Skip to content
SkillRepo vs skills.sh

skills.sh installs a skill. SkillRepo keeps your whole team on one current, approved set of skills, in every agent.

SkillRepo is the open distribution and governance layer for AI agent skills — it keeps your skills current in every dev environment, and holds your whole team to one approved version.

Team is $8/seat per month, 14-day trial, no card. Working solo? Developer is $5/month — start on your own, then bring your team onto one library.

The difference

A few months in, no one’s on the same version.

Your team’s skills are spread across everyone’s machines and repos. No one’s sure who changed what, which version each repo is on, or whether the copy in a given repo is the one you’d approve today.

That’s the gap SkillRepo closes: it keeps each skill current in every dev environment without anyone remembering to run an update, holds your whole team to one approved version, and makes drift across your repos something you can see. That’s a distribution and governance job, and it’s the one SkillRepo does.

Side by side

The team jobs, side by side.

What you needWith skills.shWith SkillRepo
Keep it currentnpx skills update, when someone runs itRefreshes at the start of a session, or on skillrepo update
Share the same skills with your teamA Pack: one unlisted URLOne library, delivered to every member and repo
Run one approved version across reposAnyone with the URL installs the current bitsApproved-version pins, scoped per repo
Pull a bad version backNot offeredRecall, with a fallback to the last approved version
See where a repo has driftedNot offeredDrift visible across your repos
Judge a skill before you run itRead it yourselfA two-layer A–F safety grade as a signal
Know who really wrote itPublisher-providedProvenance and a verified GitHub identity
Control who can installA Pack URL is unlisted, not access-controlledYour team library is private by default
Distribute

Installed once isn’t the same as current.

With skills.sh, staying current is a command someone has to remember: npx skills update, run by each person, on each machine, whenever they think of it. Skip it, and the skill on that machine stays whatever the last run left it.

SkillRepo makes current the default. skillrepo init writes the skill into the native path of every dev environment you use — Claude Code, Cursor, Windsurf, VS Code + Copilot, Gemini CLI, Codex CLI, and Cline. In most of them the library refreshes at the start of a session; anywhere else, a single skillrepo update brings it current. Keeping up stops being a habit anyone has to keep.

Govern

One approved version — and a way to pull it back.

A Pack is skills.sh’s answer for a team: one unlisted URL that hands everyone the same files. That solves “same bits” and stops there. A Pack is unlisted, not access-controlled — anyone with the link installs it — and there’s no approval step between a change and everyone picking it up. Nothing tells you which repo is on which version, and once a bad one is out, there’s no way to pull it back.

That last gap is the one SkillRepo closes. Because SkillRepo delivers your team’s skills from one library, an approved version is one you can take back. When a version you approved turns out wrong, recall it — every repo that syncs from the library drops it and falls back to the last approved version on its next sync. A copy installed straight from a URL has nothing behind it to recall; a version delivered through SkillRepo does.

SkillRepo treats the team as the unit:

  • Recall with fallback — recall a version from the library, and every repo falls back to the last version you approved on its next sync.
  • Approved-version pins — pin the version each repo runs, scoped per repo, so a repo gets the skills it needs at the version you approved, not whatever’s newest.
  • Drift you can see — spot which repos have moved off the version you approved, instead of finding out later.
  • One organization, one library — the library is your team’s and private by default; you decide what’s in it and who can change it.

This is the Team layer, at $8/seat per month, no seat minimum. It’s the difference between handing out a URL and running one approved set across your organization’s repos — one you can correct after it’s out.

Trust

Know what you’re pulling before you run it.

A skill isn’t inert. Its instructions steer your agent, and it can carry scripts that run in your environment — so installing a public skill from anywhere means trusting instructions, and sometimes code, you didn’t write. That’s a lot to trust sight unseen: 36.8% of public skills contain a security flaw (Snyk, Feb 2026).

SkillRepo puts a graded front door in front of that. Every skill carries a two-layer A–F safety grade — a signal to help you decide, not a certification, so review a skill before you run it. Provenance ties each skill to a verified GitHub identity, so what you pull is attributed to a real, named author rather than an anonymous upload. And your own skills stay private by default; you choose what to share.

A grade lowers the odds; it doesn’t make them zero. So the front door has a safety net behind it: when a version you approved and delivered through SkillRepo turns out wrong later, recall it — every repo drops it and falls back to the last approved version on its next sync. The grade is what you check before you run a skill; recall is how you take a bad one back once it’s already out to your team.

Grades are signals, not a certification. They tell you where to look; they don’t replace reading a skill before you run it.

FAQ

Questions people ask.

Isn't skills.sh free? Why would I pay?
skills.sh is free to find and install a skill. What you pay SkillRepo for is what happens next: keeping the skill current without anyone remembering to run an update (Developer, $5 per month), and holding a team to one approved version with pins, recall, and drift you can see (Team, $8/seat per month).
Can't a Vercel Pack share skills with my team?
A Pack gets the same files to everyone through one unlisted URL. It isn't access-controlled — anyone with the link installs it — and it has no approved-version pin, no recall, and no view of which repo is running which version. It's the same bits at a URL, not governance.
Which dev environments are supported?
Seven: Claude Code, Cursor, Windsurf, VS Code + Copilot, Gemini CLI, Codex CLI, and Cline. The skill lands in each one's native path.
What do the safety grades mean?
Every skill carries a two-layer A–F grade. It's a signal to help you decide, not a certification — review a skill before you run it.
What does it cost?
Developer is $5 per month — install and keep your library current across every dev environment, with a 5-day trial and no card. Team is $8/seat per month and adds approved-version pins, recall, and drift across your organization's repos, with a 14-day trial and no card.
Get started

Put your whole team on the version you approved.

Bring a skill from anywhere, and SkillRepo governs what your team runs: each skill graded and attributed to a verified GitHub identity before you run it, kept current in every dev environment, and pinned to the version you approved — recallable, with a fallback to the last approved version, if that version turns out wrong. Team is $8/seat per month, 14-day trial, no card.

Working on your own first? Developer is $5 per month — keep your own library current across every dev environment, then bring your team onto the same one. 5-day trial, no card.

Command Palette

Search for a command to run...