Add TTS Engine to Voicebox
jamiepine/voicebox
Walks through adding a new text-to-speech engine to Voicebox end to end: dependency audit, backend, frontend wiring, PyInstaller bundling and frozen-build testing.
Operate the skills-manager CLI — manage a local skill hub (install, import, distribute to agents/projects, update) and backfill provenance for source-less skills (adopt lockfile evidence, search the…
$ npx skills add shenysun/skills-manager --skill skills-manager -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install shenysun/skills-manager skills-manager --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/shenysun/skills-manager.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/skills-manager .claude/skills/skills-manager && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "skills-manager" agent skill from https://github.com/shenysun/skills-manager/tree/main/skills/skills-manager into .claude/skills/skills-manager/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "skills-manager", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/shenysun/skills-manager/tree/main/skills/skills-managerType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add shenysun/skills-manager --skill skills-manager -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install shenysun/skills-manager skills-manager --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/shenysun/skills-manager.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/skills-manager .agents/skills/skills-manager && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "skills-manager" agent skill from https://github.com/shenysun/skills-manager/tree/main/skills/skills-manager into .agents/skills/skills-manager/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "skills-manager", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add shenysun/skills-manager --skill skills-manager -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install shenysun/skills-manager skills-manager --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/shenysun/skills-manager.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/skills-manager .cursor/skills/skills-manager && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "skills-manager" agent skill from https://github.com/shenysun/skills-manager/tree/main/skills/skills-manager into .cursor/skills/skills-manager/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "skills-manager", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/shenysun/skills-manager.git --path skills/skills-manager--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add shenysun/skills-manager --skill skills-manager -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install shenysun/skills-manager skills-manager --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/shenysun/skills-manager.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/skills-manager .gemini/skills/skills-manager && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "skills-manager" agent skill from https://github.com/shenysun/skills-manager/tree/main/skills/skills-manager into .gemini/skills/skills-manager/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "skills-manager", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install shenysun/skills-manager skills-managerInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add shenysun/skills-manager --skill skills-manager -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/shenysun/skills-manager.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/skills-manager .github/skills/skills-manager && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "skills-manager" agent skill from https://github.com/shenysun/skills-manager/tree/main/skills/skills-manager into .github/skills/skills-manager/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "skills-manager", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add shenysun/skills-manager --skill skills-manager -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install shenysun/skills-manager skills-manager --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/shenysun/skills-manager.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/skills-manager .opencode/skills/skills-manager && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "skills-manager" agent skill from https://github.com/shenysun/skills-manager/tree/main/skills/skills-manager into .opencode/skills/skills-manager/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "skills-manager", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills-managerOperate the skills-manager CLI — manage a local skill hub (install, import, distribute to agents/projects, update) and backfill provenance for source-less skills (adopt lockfile evidence, search the…
Skills Manager is an agent skill from shenysun/skills-manager. Operate the skills-manager CLI — manage a local skill hub (install, import, distribute to agents/projects, update) and backfill provenance for source-less skills (adopt lockfile evidence, search the ecosystem for candidates, verify, get the user's approval, write sources). Use this skill whenever the user mentions skills-manager, the skill home / hub (~/.skills-manager), importing skills from agent runtime directories, distributing or undistributing skills, updating skills from their sources, tagging skills with…
Its SKILL.md is about 7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Development, covering Dependency management. The licence is MIT.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 3cf755f. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
npxcurlghgitFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
skills.shraw.githubusercontent.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Skills Manager loads about 7k tokens when it runs. Until then it costs about 251 tokens; SKILL.md has 3,135 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from shenysun/skills-manager at commit 3cf755f, republished under its MIT licence (© shenysun). 3,135 words, ~7,048 tokens.
.claude/skills/skills-manager/SKILL.md (or your agent's skills folder).The user's skills live in a single hub (~/.skills-manager by default; override with --home <path> or SKILL_HOME). The hub is the only content authority: skills/<name>/ directories plus a registry.yaml of metadata. Skills flow in two directions — install/import into the hub, distribute out to agent runtime directories (~/.claude/skills, ~/.cursor/skills, …) as symlinks (user scope) or copies (project scope).
