Changelog
All notable changes to skillshare are documented here. For the full commit history, see GitHub Releases.
[0.25.1] - 2026-10-07
New Features
One shared instruction file, and your own, in the same file
prependandappendmodes for single-file extras — tools without@import, such as Codex, Gemini CLI and Cursor, could only take a shared instruction file as a symlink or copy, which replaced the tool's own file.prependandappendwrite the shared file's content into the target file as a managed block at the top or end and leave the rest of the file alone. When the source changes, the next sync replaces the block in place. A block edited by hand is not overwritten:extras listshows the target asmodifieduntil you copy the edit back to the source or reapply the block. Refs: #436.skillshare extras init team-agents --file AGENTS.md --source ~/dotfiles/team \
--target ~/.codex --mode append
skillshare sync extras- The AGENTS.md tab offers
prependandappend— the mode picker lists them withimportas the modes that keep the tool's own file. Each target row's path opens the file it writes, with skillshare's blocks tinted, a hand-edited block in the warning colour with Collect and Reapply, and a link to the target page for editing.
Doctor
doctorhonors OpenCode's switches for external skills — OpenCode also reads~/.claude/skillsand~/.agents/skills, sodoctorwarned about every overlap and the warning could not be silenced. OpenCode loads one skill per name, so a skill synced to both folders is fine:doctornow warns only about skills OpenCode loads from another target's folder that are missing from its own, including ones you keep there by hand, and names them. WhenOPENCODE_DISABLE_CLAUDE_CODE_SKILLS,OPENCODE_DISABLE_CLAUDE_CODEorOPENCODE_DISABLE_EXTERNAL_SKILLSis set where skillshare runs,doctor,syncand the dashboard treat that folder as skipped. Refs: #458.! opencode loads 1 skill missing from its own folder, from: claude
Dashboard
- Uninstall a tracked repo with uncommitted changes from the dashboard — the dashboard refused such a repo, or one whose git status could not be read, with no way past it. It now says why and asks again, then moves the repo to the trash as it is, like
uninstall --force.
Bug Fixes
- Installing a git submodule path is refused instead of leaving an empty folder — skillshare does not fetch submodules, so installing one reported success with nothing in it, a path inside one failed with a misleading "does not exist", and whole-repo installs dropped its skills silently. The error now names the submodule, its pinned commit and its upstream URL, and
install,--trackandupdatewarn about each submodule they skip. Credentials in a submodule URL are never shown. Refs: #433. - Scripts stay executable when a skill is downloaded through the content API — when sparse checkout was not available, the GitHub, Gitea and CNB fallbacks wrote every file without the exec bit. A file that starts with
#!is now executable. Refs: #439. - Plugin changes keep a symlinked
config.yaml—plugin addandplugin updatereplaced aconfig.yamllinked from a dotfiles folder with a regular file, so the shared config never got the change, and they ignoredpreserve_tilde_on_save. A plugin source spelled with~also madeplugin updatefail with "snapshot ownership conflict". Refs: #460, #461. - A project's config can no longer be pointed outside the project — a cloned project could link
.skillshare/config.yaml, or itssources.mcpfile, to any file you can write, and the next save, plugin, hook or MCP change, or the dashboard's config editor, would rewrite it. These writes now refuse a destination outside the project and name the link. A global config still writes through its link. - The dashboard recognizes a project made with
init -p --visible— it looked only for.skillshare/config.yaml, so a project inskillshare/was reported as having no config and the MCP page missed its override conflict. Refs: #437. - The config schemas accept every valid key — editors flagged
plugins,cnb_hosts,gitea_hosts,extras_source,logand a skill'skindas unknown. Refs: #438. - Codex and Gemini agent conversion works inside ESM projects — in a project whose
package.jsonsets"type": "module", the bundled Codex and Gemini extensions failed withrequire is not defined. The dashboard's Sync page now shows a short cause for a failure, with the full output expandable and copyable. - The floating action bar stays on one line — on the Pi and Oh My Pi pending-changes bars, wide content wrapped and overflowed the bar.
