Agent skill

Manage Skill Flavors

by UiPath in UiPath/skills

Maintain build-time skill flavors in the UiPath skills repository.

MITAuto-check passedAgent Workflows

Install Manage Skill Flavors

skills CLI
$ npx skills add UiPath/skills --skill manage-skill-flavors -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install UiPath/skills manage-skill-flavors --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/UiPath/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/manage-skill-flavors .claude/skills/manage-skill-flavors && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
manage-skill-flavors
GitHub stars
167
Token cost
~3.5k tokens
SKILL.md length
1,804 words
Files
2 (incl. references)
Skills in repo
28
Repo updated
First seen
Licence
MIT

At a glance

Maintain build-time skill flavors in the UiPath skills repository.

  • Works in 4 steps: Confirm the repository root contains… → Read the complete canonical file being… → Read the matching relative file under… → …
  • Editing skill-flavor marker blocks
  • SKILL.md covers Start With the Complete Context, Classify the Change, Author the Smallest Exception and Prefer Additive Extension Points, plus 6 more sections
  • Calls npm and git; reaches npm.pkg.github.com

What it does

Manage Skill Flavors is an agent skill from UiPath/skills. Maintain build-time skill flavors in the UiPath skills repository. Use when adding or editing skill-flavor marker blocks, sparse flavor overrides, generic flavor discovery, marker-free default or custom npm packages, package inspection, flavor CI, or composer/package tests. Preserve SKILL.md as the complete default, keep overrides exceptional, and validate finished trees and tarballs.

Its SKILL.md is about 3.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/flavor-test-matrix.md`).

It sits in Agent Workflows, covering Skill management. It works with npm. The repository describes itself as: This is a repository of skills for interfacing UiPath capabilities to external developers. The licence is MIT.

When your agent uses it

  • Editing skill-flavor marker blocks
  • Sparse flavor overrides
  • Generic flavor discovery
  • Marker-free default

Example prompts

  • “/manage-skill-flavors”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Confirm the repository root contains skills/, skill-flavors/, and scripts/compose-skill-flavor.mjs.
  2. Read the complete canonical file being changed.
  3. Read the matching relative file under every existing skill-flavors// directory, when present. No override means that flavor intentionally…
  4. Read references/flavor-test-matrix.md completely when adding a flavor or changing discovery, composition, packaging, publishing, or CI.

What it can do on your machine

Read from SKILL.md and the folder at commit 4c7cb7c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • npm.pkg.github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Manage Skill Flavors loads about 3.5k tokens when it runs, and up to ~5.5k if it reads all its reference files. Until then it costs about 102 tokens; SKILL.md has 1,804 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~102
When it runs · the whole SKILL.md, loaded when a task matches
~3.5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from UiPath/skills at commit 4c7cb7c, republished under its MIT licence (© UiPath). 1,804 words, ~3,529 tokens.

Download SKILL.mdSave it as .claude/skills/manage-skill-flavors/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
manage-skill-flavors
description
Maintain build-time skill flavors in the UiPath skills repository. Use when adding or editing skill-flavor marker blocks, sparse flavor overrides, generic flavor discovery, marker-free default or custom npm packages, package inspection, flavor CI, or composer/package tests. Preserve SKILL.md as the complete default, keep overrides exceptional, and validate finished trees and tarballs.

Manage Skill Flavors

Maintain one complete canonical skill while building reviewed host-specific exceptions before packaging. Consumers receive finished files and never interpret markers.

Start With the Complete Context

  1. Confirm the repository root contains skills/, skill-flavors/, and scripts/compose-skill-flavor.mjs.
  2. Read the complete canonical file being changed.
  3. Read the matching relative file under every existing skill-flavors/<flavor>/ directory, when present. No override means that flavor intentionally inherits the canonical file.
  4. Read references/flavor-test-matrix.md completely when adding a flavor or changing discovery, composition, packaging, publishing, or CI.

Classify the Change

ChangeCorrect source edit
Behavior is valid in every hostEdit only the canonical file.
A host capability changes one instructionMark the smallest complete canonical passage and add one sparse replacement block.
An existing skill is safe unchanged for a flavorMake no flavor edit; it is included automatically.
A new canonical skill is addedReview it against every flavor; add sparse overrides only where canonical guidance is unsafe.
A new flavor is addedAdd its first real sparse override, or a .canonical pin, under skill-flavors/<flavor>/; generic build and CI must discover it without another registry edit.