Key vocabulary you will need when reading output:
{type: git|local, url, subpath, ref, …} on the registry entry. A skill with a url (+ subpath) is **updatable`; without one it is a snapshot.update --check and the dashboard's 可更新 check. GitHub sources compare the skill sub-directory's tree SHA (source.upstream_tree) against the GitHub Trees API — one call per repo (shared by all its skills), TTL-cached, through the logged-in gh CLI when present (5000 req/h) or anonymous HTTPS otherwise (60 req/h). A row reading 检测失败 / detection failed means the check did not complete — that is not "no update"; every failure appends a JSON line to <home>/.skills/dashboard.log.imported: true: how the skill entered the hub (via init), orthogonal to whether it has a source.npx skills would target on this machine, resolved locally from the bundled catalog snapshot.categories: [] (前端 / 金融 / backend — the user's own vocabulary, orthogonal to the frozen legacy category); a category set is the per-runtime-path applied filter state that categories status reports.name + description (an undistributed skill costs nothing). cost accounts it per physical runtime path — approximately, always shown ≈ (method: "char-approx").The CLI is non-interactive (bootstrap's agent picker is the one exception); every choice is a flag. Commands print JSON — except status (a human-readable summary), get (the skill file itself), cost (a human ledger view; --json prints the machine form), and --help. Parse stdout; don't guess the shape.
When the user's first message is a broad ask (“帮我看看我的 skills” / "what skills do I have"), or the hub turns out to be empty, do not assume any setup exists — orient first, then propose exactly one action:
skills-manager list — see what the hub holds. Empty output means a fresh bootstrap; say so plainly.~/.claude/skills, …) → skills-manager init --dry-run, report the plan, import on the user's confirmation.skills-manager add owner/repo --list first).skills-manager doctor shows it missing for an agent they use, offer skills-manager distribute --to user --skill skills-manager --agent <id>.Keep the first turn short: report state, propose one action, wait. Deeper workflows (like provenance backfill below) come when the user asks for them.
skills-manager list [--category <c>] [--include-archived]
skills-manager list --brief # compact rows — use this in conversation first; full rows are tens of KB
skills-manager get <name> # zero-retention read: full SKILL.md (frontmatter + body) on stdout
skills-manager get <name> --path # absolute hub dir, for read-only borrowing of sibling files
skills-manager status # distribution health: managed/outdated/foreign
skills-manager doctor # warnings incl. imported-without-source queue
skills-manager cost [--top <n>] [--json] # resident-cost ledger: per-path cost + report-only recall suggestions
skills-manager catalog info # snapshot stamp + detected agents (each with its runtime dir)
skills-manager catalog refresh # re-pull the upstream agent table
skills-manager backup listget is the reference layer — the zero-cost alternative to distributing. When you need a skill once (this conversation only), get <name> prints its complete SKILL.md to stdout — raw text, not JSON — and the frontmatter carries the provenance mirror (where the skill came from), so the read doubles as a trust check. Use it, then move on: nothing stays loaded. --path prints the hub directory instead — first stdout line, followed by a read-only notice (an archived skill resolves to its .skills/archive/… directory) — for reading sibling files (scripts/, references). Read-only: the hub is canonical, changes go through skills-manager commands. No distribution state is required; archived skills stay readable (in body mode an archived notice rides stderr, stdout stays the file body), and a miss suggests near names.
skills-manager add <owner/repo> --list # discover first, install nothing
skills-manager add <owner/repo> --skill <name> # install by discovered name or subpath
skills-manager add /local/path --all -y # local sources work too; -y overwrites<source> accepts GitHub owner/repo, a Git URL, a GitHub tree URL, or a local path. Always --list first when unsure what a source contains.
skills-manager init --dry-run # plan only — start here
skills-manager init # import + replace origins with symlinks
skills-manager init --prefer claude-code ~/.agents/skills hub # conflict priority this run
skills-manager init --resolve my-skill=hub # per-skill override
skills-manager backup restore <skill> # undo one importImport never guesses provenance, but it adopts evidence: entries in the npx skills lockfile (~/.agents/.skill-lock.json) with matching names become real sources automatically (ADR-0011).
When the dry-run reports conflicts (kind: "multi-runtime"), walk the user through the decision rather than quoting flag docs: each location already carries its agent ids, runtime dir, and its own description — present the sides, ask which one to trust, then map the answer to --prefer <runtime-dir> (priority for the whole run) or --resolve <skill>=<choice> (one skill). A dry-run's plannedImports names what would import.
skills-manager distribute --to user --skill <name> --agent claude-code --agent zed
skills-manager distribute --to project --project ./repo --skill <name> --mode copy
skills-manager undistribute --to user --skill <name> --agent claude-code
skills-manager redistribute --refresh # re-sync stale copy targets
skills-manager distribute rollback --to userOmitting --agent targets the detected set — which can be dozens of agents on a busy machine. Check catalog info first and name agents explicitly unless the user truly means "everywhere". User scope defaults to symlink, project scope to copy.