[0.25.0] - 2026-10-06
New Features
Serve skills over MCP
skillshare mcp serve— serves your skills read-only over MCP, for Agents that cannot reach the synced folders, such as one in a throwaway VM or behind an MCP gateway. It implements the Skills extension (SEP-2640): each skill is one entry with its full frontmatter and a manifest of its files with theirsha256digest and size. Most Agents do not support the extension yet, so the server also offers two tools,list_skillsandread_skill, which any Agent that uses MCP tools can call; a client that declares the extension gets the skills natively and does not see the tools. Changes in the source show up within 5 seconds without a restart. Refs: #428.skillshare mcp serve # stdio, every enabled skill
skillshare mcp serve --target claude # only what the claude target selects
skillshare mcp serve --check # list skipped skills and exit
SKILLSHARE_MCP_TOKEN=change-me skillshare mcp serve --http 0.0.0.0:8765 \
--tls-cert cert.pem --tls-key key.pem # HTTPS for other machines- Global by default;
-pserves the project in the current directory. - A skill is skipped, with a warning on stderr, when it breaks the Agent Skills format (for example its
namediffers from its directory), is over 512 files or 16 MiB, or contains a nested skill that is not served. --httpon a non-loopback address requiresSKILLSHARE_MCP_TOKENand HTTPS through--tls-certand--tls-key, or a loopback address behind a TLS proxy. Cross-origin browser requests are refused.- Do not connect local Agents that already sync skills; they would see each skill twice.
- Global by default;
- A Skillshare tab in the dashboard's Add server — adds
skillshare mcp serveas an MCP server, with the target and scope to serve, so the Agents you sync it to can read your skills.
Followed source links
skillshare linkandunlink— use a skills checkout where it already lives, or keep skills on an external drive, by linking the folder directly under the skills source.--enablealso turns onfollow_source_links;unlinkremoves only the link and leaves the folder alone. On Windowslinkcreates a junction, which needs no Developer Mode. Refs: #274, #419.skillshare link ~/code/dev-skills --enable # links it as _dev-skills
skillshare sync
skillshare unlink _dev-skillsfollow_source_links— with this setting on, globally or per project,list,sync,status,auditand the dashboard find the skills inside first-level links in the source. A link that would loop back into the source, overlaps a sync target, or is missing is skipped with a warning. While a linked drive is unmounted, that run deletes nothing: target links, copies and install metadata stay until it is back.update --allskips linked checkouts, because they are your own working copies; update one by name.follow_source_links: true- Link and unlink folders from the dashboard — Link folder on the Skills page takes a path, an optional name and the
follow_source_linksswitch, and shows the same reasons as the command when it refuses a folder. A linked folder is listed as its own group with the folder it points at, and its row unlinks it after a confirmation; the link can be restored from Trash.
Oh My Pi
- MCP, code hooks, plugins and extensions for Oh My Pi (
omp) — theomptarget already received skills and instructions. It now also gets MCP servers in its ownmcpServersformat, code hooks as native extensions, plugins from reviewed local or Git sources or imported from its marketplace, and a guarded Extensions tab for choosing which extensions load. An account declared withagent: ompgets skills, instructions, MCP and code hooks. Refs: #409.skillshare mcp add docs --url https://example.com/mcp --target omp -g --sync
skillshare plugin add ./my-omp-plugin --target omp -g
Targets
- DeepSeek Harness and GitLab Duo — two new built-in targets,
deepseek-harnessandgitlab-duo. - Unicode skill names under
target_naming: standard— names in lowercase letters of any script, such ascaféor日本語-tool, now sync like ASCII names instead of being skipped. Underscores are still rejected.
