# File Reference Skill

> Example skill demonstrating secure file reference resolution with supporting files

- **Type:** Skill
- **Install:** `agentstack add skill-maxvaega-skillkit-file-reference-skill`
- **Verified:** Yes — security-reviewed for prompt injection and unsafe behavior
- **Seller:** [maxvaega](https://agentstack.voostack.com/s/maxvaega)
- **Installs:** 0
- **Category:** [AI & ML](https://agentstack.voostack.com/c/ai-and-ml)
- **Latest version:** 0.1.0
- **License:** MIT
- **Upstream author:** [maxvaega](https://github.com/maxvaega)
- **Source:** https://github.com/maxvaega/skillkit/tree/main/examples/skills/file-reference-skill

## Install

```sh
agentstack add skill-maxvaega-skillkit-file-reference-skill
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

# File Reference Skill

This skill demonstrates how to use supporting files (scripts, templates, documentation) within a skill directory.

## Overview

This skill uses helper scripts and templates for data processing. All supporting files are accessible via relative paths from the skill's base directory.

## Available Supporting Files

### Scripts
- `scripts/data_processor.py` - Main data processing script
- `scripts/validator.py` - Input validation utilities
- `scripts/helper.sh` - Shell helper script

### Templates
- `templates/config.yaml` - Configuration template
- `templates/report.md` - Report generation template

### Documentation
- `docs/usage.md` - Detailed usage instructions
- `docs/examples.md` - Example use cases

## Usage

When this skill is invoked with arguments, it can access supporting files using the FilePathResolver:

```python
from pathlib import Path
from skillkit.core.path_resolver import FilePathResolver

# Get the skill's base directory (injected by BaseDirectoryProcessor)
base_dir = Path("")

# Resolve supporting files securely
processor_script = FilePathResolver.resolve_path(base_dir, "scripts/data_processor.py")
config_template = FilePathResolver.resolve_path(base_dir, "templates/config.yaml")
usage_docs = FilePathResolver.resolve_path(base_dir, "docs/usage.md")

# Read file contents
with open(processor_script) as f:
    script_code = f.read()
```

## Processing Arguments

The skill expects data file paths as arguments:

**Example invocation**: `file-reference-skill data/input.csv data/output.csv`

Processing steps:
1. Validate input using `scripts/validator.py`
2. Process data using `scripts/data_processor.py`
3. Generate report using `templates/report.md`
4. Output results to specified location

## Security Notes

- All file paths are validated to prevent directory traversal attacks
- Symlinks are resolved and verified to stay within skill directory
- Absolute paths and path traversal patterns (../) are blocked
- Any security violation raises PathSecurityError with detailed logging

## Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [maxvaega](https://github.com/maxvaega)
- **Source:** [maxvaega/skillkit](https://github.com/maxvaega/skillkit)
- **License:** MIT

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** no
- **Filesystem access:** yes
- **Shell / process execution:** no
- **Environment & secrets:** no
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: passed — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/skill-maxvaega-skillkit-file-reference-skill
- Seller: https://agentstack.voostack.com/s/maxvaega
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