Every skill can carry free-form domain categories (前端 / 金融 / backend — no controlled vocabulary; categories list keeps the wording consistent). Tagging only writes the registry — what loads changes only on an explicit apply.
skills-manager categories set <skill> 前端 后端 # replace the whole list (no values = clear)
skills-manager categories add <skill> 金融 # incremental, no full restatement
skills-manager categories remove <skill> 金融
skills-manager categories list # every tag in the hub + per-tag skill count
skills-manager edit <skill> --categories 前端 后端 # same replace semantics inside editMap conversational tagging asks ("给 X 归到前端类" / "tag this as frontend") straight onto these commands — there are no flags for the user to remember.
categories apply rewrites the selected agents' runtime dirs to exactly the skills in the given categories: distributes what's missing, removes managed skills outside the set.
skills-manager categories apply 前端 金融 -a claude-code
skills-manager categories apply --all # dissolve the filter, restore every managed skill
skills-manager categories status # per-path applied set + drift; never writesAgent selection reuses distribute's mental model, not a new one: -a repeatable, default = detected set. The CLI itself never prompts — when the user doesn't name agents, you pick in conversation, the way distribute's dashboard picker behaves: detected agents prechecked when no apply has been confirmed yet, and the last confirmed apply selection — remembered per scope, within this conversation — offered as the default next time. Agents sharing one physical runtime dir (an agent family) necessarily share one category set; selection is always by agent id.
State the strict semantics plainly whenever proposing an apply:
apply --all restores everything, and distribute rollback --to user restores the runtime content and the category-set record together.categories status reports the drift ("N skills now match the set but are undistributed") and names the re-run command that converges.Presets (预设 / 档位) give a category list a name, so switching is one command instead of restating categories (ADR-0019):
skills-manager preset set frontend 前端 ui # save / replace a named preset (categories may not exist yet — build first, tag later)
skills-manager preset list # members + mount footprint (paths carrying it; drift reported, never implied healthy)
skills-manager preset remove frontend # delete + cascade-clear the name off every mounted path (runtime untouched)
skills-manager preset apply frontend -a claude-codeMap 档位-speak straight onto these — there are no flags for the user to remember: "换个档位" / "只留前端技能" / "切到 X 组合" → preset apply; "记住这个组合" → preset set. When a name already holds the list, apply the name — never restate the categories.
preset apply carries exactly the strict semantics above (uncategorized removed, manager skill exempt, foreign untouched, reversible via distribute rollback --to user) plus two hard errors that protect the saved object: a preset resolving to zero managed skills, or one referencing a category that no longer exists, both refuse at apply time naming the preset and its categories — relay the error verbatim; it points at the fix (tag skills into the categories, or re-set the preset's list). The success output ends with the preset's resident-cost line (≈ tokens, char-approx): state the strict semantics and the cost line whenever proposing an apply — the same warnings categories apply gets, so switching 档位 never sounds cheaper or safer than it is.
skills-manager update --check # freshness detection: stale / upToDate / failed / skipped
skills-manager update --plan # candidates only (url + subpath) — no freshness check
skills-manager update --skill <name>
skills-manager update --source <key> # one repo group from the planOnly skills with source.url and source.subpath are candidates — which is why backfill (below) always writes both.
--check answers "is anything actually new": it compares each candidate's anchored tree SHA against the GitHub Trees API (one call per repo, through the logged-in gh when present), so present its stale list as the real update set. failed rows mean the check did not complete — each row carries the log path (<home>/.skills/dashboard.log) with the timestamped cause; usual suspects are network flaps and, without a logged-in gh, the 60 req/h anonymous API limit. --plan lists candidates without checking — don't present a plan entry as "has an update".
