4 min read

Vercel Skills CLI: Install Agent Skills in Any Coding Agent (GitHub, Scanned)

The npx skills command: install agent skills from GitHub into Claude Code, Codex, Cursor and more.

Vercel Skills CLI logo
✅
Scan: safe. Nothing malicious. It sends anonymous telemetry unless you opt out, and it bundles a git library with known advisories, so install only from sources you trust. Scanned Oct 8, 2026; the full report is below.

skills is a command-line installer for Agent Skills, the SKILL.md folders that coding agents load when a task calls for them. Point it at a GitHub repository, a GitLab or Azure Repos URL, any git URL, a direct download or a local folder, and it copies or symlinks the skills into the right directory for each agent you choose. The README lists support for OpenCode, Claude Code, Codex, Cursor and 75 more.

Beyond add, it can list, update, remove and search skills (through the skills.sh directory), scaffold a new SKILL.md with init, and run a skill once without installing it with skills use. Skills go into the project by default, so they can be committed for a team, or into your home directory with -g.

Vercel Labs publishes it as the npm package skills, at version 1.7.1 when scanned. It is TypeScript, MIT-licensed, with about 33,400 stars and 155 contributors. Many other repositories on this list, Vercel's own skills among them, use npx skills add as their install command.

Who it is for

Anyone who uses more than one coding agent, or wants a single command to install, update and remove skills from GitHub without copying folders by hand.

Getting started

1. Install skills from a repository (you choose which skills and agents)

npx skills add vercel-labs/agent-skills

2. See what a repository offers without installing

npx skills add vercel-labs/agent-skills --list

3. Search the skills.sh directory

npx skills find typescript

4. Update installed skills

npx skills update

Needs Node.js. The CLI sends anonymous usage telemetry to skills.sh; set DISABLE_TELEMETRY=1 or DO_NOT_TRACK=1 to turn it off.

Safety scan

We cloned vercel-labs/skills at commit 87a2669 on Oct 8, 2026 and ran the checks described on the GitHub Tools page: credential patterns, decode-and-execute code, install-time scripts, committed binaries, risky CI workflows, every host the code talks to, known vulnerabilities in pinned dependencies, and project hygiene. A person read every hit. This is what we found.

  • No secrets, no suspicious code patterns and no committed binaries across 135 files and about 33,000 lines of TypeScript. A second, skill-specific pass found nothing malicious. The many git hosts in the code (gitlab.example.com, dev.azure.com and similar) are test fixtures for its URL parsing.
  • Telemetry: on add, remove, update and find, the CLI sends anonymous events to skills.sh, including the repository and skill names for GitHub repositories confirmed as public. During install it also asks skills.sh for partner security-audit results on those skills. Both are documented in the README and switched off by DISABLE_TELEMETRY=1 or DO_NOT_TRACK=1.
  • 12 known advisories (2 critical, 7 high) in pnpm-lock.yaml. The ones that matter are in simple-git 3.36.0, which the build bundles into the CLI: they describe ways around simple-git's guard against unsafe git options when untrusted input reaches them. The CLI clones the URLs you type, so install only from sources you trust. The rest (nanoid, postcss, source-map-js) are build tooling.
  • The only npm lifecycle script is prepare: husky, which sets up git hooks for contributors working in a clone and does not run when you use npx skills.
  • Three workflows, none using pull_request_target, with all 6 third-party actions pinned to commits. Licence present; no security policy, contributing guide or Dependabot.

What the scanner counted

CheckResult
SecretsNone found.
Suspicious codeNone found.
Install-time code1 npm lifecycle script
Committed binariesNone.
CI workflows3 workflows. None use pull_request_target. 0 of 6 third-party actions pinned to a tag rather than a commit.
Network hosts40 distinct hosts referenced from source; most often github.com, gitlab.com, gitlab.example.com, dev.azure.com. No URLs to bare IP addresses.
Known vulnerabilities12 advisories across 156 pinned packages: 2 critical, 7 high, 3 moderate, 0 low. pnpm-lock.yaml: 156 packages, 12 advisories.
Project hygieneHas licence file. Missing security policy, automated dependency updates, CodeQL, contributing guide.
OpenSSF ScorecardNot scored: the project is not in Scorecard's weekly index.

The raw findings

Every hit the scanner wrote out, with a link to the exact line at the scanned commit. Secrets candidates are redacted.

npm lifecycle scripts (1)
  • package.json prepare: husky
Worst known vulnerabilities (12 of 12)
AdvisorySeverityPackageSummary
GHSA-v5rq-49vh-5v5ccritical@simple-git/argv-parser@1.1.1simple-git: `VISUAL` editor environment variable is omitted from unsafe editor detection
GHSA-x6jw-m9v5-85vhcriticalsimple-git@3.36.0simple-git unsafe-operation guard does not block trailer command configuration
GHSA-28wg-ghj8-5hjvhighnanoid@3.3.15nanoid: non-secure generators can loop indefinitely with negative size
GHSA-2v37-7h3g-55p8highnanoid@3.3.15nanoid: custom generators can loop indefinitely when size is zero
GHSA-r28c-9q8g-f849highpostcss@8.5.16PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure
GHSA-858h-whjf-mvg5highsimple-git@3.36.0simple-git: unsafe-operations plugin bypass via git long-option abbreviation (--receive-p/--exe) -> command execution (r…
GHSA-g4wm-2vf7-vfgrhighsimple-git@3.36.0simple-git allows command execution through unblocked Git configuration includes
GHSA-68fv-2mgg-jv7qhighsource-map-js@1.2.1source-map-js allows event-loop denial of service through indexed source-map section offsets
GHSA-r292-9mhp-454mhightar@7.5.20node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar w…
GHSA-82fw-gwwq-j7x9moderate@vitest/mocker@4.1.10Vitest: Path Traversal / Arbitrary File Read via @vitest/mocker Redirect Mock
GHSA-fxqj-rqcc-2cmpmoderatepostcss@8.5.16PostCSS: incomplete fix of GHSA-6g55-p6wh-862q - attacker-controlled sourceMappingURL reads arbitrary .map files when `f…
GHSA-82fw-gwwq-j7x9moderatevitest@4.1.10Vitest: Path Traversal / Arbitrary File Read via @vitest/mocker Redirect Mock

By the numbers

Stars33.4K
Forks2,856
Contributors155
Commits551
Open issues721
Open pull requests356
Releases48
Latest releasev1.7.1
LicenceMIT
Main languageTypeScript
Project age8 months
Last pushOct 7, 2026
Tracked files135
Lines of code33.4K
Checkout size1 MB

Lines by language: TypeScript 31.7K, Markdown 1,077, YAML 441, JSON 185, JavaScript 22.

Questions

Is the Vercel Skills CLI free?

Yes. It is MIT-licensed and free on npm, and needs no Vercel account. The skills it installs carry their own licences, and running them still needs a coding agent such as Claude Code, Codex or Cursor under that product's pricing.

Does it work with private repositories?

Yes. It uses the git credentials you already have: your credential helper, then GitHub CLI, then SSH. The README says it never reads or copies the GitHub CLI's stored token. GITHUB_TOKEN or GH_TOKEN can be set for API access.

What is skills.sh?

Vercel's public directory of agent skills, which npx skills find searches and which receives the CLI's anonymous telemetry. You can install from any git source without using the directory.


This post is part of GitHub Tools, where every repository is cloned and scanned before it is written up. The scan is a snapshot of one commit on one day; the repository has moved on since, so check it before you install.