Do not create an exception merely to reword shared guidance.

Author the Smallest Exception

Keep the canonical SKILL.md or reference complete. Put standalone boundaries around only the passage that differs:

markdown
<!--skill-flavor:project-creation:start-->
Create the project with the default local workflow.
<!--skill-flavor:project-creation:end-->

Mirror the canonical path below the flavor root and write only complete replacement blocks plus whitespace:

text
skills/uipath-example/references/setup.md
skill-flavors/studioweb/uipath-example/references/setup.md
markdown
<!--skill-flavor:project-creation:start-->
Create the project with the host project-creation tool.
<!--skill-flavor:project-creation:end-->

Marker names must be lowercase kebab-case, unique within a file, unnested, and identical in canonical and override files. An override cannot add an unmarked introduction, heading, or note.

Use the compact marker form with no whitespace inside the HTML comment, and start every boundary at column 1 with no leading or trailing spaces or tabs. Keep the Markdown indentation on the content inside the block instead. For example, wrap a nested list item like this:

markdown
<!--skill-flavor:connector-registration:start-->
    - Nested host-specific instruction.
<!--skill-flavor:connector-registration:end-->

If a new flavor needs a smaller exception than an existing multi-paragraph block, split that block into adjacent sibling blocks. Update every existing override that used the old block, and compare its complete built file before and after the refactor—the existing flavor's consumer text must remain unchanged. Never nest a narrower block inside the old one.

Prefer Additive Extension Points

Do not replace a complete shared table, list, or navigation section merely to add host guidance. A replacement freezes that whole passage for the flavor, so later canonical additions inside it no longer propagate. Keep the shared content unmarked and put an empty extension block next to it:

markdown
| Shared reference | Shared purpose |
|---|---|
| references/common.md | Used by every host |
<!--skill-flavor:reference-navigation-extra:start-->

<!--skill-flavor:reference-navigation-extra:end-->

Fill only that extension in the sparse override. The default emits nothing at the extension point; the flavor receives the complete shared section plus its addition. If one existing row genuinely differs, mark only that row instead of copying the whole table. Whenever a canonical marked passage changes, read every override for that block because those flavors do not inherit the edit.

Treat Missing Overrides as Intentional Inheritance

Every custom flavor package contains every canonical skill. Sparse files only replace passages that differ for that host.

  • Add no flavor file when canonical guidance is correct for the host.
  • Add the smallest replacement block when canonical guidance is wrong for the host.
  • Review every new or materially changed canonical skill against every existing flavor because inclusion is automatic. Update or add the smallest necessary sparse override wherever the canonical guidance is not correct for that flavor.
  • Do not create an empty flavor. A flavor needs at least one sparse override or .canonical pin; if a host has no exceptions, it should consume the default package.

Pin a Skill to Its Previous Generation (Rare)

Use this only when a canonical skill was replaced by a new generation that a host cannot run yet, so no set of sparse overrides can make it correct there.

  • Keep the previous tree at classic/skills/<skill>/ (same layout as skills/, no symlinks). It is not in the root npm package or any plugin catalog.
  • Add skill-flavors/<flavor>/<skill>/.canonical containing exactly classic. That flavor then composes <skill> from the classic tree, and its overrides for that skill target classic paths and markers.
  • A pin may only swap the source of a skill skills/ already ships. npm run skills:validate fails on a pin to an unknown skill, a pin to a missing classic tree, and a classic/skills/<skill> that no flavor pins. Delete the classic tree when its last pin goes.
  • A link from another skill into a pinned skill must resolve in both trees; npm run skills:check-links checks the file and its anchor in each. When the two generations cover the topic in different files, wrap the pointer in a flavor block: the canonical text links the current generation's file, and the pinning flavor's override links the classic file. The checker then asks each tree only for the link it composes.
  • Name the skill (/uipath:<skill>) instead of a file only when both generations hold the content the sentence promises. When the current generation has no equivalent, state the rule inline or drop the pointer. A skill name with nothing behind it is a pointer no check can catch.

