load-skill CLAUDE.md

A set of project instructions for load-skill, a command-line tool that collects coding skills from GitHub repositories into a searchable registry. It explains the project structure, commands, tests, and design decisions.

In plain words
What is it for?
It is for developing, testing, linting, scraping, and running the load-skill command-line tool.
Why use it?
It gives an agent the context needed to work on the repository without first discovering how its commands and files fit together.

Instructions file

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add instructions/fix2015/load-skill/claude-md
Clone the repo
git clone --depth 1 https://github.com/fix2015/load-skill
Per session 712 This file is loaded in full into every session.
When invoked 712 The same file — it is already loaded in full.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00712 $0.00712
Opus 5 $0.00356 $0.00356
Sonnet 5 $0.00142 $0.00142
Haiku 4.5 $0.00071 $0.00071

Measured 2d ago against content hash acfee3fbfd4c, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

load-skill CLAUDE.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

CLAUDE.md · 52 lines

How it starts

The opening of the file, as written. The whole thing — 52 lines — stays where its author put it; the contents beside it link to each section on GitHub.

CLAUDE.md

This file provides guidance to Claude Code (claude.ai/code) when working with code in this repository.

What This Project Is

load-skill is a CLI tool (published to npm) that aggregates AI coding skills from multiple GitHub repositories into a single searchable registry. Users run npx load-skill install <name> to install skills for Claude Code, Cursor, Codex, or Gemini CLI.

Commands

npm install          # Install dependencies
npm test             # Run all tests (node:test runner)
npm run lint         # ESLint across src/ bin/ test/
npm run scrape       # Rebuild registry from GitHub sources (needs GITHUB_TOKEN for rate limits)
node bin/load-skill.js --help   # Test CLI locally

Run a single test file:

node --test test/registry.test.js

Architecture

  • bin/load-skill.js — CLI entry point (shebang, commander arg parsing, routes to commands)
  • src/commands/ — One file per CLI command (install, list, search, info, tags, sources, update). Each exports a single function.
  • src/registry.js — Core module: loads data/skills-registry.json, provides search/filter/find functions. Used by all commands and the public API.
  • src/installer.js — Fetches SKILL.md from GitHub raw URLs and writes to the correct tool-specific path (~/.claude/skills/, .cursor/rules/, etc.)
  • src/scraper/index.js — Standalone script that hits GitHub API to discover skills across configured repos and rebuilds the registry JSON. Also exports inferTags and parseYamlFrontmatter utilities.
  • src/index.js — Public programmatic API (re-exports from registry + installer)
  • data/skills-registry.json — The skill index: sources array + skills array. Each skill has name, description, tags, source, compatible tools, raw_url, repo_url. This is the single source of truth shipped with the npm package.

Key Design Decisions

  • Uses CommonJS (require) and chalk v4 / ora v5 (CJS-compatible versions) to avoid ESM complications with npx
  • commander for CLI parsing — all commands registered in bin/load-skill.js. Bare load-skill <name> (no subcommand) defaults to install.
  • The registry is a single JSON file cached in memory (not a database) — clearCache() must be called after writes
  • Skills are fetched at install-time from raw.githubusercontent.com URLs, not bundled
  • The scraper uses inferTags() to auto-tag skills based on keyword matching against name + description
  • Node.js built-in test runner (node:test + node:assert) — no test framework dependency

Read the full file on GitHub · 52 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 52 lines · 712 tokens per session scan A acfee3fbfd4c

Subscribe to this mod's changes

load-skill CLAUDE.md is an instructions file published in the GitHub repository fix2015/load-skill (2 stars, last pushed 4mo ago), licensed MIT. It adds 712 tokens to every session, about $0.0036 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.