Repo2skill
zhangyanxs/repo2skill
Convert GitHub/GitLab/Gitee repositories into comprehensive OpenCode Skills using embedded LLM calls with multiple mirrors and rate limit handling
Get a CLI tool — native binary or PHAR — from a GitHub release into a project folder with dload (vendor/bin/dload).
$ npx skills add php-internal/dload --skill dload-fetch-tool -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install php-internal/dload dload-fetch-tool --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/php-internal/dload.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/dload-fetch-tool .claude/skills/dload-fetch-tool && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "dload-fetch-tool" agent skill from https://github.com/php-internal/dload/tree/1.x/skills/dload-fetch-tool into .claude/skills/dload-fetch-tool/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dload-fetch-tool", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/php-internal/dload/tree/1.x/skills/dload-fetch-toolType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add php-internal/dload --skill dload-fetch-tool -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install php-internal/dload dload-fetch-tool --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/php-internal/dload.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/dload-fetch-tool .agents/skills/dload-fetch-tool && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "dload-fetch-tool" agent skill from https://github.com/php-internal/dload/tree/1.x/skills/dload-fetch-tool into .agents/skills/dload-fetch-tool/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dload-fetch-tool", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add php-internal/dload --skill dload-fetch-tool -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install php-internal/dload dload-fetch-tool --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/php-internal/dload.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/dload-fetch-tool .cursor/skills/dload-fetch-tool && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "dload-fetch-tool" agent skill from https://github.com/php-internal/dload/tree/1.x/skills/dload-fetch-tool into .cursor/skills/dload-fetch-tool/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dload-fetch-tool", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/php-internal/dload.git --path skills/dload-fetch-tool--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add php-internal/dload --skill dload-fetch-tool -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install php-internal/dload dload-fetch-tool --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/php-internal/dload.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/dload-fetch-tool .gemini/skills/dload-fetch-tool && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "dload-fetch-tool" agent skill from https://github.com/php-internal/dload/tree/1.x/skills/dload-fetch-tool into .gemini/skills/dload-fetch-tool/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dload-fetch-tool", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install php-internal/dload dload-fetch-toolInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add php-internal/dload --skill dload-fetch-tool -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/php-internal/dload.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/dload-fetch-tool .github/skills/dload-fetch-tool && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "dload-fetch-tool" agent skill from https://github.com/php-internal/dload/tree/1.x/skills/dload-fetch-tool into .github/skills/dload-fetch-tool/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dload-fetch-tool", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add php-internal/dload --skill dload-fetch-tool -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install php-internal/dload dload-fetch-tool --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/php-internal/dload.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/dload-fetch-tool .opencode/skills/dload-fetch-tool && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "dload-fetch-tool" agent skill from https://github.com/php-internal/dload/tree/1.x/skills/dload-fetch-tool into .opencode/skills/dload-fetch-tool/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dload-fetch-tool", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
dload-fetch-toolGet a CLI tool — native binary or PHAR — from a GitHub release into a project folder with dload (vendor/bin/dload).
Dload Fetch Tool is an agent skill from php-internal/dload. Get a CLI tool — native binary or PHAR — from a GitHub release into a project folder with dload (vendor/bin/dload). Use when the user wants tool X (rr, temporal, buf, a PHAR…) downloaded into the project or added to dload.xml, when a download picks the wrong asset or none, or when setting up dload's release cache (version registry) locally or in CI, including GitHub API rate limits.
Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including reference files (for example `references/archive-mode.md`, `references/registry-entry.md` and `references/troubleshooting.md`).
It sits in Backend & APIs, covering Rate limiting. It works with GitHub. The repository describes itself as: Helps to download binaries from release assets. The licence is BSD-3-Clause.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 58ff7cd. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
composerphpFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
w3.orgFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
GITHUB_TOKENFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Dload Fetch Tool loads about 1.1k tokens when it runs, and up to ~4.9k if it reads all its reference files. Until then it costs about 102 tokens; SKILL.md has 415 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from php-internal/dload at commit 58ff7cd, republished under its BSD-3-Clause licence (© php-internal). 415 words, ~1,077 tokens.
.claude/skills/dload-fetch-tool/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.The task — "tool X from GitHub, available in this project's folder" — turns on one question: does dload already know this tool? If yes, dload.xml gets one <download> line. If no, the tool is also described inline in the same file. Native binaries and .phar files are both first-class; they differ in a couple of fields.
Everything happens in the consuming project's own dload.xml (dload itself is installed via composer require internal/dload).
./vendor/bin/dload softwarePrints every built-in tool with its alias. Tool listed → Step 3. Not listed → Step 2.
Add a <software> block to the <registry overwrite="false"> element of the project's dload.xml. Read references/registry-entry.md first: it lists the facts to collect from the GitHub release and how to design asset-pattern and binary.pattern for binaries and PHARs.
Done when the block has a <repository> whose asset-pattern matches every OS/arch variant of the tool and nothing else in the release.
<download> action<?xml version="1.0"?>
<dload
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
xsi:noNamespaceSchemaLocation="https://raw.githubusercontent.com/php-internal/dload/refs/heads/main/dload.xsd"
temp-dir="./runtime"
>
<actions>
<download software="buf" />
<download software="trap" type="phar" version="^1.1" />
</actions>
<registry overwrite="false">
<!-- inline <software> blocks from Step 2, if any -->
</registry>
</dload>| Attribute | Purpose |
|---|---|
software | Alias or name of the tool (built-in or inline). Required. |
version | Composer-style constraint: ^2025.1, ~1.0.0, ^2.12.0@beta, ^2.12.0-hotfix@rc. Omit for latest stable. Stability order follows Composer, stable by default. |
extract-path | Target folder (default: project root). |
type | binary (default), phar (required for PHAR — skips extraction), archive (unpack the whole asset keeping its folder layout). |
type="archive" is for tools that ship more than one executable — frontend bundles, docs, a binary that loads sibling libraries by relative path. Read references/archive-mode.md before using it.