Preserve Generic Discovery and Package Naming

Every direct lowercase kebab-case directory under skill-flavors/ is a flavor. Never hardcode studioweb in the composer, npm build scripts, generic validation loop, or reusable flavor publisher. Publication is intentionally different: each released flavor must opt in through an explicit reviewed caller so its registry policy cannot expand implicitly.

Package names derive mechanically from the root package:

VariantPackage
default@uipath/skills
studioweb@uipath/skills-studioweb
<flavor>@uipath/skills-<flavor>

Do not add an allowlist, skill.build.json, a flavor registry, or per-flavor package metadata. The directory name and sparse overrides are the source contract.

Show full SKILL.md (870 more words)Show less

Validate the Consumer Artifacts

Run the repository commands in order:

bash
npm run skills:validate
npm run skills:build
npm run skills:pack
npm run skills:test
git diff --check

skills:build must produce complete marker-free trees under build/skills/. skills:pack must rebuild those trees, stage packages under build/packages/, run real npm pack, and verify tarballs under build/npm/. Flavor publishing jobs must select one verified .tgz by manifest identity and publish only that exact path; they must never publish a wildcard containing the default or another flavor.

Normal npm pack and npm publish at the repository root remain backward compatible default-package commands. Their prepack lifecycle transactionally activates a marker-free default skills/ tree, and postpack restores the exact canonical source tree before the command finishes. They produce or publish only @uipath/skills; they do not replace npm run skills:pack, which builds every discovered flavor. If npm fails or is interrupted between those lifecycle steps and build/.root-pack-transaction remains, first confirm the original npm process has ended, then run npm run skills:recover before retrying. Recovery restores canonical sources; if it finds unexpected overlay edits, it preserves them under build/.root-pack-recovery-* and exits nonzero so they cannot be missed. Never use --ignore-scripts for root source packaging because it intentionally bypasses this composition lifecycle.

Inspect the final package contract, not only sparse sources:

  • The default contains every canonical skill and retains canonical block bodies without marker boundaries.
  • Each custom package contains every canonical skill and its flavor replacements.
  • Every staged manifest uses the root version and the derived package name.
  • Custom manifests contain no repository lifecycle scripts or package.json.repository field. They pin both publishConfig.registry and publishConfig["@uipath:registry"] to https://npm.pkg.github.com/; the scoped pin prevents an ambient @uipath npmjs configuration from winning. The publisher still validates the effective scoped registry and supplies the reviewed dev or preview tag. Do not set an access value during normal publishing because the existing Internal visibility must remain unchanged.
  • No built tree, staged package, or tarball contains skill-flavor: comments, skill-flavors/, repository tests, or composer source.
  • Binary and template assets remain byte-identical.

Clarify what "available" means before release work: a successful skills:pack makes a local tarball available; registry availability requires an explicit publisher. When publication is in scope, read docs/RELEASE.md completely and confirm the target registry and channel. Keep publish.yml's established default jobs root-only. Give each published flavor an isolated, reviewed caller that passes its flavor and channel to publish-skill-flavor.yml. The reusable workflow validates the flavor, derives its package name, and publishes one selected tarball to GitHub Packages only. Studio Web callers pass flavor: studioweb; never add Studio Web to the default npmjs path. A future flavor is automatically buildable, not automatically publishable, until an explicit caller is added. The reusable publisher also requires the repository variable ENABLE_SKILL_FLAVOR_PUBLISH=true; leave it absent or false until an operator has confirmed that every explicitly published custom package has been bootstrapped as Internal, does not inherit access from the public repository, and grants UiPath/skills Actions write access. Registry routing and GitHub package visibility are separate controls, and this variable is an enablement switch rather than a live visibility check. Follow the one-time procedure in docs/RELEASE.md, and disable the global gate again before adding a caller for another not-yet-bootstrapped flavor.

