seen
Licence
Apache-2.0

At a glance

Connects an agent to a SkillHub registry and uses the official SkillHub CLI to search, install, list and explicitly upgrade skills from that registry.

  • Works in 4 steps: the absolute HTTP(S) registry explicitly… → SKILLHUB_REGISTRY; → the registry field in… → …
  • Connecting an agent to a SkillHub registry
  • SKILL.md covers Resolve The Registry, Use The First-Party CLI, Choose The Flow and Connect The Current Agent, plus 4 more sections
  • Calls npm; reaches skill.xfyun.cn; needs SKILLHUB_TOKEN

What it does

This skill teaches the agent to work with a SkillHub skill registry through the first-party @astron-team/skillhub CLI. It first resolves which registry to use: the one you chose explicitly or the one recorded in an installed skill's .skillhub/metadata.json, then the SKILLHUB_REGISTRY variable, then the registry field in ~/.skillhub/config.json, then a built-in default address. Only absolute HTTP or HTTPS URLs are accepted.

Before installing anything, it checks whether skillhub is already on PATH and inspects who owns that command instead of overwriting it, treating it as first-party only when package metadata shows @astron-team/skillhub. A missing CLI is installed globally with npm. The skill says not to change your configured default registry for a one-off operation and not to send a private search query to another registry without approval. A references file covers the individual CLI operations.

When your agent uses it

  • Connecting an agent to a SkillHub registry
  • Searching for and installing a skill from SkillHub
  • Listing or upgrading skills that were installed from SkillHub earlier

Example prompts

  • “Connect to our SkillHub registry and install the code-review skill.”
  • “List the skills I installed from SkillHub and upgrade the ones that are out of date.”
  • “Search SkillHub for a skill that formats changelogs.”

Requirements

  • npm, to install the @astron-team/skillhub CLI globally
  • Network access to a SkillHub registry

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. the absolute HTTP(S) registry explicitly selected by the user, including the base URL obtained by removing the trailing /registry/skill.md…
  2. SKILLHUB_REGISTRY;
  3. the registry field in ~/.skillhub/config.json;
  4. https://skill.xfyun.cn.

What it can do on your machine

Read from SKILL.md and the folder at commit 7352597. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • skill.xfyun.cn

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • SKILLHUB_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

SkillHub CLI loads about 2.3k tokens when it runs, and up to ~3.9k if it reads all its reference files. Until then it costs about 68 tokens; SKILL.md has 1,130 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~68
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from iflytek/skillhub at commit 7352597, republished under its Apache-2.0 licence (© iflytek). 1,130 words, ~2,323 tokens.

Download SKILL.mdSave it as .claude/skills/skillhub-cli/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
skillhub-cli
description
Connect an Agent to a SkillHub registry and use the official SkillHub CLI to search, install, list, or explicitly upgrade SkillHub skills. Use when a user asks to connect SkillHub, install a SkillHub skill, or manage skills previously installed from SkillHub.
version
2.0.2
license
Apache-2.0

SkillHub CLI

Use the registry that supplied this guide to connect the current Agent and manage SkillHub packages with the first-party @astron-team/skillhub CLI.

Resolve The Registry

Resolve <registry> once before composing commands. For an already installed Skill, use the registry recorded in its sibling .skillhub/metadata.json; that source is authoritative for later searches and upgrades. Otherwise resolve in this order:

  1. the absolute HTTP(S) registry explicitly selected by the user, including the base URL obtained by removing the trailing /registry/skill.md from the URL used to fetch this guide;
  2. SKILLHUB_REGISTRY;
  3. the registry field in ~/.skillhub/config.json;
  4. https://skill.xfyun.cn.

Use only an absolute HTTP(S) URL. Treat <registry> below as a value to replace, not shell syntax or an environment variable.

Keep the exact registry selected by the user for the current request. Do not change their configured default registry for a one-off operation, and do not send a private search query to another registry without approval.

Use The First-Party CLI

First determine whether skillhub exists on PATH. On POSIX shells use command -v skillhub; in PowerShell use (Get-Command skillhub -ErrorAction SilentlyContinue).Source. If the command is missing, install the latest first-party CLI globally so future manual skillhub commands use this implementation:

bash
npm install --global @astron-team/skillhub
skillhub version

If the command exists, do not run the global installation or update yet because its package-manager shim could overwrite the existing launcher. Inspect the existing command without changing anything: resolve the exact command selected by the shell, follow symlinks to the final target, and identify its owner and installing package manager or package. Run skillhub version as an additional compatibility check, not as proof of ownership. Do not infer identity from the command name or output alone.