Bug Fixes
updateno longer pulls a Git repository that a link points at — a link inside the skills source to a checkout elsewhere was treated as a tracked repo, soskillshare updateand the dashboard rangit pullthere, and with--forcereset it. A linked checkout is now only updated when you name it. Git worktrees and submodules, which have a.gitfile, get the same guards. Refs: #410.- Option values that look like a scope flag are kept — in commands such as
link --name -g, the value was read as the-gflag, which changed the scope or reported a mode conflict. A value after an option that takes one now stays its value, and--ends the options. Refs: #422. - Moving a Windows junction to another drive keeps it a junction — when the skills source and the trash were on different drives,
unlinkandtrash restorerecreated a junction as a symlink, which needs Developer Mode, so they could fail afterlinkhad worked. Refs: #420. - A plugin whose source changes without a new version shows the commits —
plugin checkcompares the source, not the version, so a repository that pushes commits without changing its version showed the same version with an Update button. The version tag now adds the old → new commit. - Pi MCP settings with invalid OAuth client registration are rejected before sync —
oauth.clientRegistrationacceptsdcrorcimd; withcimd, aclientIdorclientName, or acallbackUrlother than HTTP onlocalhostor127.0.0.1with path/callback, is reported instead of being written to Pi. - Searching skills with no match shows the no-match state — linked folders no longer appear as empty groups while a search or filter excludes every skill, so Clear filters is shown.
[0.24.6] - 2026-10-05
New Features
- Memory has a Refresh button, and agents keep short facts in
INDEX.md— an agent writes shared notes from outside the dashboard, so the note list and the open note stayed stale until you reloaded the page. Refresh sits next to the search box and reloads both. Theactiveguidance also told agents to create a separate file for every durable fact, which left a folder of one-sentence files. A fact that fits in a sentence or two now goes as one bullet under## NotesinINDEX.md; only a longer note gets its own file. Existingactiveguidance blocks show as Outdated on the Memory page; reconnect to update them.skillshare extras memory instructions --update-mode active -g - The Targets list links each part of a target to its tab — the Syncing column described what a target gets as one line of text, and the whole row led to the Skills tab. MCP, Hooks and the instruction file are now separate links into their own tabs, and the connected shared
AGENTS.mdshows by its file name, so the list shows at a glance which targets are not connected yet.
Bug Fixes
diffand the Sync tab no longer list synced agents as pending when a target converts them — after a successful sync, a target with an agent extension (for example Codex writingreviewer.toml) still showed every agent as New inskillshare diffand in the dashboard's Sync tab, because they looked for the source name. They now check what the sync recorded, so converted agents drop out once synced and show again when the source changes. An output whose agent was removed from the source shows as a removal, anddiffleaves out the agents a target would not receive because of its include/exclude or an agent'stargetsfrontmatter, assyncdoes. Refs: #391.skillshare sync agents
skillshare diffstatusno longer counts a plain copy as a converted agent — when a target that already held copied agents started using an agent extension,status,doctor,diffand the dashboard counted the oldreviewer.mdcopy as the converted output, although the next sync writesreviewer.tomland removes the copy. Only outputs the extension wrote count now. A converted output written before 0.24.5 shows as pending until the next sync records its source.- The dashboard rejects skill names that point outside the skills folder — the audit, update and batch uninstall routes joined the name from the request to the source without checking it, so a name such as
../../xmade audit scan a folder outside the skills source and report it clean. These routes now answer with an error for such a name. Nested names such asgroup/skillwork as before. Refs: #402. skillshare audit agentskeeps the Skills tab on skills — the audit screen opened for agents only discovered skills inside the agents folder, andaudit agents --jsonreported names such as../agents/helper.mdwhen the two folders are siblings. Agents are now named relative to the agents folder and the Skills tab reads the skills source.- The hub filters sit on the title row — the title and the filters used two rows with a wide empty strip above and below the filters; they now share one row.
[0.24.5] - 2026-10-04
New Features
- Pi packages show their version, and Check updates finds new ones on npm — an npm package in Pi had no recorded version and no source, so the Plugins page showed none and Check updates could only say to check in Pi. The version now comes from the package Pi installed, on the Plugins page and in a Pi target's Extensions tab, for npm, git and local packages alike. For an npm package added without a version,
checkcompares it with npm'slatest. A newer version shows asold → newwith an Update button on the row and in the check's result; it opens the update preview for that one plugin and Agent and runspi update <source>for that package only. A package added with a version range or tag, or one that npm resolves to a registry other than npmjs, is left to Pi.skillshare plugin check -g
skillshare plugin update pi-mcp-adapter --target pi -g - The Plugins page's Sync box puts what needs a look first — after a run, failures come first with their message, then the other changes, and Agents that ended the same way share one row with their logos (each names itself on hover). What stayed the same folds into one Unchanged line that opens to one row per plugin, with Pi packages apart. The preview folds what it leaves alone the same way, below the changes it will make.
