skills is a command-line installer for Agent Skills, the SKILL.md folders that coding agents load when a task calls for them. Point it at a GitHub repository, a GitLab or Azure Repos URL, any git URL, a direct download or a local folder, and it copies or symlinks the skills into the right directory for each agent you choose. The README lists support for OpenCode, Claude Code, Codex, Cursor and 75 more.
Beyond add, it can list, update, remove and search skills (through the skills.sh directory), scaffold a new SKILL.md with init, and run a skill once without installing it with skills use. Skills go into the project by default, so they can be committed for a team, or into your home directory with -g.
Vercel Labs publishes it as the npm package skills, at version 1.7.1 when scanned. It is TypeScript, MIT-licensed, with about 33,400 stars and 155 contributors. Many other repositories on this list, Vercel's own skills among them, use npx skills add as their install command.
- Repository: github.com/vercel-labs/skills
- Licence: MIT (MIT License)
- Language: TypeScript. Stars: 33.4K. Forks: 2,856. Last push: Oct 7, 2026.
- Scan: safe, Oct 8, 2026, commit 87a2669
Who it is for
Anyone who uses more than one coding agent, or wants a single command to install, update and remove skills from GitHub without copying folders by hand.
Getting started
1. Install skills from a repository (you choose which skills and agents)
npx skills add vercel-labs/agent-skills2. See what a repository offers without installing
npx skills add vercel-labs/agent-skills --list3. Search the skills.sh directory
npx skills find typescript4. Update installed skills
npx skills updateNeeds Node.js. The CLI sends anonymous usage telemetry to skills.sh; set DISABLE_TELEMETRY=1 or DO_NOT_TRACK=1 to turn it off.
Safety scan
We cloned vercel-labs/skills at commit 87a2669 on Oct 8, 2026 and ran the checks described on the GitHub Tools page: credential patterns, decode-and-execute code, install-time scripts, committed binaries, risky CI workflows, every host the code talks to, known vulnerabilities in pinned dependencies, and project hygiene. A person read every hit. This is what we found.
- No secrets, no suspicious code patterns and no committed binaries across 135 files and about 33,000 lines of TypeScript. A second, skill-specific pass found nothing malicious. The many git hosts in the code (gitlab.example.com, dev.azure.com and similar) are test fixtures for its URL parsing.
- Telemetry: on add, remove, update and find, the CLI sends anonymous events to skills.sh, including the repository and skill names for GitHub repositories confirmed as public. During install it also asks skills.sh for partner security-audit results on those skills. Both are documented in the README and switched off by DISABLE_TELEMETRY=1 or DO_NOT_TRACK=1.
- 12 known advisories (2 critical, 7 high) in pnpm-lock.yaml. The ones that matter are in simple-git 3.36.0, which the build bundles into the CLI: they describe ways around simple-git's guard against unsafe git options when untrusted input reaches them. The CLI clones the URLs you type, so install only from sources you trust. The rest (nanoid, postcss, source-map-js) are build tooling.
- The only npm lifecycle script is prepare: husky, which sets up git hooks for contributors working in a clone and does not run when you use npx skills.
- Three workflows, none using pull_request_target, with all 6 third-party actions pinned to commits. Licence present; no security policy, contributing guide or Dependabot.
What the scanner counted
| Check | Result |
|---|---|
| Secrets | None found. |
| Suspicious code | None found. |
| Install-time code | 1 npm lifecycle script |
| Committed binaries | None. |
| CI workflows | 3 workflows. None use pull_request_target. 0 of 6 third-party actions pinned to a tag rather than a commit. |
| Network hosts | 40 distinct hosts referenced from source; most often github.com, gitlab.com, gitlab.example.com, dev.azure.com. No URLs to bare IP addresses. |
| Known vulnerabilities | 12 advisories across 156 pinned packages: 2 critical, 7 high, 3 moderate, 0 low. pnpm-lock.yaml: 156 packages, 12 advisories. |
| Project hygiene | Has licence file. Missing security policy, automated dependency updates, CodeQL, contributing guide. |
| OpenSSF Scorecard | Not scored: the project is not in Scorecard's weekly index. |
The raw findings
Every hit the scanner wrote out, with a link to the exact line at the scanned commit. Secrets candidates are redacted.