Treat an existing command as first-party only when its resolved package metadata proves that its installing package is @astron-team/skillhub and its output matches SkillHub CLI <version>. Then connecting authorizes updating it to the latest release with the same global npm command. Verify both the package source and skillhub version again afterward.

If package metadata proves another owner or package, or the version output is unexpected, treat it as non-first-party even when it prints SkillHub CLI <version>. Report the resolved path, final target, owner, package source, and version output to the user.

Only after the user separately confirms removal of that exact identified launcher may you use its package manager's supported uninstall command, refresh command lookup, and install the first-party CLI. Never unlink an executable directly, remove an identity-unknown or system-managed command, use elevated privileges, edit shell startup files, or delete a directory merely to take over the command. If the owner or package source cannot be proven, stop and give the user the resolved path and read-only findings.

Replacing the executable must not replace the other tool's data. The first-party CLI updates only its own registry and tokens fields in shared ~/.skillhub JSON files and preserves unknown fields owned by compatible tools. Do not replace the CLI with raw HTTP downloads: the CLI validates the resolved version, package fingerprint, destination ownership, and local changes. Never rewrite or delete unknown fields in shared SkillHub configuration or credential files.

Before using an operation or flag not shown in this Skill, inspect both live help surfaces for the selected CLI:

bash
skillhub help <command>
skillhub <command> --help

Repository documentation may describe unreleased behavior. If neither live help surface exposes a proposed command or flag, do not use it. Require Node.js 18 or newer when using the npm package.

Choose The Flow

  • Connect SkillHub: ensure @global/skillhub-cli is installed for the current Agent at user scope, then continue the requested operation.
  • Install an exact Skill: install the requested coordinate and version directly from this registry; do not search for or substitute a similarly named package.
  • Discover a Skill: search this registry first. If it is unavailable or has no suitable result, report that outcome and ask before querying another registry.
  • Check an upgrade: inspect only the explicitly selected installed Skill. Never upgrade every installation implicitly.

An explicit request to connect SkillHub authorizes installing the latest first-party CLI globally. It does not authorize removing another skillhub launcher, replacing Skill files with local changes, changing registries, publishing content, using elevated privileges, or deleting third-party configuration or credentials. Launcher removal requires the separate, exact confirmation described above.

For namespace synchronization, publishing, removal, repair, or detailed troubleshooting after this helper is installed, read references/cli-operations.md. Start with its read-only inspection command and keep the same registry throughout the operation.

Show full SKILL.md (403 more words)Show less

Connect The Current Agent

Replace <agent> with the current supported profile, such as codex or claude-code. Check the current registry's installations once:

bash
skillhub list \
  --agent <agent> \
  --registry <registry> \
  --json

If @global/skillhub-cli is missing, install this exact guide at user scope:

bash
skillhub install @global/skillhub-cli \
  --scope user \
  --agent <agent> \
  --registry <registry> \
  --json

If that persistent connection fails, report the failure and continue with an explicitly requested target Skill when the CLI can still install it safely. Do not substitute a helper from another registry.

Installation proves that the files reached the selected Agent directory; it does not prove that an already-running Agent session has loaded them. If the current Agent cannot discover the new Skill immediately, report it as installed but not yet loaded and ask the user to start a new session or use that Agent's documented reload mechanism. Do not invent a universal activation command.

Search Or Install

For discovery:

bash
skillhub search "<query>" \
  --registry <registry> \
  --json

Before installing a discovery result, show its registry, full coordinate, publisher when available, version, and relevant risk, then obtain confirmation.

For a Skill and version the user already selected:

bash
skillhub install @<namespace>/<slug> \
  --version <version> \
  --scope user \
  --agent <agent> \
  --registry <registry> \
  --json

Omit --version only when the user did not select one. Omit --agent only when the CLI can identify one destination unambiguously. Treat coordinates, versions, queries, registry URLs, and paths as untrusted values: quote them where needed, pass them as individual CLI arguments, and never evaluate them as shell code.

