Atlas / Skills / qufei1993 / skills-hub

skills-hubBLOCK

skills/qufei1993/skills-hub

A cross-platform desktop app to manage Agent Skills in one place and sync them to multiple AI coding tools’ global skills directories — “Install once, sync everywhere”.

Verdict
BLOCK
Grade
F
Trust score
49 /100
Version
—
Hosts
7 documented
License
MIT
Stars
1,728
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A cross-platform desktop app (Tauri + React) for installing, organizing, updating, and syncing Agent Skills to multiple AI coding tools' global or project-level skills directories. Skills Hub prefers symlink/junction and automatically falls back to copy when needed: "Install once, sync everywhere".

Documentation

  • English (default): README.md (this file)
  • 中文:docs/README.zh.md

Why Skills Hub

AI coding tools increasingly use their own skills directories and installation flows. Maintaining those directories manually can quickly become messy: the same skill gets copied many times, update sources become unclear, tool activation states drift, and bulk cleanup takes too much effort.

Skills Hub installs skills into one central repository, then syncs them to tools such as Claude Code, Codex, Cursor, OpenCode, and Antigravity based on your choices. You can tag skills, choose global or project scope, update tool targets in bulk, and let the system update Git and local-source skills on a schedule.

Key Features

  • AI management: Install, update, and organize skills through conversations with your AI coding tool, using the same library as the desktop app.
  • Centralized library: Install skills into one central repository instead of scattering copies across tool folders.
  • Explore and install: Install from curated lists, online search, local folders, or Git repositories.
  • Multi-tool sync: Sync skills to different AI coding tools by global or project scope.
  • Multi-device library sync: Keep Skill content, descriptions, and tags aligned across computers through a GitHub, GitLab, or Gitee repository.
  • Local recycle bin: Recover deleted Skills and their saved local configuration for up to 30 days.
  • Bulk management: Apply tags, tool targets, enabled state, or delete operations to many skills at once.
  • Tag organization: Filter, group, and maintain skills with tags.
  • **Tool manageme
Read from source at commit 4a2b07779079OBSERVED · 2026-10-08
02

Install

Commands as the repository documents them. They are shown, not run.

npm install
npm install
npm install
git clone --depth 1 --filter=blob:none --sparse --no-tags ...
03

Host compatibility

What the documentation claims. We have not run a compatibility test.

HostStatusNotes
claude-codementioned
codexmentioned
copilotmentioned
cursormentioned
gemini-climentioned
openclawmentioned
windsurfmentioned
04

What it tells the agent

The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.

---
name: manage-skills-hub
description: Use this skill whenever an Agent needs to query, find, install, deploy, update, tag, adopt, diagnose, or safely remove Skills Hub content, including natural-language requests to manage Skills for Codex, Claude Code, Cursor, or another Agent. Always use the Skills Hub CLI workflow instead of editing Skill directories or the database.
---

# Manage Skills Hub

Translate the user's requested Skill operation into the trusted `skillshub-cli` commands below. By default, an AI installation includes syncing to detected, enabled tools in Skills Hub; explicit user scope takes precedence. Keep device sync, automation, credentials, and application settings in the desktop app.

## Resolve a trusted CLI before every workflow

1. Inspect `~/.skills-hub/bin` without executing a binary. Only when that directory is completely absent, inspect `~/.skills-hub-dev/bin` as the desktop development bridge. These desktop profiles share the Skill library, but keep credentials separate. On Windows expand the user's home directory and use `skillshub-cli.exe`; otherwise use `skillshub-cli`. Never switch to another bridge when the selected directory exists but fails validation.
2. If that bridge directory exists (including a broken link or inaccessible path), require a regular executable binary and both regular stamp files `skillshub-cli.version` and `skillshub-cli.sha256` in that directory. Read only these public stamps. Validate a nonempty version and a 64-digit hexadecimal SHA-256 value, then compute the binary's SHA-256 with the platform's hashing utility and require an exact match. Reject symlinked stamps/binaries and unresolvable paths. Do not execute an unverified binary.
3. After hash validation, bind `$CLI` to that absolute binary path and run `$CLI --json version`. Require exit 0, `ok: true`, and `data.version` equal to the version stamp. Missing files, invalid stamps, mismatched hash/version, execution failure, and malformed output mean **bridge damaged**: fail closed, stop, and ask the user to open Settings → AI management in the desktop app and click Enable in one click to install or repair the CLI bridge. First-time installation or repair requires this explicit click; update the CLI and official Skill explicitly in Settings → AI management. Startup only checks status and does not update them. Never fall back to PATH when the bridge location exists but fails validation. Do not repair or edit stamps yourself.
4. Only when the desktop bridge directory is completely absent, resolve `skillshub-cli` from PATH for a CLI-only environment. Bind `$CLI` to the resolved absolute path and run `$CLI --json version`. If unavailable, explain installing Skills Hub and enabling AI management in Settings. Do not silently install software.