Critical Rules

  1. Keep canonical files complete. Default/local consumers must understand SKILL.md without a build manifest.
  2. Build files before packages. Packages consume complete build/skills/<variant> trees, never canonical and sparse sources directly.
  3. Make additions automatic. A valid new flavor directory must receive a tree and package without code, npm-script, or workflow edits.
  4. Preserve root command compatibility. Normal root npm pack and npm publish must compose only the marker-free default package and restore canonical sources; npm run skills:pack remains the all-flavor command.
  5. Never edit generated output. Change canonical files, sparse overrides, or the composer; do not modify or commit build/.
  6. Fail before replacement. Validate every flavor and inspect every tarball before replacing the last successful generated artifacts.
  7. Recover without data loss. Keep root packaging transactional, reject overlapping transactions, and preserve unexpected overlay edits before restoring canonical sources.
  8. Isolate publication. Keep default root publishing separate from flavor publishing; registry-lock and select one exact flavor tarball, and keep operator enablement off until every called flavor package is confirmed Internal.
  9. Keep shared evolution automatic. Prefer empty additive extension points for host-only additions; never copy a shared table or list into a broad replacement that can silently hide later canonical changes.

What Not to Do

  • Do not copy an entire skill into a flavor to change a few paragraphs. A whole-generation difference goes in classic/skills/ with a .canonical pin, never in skill-flavors/.
  • Do not introduce JSON tags, fragment manifests, or runtime composition.
  • Do not add one npm build command or generic validation-CI branch per flavor; an explicitly published flavor still needs a reviewed caller of the correct publisher.
  • Do not ship default plugin hooks or manifests in a minimal host package.
  • Do not validate only studioweb; enumerate every discovered flavor.
  • Do not trust a source-tree scan as proof of package safety; inspect the actual tarballs.
  • Do not remove or bypass the root prepack/postpack lifecycle; source markers must never reach the default npm package.
  • Do not make the default publisher iterate over build/npm/*.tgz, and do not publish a flavor through an unreviewed registry wildcard.
  • Do not configure npmjs credentials, OIDC trusted publishing, provenance, or public access for a custom flavor package.

© UiPath, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in .claude/skills/manage-skill-flavors of UiPath/skills.

  • SKILL.md
  • references/flavor-test-matrix.md

Open the folder on GitHubat commit 4c7cb7c

Compare with similar skills

Manage Skill Flavors next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Manage Skill Flavors compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Manage Skill Flavors this skillUiPath/skills167—~3.5kAutomated safety check: PassMIT
SkillHub CLIiflytek/skillhub5.2k—~2.3kAutomated safety check: PassApache-2.0
TeamAI Setup and LifecycleTencent/teamai-cli5.2k—~1.2kAutomated safety check: PassCustom licence
Skill Base CLIginuim/skill-base121—~1.9kAutomated safety check: PassNone
MCP IntegrationLunCoSim/lunco-sim107—~547Automated safety check: PassApache-2.0
TeamAI Team SyncTencent/teamai-cli5.2k—~632Automated safety check: PassCustom licence

Similar skills

  • SkillHub CLI

    iflytek/skillhub

    Connects an agent to a SkillHub registry and uses the official SkillHub CLI to search, install, list and explicitly upgrade skills from that registry.

    5.2k GitHub stars~2.3k tokensUpdated yesterday
    Agent WorkflowsAuto-check passed
  • TeamAI Setup and Lifecycle

    Tencent/teamai-cli

    Walks a non-technical user through creating or joining a TeamAI team repo, then managing members, roles, MCP, and environment settings.

    5.2k GitHub stars~1.2k tokensUpdated yesterday
    Agent WorkflowsAuto-check passed
  • Skill Base CLI

    ginuim/skill-base

    Uses the skb command to search, install, update, delete, publish and import skills on a Skill Base site, including curated collections and GitHub imports.

    121 GitHub stars~1.9k tokensUpdated 19 days ago
    Agent WorkflowsAuto-check passed
  • MCP Integration

    LunCoSim/lunco-sim

    Install, register, test, or troubleshoot the LunCoSim MCP server and its portable skills.

    107 GitHub stars~547 tokensUpdated yesterday
    Agent WorkflowsAuto-check passed
  • TeamAI Team Sync

    Tencent/teamai-cli

    Make every team AI native — TeamAI syncs a team's AI skills, rules, docs and env across AI coding tools. Use when the task operates on team-shared AI…

    5.2k GitHub stars~632 tokensUpdated yesterday
    Knowledge ManagementAuto-check passed
  • MCP Server Builder

    shareAI-lab/learn-claude-code

    Walks through building MCP servers in Python or TypeScript that expose tools, resources and prompts to Claude, with templates, registration and testing.