Bug Fixes
- Agents synced through an agent extension no longer show as drift — a target that converts agents (for example to
reviewer.toml) was reported as0/Nwith drift bystatus,doctorand the dashboard after every successful sync, because the converted names never matched the sources. Converted outputs now count as synced, and editing an agent in the source shows as drift until the next sync. Outputs written by earlier releases count as current until that sync records their source. Refs: #391.skillshare sync agents
skillshare status statusexpects only the agents a target would sync —statuscounted every agent against each target, whilesyncleaves out the ones.agentignore, the target's include/exclude and an agent'stargetsfrontmatter exclude, so such a target showedN/Mwith drift after a complete sync, in the table and in--json.statusnow applies the same filters, and a leftover link for an agent the target no longer syncs no longer stands in for a missing one.doctorand the dashboard already filtered this way. Refs: #395.- Updating a Codex plugin that ships a portable
plugin.jsonno longer fails on every sync — Codex installs from a rootplugin.jsonahead of.codex-plugin/plugin.json, and reports1.0.0when that manifest has no version. Skillshare expected the version from.codex-plugin/plugin.json, so a package that ships both failed withnative update returned version 1.0.0; expected 4.10.3. Skillshare now expects the version Codex reads, keeps the logo from.codex-plugin/plugin.json, and still checks the version of a package whose portable manifest has none.skillshare sync plugins - Disabling a skill that
.skillignore.localkeeps on now fails with the reason — a!rule in.skillignore.localis applied after.skillignore, so the skill stayed enabled while the dashboard reported success. Single and batch toggles now report such a skill as failed and name the file that overrides it, the attempt is logged, and Settings › Files shows the.localrules above the editor. - Plugins Skillshare installs into Pi are listed and named as plugins — a plugin installed from a Git source and bound only to Pi landed in Pi packages, and Pi's Extensions tabs titled it by its state path, in global and project views. It now stays under the managed plugins, and the tabs show its name with the Managed by Skillshare tag. The Import dialog leaves out what Skillshare already manages and says when an Agent has nothing left to import.
- A folder switch that is partly on reads as partly on — in the resource tree, the mixed state looked like a stuck off switch; it now has a half-tone track and a dash, like an indeterminate checkbox.
[0.24.4] - 2026-10-04
Bug Fixes
- A skill that ships its own
.claude/skills/no longer floods your Agents with the author's dev skills — installing a repository whose root is a skill copies the whole repository into the source, including any.claude/skills/the author keeps for working on it. Those showed up as nested skills such asffmpeg-skill/.claude/skills/code-reviewand were synced to every target. Discovery now skips target directories (.claude,.cursor,.factory, ...) nested below the source root, asinstallalready did. Host-style paths directly under the root, such as.cursor/skills/*, still work and still pick their target. The next sync removes the stray links.skillshare sync - The shared-memory guidance says which notes go to the project and which to the shared folder — an Agent that reads both a global and a project guidance block saw the same text twice and had to guess where a user preference or a project decision belongs. The global block now points project notes at the project memory when one exists and keeps user preferences, decisions that apply across projects and pitfalls in a tool; the project block keeps decisions, conventions and pitfalls of that project and says that notes about you, your tools or other projects do not belong in it. Existing guidance blocks show as Outdated on the dashboard's Memory page; reconnect to update them.
