Darwin Skill Optimizer
alchaincyf/darwin-skill
Scores SKILL.md files on a nine-dimension rubric, then improves them in a keep-or-revert loop with independent judge agents, test prompts, git history and human checkpoints.
Audits and repairs how coding-agent Skills are owned, copied and exposed across runtimes, from canonical sources to quarantine and retirement.
$ npx skills add majiayu000/spellbook --skill skill-ecosystem-doctor -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install majiayu000/spellbook skill-ecosystem-doctor --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/majiayu000/spellbook.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/skill-ecosystem-doctor .claude/skills/skill-ecosystem-doctor && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "skill-ecosystem-doctor" agent skill from https://github.com/majiayu000/spellbook/tree/main/skills/skill-ecosystem-doctor into .claude/skills/skill-ecosystem-doctor/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "skill-ecosystem-doctor", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/majiayu000/spellbook/tree/main/skills/skill-ecosystem-doctorType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add majiayu000/spellbook --skill skill-ecosystem-doctor -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install majiayu000/spellbook skill-ecosystem-doctor --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/majiayu000/spellbook.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/skill-ecosystem-doctor .agents/skills/skill-ecosystem-doctor && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "skill-ecosystem-doctor" agent skill from https://github.com/majiayu000/spellbook/tree/main/skills/skill-ecosystem-doctor into .agents/skills/skill-ecosystem-doctor/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "skill-ecosystem-doctor", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add majiayu000/spellbook --skill skill-ecosystem-doctor -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install majiayu000/spellbook skill-ecosystem-doctor --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/majiayu000/spellbook.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/skill-ecosystem-doctor .cursor/skills/skill-ecosystem-doctor && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "skill-ecosystem-doctor" agent skill from https://github.com/majiayu000/spellbook/tree/main/skills/skill-ecosystem-doctor into .cursor/skills/skill-ecosystem-doctor/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "skill-ecosystem-doctor", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/majiayu000/spellbook.git --path skills/skill-ecosystem-doctor--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add majiayu000/spellbook --skill skill-ecosystem-doctor -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install majiayu000/spellbook skill-ecosystem-doctor --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/majiayu000/spellbook.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/skill-ecosystem-doctor .gemini/skills/skill-ecosystem-doctor && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "skill-ecosystem-doctor" agent skill from https://github.com/majiayu000/spellbook/tree/main/skills/skill-ecosystem-doctor into .gemini/skills/skill-ecosystem-doctor/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "skill-ecosystem-doctor", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install majiayu000/spellbook skill-ecosystem-doctorInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add majiayu000/spellbook --skill skill-ecosystem-doctor -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/majiayu000/spellbook.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/skill-ecosystem-doctor .github/skills/skill-ecosystem-doctor && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "skill-ecosystem-doctor" agent skill from https://github.com/majiayu000/spellbook/tree/main/skills/skill-ecosystem-doctor into .github/skills/skill-ecosystem-doctor/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "skill-ecosystem-doctor", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add majiayu000/spellbook --skill skill-ecosystem-doctor -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install majiayu000/spellbook skill-ecosystem-doctor --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/majiayu000/spellbook.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/skill-ecosystem-doctor .opencode/skills/skill-ecosystem-doctor && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "skill-ecosystem-doctor" agent skill from https://github.com/majiayu000/spellbook/tree/main/skills/skill-ecosystem-doctor into .opencode/skills/skill-ecosystem-doctor/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "skill-ecosystem-doctor", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skill-ecosystem-doctorAudits and repairs how coding-agent Skills are owned, copied and exposed across runtimes, from canonical sources to quarantine and retirement.
The skill treats agent Skills as a governed supply chain: audit first, plan repairs from evidence, apply only authorized changes, then verify and hand off. It stays out of project-local questions about whether a tool already loaded a Skill, sending those to that tool's own setup, and engages only for cross-runtime ownership, exposure or repair governance. Five modes are selected from intent: audit for read-only inspection, plan for explaining a change with no mutation, repair for fixing or retiring with an explicit scope and rollback, verify for rechecking a governance file, and an external-action mode for anything needing the action granted first. A mixed request runs audit before repair.