Git installs and updates are shallow (--depth 1); a network-class clone failure (HTTP/2 stream reset and friends) is retried once over HTTP/1.1 automatically. Detection anchors on the skill sub-directory's tree SHA, so an unrelated upstream commit (a README bump) does not flag an update. When the dashboard shows 检测失败 (detection failed), read <home>/.skills/dashboard.log for the timestamped cause — usual suspects are network flaps and, without a logged-in gh, the 60 req/h anonymous API limit.
skills-manager edit <skill> --source-git <owner/repo> --subpath <path> [--source-ref <ref>]
skills-manager edit <skill> --title "New title" --description "…" --category <c> --tags a b--source-git normalizes owner/repo (or a full GitHub URL) to the canonical repo URL, so the entry lands in exactly the shape add writes and immediately qualifies for update.
skills-manager provenance list [--json] # the backfill queue (see workflow)
skills-manager provenance adopt [--dry-run] [--skill <name>]
skills-manager archive <skill> # keep content, hide from lists
skills-manager rebuild-collections
skills-manager migrate-consumers # one-shot legacy-tag migration
skills-manager migrate-views # leftover hub views → runtimes (legacy)
skills-manager bootstrap [--agent <id...>] [--force] # (re)mount this skill onto agents
skills-manager web [-p 4777] # local dashboardRun this when the user asks "帮我找个处理 PDF 的 skill" / "find a skill for X" — discovering a new skill from the ecosystem is a first-class flow, not a backfill side effect. The sequence:
Distill English keywords from the ask. The channels are English-keyword search engines: a Chinese ask becomes 2–3 English words ("处理 PDF 的" → pdf), never a translated sentence.
Search the shared channel table (below) — one query; the first channel that answers serves the result.
Verify before presenting — the same bar as backfill: for each top candidate, fetch the upstream SKILL.md and compare its name/description against what the user asked for. Discard mismatches — junk candidates cost more trust than fewer, better ones.
Present with evidence: name, owner/repo, installs (an adoption signal, never a quality verdict — say so when showing the number), and the skills.sh link (https://skills.sh/<owner>/<repo>/<skillId>). Name the channel that served the result.
Install only on the user's pick, through the unchanged source-first machinery. The API's source field is already owner/repo and skillId is the skill's directory inside that repo:
skills-manager add <source> --list # confirm the skill is there and its exact name/subpath
skills-manager add <source> --skill <skillId> # the selector matches a discovered name or subpathDistribution stays a separate, explicit step — offer distribute afterwards if the user wants the skill live for an agent.
Both consumers use this one table: the find workflow above and provenance backfill Step 3. Defined once here, referenced there.
| # | Channel | Command |
|---|---|---|
| ① | skills.sh direct API (primary) | curl -s --max-time 30 "https://skills.sh/api/search?q=<kw>" |
| ② | npx skills find (second — buffer against API drift) | npx -y skills find "<kw>" |
| ③ | GitHub code search (last resort) | `gh api -X GET search/code -f q='filename:SKILL.md "<kw>" in:file' -f per_page=10 --jq '.items[] |
Channel discipline:
skills array all mean "try the next channel". The user sees one result set, not the failed attempts — but the presented result names the channel that produced it.skills: [{id, skillId, name, installs, source}] — with source = owner/repo and id = source/skillId.owner/repo@skillname <installs> with a https://skills.sh/... link; on some npm setups npx chokes on this package with Unknown command — that is the channel being unavailable, not your query being wrong.Run this when the user asks to "补齐来源 / fix sources / find out where these skills came from / make them updatable", or when doctor reports imported-without-source skills. The rule that governs everything: evidence is adopted automatically; guesses are never written without the user picking them, one skill at a time (ADR-0012).
skills-manager provenance adopt --dry-run # preview, then:
skills-manager provenance adoptThis re-runs the lockfile-evidence adoption over legacy imports. Report how many were adopted and how many remain.
skills-manager provenance list --jsonTwo buckets: importedWithoutSource (came from runtime dirs, evidence missing) and locallyAuthored (the user wrote them). Work through both — locally-authored skills usually just need a "confirm" (Step 4), not a source.
When the queue is more than a handful (5+), fan the search out to parallel subagents — each takes a slice of skills through the steps below and returns structured candidates — then come back and run Step 4 yourself. Searching parallelizes; approving does not.
For each pending skill:
Read its SKILL.md frontmatter (name, description) from the hub — that's the query material. Distill it to English keywords per the channel table's discipline.
Search the shared channel table — the ordered three channels and their discipline live in one place: the "Search channel table" section under Workflow: find and install a skill (above). This step is the table's other consumer; it never redefines it.
Verify before presenting. For each top candidate, fetch the upstream SKILL.md and compare its name/description with the local copy:
curl -sL https://raw.githubusercontent.com/<owner>/<repo>/HEAD/<path-without-SKILL.md>/SKILL.mdA matching name plus a matching (or clearly evolved) description is a verified candidate. Discard mismatches — showing the user junk candidates costs more trust than showing fewer, better ones.