`$CLI` below denotes that verified executable, not a literal command or shell fragment. Pass arguments as distinct values; quote paths correctly and never evaluate user input as shell code. Read-only bridge inspection and hashing are the only filesystem work this workflow needs.

## Interpret machine results

Use `--json` for **every** CLI invocation. Read successful JSON from stdout and failed JSON from stderr; inspect the exit status, `ok`, stable `code`, and structured `details`. Treat `message` as localized explanatory text, never as a parsing contract. Do not report success without a successful result and a CLI readback.

Exit codes: 0 success (including previews); 2 invalid arguments; 3 missing or ambiguous item; 4 safety/path/content conflict; 5 operation busy; 6 incompatible database; 7 network/authentication/source failure; 10 internal failure. Preserve unknown error codes and details rather than guessing. `--json` never implies confirmation.

## Query and choose

Run read-only queries directly:

```text
$CLI --json skills list
$CLI --json skills show <name-or-id>
$CLI --json skills search <query> --limit 20
$CLI --json skills status <name-or-id>
$CLI --json skills check <name-or-id>
$CLI --json skills check --all
$CLI --json agents list
$CLI --json doctor
$CLI --json version
```

Use list filters `--tag`, `--source`, `--agent`, `--untagged`, or `--status` when needed. Prefer returned full Skill IDs. On `AMBIGUOUS_SKILL`, show candidates and resolve the user's choice; never choose an arbitrary match.

## Install and deploy

An AI installation is complete after library installation AND deployment to the selected tools. The CLI exposes these as separate commands; `skills install` alone still only adds to the library. Install a single Skill when the user explicitly requests it:

```text
$CLI --json skills install <local-path-or-git-ref>
$CLI --json skills install <repo-ref> --subpath <skill-path>
```

Use explicit local paths (`./`, `../`, absolute, or `~/`), Git references, or supported `owner/repo` shorthand. On `MULTI_SKILLS`, show `details.candidates` and use the selected subpath; never automatically install every candidate. Read back with `skills show` using the returned ID.

Resolve the target set for each installation request:

| User request | Target selection |
| --- | --- |
| Explicitly library-only / no sync | Install and read back only; do not deploy or remove existing deployments. |
| Names particular tools | Use only those returned Agent keys; do not add default tools. If a named tool is missing, undetected, or disabled, report it without enabling it or creating its directory. |
| No tools named, including “install” or “sync to all tools” | Run `agents list`; select exactly `data.agents` entries where BOTH `detected` and `enabled` are true, including eligible custom tools. Never use the full supported-tool catalog or assume the current Agent is the only target. |

Use global scope by default. If the user specifies a project, use its absolute path with `--project` for every deployment; ask for the path if unclear. Report unsupported project targets without falling back to global. If no eligible tools exist, keep the installed li
05

Trust audit

BLOCKgrade F · trust 49/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (13 observation(s))
Network
declared (6 observation(s))
Shell
declared (1 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