skillshare extras memory instructions --update-mode active -g
[0.24.3] - 2026-10-04
New Features
doctorpoints out links at the top of the skills source — a symlink or Windows junction directly inside the skills source is not followed by discovery, so the skills behind it never reach your Agents.doctornow lists each one as a Source link info row, in global and project mode, without following it;doctor --jsonreports them asundeclared_source_linkschecks with statusinfo. A write into the skills source whose path crosses such a link is refused instead of written through it. Refs: #274.skillshare doctor
Bug Fixes
- Plugin commands find the Codex CLI that the desktop app ships — Codex installed only through the Codex desktop app, Homebrew or the Windows installer was not on
PATHfor Skillshare, so plugin commands for thecodextarget stopped with a missing-CLI error. Skillshare now also looks in those places (macOSChatGPT.app, Windows%LOCALAPPDATA%\OpenAI\Codex\bin\<version>,/opt/homebrew/bin,/usr/local/bin), and the error lists every place it searched. On a machine where Codex lives elsewhere, setSKILLSHARE_CODEX_CLI; it is read from the environment, so aconfig.yamlshared between machines needs no machine-specific path. Refs: #338.export SKILLSHARE_CODEX_CLI=/path/to/codex
skillshare sync plugins - The shared-memory
activeguidance says where a lesson goes — a durable fact or decision gets its own note linked fromINDEX.md; a lesson from a failure goes under a new heading inLEARNED.md, as the starter file and the sharing-memory guide describe. The--update-modehelp now also says thatpassivesaves notes when you ask, not only points them out.
Performance
- Agents are told to save to the shared notes instead of their own memory — the guidance block connected to each Agent now says that the notes folder is shared by every coding tool, to read
INDEX.mdat the start of each task, and, inactivemode, to save a fact worth keeping here rather than in the tool's own memory, with a note format and theINDEX.mdline to add.passivestill saves only on request, but points out facts worth keeping so you can ask. Existing guidance blocks show as Outdated in the dashboard's Memory page; reconnect to update them.skillshare extras memory instructions --update-mode active -g
[0.24.2] - 2026-10-04
Performance
- Upgrades and the first dashboard start download much faster on throttled networks — GitHub's release file server limits each connection on some networks, so
skillshare upgradecould spend minutes on the 9 MB archive and the firstskillshare uiof a new version waited again for the dashboard files. Downloads now split the file into 8 parts fetched at the same time, each on its own connection; in one measurement the darwin_arm64 archive went from 171 s to 25 s. Checksums are verified as before, and a server without partial download support gets a single download as before.skillshare upgrade
[0.24.1] - 2026-10-04
New Features
- Agents can keep the shared memory notes up to date — each connected agent now has an update mode.
passive, the default, reads the notes and updates them only when you ask.activealso lets the agent save facts that will matter in later sessions, such as a stated preference or a decision with its reason; it skips one-off details, asks before saving when unsure, updates an existing note instead of adding a duplicate, and tells you what it saved. Choose the mode per agent in the dashboard's Connect to agents, which now shows each file's change as one diff, or print the guidance from the CLI:Agents that read the same file share one mode. The dashboard flags an agent that reads guidance in both modes from different files.skillshare extras memory instructions --update-mode active -g - Config files saved by the CLI are laid out like the dashboard's Beautify — when a command saves
config.yaml, globally or in a project, its sections follow the dashboard's order with a blank line between them, instead of running together withmcp,pluginsandhooksabove the sources. A file that uses YAML aliases keeps its order where sorting would break them.
Bug Fixes
- Pi turns a global MCP server off in a project with its own override — a
disabledentry now writes"NAME": {"enabled": false}to.pi/mcp.json, the override Pi 1.0.1 and later read, instead of a copy of the global server's command or url. Turning the server back on with Pi's/mcpused to start it without its args, env or headers; now the global server keeps all of them. It also works in project mode, wherepiin adisabledentry used to be an error. The next sync rewrites switches written by earlier releases, and an identical override made with Pi's/mcpis no longer a conflict. Older Pi reports the override as invalid. Refs: #378. - Audit no longer blocks config keys named like role labels —
prompt-injection-1reported lines such asroot: ./src,admin: falseorignore: { tags: ["design"] }as CRITICAL prompt overrides and blocked the install. Lowercase config keys with a plain value now pass, while directives such asSYSTEM: jailbreak,system: Override ...or an emptysystem:opening an indented block are still flagged. Refs: #374. - The dashboard counts hooks — the global and project dashboards listed every resource type except hooks, so a source with hooks looked empty. Hooks now appear between MCP and Plugins, as in the sidebar.
