Install
$ agentstack add skill-osolmaz-skillflag-skillflag ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Skillflag + skill-install
This skill documents how to use the Skillflag producer CLI (skillflag) and the installer CLI (skill-install).
What this repo provides
skillflag --skill listlists bundled skill IDsskillflag --skill exportexports a skill bundle as a tar streamskill-installconsumes a skill directory or tar stream and installs it into a target agent scope
Quick start
List skills:
skillflag --skill list
Export the bundled skill and install into Codex repo scope:
skillflag --skill export skillflag | skill-install --agent codex --scope repo
Export the bundled skill and install into Claude repo scope:
skillflag --skill export skillflag | skill-install --agent claude --scope repo
skill-install inputs
Directory input:
skill-install ./skills/skillflag --agent codex --scope repo
Tar stream input (from producer):
skillflag --skill export skillflag | skill-install --agent codex --scope repo
Tar stream input with interactive target selection (when a TTY is available):
skillflag --skill export skillflag | skill-install
Show installer usage/help:
skill-install --help
Notes
skillflagis the producer interface; it never installs.skill-installvalidatesSKILL.mdfrontmatter and installs by copy.- The full specification lives at
docs/SKILLFLAG_SPEC.md.
Spec essentials (producer)
- Producer CLIs MUST implement:
--skill list--skill export--skill list --jsonMAY be provided and must emit a single JSON object to stdout.--skill listwrites only skill IDs to stdout (no banners).--skill exportstreams a tar with a single top‑level/and/SKILL.md.- Export output MUST be deterministic: sorted entries, fixed
mtime = 0,uid/gid = 0. - All errors go to stderr, exit code
1on failure. - Skills should be bundled under
skills//SKILL.mdor.agents/skills//SKILL.md.
Adding Skillflag to a Node CLI (library integration)
Install the library:
npm install skillflag
Global install (exposes skillflag and skill-install on PATH):
npm install -g skillflag
Run without installing (uses bundled binaries):
npx skillflag --skill list
npx skillflag install --agent codex --scope repo ./skills/skillflag
Early‑intercept in your CLI entrypoint so stdout stays clean:
// src/bin/cli.ts
import { findSkillsRoot, maybeHandleSkillflag } from "skillflag";
await maybeHandleSkillflag(process.argv, {
skillsRoot: findSkillsRoot(import.meta.url),
// includeBundledSkill: false, // opt out of the built-in skillflag skill
});
// ... normal CLI startup here
Repository layout (bundled skills):
skills/
my-skill/
SKILL.md
templates/...
Portable agent-skill layout is also supported:
.agents/
skills/
my-skill/
SKILL.md
templates/...
Package distribution:
- Ensure
skills/or.agents/skills/is included inpackage.jsonfilesso it ships with the npm tarball.
Installing without global install
Use the skillflag install convenience command to avoid a global install:
npx skillflag install --agent codex --scope repo ./skills/skillflag
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: osolmaz
- Source: osolmaz/skillflag
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.