Before creating anything, the agent searches active roots and source repositories, locates every applicable AGENTS.md before editing a source repository, and classifies each path as a canonical source, a managed projection, a generated cache or unknown using a runtime-contracts reference. Direct actions are limited to read-only discovery, deterministic audits, report drafts and local validation, while destructive changes, credential actions, history rewriting or remote publication require escalation. The toolkit includes several scripts for checks, exposure, governance and modeling, plus references on governance schema, lifecycle drift and a remediation playbook.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit ed52af7. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 6 files in scripts/ (Python, from the files we listed), which the agent can run.
Shell commands in SKILL.md call:
python3gitFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Skill Ecosystem Doctor loads about 3k tokens when it runs, and up to ~8k if it reads all its reference files. Until then it costs about 106 tokens; SKILL.md has 1,449 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from majiayu000/spellbook at commit ed52af7, republished under its MIT licence (© majiayu000). 1,449 words, ~3,011 tokens.
.claude/skills/skill-ecosystem-doctor/SKILL.md (or your agent's skills folder). This skill also uses 20 other files; get the full folder from GitHub.Treat the local Skill collection as a governed software supply chain. Audit first, plan repairs from evidence, apply only authorized changes, and finish with fresh cross-runtime verification and a durable handoff.
This workflow is at skill maturity, not unattended automation maturity. Do
not schedule or silently apply repairs.
Questions such as “Did Studio load or start these Skills?” belong to Studio's own configuration, projections, and runtime inventory. Inspect that project/runtime directly. Invoke this Doctor only when the user explicitly asks for cross-runtime or cross-scope ownership, projection, exposure, lifecycle, or repair governance.
| User intent | Mode | Routing |
|---|---|---|
| Inspect, review, inventory, or diagnose | audit | execute_direct; read-only |
| Explain what should change | plan | plan_first; no mutations |
| Fix, unify, quarantine, or retire | repair | plan_first; explicit scope and rollback |
| Recheck an existing governance file | verify | execute_direct; read-only |
| Rotate credentials, rewrite history, push, publish, or change remotes | external action | clarify_first unless the current request grants that exact action |
If the request mixes modes, run audit before repair. Do not infer repair
authorization from a request to inspect or diagnose.
AGENTS.md or equivalent before editing a source
repository.flowguard and keep the
handoff outside parent context.Common roots are discovery candidates, not declarations. Verify them on the current machine; no data means unknown, not a guessed source relationship.
Use an existing governance file when one exists. Otherwise read the governance schema, adapt the example from discovered facts, and show the proposed configuration before writing it.
The Doctor accepts both its portable schema and the deployed Loom-style
SKILL_GOVERNANCE_POLICY.json; do not create a second policy when the latter
already exists.
For a large deployed catalog, prefer default_scope: "review" with an explicit
global_allowlist. Keep specialist Skills in named profiles, bind profiles to
project roots only when needed, and enforce an exposure_budget. A retained
profile Skill is still canonical and usable on demand; it is not globally
injected until a declared profile scope projects it.
From this Skill directory, run:
python3 scripts/ecosystem_doctor.py --governance ./skill-ecosystem-governance.json
python3 scripts/ecosystem_doctor.py --governance ./skill-ecosystem-governance.json --jsonUse --skip-loom only when Loom is intentionally outside scope. A missing Loom
binary is an error when Loom validation is requested. Use --fail-on-warn for a
strict release gate.