[0.24.0] - 2026-10-03
Breaking Changes
initwithout a terminal now sets up what pressing Enter would — in CI, scripts and AI agents,initused to do less than the interactive defaults. It now enables git, installs the built-in skill and selects every detected tool, and prints each decision with the flag that changes it. To keep the previous minimal setup, pass the flags explicitly:skillshare init --no-git --no-skill --no-targets --no-copy- Output that is not a terminal is plain text — piped or redirected output no longer contains ANSI colors. Parse
--jsonwhere a command offers it rather than the human-readable text, which changed throughout this release.
New Features
Init
- Init asks first, then writes —
initcollects every answer, shows a summary with Yes / Change settings / Cancel, and writes nothing until you confirm. Esc cancels cleanly, and--dry-runno longer creates tool folders. The built-in skill is installed by default, and the first sync runs at the end so the tools work right away. - Connect an existing skillshare repo — on a second machine, choose "Connect my existing skillshare repo". Init checks the repo before writing, detects its layout, prefers the repo's version of a skill with the same name, and keeps local-only skills for the next push. Init no longer writes a git identity into a repo that already exists.
Command output
- One output style for every command —
sync,status,install,update,check,push,pull,doctor,audit,mcp,plugin,extras,targetand the other commands report results as aligned rows and end with one closing line or the next step to take, without boxes, logos or trees. - Help that fits on one screen —
skillshare helplists one line per command, and--helpafter a subcommand shows that subcommand's help instead of running it.skillshare extras memory --help doctorwarns about an outdated built-in skill — when a newer built-in skill is published,doctorsays so and counts it in the summary.trash empty --force— empties the trash without asking.
Terminal UI
- One frame and keymap for every full-screen TUI —
list,trash,log,audit,analyze,diff,restore,search,target,extrasand the MCP manager share one title line, one key line with the common keys and the position, and lowercase letters for actions. Less common keys are under?, and confirmations ask on the key line so the list stays visible. Inlist,tabswitches between skills and agents; the All tab and thesstatus cycle are gone, andstatus:in the filter or--statuscovers enabled and disabled. - Small choices are asked inline — the install skill picker, a large repo's folder picker, the restore source, the
newwizard,extras initand MCP and plugin values no longer take over the screen. The question appears in place and collapses into a✓line that stays in the scrollback. Long lists can be narrowed with/, and long descriptions are cut to one row. - A file viewer in the TUIs — browse a skill's files from
list,extras,audit(opened at the finding),analyzeandtrash(before restoring). Control characters and hidden Unicode are shown as symbols, and very large files are skipped.
Git sync
push --pullsyncs both ways in one command — commits local changes, merges the remote the same waypulldoes, pushes, and syncs the scope's targets. A conflict stops before anything is pushed and keeps the local commit. It never rebases or force-pushes.The dashboard's Git Sync page has the same action as Sync both ways, which lists what it will do before changing anything.skillshare push --pull
Memory
- Shared Markdown memory across agents — keep notes in
extras/memory, globally or per project, and connect the agents that should read them. The dashboard has a two-pane Memory browser with search, moves and renames, version history and recovery from backups. From the CLI:This is a shared file overlay; each agent's own automatic memory stays separate.skillshare extras memory init
skillshare extras memory list --search deploy
skillshare extras memory instructions # guidance to add to your agent instructions
Pi
- Turn individual Pi extensions on and off — a Pi target's Extensions tab in the dashboard lists every package in Pi's settings, including ones installed with Pi itself, and switches each extension for the global, account or project target. Each change shows the exact edit to Pi's settings before it is written, changes only that package's extension list, and is refused if Pi would apply it differently. Turning a file back to what the package loads by default removes its rule instead of adding the opposite one. Editing needs Pi 0.99.2 or later; older versions are read-only and say which version is needed.
