Install
$ agentstack add skill-rooftop-owl-skill-factory-external-skill-acquisition ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ● Network access Used
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
External Skill Acquisition
Workflow for acquiring domain skills when the local skill library doesn't cover the task.
When to Trigger
Invoke this workflow when ALL conditions are true:
- No local match: You checked installed skills in
.claude/skills/and found nothing for the task domain - Domain expertise needed: The task requires domain-specific knowledge beyond general coding
- Named domain: The gap involves a recognized field — finance, climate, legal, medical, security, etc.
DO NOT trigger when:
- General uncertainty or unfamiliar libraries (use web search instead)
- Task solvable with general coding knowledge
- One-off API questions (use documentation lookup)
Decision Flow
Task arrives → check .claude/skills/
│
├─ Match found → load the skill → DONE
│
└─ No match → Is this a named domain expertise gap?
│
├─ NO → Use general knowledge or web search → DONE
│
└─ YES → Proceed to 3-Tier Acquisition ↓
3-Tier Acquisition
Tier 1: Auto-Install (MIT/Apache-2.0, verified repos)
Search these repos first — they're community-vetted and license-safe:
| Repo | Focus | Skills | |------|-------|--------| | obra/superpowers | Dev workflow (TDD, debugging, planning) | ~16 skills | | vercel-labs/agent-skills | Web/React/Next.js | ~50 skills | | anthropics/skills | Claude-specific patterns | ~10 skills |
Search before installing:
# Search marketplace
curl -s "https://api.skyll.app/search?q=&limit=5"
# Or use the npx CLI
npx --yes skills find
If found → install with /skills-install .
Tier 2: Manual Review (community repos)
If Tier 1 misses, search GitHub for community skills:
gh search repos "topic:claude-skills topic:agent-skills " --sort stars --limit 10
Before installing from unknown repos:
- Check license: Must be MIT, Apache-2.0, MPL-2.0, BSD-2/3, CC-BY-4.0, or CC-BY-SA-4.0
- Check quality: Read the SKILL.md — does it have clear procedures or just vague advice?
- Check freshness: Last commit within 6 months?
If acceptable → install with /skills-install .
Tier 3: Synthesize from Documentation
When no existing skill covers the domain, create one from documentation:
- Find authoritative docs: Official API docs, framework guides, specification pages
- Extract procedures: Convert docs into step-by-step agent instructions
- Create SKILL.md: Use
/skills-createto scaffold, then fill in:
- Trigger conditions (when to load)
- Step-by-step procedures
- Common pitfalls and error handling
- Validate: Run
/skills-validateto check frontmatter
Same-Session Use
Newly installed skills won't be auto-discovered until the next session. To use immediately, inject the skill content directly into your working context:
# Read the newly acquired skill
skill_content = read(".claude/skills//SKILL.md")
# Include it in your current context
# The agent will follow the skill's procedures for the remainder of this session
License Gate
Only auto-install skills with these licenses:
- MIT
- Apache-2.0
- MPL-2.0
- BSD-2-Clause / BSD-3-Clause
- CC-BY-4.0 / CC-BY-SA-4.0
Unknown or restrictive licenses → manual review only (Tier 2 with explicit user approval).
When to Load This Skill
Load external-skill-acquisition when:
- Delegating work in an unfamiliar domain and no installed skill matches
- User asks about acquiring or finding domain-specific skills
- Planning work in a novel domain
- Searching for skills to install
Not needed when:
- Existing skills cover the domain
- Task is general coding, testing, or infrastructure
- Already know which repo to install from (just use
/skills-install)
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: rooftop-Owl
- Source: rooftop-Owl/skill-factory
- License: MPL-2.0
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.