Install
$ agentstack add skill-modiqo-skillspec-skill-router ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Skill Router
This skill is a thin native harness loader for the SkillSpec router. When router mode is enabled and the harness has been restarted, this router is the first hop for every user request in managed skill roots. All routed skills are explicit-only/manual-only, so check the router index before reading, searching for, or guessing at a domain skill.
The router does not execute task work. It decides whether a local skill should be loaded, reports confidence and candidate paths, and asks for direct or durable execution only after a use_skill decision when the task will use tools and the user has not already chosen an execution mode.
Runtime Contract
- For ordinary requests with prompt-hook context
first_hop_ready=true, use the fast path: do not read./skill.spec.ymland do not runskillspec router index status. - Run one route query:
``bash skillspec route --index --query '' --top 5 --json ``
- If route output says
decision: "use_skill"andselectedis non-null, read that skill'sSKILL.mdand follow it. - If route output says
decision: "bypass", do not load any candidate skill; continue with normal agent behavior for the request. - If route output says
decision: "ambiguous", do not silently choose a candidate. Ask only when the user explicitly requested skill selection; otherwise continue with normal agent behavior. - If route output includes
execution_mode_direct_or_durablefor ause_skilldecision, ask the user whether to run direct or durable before tool-backed execution. - Load and follow
./skill.spec.ymlonly for router lifecycle, repair, visibility, guard, index status, index refresh, or when guard context is missing or failed. - If the user chooses durable execution, hand the selected skill and task context to
durable-executor. The router still only routes; durable-executor owns workspace evidence, rote execution policy, alignment, token stats, and final closure.
Router Management
Use lifecycle commands for managed installation:
skillspec router install --roots ... --index
skillspec router index status --roots ... --index --visibility-manifest
skillspec router index refresh --roots ... --index --visibility-manifest
skillspec router uninstall
Any index argument can be either the SQLite file itself or the router directory; directory paths resolve to skill-index.sqlite.
Use visibility commands for explicit controls:
skillspec visibility plan --roots ... --json
skillspec visibility apply --roots ... --manifest --json
skillspec visibility restore --manifest --json
skillspec skills set-visibility manual-only --roots ... --manifest
skillspec skills disable --roots ... --manifest
skillspec skills enable --roots ... --manifest
The manifest is the rollback boundary. Do not bulk-restore visibility by inference when the manifest is missing.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: modiqo
- Source: modiqo/skillspec
- License: Apache-2.0
- Homepage: https://skillspec.sh
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.