AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified Apache-2.0 Self-run

Jfrog Ai Catalog Skills

skill-jfrog-jfrog-skills-jfrog-ai-catalog-skills · by jfrog

>-

No reviews yet
0 installs
2 views
0.0% view→install

Install

$ agentstack add skill-jfrog-jfrog-skills-jfrog-ai-catalog-skills

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-jfrog-jfrog-skills-jfrog-ai-catalog-skills)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
1mo ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Jfrog Ai Catalog Skills? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

JFrog AI Catalog Skills

Discover, install, and manage agent skills from the JFrog AI Catalog (Artifactory skills repositories), and publish your own skills back to it, all through the JFrog CLI (jf skills) and the JFrog Agent Guard.

Choose a reference file

Pick the row matching the user's intent and read that reference file.

| Intent | Read | |--------|------| | "What skills are available?" / browse the catalog / list versions / search by name | [references/discovering-skills.md](references/discovering-skills.md) | | Install or update a skill (latest or a pinned version), or a download is blocked | [references/installing-skills.md](references/installing-skills.md) | | "What's installed?" / remove an installed skill | [references/managing-installed-skills.md](references/managing-installed-skills.md) | | Publish / upload / release a skill to the catalog | [references/publishing-skills.md](references/publishing-skills.md) |

Prerequisites

  • Read the base jfrog skill first. [../jfrog/SKILL.md](../jfrog/SKILL.md)

owns the shared guards this skill depends on, so this skill does not repeat them — follow them there:

  • The [environment check](../jfrog/SKILL.md#environment-check) — confirm jf

is installed before the first jf call, and install it if missing.

  • The [server selection rules](../jfrog/SKILL.md#server-selection-rules-mandatory)

— resolve the default ` once and reuse it, pass --server-id after the subcommand on every jf` call, and use one server per request.

  • The stop-on-error rule — on any jf failure, stop and never switch servers.

One addition specific to this skill: never cat or parse ~/.jfrog/jfrog-cli.conf.v6 (it can hold access tokens); list servers only with jf config show, which redacts secrets.

  • Agent Guard registry. Catalog discovery and repo provisioning run through

npx --yes @jfrog/agent-guard. ` is the npm registry that provides the @jfrog/agent-guard package itself: use JFROGAGENTGUARDREPO if set, otherwise https://releases.jfrog.io/artifactory/api/npm/coding-agents-npm/. Pass the same to Agent Guard as --server "" so it targets the same server as your jf calls. Agent Guard also reads JFROGURL / JF_URL directly when set, so make sure the ` you resolved points at that same host.

  • Resolve the project (``) only when needed, and always to a key.

` must be the JFrog **project key**, not the display name. It is required for --list-skills, --list-skill-versions, and --provision-skills-repository. Take the value from JF_PROJECT or the user, then resolve it to a key against the projects list (see *List all projects* in the base jfrog skill's [references/projects-api.md](../jfrog/references/projects-api.md)): `bash jf api '/access/api/v1/projects' --server-id "" \ | jq -r '.[] | select(.project_key=="" or .display_name=="") | .project_key' ` Use the printed key. If it prints nothing, ask the user for the key. Never assume default, never invent one. Install, update, remove, and publishing to an explicit --repo` are keyed by skill name and/or repo, not a project.

Workflow overview

flowchart TD
    A[User request] --> B{jf CLI installed?}
    B -->|No| C[Ask user to install jf CLI, then continue]
    B -->|Yes| D{Intent}
    C --> D
    D -->|List all / versions| E[npx @jfrog/agent-guard --list-skills]
    D -->|Install / update| F[Resolve slug + version, then jf skills install/update]
    D -->|List installed / remove| G[jf skills list / rm -rf install dir]
    D -->|Publish| H[Resolve/provision repo, validate bundle, jf skills publish]

Gotchas

Catalog-specific rules only. The shared jf guards — single server per request, stop-on-error, and cautious mutation — live in the base [jfrog skill](../jfrog/SKILL.md); follow those too. Flow-specific rules live in the reference files above.

  • Which operations mutate: install and list are read-mostly; remove, registry

delete, and publish mutate state — the base skill's cautious-mutation rule applies to those three.

  • Session pickup: installs, updates, and removals usually take effect only at

the next agent session start, so tell the user to restart.

  • Don't leak the plumbing: present skills/versions/repos to the user, never

the npx/Agent Guard commands, --registry, flags, or cursors. Run follow-ups yourself.

  • Use the response templates verbatim: where a reference file gives a "reply

using this exact template" block, fill the placeholders and send exactly that, with the same wording every time and no extra preamble or commentary.

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.