Present exactly one question per skill (AskUserQuestion or equivalent single choice), batched at the platform's per-prompt cap — 4 questions per round on Claude Code, so a 17-skill queue is ~5 rounds, not 17 interruptions. Each question shows the verified candidates (labelled with owner/repo, install count, and how well it matched), plus:
When the user picks a candidate, write it immediately:
skills-manager edit <skill> --source-git <owner/repo> --subpath <dir-inside-repo>If the search or verification produced nothing trustworthy, say so plainly and offer only locally-authored / skip — do not pad the list with unverified guesses.
skills-manager doctorSummarize: adopted-from-lockfile count, sources written by approval, confirmed locally-authored, skipped, and the before/after of the doctor queue.
Every distributed skill charges every message the tokens of its frontmatter name + description — its resident cost. That is the account skills-manager cost keeps: totals grouped by physical runtime path (a shared path counted once, its agent family noted), per-skill lines under each path, and report-only recall suggestions. Consult it unprompted when the user wonders what their agents pay per message (常驻成本 / context cost) — and when it shows expensive or zero-controversy distributions, propose the recall yourself instead of waiting to be asked.
skills-manager cost --json # the full three-layer ledger — parse this in conversation
skills-manager cost # human view: path groups → per-skill lines → total + unmanaged line → suggestions
skills-manager cost --top 10 # widen the expensive-descriptions list (default 5)The JSON carries paths[] (each with runtimeDir, kind, agents, per-skill lines), the top-level totalTokens and method, a three-layer suggestions object, an unmanaged count for foreign entries the ledger honestly omits, and an errors list for unreadable entries (counted 0; entries missing a description are flagged incomplete).
method is "char-approx" (CJK characters ×1, everything else ÷4) and every displayed number is ≈-prefixed — never relay a ledger number to the user as an exact token count.undistribute command (including the required --to, and --project where the path is a project target). Acting on it is the user's decision. Only undistribute is ever suggested — get (the reference layer) and archive are user-side follow-ups you may narrate but not run.Run this when the user asks "我想在另一台机器上用这些 skills" / "sync my skills" / "多台电脑怎么同步". The hub itself becomes a git repository; push/pull over the user's own remote is the whole sync mechanism (ADR-0020) — no device codes, no managed tokens, git stays the merge tool. Three moments, three commands:
First machine — set up once:
skills-manager sync init --remote <url> # git init (or adopt), canonical .gitignore, baseline commit, attach origininit adopts an existing .git/ (a manually git-ified hub is a step ahead, not an error — history kept), appends only the missing canonical .gitignore lines, makes one baseline commit when the tree has anything to commit, and reports exactly what it did, zero omission. .backups/ and .skills/ (distribution index, rollback snapshots, activity log) are machine-local and never sync — distribution is per machine, on purpose. A local bare repo works as the remote too. The output ends with a reminder to confirm the hub holds no secrets before it is pushed — relay it, don't bury it.
After changes — the routine, on every machine:
skills-manager sync push # add -A + one skill-level summary commit + push
skills-manager sync status # read-only probe: git-ified?, remote, dirty count, ahead/behind, last sync commitpush is snapshot-at-push-time — no write point ever auto-commits. With a clean tree and an up-to-date remote it reports "already in sync" and exits 0, never an empty commit. status is zero-network: ahead/behind reads the remote-tracking ref as of the last fetch and says so. sync status --json is the machine-readable form when you need to report sync posture in conversation.
New machine — get the content, then distribute yourself:
skills-manager sync pull # fetch + merge; ends with skill-level stats and a distribute reminderpull ends with what the merge brought in (added / updated / removed skills, registry flag); the not yet distributed reminder prints only when skills actually arrived — the follow-up is the user's call. Offer distribute as the explicit next step when they want pulled skills live for an agent; never run it unprompted after a pull.
Discipline — matching the CLI's hard gates. When the user hits one, the nonzero exit already carries this guidance; relay it, don't soften it:
sync push or manual handling. It never stashes.git -C <hub> status — skills-manager never makes merge decisions over user data. The single exception: when registry.yaml is the only conflicted path, the local content is the empty placeholder (skills: {}), and local history is nothing but the init baseline commit, pull keeps the remote's real registry and says so — in that state no local user data exists. Merge commits are allowed; there is no rebase and no ff-only.sync status on an un-gitified hub is the exception: a friendly hint plus exit 0.npx skills lockfile (read-only evidence).skills-manager --help and docs/CLI.md in the skills-manager repo are the authority.npx skills interoperability after import is not promised; advise the user to manage skills through skills-manager once imported.© shenysun, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/skills-manager of shenysun/skills-manager.