For the deployed policy, run the exposure reconciler without --apply first:
python3 scripts/ecosystem_reconcile.py \
--registry ~/.loom-registry \
--policy ~/.loom-registry/SKILL_GOVERNANCE_POLICY.jsonThe dry-run reports trigger hardening, global/project/profile/review exposure,
catalog budgets, plugin-state changes, and stale registry state. Run the same
command with --apply only during an explicitly authorized repair run. Plugin
configuration receives a timestamped backup before its exact boolean values are
changed. Re-run the dry-run afterward and require an empty plan.
If the policy declares exact progressive-disclosure splits, inspect them with:
python3 scripts/ecosystem_split.py \
--registry ~/.loom-registry \
--policy ~/.loom-registry/SKILL_GOVERNANCE_POLICY.jsonUse --apply only after reviewing the extracted headings and destinations.
The audit checks:
SKILL.mdWhen the request concerns Skills that stopped triggering, aged out, or depend on possibly dead external projects, also read lifecycle drift. Treat missing maintenance metadata as unknown evidence, not proof that a Skill is unhealthy.
Treat test-fixture secret patterns as visible warnings, not silent allowlists.
Order repairs by security, logic, data integrity, source lineage, and naming. Separate facts from decisions:
Read the remediation playbook before planning mutations.
For every proposed action, record:
Use disjoint file ownership for any parallel work. Do not let two agents edit a shared registry, lockfile, manifest, or high-context file.
Safe direct actions are read-only inspection, report generation, local tests,
and drafting a plan. During an authorized repair run:
Keep usage evidence read-only. When classification depends on local invocation
history, run skill-usage-stats or its governance matrix report, then return
here for exposure changes.
Never print secrets, overwrite unknown user content, use force push, rewrite history, or claim external credential rotation without direct evidence.
Run verification from the current session:
ecosystem_doctor.py and require zero errors.ecosystem_reconcile.py without --apply and require no planned changes.gemini/cursor named in projection_runtimes or
managed_global_sources[].runtimes — resolves the intended source or exact
pin. Check each runtime's Skill home: Codex uses ~/.agents/skills while
Codex configuration remains under ~/.codex.
When projection_runtimes is explicitly empty, verify every declared
managed_projection inventory root instead and require a zero-link
reconciliation plan.git diff --check in every changed Git worktree.Use the eval cases when forward-testing trigger boundaries, read-only behavior, secret redaction, retirement, or dirty-worktree handling.
If commit, push, PR, merge, or landing is requested, prepare a review pack. Use
review-gate when installed; otherwise present the same evidence and wait for
explicit approval unless the current request grants that exact action.
Patch this Skill when the validator no longer understands an installed layout, the same false positive recurs, a runtime changes projection semantics, or users repeat the same safety correction.
© majiayu000, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 20 other files (scripts, references, assets) in skills/skill-ecosystem-doctor of majiayu000/spellbook.
Open the folder on GitHubat commit ed52af7
Skill Ecosystem Doctor next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Skill Ecosystem Doctor this skillmajiayu000/spellbook | 287 | — | ~3k | Automated safety check: Pass | MIT | |
| Darwin Skill Optimizeralchaincyf/darwin-skill | 6.2k | 1 repos | ~4.7k | Automated safety check: Pass | MIT | |
| Skill Creatorzhayujie/CowAgent | 47k | — | ~4.7k | Automated safety check: Notes | MIT | |
| Open-Science Skill Creatoraipoch/open-science | 5.5k | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | |
| Skill Quality ReviewerGalaxy-Dawn/claude-scholar | 5.7k | 1 repos | ~3k | Automated safety check: Pass | MIT | |
| Prismer Skill CreatorPrismer-AI/PrismerCloud | 1.6k | — | ~2.6k | Automated safety check: Notes | MIT |
alchaincyf/darwin-skill
Scores SKILL.md files on a nine-dimension rubric, then improves them in a keep-or-revert loop with independent judge agents, test prompts, git history and human checkpoints.
zhayujie/CowAgent
Guides creating, installing and updating agent skills in a workspace: SKILL.md frontmatter, bundled scripts and references, with scripts to scaffold, validate and package.
aipoch/open-science
Creates, revises, evaluates and publishes skills in the Open-Science app through its native host.skills composer, with optional test prompts and benchmarks.