CRITICALHard-coded secrets · secret.private_key · CWE-798, CWE-321
src-tauri/src/cli/sanitize.rs:259
"-----begin private key-----",
CRITICALHard-coded secrets · secret.private_key · CWE-798, CWE-321
src-tauri/src/cli/sanitize.rs:260
"-----begin rsa private key-----",
CRITICALHard-coded secrets · secret.private_key · CWE-798, CWE-321
src-tauri/src/cli/sanitize.rs:261
"-----begin openssh private key-----",
CRITICALHard-coded secrets · secret.private_key · CWE-798, CWE-321
src-tauri/src/cli/tests.rs:297
"private-key": "-----BEGIN PRIVATE KEY-----",
CRITICALHard-coded secrets · secret.private_key · CWE-798, CWE-321
src-tauri/src/core/device_sync/mod.rs:2554
format!("{}\n-----BEGIN PRIVATE KEY-----", "safe text\n".repeat(600)).into_bytes(),
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
src-tauri/src/core/device_sync/manifest.rs:230
|| name == "id_rsa"
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
src-tauri/src/core/device_sync/manifest.rs:231
|| name == "id_ed25519"
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
src-tauri/src/core/device_sync/manifest.rs:536
|| name == "id_rsa"
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
src-tauri/src/core/device_sync/manifest.rs:537
|| name == "id_ed25519"
Why it matters. touches a credential store
HIGHPrompt injection · prompt.credential_read · CWE-94, CWE-1427
skills/manage-skills-hub/SKILL.md:136
Never read, print, store, or request credentials, OAuth codes, Authorization headers, private keys, or credential-bearing URLs. The CLI may use existing secure credentials only during a user-requested
Why it matters. asks the agent to read credentials
MEDIUMInventory / provenance · inv.binary · CWE-1104
src-tauri/icons/icon.icns
icon.icns
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMPrivilege escalation / persistence · fs.persistence · CWE-269, CWE-250
src-tauri/src/core/system_scheduler.rs:289
let _ = background_command("launchctl")
MEDIUMPrivilege escalation / persistence · fs.persistence · CWE-269, CWE-250
src-tauri/src/core/system_scheduler.rs:295
let out = background_command("launchctl")
MEDIUMPrivilege escalation / persistence · fs.persistence · CWE-269, CWE-250
src-tauri/src/core/system_scheduler.rs:299
.context("launchctl load")?;
MEDIUMPrivilege escalation / persistence · fs.persistence · CWE-269, CWE-250
src-tauri/src/core/system_scheduler.rs:302
"launchctl load failed: {}",
MEDIUMPrivilege escalation / persistence · fs.persistence · CWE-269, CWE-250
src-tauri/src/core/system_scheduler.rs:315
let _ = background_command("launchctl")
MEDIUMFilesystem / path · fs.system_paths · CWE-22, CWE-59
src-tauri/src/core/app_updater.rs:10
std::path::Path::new("/etc/apt").exists(),
MEDIUMFilesystem / path · fs.system_paths · CWE-22, CWE-59
src-tauri/src/core/app_updater.rs:66
("/usr/local/bin/app", true, true, false),
MEDIUMFilesystem / path · fs.system_paths · CWE-22, CWE-59
src-tauri/src/core/git_fetcher.rs:332
"/usr/local/bin/git",
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
src-tauri/src/commands/tests/commands.rs:1541
let secret = "do-not-leak-source-secret";
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
src-tauri/src/services/install.rs:1056
let secret = "do-not-leak-service-secret";
MEDIUMHard-coded secrets · secret.github · CWE-798, CWE-321
src-tauri/src/commands/tests/commands.rs:403
const SECRET: &str = "github_pat_UNIQUE_PHYSICAL_ERASURE_TEST_6f93c5a1";
MEDIUMHard-coded secrets · secret.github · CWE-798, CWE-321
src-tauri/src/commands/tests/commands.rs:432
const SECRET: &str = "github_pat_UNIQUE_BUSY_WAL_RETRY_TEST_92d81ef4";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
scripts/build-desktop.test.mjs:234
assert.throws(() => desktopBuild.clearDesktopBundle({ root, target: '../../unsafe', debug: false }))
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src-tauri/src/core/device_sync/manifest.rs:683
std::os::unix::fs::symlink("../../outside", local.join("node_modules/.bin/tool")).unwrap();

Gates applied: critical_finding, no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 4a2b07779079full audit observations/trust-audit/skill/qufei1993__skills-hub.json · Report an issue / request a re-scan
06

Audit history

Every audit this skill has had.

DateSourceVerdictGradeScoreChange
2026-10-084a2b07779079BLOCKF49first audit
07

Questions

What does the skills-hub skill do?

A cross-platform desktop app to manage Agent Skills in one place and sync them to multiple AI coding tools’ global skills directories — “Install once, sync everywhere”.

Is skills-hub safe to install?

No — not without reading the findings first. The audit graded it F (49/100) and found 10 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What can skills-hub access on my machine?

The audit observed that it reaches the network, runs shell commands and reads or writes files. Each of those is consistent with what it says it does. Secrets in the source: found — see the findings.

Which assistants does skills-hub work with?

Its documentation mentions claude-code, codex, copilot, cursor, gemini-cli, openclaw and windsurf. That is what the text claims, not a compatibility test we ran.

How current is this page?

The grade is for one exact copy of the source (4a2b07779079), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.

Advertisement