The authoritative schema is vendor/internal/dload/dload.xsd.
<actions>
<download software="rr" extract-path="./bin" />
<download software="trap" type="phar" extract-path="./tools" />
</actions>extract-path is the literal folder the file lands in, for binaries and PHARs alike. Keep the folder in VCS with a .gitkeep and put the downloaded file in .gitignore — only dload.xml belongs in git.
./vendor/bin/dload get # every <download> entry in dload.xml
./vendor/bin/dload get <alias> # one entryDone when the tool runs: ./bin/rr --version, php ./tools/trap.phar --version.
Release lists are answered from a local cache — the version registry — for 10 minutes after the last check of a repository, so a release published moments ago may need dload get --refresh. For cache location and TTL, and for any CI setup — passing GITHUB_TOKEN and carrying the registry between runs, with GitHub Actions and GitLab examples — read references/version-registry.md.
dload get exits non-zero and prints, per failed tool, the API error, the releases it checked, their assets, and the filter that rejected them. Read that report, then walk the selection stages in references/troubleshooting.md.
© php-internal, BSD-3-Clause. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 4 other files (references) in skills/dload-fetch-tool of php-internal/dload.
Open the folder on GitHubat commit 58ff7cd
Dload Fetch Tool next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Dload Fetch Tool this skillphp-internal/dload | 105 | — | ~1.1k | Automated safety check: Pass | BSD-3-Clause | |
| Repo2skillzhangyanxs/repo2skill | 246 | — | ~3.6k | Automated safety check: Pass | None | |
| Better Auth Security Best PracticesEpicenterHQ/epicenter | 4.8k | — | ~896 | Automated safety check: Pass | Custom licence | |
| Apikerhodgef/apiker | 127 | — | ~1.4k | Automated safety check: Pass | MIT | |
| Goosetown Researcher GitHubaaif-goose/goosetown | 154 | — | ~1.6k | Automated safety check: Pass | Apache-2.0 | |
| Implementing API Key Security Controlsmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~4k | Automated safety check: Pass | Apache-2.0 |
zhangyanxs/repo2skill
Convert GitHub/GitLab/Gitee repositories into comprehensive OpenCode Skills using embedded LLM calls with multiple mirrors and rate limit handling
EpicenterHQ/epicenter
Better Auth security hardening: rate limits, secrets, CSRF, trusted origins, cookies, sessions, OAuth tokens, and audit logging.
hodgef/apiker
Develop, review, and extend the Apiker library — a framework for building serverless REST APIs on Cloudflare Workers + Durable Objects.
aaif-goose/goosetown
Search GitHub issues, PRs, code, and discussions using the gh CLI.
mukul975/Anthropic-Cybersecurity-Skills
Implements secure API key generation with sufficient entropy, server-side hashing (SHA-256/bcrypt) instead of plaintext storage, per-key scoping to endpoints/IPs/rate limits, zero-downtime rotation…
aaddrick/claude-pipeline
Batch process GitHub issues via batch-orchestrator.sh with rate limit handling and session resumption
Works with
Categories
Get a CLI tool — native binary or PHAR — from a GitHub release into a project folder with dload (vendor/bin/dload). Dload Fetch Tool is an agent skill from php-internal/dload. Get a CLI tool — native binary or PHAR — from a GitHub release into a project folder with dload (vendor/bin/dload).
Dload Fetch Tool fits situations like: the user wants tool X (rr; A PHAR…) downloaded into the project; added to dload.xml; A download picks the wrong asset.
Run `npx skills add php-internal/dload --skill dload-fetch-tool -a claude-code`. Or copy the skill folder (skills/dload-fetch-tool in php-internal/dload) into .claude/skills/dload-fetch-tool in your project. Claude Code loads it when a task matches its description.
Run `npx skills add php-internal/dload --skill dload-fetch-tool -a codex`. Or copy the skill folder (skills/dload-fetch-tool in php-internal/dload) into .agents/skills/dload-fetch-tool in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add php-internal/dload --skill dload-fetch-tool -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dload-fetch-tool, .gemini/skills/dload-fetch-tool, .github/skills/dload-fetch-tool and .opencode/skills/dload-fetch-tool in your project.
Going by SKILL.md and its folder, Dload Fetch Tool needs the command-line tools its instructions call (composer and php) and credentials named GITHUB_TOKEN. Our summary lists: A credential in GITHUB_TOKEN.
SKILL.md names 1 domain. In commands or code: w3.org; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Dload Fetch Tool is published under the BSD-3-Clause licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.1k tokens (SKILL.md is roughly 4.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.8k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Dload Fetch Tool: Repo2skill (zhangyanxs/repo2skill, 246 stars), Better Auth Security Best Practices (EpicenterHQ/epicenter, 4.8k stars), Apiker (hodgef/apiker, 127 stars) and Goosetown Researcher GitHub (aaif-goose/goosetown, 154 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
php-internal (a GitHub organization) maintains it in php-internal/dload, which has 105 GitHub stars. The repository was last updated on October 6, 2026.
Source: php-internal/dload on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.