Atlas / Skills / creminiai / skillpack

skillpackBLOCK

skills/creminiai/skillpack

Pack and deploy local AI agents for your team in minutes

Verdict
BLOCK
Grade
D
Trust score
69 /100
Version
—
Hosts
4 documented
License
MIT
Stars
1,202
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Skillpack helps teams turn AI skills into trusted local agents that can run in their own environment and be used directly from Slack and Telegram. Our vision is to achieve distributed intelligence network, much like cremini mushrooms that grow from a vast, interconnected mycelial network.

What is SkillPack

skillpack.sh is an open-source way to package AI skills into runnable local agents. If skills and tools are like LEGO pieces, a SkillPack is the finished product that assembles them into a complete solution. Instead of juggling prompts, scripts, docs, and one-off automations, Skillpack gives you a simple way to:

  • package AI skills into reusable agents
  • run them locally
  • keep sensitive data in your own environment
  • use agents from tools your team already uses, like Slack and Telegram

Skillpack is built for teams that want AI Agents to be deployable, trusted, and easy to use.

Quick Start

1. Run a skillpack

  1. Download the example
  2. Garry Tan SkillPack
  3. Company Deep Research SkillPack
  4. Unzip it and Run ./start.sh on Mac OS, Or double click start.bat on Windows (see below), the server starts and opens http://127.0.0.1:26313 in your browser
# macOS / Linux
./start.sh

# Windows
start.bat
  1. Enter an LLM API key (OpenAI or Claude API Key) in the left menu, use the prompt example to try it!
  2. (Optional) Refer to the instructions Slack/Telegram Integrations below to integrate with Slack and Telegram.

2. Create a new skillpack

npx @cremini/skillpack create

Step by step:

  1. Set the pack name and description.
  2. Add skills from GitHub repos, URLs, or local paths.
  3. Add prompts to tell the agent how to orchestrate those ski
Read from source at commit 843277410bd9OBSERVED · 2026-10-09
02

Install

Commands as the repository documents them. They are shown, not run.

npm install
npm init -y
npm install /Users/yava/myspace/finpeak/skill-pack/cremini-skillpack-*.tgz
03

Host compatibility

What the documentation claims. We have not run a compatibility test.

HostStatusNotes
claude-codementioned
codexmentioned
cursormentioned
openclawmentioned
04

What it tells the agent

The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.

---
name: skillpack-creator
description: Create a reusable SkillPack from a successful completed task. Use when the user wants to convert a one-off research, coding, analysis, or content workflow into a distributable local SkillPack with `skillpack.json`, local skills under `skills/`, starter prompts, start scripts, and an optional zip package.
---

# Skillpack Creator

## Overview

Turn a successful task into a reusable SkillPack. Extract the stable workflow, decide what belongs in a local skill versus pack-level prompts, generate the pack structure, and package it only after the workflow is explicit and repeatable.

## Workflow

### 1. Normalize the source task

Reduce the finished task into a clean execution spec:

- Capture the user goal, concrete deliverable, and the final successful workflow (not the full exploratory transcript).
- List required skills, tools, files, secrets, and environment assumptions.
- Separate deterministic steps from heuristic steps; remove dead ends and debugging noise.
- If the task is still too broad, narrow the scope instead of writing a vague mega-skill. If key success conditions depend on hidden human judgment, mark the pack as a best-effort assistant workflow.

Ask for missing stable facts or infer only the low-risk pieces.

### 2. Decide what the pack should contain

- **Local skill** (`skills/`): reusable procedural knowledge. Keep scripts minimal unless reproducibility depends on exact file generation or repetitive shell steps.
- **Scripts** (`scripts/`): repeated shell or file-generation logic where reliability matters.
- **References** (`references/`): detailed schemas, API notes, or conventions that should not bloat `SKILL.md`.
- **Prompts** (`skillpack.json`): 1–3 pack-level starter inputs for the UI — not a DAG or state machine. See `references/skillpack-format.md` for exact pack semantics.