Open the folder on GitHubat commit 3cf755f
Skills Manager next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Skills Manager this skillshenysun/skills-manager | 197 | — | ~7k | Automated safety check: Pass | MIT | |
| Add TTS Engine to Voiceboxjamiepine/voicebox | 57k | — | ~1.3k | Automated safety check: Pass | MIT | |
| Dep Updatestrufflesecurity/trufflehog | 28k | — | ~1.3k | Automated safety check: Pass | AGPL-3.0 | |
| Merge Dependabot PRsonyx-dot-app/onyx | 32k | 1 repos | ~2.2k | Automated safety check: Pass | MIT | |
| Senior Architect Toolkitmaslennikov-ig/claude-code-orchestrator-kit | 260 | 8 repos | ~1.2k | Automated safety check: Notes | Custom licence | |
| Update .NET OS Packagesdotnet/core | 22k | — | ~2.3k | Automated safety check: Pass | MIT |
jamiepine/voicebox
Walks through adding a new text-to-speech engine to Voicebox end to end: dependency audit, backend, frontend wiring, PyInstaller bundling and frozen-build testing.
trufflesecurity/trufflehog
Plan and apply Go dependency updates, including advisory-driven bumps, Trivy/govulncheck validation, and supply-chain review.
onyx-dot-app/onyx
Triages and lands a batch of open Dependabot PRs in the Onyx repo, where main is gated exclusively by GitHub's merge queue: approves and enqueues green PRs, closes superseded duplicates, fixes…
maslennikov-ig/claude-code-orchestrator-kit
Comprehensive software architecture skill for designing scalable, maintainable systems using ReactJS, NextJS, NodeJS, Express, React Native, Swift, Kotlin…
dotnet/core
Audits and updates os-packages.json files listing the Linux packages each .NET release needs per distro, then regenerates the Markdown from the JSON.
teambit/bit
Work on the pnpm Rust engine (@pnpm/napi, the pacquet crates) that bit install runs through.
shenysun/skills-manager
Run the four-role Herdr team (pm, po, dev, qa panes) that ships one feature of this repo.
Categories
Operate the skills-manager CLI — manage a local skill hub (install, import, distribute to agents/projects, update) and backfill provenance for source-less skills (adopt lockfile evidence, search the…. Skills Manager is an agent skill from shenysun/skills-manager. Operate the skills-manager CLI — manage a local skill hub (install, import, distribute to agents/projects, update) and backfill provenance for source-less skills (adopt lockfile evidence, search the ecosystem for candidates, verify, get the user's approval, write sources).
Skills Manager fits situations like: the user mentions skills-manager; the skill home / hub (~/.skills-manager); importing skills from agent runtime directories; undistributing skills.
Run `npx skills add shenysun/skills-manager --skill skills-manager -a claude-code`. Or copy the skill folder (skills/skills-manager in shenysun/skills-manager) into .claude/skills/skills-manager in your project. Claude Code loads it when a task matches its description.
Run `npx skills add shenysun/skills-manager --skill skills-manager -a codex`. Or copy the skill folder (skills/skills-manager in shenysun/skills-manager) into .agents/skills/skills-manager in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add shenysun/skills-manager --skill skills-manager -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/skills-manager, .gemini/skills/skills-manager, .github/skills/skills-manager and .opencode/skills/skills-manager in your project.
Going by SKILL.md and its folder, Skills Manager needs the command-line tools its instructions call (npx, curl, gh and git). Our summary lists: Node.js.
SKILL.md names 2 domains. In commands or code: skills.sh and raw.githubusercontent.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Skills Manager is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 7k tokens (SKILL.md is roughly 28k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Skills Manager: Add TTS Engine to Voicebox (jamiepine/voicebox, 57k stars), Dep Updates (trufflesecurity/trufflehog, 28k stars), Merge Dependabot PRs (onyx-dot-app/onyx, 32k stars) and Senior Architect Toolkit (maslennikov-ig/claude-code-orchestrator-kit, 260 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
shenysun (a GitHub user) maintains it in shenysun/skills-manager, which has 197 GitHub stars. The repository holds 2 skills in this directory. The repository was last updated on September 18, 2026.
Source: shenysun/skills-manager on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.