    78k GitHub starsUsed in 4 repos~1.2k tokens
    Agent WorkflowsAuto-check passed

More from UiPath/skills

All 28 skills in this repo
  • UiPath automation discovery — mines Slack/email/wikis/CRM/HRIS/ERP for repetitive work, SPOFs, and replicable models; produces a 4-tier prioritized opportunity report with UiPath implementation…

    167 GitHub stars~3.7k tokensUpdated today
    Auto-check passed
  • Uipath Functions

    UiPath/skills

    UiPath Coded Functions — deterministic Python or TypeScript/JavaScript units built with the uip function CLI (new -l py|ts|js, init, serve, run, pack, publish); the functions map in uipath.json…

    167 GitHub stars~3.6k tokensUpdated today
    Auto-check: notes
  • Uipath Maestro Bpmn

    UiPath/skills

    TRIGGER for authoring, operating or diagnosing UiPath Maestro BPMN.

    167 GitHub stars~4.2k tokensUpdated today
    Auto-check: notes
  • Uipath Maestro Case

    UiPath/skills

    TRIGGER for authoring UiPath Maestro Case plans as <Name.case.ts with the reference-mode TypeScript builder SDK (@uipath/maestro-builder-sdk/case), compiling to caseplan.json, and running the uip…

    167 GitHub stars~2k tokensUpdated today
    Auto-check: notes
  • Uipath Troubleshoot

    UiPath/skills

    UiPath causal investigation across every product, runtime, and activity package.

    167 GitHub stars~5.3k tokensUpdated today
    Auto-check passed
  • Uipath API Workflow

    UiPath/skills

    UiPath API Workflow assistant — author, run, validate, package, publish, deploy, and troubleshoot JSON workflows for uip api-workflow.

    167 GitHub stars~7.5k tokensUpdated today
    Auto-check: notes

Works with

Categories

Questions about Manage Skill Flavors

What does Manage Skill Flavors do?

Maintain build-time skill flavors in the UiPath skills repository. Manage Skill Flavors is an agent skill from UiPath/skills. Maintain build-time skill flavors in the UiPath skills repository.

When should I use Manage Skill Flavors?

Manage Skill Flavors fits situations like: editing skill-flavor marker blocks; sparse flavor overrides; generic flavor discovery; marker-free default.

How do I install Manage Skill Flavors in Claude Code?

Run `npx skills add UiPath/skills --skill manage-skill-flavors -a claude-code`. Or copy the skill folder (.claude/skills/manage-skill-flavors in UiPath/skills) into .claude/skills/manage-skill-flavors in your project. Claude Code loads it when a task matches its description.

How do I install Manage Skill Flavors in Codex?

Run `npx skills add UiPath/skills --skill manage-skill-flavors -a codex`. Or copy the skill folder (.claude/skills/manage-skill-flavors in UiPath/skills) into .agents/skills/manage-skill-flavors in your project. Codex loads it when a task matches its description.

Can I use Manage Skill Flavors in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add UiPath/skills --skill manage-skill-flavors -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/manage-skill-flavors, .gemini/skills/manage-skill-flavors, .github/skills/manage-skill-flavors and .opencode/skills/manage-skill-flavors in your project.

What does Manage Skill Flavors need to run?

Going by SKILL.md and its folder, Manage Skill Flavors needs the command-line tools its instructions call (npm and git).

Does Manage Skill Flavors access the network?

SKILL.md names 1 domain. In commands or code: npm.pkg.github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Manage Skill Flavors safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Manage Skill Flavors use?

Manage Skill Flavors is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Manage Skill Flavors use?

About 3.5k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2k tokens, read only when the agent opens those files.

What are the alternatives to Manage Skill Flavors?

Skills that share tags, products or a category with Manage Skill Flavors: SkillHub CLI (iflytek/skillhub, 5.2k stars), TeamAI Setup and Lifecycle (Tencent/teamai-cli, 5.2k stars), Skill Base CLI (ginuim/skill-base, 121 stars) and MCP Integration (LunCoSim/lunco-sim, 107 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Manage Skill Flavors?

UiPath (a GitHub organization) maintains it in UiPath/skills, which has 167 GitHub stars. The repository holds 28 skills in this directory. The repository was last updated on October 11, 2026.

Source: UiPath/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.