### 3. Create the pack specification

Before writing files, define the pack spec. Prefer one local orchestrator skill plus a small number of external skills. Example minimal manifest:

```json
{
  "name": "company-research",
  "description": "Research a company and produce a summary report",
  "version": "1.0.0",
  "prompts": ["Research {company} and create a report with financials and competitors"],
  "skills": [
    { "name": "research-orchestrator", "source": "./skills/research-orchestrator", "description": "Orchestrate company research across multiple sources" }
  ]
}
```

### 4. Create the local orchestrator skill

Create `skills/<skill-name>/SKILL.md` with frontmatter and imperative workflow instructions:

```yaml
---
name: research-orchestrator
description: "Orchestrate multi-source company research. Use when the user wants a structured company report covering financials, competitors, and market position."
---
```

- Write the stable workflow as imperative steps in the body.
- Add `scripts/` only for fragile or repeated operations; add `references/` only for detailed information.

### 5. Materialize the pack

Use `scripts/scaffold_skillpack.py` when you have the pack spec:

```bash
# Basic
python3 skills/skillpack-creator/scripts/scaffold_skillpack.py \
  --manifest /tmp/skillpack.json \
  --output /absolute/path/to/output-pack

# With zip
python3 skills/skillpack-creator/scripts/scaffold_skillpack.py \
  --manifest /tmp/skillpack.json \
  --output /absolute/path/to/output-pack \
  --zip
```

The script validates the manifest, writes `skillpack.json`, creates `skills/`, copies `start.sh`/`start.bat` from `templates/`, and optionally runs `npx -y @cremini/skillpack zip`.

### 6. Validate the result

Before handing the pack back, confirm:

- The manifest matches the intended pack scope
- Every declared skill has a valid `name`, `source`, and `description`
- Local skills are present under the target pack's `skills/`
- Starter prompts are concrete enough to reproduce the workflow
- Zip only after the pack runs as a directory

## Output Standard

Produce:

1. A short summary of the stabilized workflow.
2. The target pack structure and skill inventory.
3. The created or updated local skill files.
4. The generated `skillpack.json`.
5. Whether the pack was zipped and where the zip lives.
05

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (6 observation(s))
Network
declared (5 observation(s))
Shell
declared (2 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (9)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/runtime/server.ts:336
exec(cmd, (err) => {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/runtime/registry.ts:85
return crypto.createHash("md5").update(canonicalizeDir(dir)).digest("hex");
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/runtime/adapters/ipc.ts:5
import type { ScheduledJobConfig } from "../../job-config.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/runtime/adapters/scheduler.ts:15
} from "../../job-config.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/runtime/adapters/scheduler.ts:16
import { hasJobSchedule, normalizeJobCron } from "../../job-schedule.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/runtime/tools/manage-schedule-tool.ts:13
import type { ScheduledJobConfig } from "../../job-config.js";
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:26
2. Unzip it and Run ./start.sh on Mac OS, Or double click start.bat on Windows (see below), the server starts and opens http://127.0.0.1:26313 in your browser
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@earendil-works/pi-coding-agent, @larksuiteoapi/node-sdk, @sinclair/typebox, @slack/bolt, ajv, archiver, chalk, commander
Why it matters. 24 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/runtime/im-adapters.md:132
- If the `apiKey` / `provider` fields are absent or the file cannot be read, the environment variables `OPENAI_API_KEY` / `ANTHROPIC_API_KEY` are used as a fallback.
Why it matters. asks the agent to read credentials

Gates applied: no_behavioural_pass.

Audited 2026-10-09 · audit v0.4.1 · source sha 843277410bd9full audit observations/trust-audit/skill/creminiai__skillpack.json · Report an issue / request a re-scan
06

Audit history

Every audit this skill has had.

DateSourceVerdictGradeScoreChange
2026-10-09843277410bd9BLOCKD69first audit
07

Questions

What does the skillpack skill do?

Pack and deploy local AI agents for your team in minutes

Is skillpack safe to install?

No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.

What can skillpack access on my machine?

The audit observed that it reaches the network, runs shell commands and reads or writes files. Each of those is consistent with what it says it does. Secrets in the source: none found.

Which assistants does skillpack work with?

Its documentation mentions claude-code, codex, cursor and openclaw. That is what the text claims, not a compatibility test we ran.

How current is this page?

The grade is for one exact copy of the source (843277410bd9), read on 2026-10-09. The repository is watched, and a new audit runs when it changes — this is the first audit.

Advertisement