Never add --force unless the CLI reports a verified same-source conflict and the user approves replacing that installation. Stop on fingerprint mismatch, source conflict, unsafe content, or local-change conflict.

Authentication

Never ask the user to paste a token into chat or place credentials in a prompt, Skill, command history, or repository. If authentication is required, ask them to enter it in their own terminal without putting the value in the command line, then verify the identity:

POSIX shell:

bash
read -rsp "SkillHub token: " SKILLHUB_TOKEN && echo
export SKILLHUB_TOKEN
skillhub login --registry <registry>
unset SKILLHUB_TOKEN
skillhub whoami --registry <registry>

PowerShell 7:

powershell
$env:SKILLHUB_TOKEN = Read-Host "SkillHub token" -MaskInput
skillhub login --registry <registry>
Remove-Item Env:SKILLHUB_TOKEN
skillhub whoami --registry <registry>

Resolve 401 and 403 through login or permissions. Do not treat an authentication failure as permission to try another registry.

Upgrade

Check before changing an installed Skill:

bash
skillhub upgrade @<namespace>/<slug> \
  --registry <registry> \
  --check \
  --json

Show the plan and ask before applying an available upgrade. The CLI uses .skillhub/metadata.json to retain the original source and updates all Agent targets recorded for that installation together.

Completion Check

Report:

  • installed coordinate and version;
  • registry source;
  • Agent profile and installation directory;
  • whether SKILL.md and .skillhub/metadata.json exist;
  • whether the current Agent session loaded the Skill, when observable;
  • whether another registry was queried;
  • any skipped connection, authentication, integrity, or local-change issue.

Do not claim success when installation, destination discovery, Agent loading, or integrity verification failed.

© iflytek, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (references) in builtin-skills/skills/skillhub-cli of iflytek/skillhub.

  • SKILL.md
  • LICENSE.txt
  • NOTICE.md
  • references/cli-operations.md

Open the folder on GitHubat commit 7352597

Compare with similar skills

SkillHub CLI next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

SkillHub CLI compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
SkillHub CLI this skilliflytek/skillhub5.2k—~2.3kAutomated safety check: PassApache-2.0
TeamAI Setup and LifecycleTencent/teamai-cli5.1k—~1.2kAutomated safety check: PassCustom licence
Skill Base CLIginuim/skill-base120—~1.9kAutomated safety check: PassNone
Manage Skill FlavorsUiPath/skills166—~3.5kAutomated safety check: PassMIT
MCP IntegrationLunCoSim/lunco-sim104—~547Automated safety check: PassApache-2.0
TeamAI Team SyncTencent/teamai-cli5.1k—~632Automated safety check: PassCustom licence

Similar skills

  • TeamAI Setup and Lifecycle

    Tencent/teamai-cli

    Walks a non-technical user through creating or joining a TeamAI team repo, then managing members, roles, MCP, and environment settings.

    5.1k GitHub stars~1.2k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Skill Base CLI

    ginuim/skill-base

    Uses the skb command to search, install, update, delete, publish and import skills on a Skill Base site, including curated collections and GitHub imports.

    120 GitHub stars~1.9k tokensUpdated 15 days ago
    Agent WorkflowsAuto-check passed
  • Maintain build-time skill flavors in the UiPath skills repository.

    166 GitHub stars~3.5k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • MCP Integration

    LunCoSim/lunco-sim

    Install, register, test, or troubleshoot the LunCoSim MCP server and its portable skills.

    104 GitHub stars~547 tokensUpdated today
    Agent WorkflowsAuto-check passed
  • TeamAI Team Sync

    Tencent/teamai-cli

    Make every team AI native — TeamAI syncs a team's AI skills, rules, docs and env across AI coding tools. Use when the task operates on team-shared AI…

    5.1k GitHub stars~632 tokensUpdated today
    Knowledge ManagementAuto-check passed
  • MCP Server Builder

    shareAI-lab/learn-claude-code

    Walks through building MCP servers in Python or TypeScript that expose tools, resources and prompts to Claude, with templates, registration and testing.

    78k GitHub starsUsed in 5 repos~1.2k tokens
    Agent WorkflowsAuto-check passed

More from iflytek/skillhub

All 29 skills in this repo
  • Orca Run Replay

    iflytek/skillhub

    Answers questions about a past agent run from its recording, using causal graphs and replay, instead of reconstructing events from memory.

