skills.sh installs a skill. SkillRepo keeps your whole team on one current, approved set of skills, in every agent.
Team is $8/seat per month, 14-day trial, no card. Working solo? Developer is $5/month — start on your own, then bring your team onto one library.
A few months in, no one’s on the same version.
Your team’s skills are spread across everyone’s machines and repos. No one’s sure who changed what, which version each repo is on, or whether the copy in a given repo is the one you’d approve today.
That’s the gap SkillRepo closes: it keeps each skill current in every dev environment without anyone remembering to run an update, holds your whole team to one approved version, and makes drift across your repos something you can see. That’s a distribution and governance job, and it’s the one SkillRepo does.
The team jobs, side by side.
| What you need | With skills.sh | With SkillRepo |
|---|---|---|
| Keep it current | npx skills update, when someone runs it | Refreshes at the start of a session, or on skillrepo update |
| Share the same skills with your team | A Pack: one unlisted URL | One library, delivered to every member and repo |
| Run one approved version across repos | Anyone with the URL installs the current bits | Approved-version pins, scoped per repo |
| Pull a bad version back | Not offered | Recall, with a fallback to the last approved version |
| See where a repo has drifted | Not offered | Drift visible across your repos |
| Judge a skill before you run it | Read it yourself | A two-layer A–F safety grade as a signal |
| Know who really wrote it | Publisher-provided | Provenance and a verified GitHub identity |
| Control who can install | A Pack URL is unlisted, not access-controlled | Your team library is private by default |
Installed once isn’t the same as current.
With skills.sh, staying current is a command someone has to remember: npx skills update, run by each person, on each machine, whenever they think of it. Skip it, and the skill on that machine stays whatever the last run left it.
SkillRepo makes current the default. skillrepo init writes the skill into the native path of every dev environment you use — Claude Code, Cursor, Windsurf, VS Code + Copilot, Gemini CLI, Codex CLI, and Cline. In most of them the library refreshes at the start of a session; anywhere else, a single skillrepo update brings it current. Keeping up stops being a habit anyone has to keep.
One approved version — and a way to pull it back.
A Pack is skills.sh’s answer for a team: one unlisted URL that hands everyone the same files. That solves “same bits” and stops there. A Pack is unlisted, not access-controlled — anyone with the link installs it — and there’s no approval step between a change and everyone picking it up. Nothing tells you which repo is on which version, and once a bad one is out, there’s no way to pull it back.
That last gap is the one SkillRepo closes. Because SkillRepo delivers your team’s skills from one library, an approved version is one you can take back. When a version you approved turns out wrong, recall it — every repo that syncs from the library drops it and falls back to the last approved version on its next sync. A copy installed straight from a URL has nothing behind it to recall; a version delivered through SkillRepo does.
SkillRepo treats the team as the unit:
- Recall with fallback — recall a version from the library, and every repo falls back to the last version you approved on its next sync.
- Approved-version pins — pin the version each repo runs, scoped per repo, so a repo gets the skills it needs at the version you approved, not whatever’s newest.
- Drift you can see — spot which repos have moved off the version you approved, instead of finding out later.
- One organization, one library — the library is your team’s and private by default; you decide what’s in it and who can change it.
This is the Team layer, at $8/seat per month, no seat minimum. It’s the difference between handing out a URL and running one approved set across your organization’s repos — one you can correct after it’s out.
Know what you’re pulling before you run it.
A skill isn’t inert. Its instructions steer your agent, and it can carry scripts that run in your environment — so installing a public skill from anywhere means trusting instructions, and sometimes code, you didn’t write. That’s a lot to trust sight unseen: 36.8% of public skills contain a security flaw (Snyk, Feb 2026).
SkillRepo puts a graded front door in front of that. Every skill carries a two-layer A–F safety grade — a signal to help you decide, not a certification, so review a skill before you run it. Provenance ties each skill to a verified GitHub identity, so what you pull is attributed to a real, named author rather than an anonymous upload. And your own skills stay private by default; you choose what to share.
A grade lowers the odds; it doesn’t make them zero. So the front door has a safety net behind it: when a version you approved and delivered through SkillRepo turns out wrong later, recall it — every repo drops it and falls back to the last approved version on its next sync. The grade is what you check before you run a skill; recall is how you take a bad one back once it’s already out to your team.
Grades are signals, not a certification. They tell you where to look; they don’t replace reading a skill before you run it.
Questions people ask.
- Isn't skills.sh free? Why would I pay?
- skills.sh is free to find and install a skill. What you pay SkillRepo for is what happens next: keeping the skill current without anyone remembering to run an update (Developer, $5 per month), and holding a team to one approved version with pins, recall, and drift you can see (Team, $8/seat per month).
- Can't a Vercel Pack share skills with my team?
- A Pack gets the same files to everyone through one unlisted URL. It isn't access-controlled — anyone with the link installs it — and it has no approved-version pin, no recall, and no view of which repo is running which version. It's the same bits at a URL, not governance.
- Which dev environments are supported?
- Seven: Claude Code, Cursor, Windsurf, VS Code + Copilot, Gemini CLI, Codex CLI, and Cline. The skill lands in each one's native path.
- What do the safety grades mean?
- Every skill carries a two-layer A–F grade. It's a signal to help you decide, not a certification — review a skill before you run it.
- What does it cost?
- Developer is $5 per month — install and keep your library current across every dev environment, with a 5-day trial and no card. Team is $8/seat per month and adds approved-version pins, recall, and drift across your organization's repos, with a 14-day trial and no card.
Put your whole team on the version you approved.
Bring a skill from anywhere, and SkillRepo governs what your team runs: each skill graded and attributed to a verified GitHub identity before you run it, kept current in every dev environment, and pinned to the version you approved — recallable, with a fallback to the last approved version, if that version turns out wrong. Team is $8/seat per month, 14-day trial, no card.
Working on your own first? Developer is $5 per month — keep your own library current across every dev environment, then bring your team onto the same one. 5-day trial, no card.