npm lifecycle scripts (1)
package.jsonprepare:husky
Worst known vulnerabilities (12 of 12)
| Advisory | Severity | Package | Summary |
|---|---|---|---|
| GHSA-v5rq-49vh-5v5c | critical | @simple-git/argv-parser@1.1.1 | simple-git: `VISUAL` editor environment variable is omitted from unsafe editor detection |
| GHSA-x6jw-m9v5-85vh | critical | simple-git@3.36.0 | simple-git unsafe-operation guard does not block trailer command configuration |
| GHSA-28wg-ghj8-5hjv | high | nanoid@3.3.15 | nanoid: non-secure generators can loop indefinitely with negative size |
| GHSA-2v37-7h3g-55p8 | high | nanoid@3.3.15 | nanoid: custom generators can loop indefinitely when size is zero |
| GHSA-r28c-9q8g-f849 | high | postcss@8.5.16 | PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure |
| GHSA-858h-whjf-mvg5 | high | simple-git@3.36.0 | simple-git: unsafe-operations plugin bypass via git long-option abbreviation (--receive-p/--exe) -> command execution (r… |
| GHSA-g4wm-2vf7-vfgr | high | simple-git@3.36.0 | simple-git allows command execution through unblocked Git configuration includes |
| GHSA-68fv-2mgg-jv7q | high | source-map-js@1.2.1 | source-map-js allows event-loop denial of service through indexed source-map section offsets |
| GHSA-r292-9mhp-454m | high | tar@7.5.20 | node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar w… |
| GHSA-82fw-gwwq-j7x9 | moderate | @vitest/mocker@4.1.10 | Vitest: Path Traversal / Arbitrary File Read via @vitest/mocker Redirect Mock |
| GHSA-fxqj-rqcc-2cmp | moderate | postcss@8.5.16 | PostCSS: incomplete fix of GHSA-6g55-p6wh-862q - attacker-controlled sourceMappingURL reads arbitrary .map files when `f… |
| GHSA-82fw-gwwq-j7x9 | moderate | vitest@4.1.10 | Vitest: Path Traversal / Arbitrary File Read via @vitest/mocker Redirect Mock |
By the numbers
| Stars | 33.4K |
|---|---|
| Forks | 2,856 |
| Contributors | 155 |
| Commits | 551 |
| Open issues | 721 |
| Open pull requests | 356 |
| Releases | 48 |
| Latest release | v1.7.1 |
| Licence | MIT |
| Main language | TypeScript |
| Project age | 8 months |
| Last push | Oct 7, 2026 |
| Tracked files | 135 |
| Lines of code | 33.4K |
| Checkout size | 1 MB |
Lines by language: TypeScript 31.7K, Markdown 1,077, YAML 441, JSON 185, JavaScript 22.
Questions
Is the Vercel Skills CLI free?
Yes. It is MIT-licensed and free on npm, and needs no Vercel account. The skills it installs carry their own licences, and running them still needs a coding agent such as Claude Code, Codex or Cursor under that product's pricing.
Does it work with private repositories?
Yes. It uses the git credentials you already have: your credential helper, then GitHub CLI, then SSH. The README says it never reads or copies the GitHub CLI's stored token. GITHUB_TOKEN or GH_TOKEN can be set for API access.
What is skills.sh?
Vercel's public directory of agent skills, which npx skills find searches and which receives the CLI's anonymous telemetry. You can install from any git source without using the directory.
This post is part of GitHub Tools, where every repository is cloned and scanned before it is written up. The scan is a snapshot of one commit on one day; the repository has moved on since, so check it before you install.