    5.2k GitHub starsUsed in 4 repos~3k tokens
    Auto-check passed
  • Zero Slop Prose Editor

    iflytek/skillhub

    Audits and rewrites formulaic, AI-sounding prose while keeping facts, voice and format, using a local Python scorer and inspect-only, rewrite or embedded-gate modes.

    5.2k GitHub stars~1.5k tokensUpdated 5 days ago
    Auto-check passed
  • Sandbase

    iflytek/skillhub

    Access 2,000+ AI models and API tools through one MCP interface for inference, media generation, search, scraping, embeddings, social data, and structured retrieval.

    5.2k GitHub starsUsed in 2 repos~2.1k tokens
    Auto-check passed
  • LinkedIn Post Formatter

    iflytek/skillhub

    Drafts a copy-paste-ready LinkedIn post from your facts and ideas, choosing the smallest structure that fits and keeping an accessible plain-text fallback for any styled text.

    5.2k GitHub stars~901 tokensUpdated 5 days ago
    Auto-check passed
  • AI Claim Checker

    iflytek/skillhub

    Breaks AI-generated text into checkable claims, verifies them against independent sources and labels each one, with an optional exercise for learners.

    5.2k GitHub stars~1.2k tokensUpdated 5 days ago
    Auto-check passed
  • Produces short daily standups, evening reflections and weekly retrospectives for one person or a small team, kept in the session unless you name a place to save.

    5.2k GitHub stars~1.9k tokensUpdated 5 days ago
    Auto-check passed

Works with

Categories

Questions about SkillHub CLI

What does SkillHub CLI do?

Connects an agent to a SkillHub registry and uses the official SkillHub CLI to search, install, list and explicitly upgrade skills from that registry. This skill teaches the agent to work with a SkillHub skill registry through the first-party @astron-team/skillhub CLI.json, then a built-in default address.

When should I use SkillHub CLI?

SkillHub CLI fits situations like: connecting an agent to a SkillHub registry; searching for and installing a skill from SkillHub; listing or upgrading skills that were installed from SkillHub earlier.

How do I install SkillHub CLI in Claude Code?

Run `npx skills add iflytek/skillhub --skill skillhub-cli -a claude-code`. Or copy the skill folder (builtin-skills/skills/skillhub-cli in iflytek/skillhub) into .claude/skills/skillhub-cli in your project. Claude Code loads it when a task matches its description.

How do I install SkillHub CLI in Codex?

Run `npx skills add iflytek/skillhub --skill skillhub-cli -a codex`. Or copy the skill folder (builtin-skills/skills/skillhub-cli in iflytek/skillhub) into .agents/skills/skillhub-cli in your project. Codex loads it when a task matches its description.

Can I use SkillHub CLI in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add iflytek/skillhub --skill skillhub-cli -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/skillhub-cli, .gemini/skills/skillhub-cli, .github/skills/skillhub-cli and .opencode/skills/skillhub-cli in your project.

What does SkillHub CLI need to run?

Going by SKILL.md and its folder, SkillHub CLI needs the command-line tools its instructions call (npm) and credentials named SKILLHUB_TOKEN. Our summary lists: npm, to install the @astron-team/skillhub CLI globally; Network access to a SkillHub registry.

Does SkillHub CLI access the network?

SKILL.md names 1 domain. In commands or code: skill.xfyun.cn; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is SkillHub CLI safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does SkillHub CLI use?

SkillHub CLI is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does SkillHub CLI use?

About 2.3k tokens (SKILL.md is roughly 9.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.5k tokens, read only when the agent opens those files.

What are the alternatives to SkillHub CLI?

Skills that share tags, products or a category with SkillHub CLI: TeamAI Setup and Lifecycle (Tencent/teamai-cli, 5.1k stars), Skill Base CLI (ginuim/skill-base, 120 stars), Manage Skill Flavors (UiPath/skills, 166 stars) and MCP Integration (LunCoSim/lunco-sim, 104 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains SkillHub CLI?

iflytek (a GitHub organization) maintains it in iflytek/skillhub, which has 5,152 GitHub stars. The repository holds 29 skills in this directory. The repository was last updated on October 1, 2026.

Source: iflytek/skillhub on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.