skill-installer

A guide for creating, importing, updating, validating, or moving portable skill bundles for coding agents. A skill bundle can include instructions, references, scripts, assets, tests, and metadata.

In plain words
What is it for?
Use it to author a new skill, install or import an existing one, update its files, validate its trigger cases, or relocate it between supported skill directories.
Why use it?
It provides a defined structure and process for making skills that can be found, triggered, checked, and reused consistently. It also helps avoid overwriting a higher-priority copy by mistake.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/evoelsewhere/evoflux/skill-installer
Any agent
npx skills add evoelsewhere/evoflux --skill skill-installer
Clone the repo
git clone --depth 1 https://github.com/evoelsewhere/evoflux

Made for: Claude Code, Codex.

Per session 71 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 797 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00071 $0.00797
Opus 5 $0.00036 $0.00398
Sonnet 5 $0.00014 $0.00159
Haiku 4.5 $0.00007 $0.00080

Measured 2d ago against content hash 37eb5f55e4f9, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

skill-installer scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

app/agent/builtin_skills/skill-installer/SKILL.md · 90 lines

How it starts

The opening of the file, as written. The whole thing — 90 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Create or install a skill bundle

Treat a skill as a runtime bundle, not a standalone prompt file. Do not load an existing bundle's references, scripts, or assets before the requested workflow creates a concrete need for them.

Resolve destination and identity

Use the first matching name in project EvoFlux, project OpenCode, user EvoFlux, user OpenCode, then bundled roots. Default new user-owned skills to {SKILLS_DIR} unless the user requests project-local sharing. Never overwrite a higher-precedence variant without identifying the exact selected root.

Use a lowercase hyphenated name under 64 characters. SKILL.md frontmatter contains only name and description; the description must explain both what the skill does and which requests should trigger it.

State machine

1. SPECIFY

Derive concrete positive and near-miss trigger examples. Choose the degree of freedom: prose for judgment-heavy work, a state machine/decision table for fragile workflows, and a script for repeated deterministic operations.

2. PLAN THE BUNDLE

Use only necessary paths:

skill-name/
├── SKILL.md
├── agents/evoflux.yaml
├── references/
├── scripts/
├── assets/
└── evals/trigger-cases.json

Keep the core workflow, state transitions, stop conditions, and resource routing in SKILL.md. Put detailed knowledge in references/, repeated exact work in scripts/, and output material in assets/. Every optional resource must be linked directly from SKILL.md with the evidence condition for reading or running it. Do not add README, changelog, setup guide, or placeholder files.

Put UI fields and implicit-invocation policy in agents/evoflux.yaml. Keep Work/Coding/Both and slash-menu preferences in EvoFlux runtime settings or the supported .evoflux.json sidecar rather than adding non-portable frontmatter.

3. IMPORT OR UPDATE

For a URL, fetch to a temporary location, reject HTML masquerading as raw content, inspect every archive/repository path, and reject absolute paths, traversal, escaping symlinks, oversized content, and executable surprises.

Read the full file on GitHub · 90 lines

Files

What ships with it

2 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 90 lines · 71 tokens per session scan A 37eb5f55e4f9

Subscribe to this mod's changes

skill-installer is a skill published in the GitHub repository evoelsewhere/evoflux (5 stars, last pushed 5d ago), licensed Apache-2.0. It adds 71 tokens to every session and 797 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other skills, from other repositories

kane-cli

Browser automation + AI test authoring via kane-cli - run browser objectives, generate & refine test scenarios/cases from a description, design requirement-linked test suites from a PRD/spec (assurance), parse NDJSON output, inspect logs, save runnable test.md. Use for any task requiring a real browser (navigate…

LambdaTest/kane-cli · 159 tokens

rove

Use when controlling Rove tasks, parallel coding attempts, hosted agent sessions, task lifecycle, or the daemon-owned issue tracker from a shell. Also the ONLY channel for messaging another agent session on this machine — rove api send, never a peer/MCP side channel.

Sma1lboy/rove · 56 tokens

E2E Testing Nori Skillsets Subcommands

Use when you need to interactively test a nori-skillsets CLI subcommand end-to-end via tmux, with full filesystem isolation.

tilework-tech/nori-skillsets · 39 tokens

general-video

The fallback workflow for authoring custom HyperFrames video compositions at any length or format — longer or multi-scene pieces, brand / sizzle reels, montages, title cards, static loops, and freeform compositions. Input- and length-agnostic. If a specialized workflow clearly fits the input — a marketed product, a…

Sma1lboy/rove · 114 tokens

release

Autonomously cut a Rove (@sma1lboy/rove) release end-to-end — detect the semver bump from pending changesets (flagging an upstream minor you didn't intend), run the release gates, bump/tag/push via scripts/release.sh, then poll the GitHub Actions Release workflow with gh until npm publish completes, diagnosing CI…

Sma1lboy/rove · 155 tokens

hyperframes-cli

HyperFrames CLI dev loop. Use when running npx hyperframes init, add, catalog, capture, lint, validate, inspect, layout, snapshot, preview, play, render, publish, lambda, doctor, browser, info, upgrade, skills, compositions, docs, benchmark, telemetry, transcribe, or remove-background, or when troubleshooting the…

Sma1lboy/rove · 101 tokens