Galaxy-Dawn/claude-scholar
Scores a skill across description, content organization, writing style and structure, then produces letter grades and a prioritized improvement plan.
Prismer-AI/PrismerCloud
Walks an agent through creating, importing, editing, validating, testing and publishing Prismer Skills with a fixed workflow and bundled scripts.
sangrokjung/claude-forge
Analyze session work and automatically convert reusable patterns into Claude Code skills.
majiayu000/spellbook
Scans a repository for real evidence and proposes, or on request writes, a small stack of root and scoped AGENTS.md files with validation commands and generated-file boundaries.
majiayu000/spellbook
Plans, produces or diagnoses evidence-backed product demo videos: script, capture plan, pacing checks and verified final media built on real product behavior.
majiayu000/spellbook
Single entry point that routes long or ambiguous agent tasks, checks live state, bounds autonomous loops and leaves a resumable handoff.
majiayu000/spellbook
Scans a repository, its lockfiles and node_modules for known malicious npm package versions and install-time indicators, using a read-only Python scanner.
majiayu000/spellbook
Product management helpers: a RICE scoring script, an interview transcript analyzer and PRD templates for prioritizing features, synthesizing research and writing requirements.
majiayu000/spellbook
Audits a repository's agent-readable context, from AGENTS.md and CLAUDE.md to skills and PRODUCT or TECH specs, and recommends the smallest useful improvements.
Categories
Audits and repairs how coding-agent Skills are owned, copied and exposed across runtimes, from canonical sources to quarantine and retirement. The skill treats agent Skills as a governed supply chain: audit first, plan repairs from evidence, apply only authorized changes, then verify and hand off. It stays out of project-local questions about whether a tool already loaded a Skill, sending those to that tool's own setup, and engages only for cross-runtime ownership, exposure or repair governance.
Skill Ecosystem Doctor fits situations like: auditing which Skill definitions are canonical versus duplicated across runtimes; planning a cross-runtime consolidation of Skills before touching anything; quarantining or retiring a Skill with an explicit rollback plan; rechecking a saved governance file after a previous repair.
Run `npx skills add majiayu000/spellbook --skill skill-ecosystem-doctor -a claude-code`. Or copy the skill folder (skills/skill-ecosystem-doctor in majiayu000/spellbook) into .claude/skills/skill-ecosystem-doctor in your project. Claude Code loads it when a task matches its description.
Run `npx skills add majiayu000/spellbook --skill skill-ecosystem-doctor -a codex`. Or copy the skill folder (skills/skill-ecosystem-doctor in majiayu000/spellbook) into .agents/skills/skill-ecosystem-doctor in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add majiayu000/spellbook --skill skill-ecosystem-doctor -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/skill-ecosystem-doctor, .gemini/skills/skill-ecosystem-doctor, .github/skills/skill-ecosystem-doctor and .opencode/skills/skill-ecosystem-doctor in your project.
Going by SKILL.md and its folder, Skill Ecosystem Doctor needs Python for the scripts in its folder and the command-line tools its instructions call (python3 and git). Our summary lists: Python, with the packages listed in requirements.txt.
SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Skill Ecosystem Doctor is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 5k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Skill Ecosystem Doctor: Darwin Skill Optimizer (alchaincyf/darwin-skill, 6.2k stars), Skill Creator (zhayujie/CowAgent, 47k stars), Open-Science Skill Creator (aipoch/open-science, 5.5k stars) and Skill Quality Reviewer (Galaxy-Dawn/claude-scholar, 5.7k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
majiayu000 (a GitHub user) maintains it in majiayu000/spellbook, which has 287 GitHub stars. The repository holds 97 skills in this directory. The repository was last updated on October 8, 2026.
Source: majiayu000/spellbook on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.