- Add npm packages from pi.dev —
plugin add npm:<package>installs a Pi package throughpi installand records it like an import. The preview says that Pi runs the package's install scripts, and only targets that run Pi take npm sources. The dashboard also accepts a pastedpi installcommand or a pi.dev address.skillshare plugin add npm:@scope/package --target pi -g
Install and check
checkdetects changes at local install sources — skills installed from a local path, such as one shipped inside an app, used to show only "local source".checknow compares the files at that path with the ones installed and reports an available update, or an error naming the path when the source is gone. Project installs with a relative path are compared against the project root.- Paste an
npx skills addcommand in the install dialog — the dashboard reducesnpx skills@latest add owner/repo --skill=nameorowner/repo@skillto its source and preselects the named skills.
Bug Fixes
Git sync
- Pull no longer discards local commits that hold only files — a first pull treated an agents or extras repo whose content was root-level files as empty and reset it onto the remote without
--force. - This machine's
config.yamlis protected at the root git scope — a first pull is refused when the remote tracksconfig.yaml, a later pull that brings in a tracked copy keeps the local file and warns, and a push is refused when unpushed commits add or changeconfig.yaml. The refusal says how to repair the history. - Pull syncs extras at the root git scope — in the CLI and the dashboard, merged extras changes now reach their targets.
- The pull conflict dialog shows what differs — both versions get taller panes, lines only one side has are tinted, each side scrolls to its first difference, and the header counts the differing lines.
Install and upgrade
upgradeverifies the download before replacing the binary — the release archive is checked against the release'schecksums.txt; a mismatch or an unreachable checksums file stops the upgrade and leaves the running binary untouched.- Local installs update from any directory — global installs record the absolute path of a local source, so
updateandcheckno longer fail with "source path does not exist" when run elsewhere. A skill installed as itsSKILL.mdalone is updated in that shape instead of copying the whole folder.
Windows
- No more flashing console windows — started without a console, such as from a scheduled task or
pythonw, a singlepullopened about ten terminal windows. Skillshare now runs its child processes in a hidden console. - Stopping skillshare stops its child processes — killing it mid-pull no longer leaves git, ssh or hooks running. The
ui startserver, browser and editor still keep running. install file:///C:/...works — the URL is no longer rewritten with backslashes before it is handed to git.- Interrupted or oversized downloads no longer leave temp files in
%TEMP%,auditno longer reportscontent-missingfor absolute paths in skill metadata, and Pi's locks left by a crashed process are recovered.
Plugins and MCP
- Symlinked config folders are accepted — a linked
/varon macOS, a home on a linked volume, a dotfiles-linked~/.pi, or aPI_CODING_AGENT_DIR,CLAUDE_CONFIG_DIRorCODEX_HOMEbehind a link no longer fails with "refusing to modify symlinked native path". A linked file or folder inside the config folder is still refused. - Pi project MCP overrides are explained — a
.pi/mcp.jsonentry that only enables or disables a global server, as/mcpin Pi 1.0.1 writes, is reported as a project override with nothing to import, and a sync conflict with it says to replace it or change it with/mcpin Pi.
[0.23.5] - 2026-10-02
Bug Fixes
Sync
- An
includepattern that matches no skill is reported — target filters match the source path name, such asfrontend__dev, even whentarget_naming: standardshows the folder asdev. A pattern written with the name the target shows selected nothing, and sync removed what a working pattern had linked without saying why. Sync now warns about eachincludepattern that matches no skill, names the target, and suggests the source path name when one fits. The warning appears inskillshare syncand in the dashboard's sync results.--jsonoutput is unchanged.! claude: include pattern "dev" matches no skill in the source (filters use the source path name; did you mean "frontend__dev"?)
[0.23.4] - 2026-10-01
Bug Fixes
Plugins
- Claude marketplace cleanup no longer fails after settings lost the declaration — when a Skillshare marketplace was only recorded in Claude's
known_marketplaces.json, for example after a dotfile manager overwrote~/.claude/settings.json, every sync failed with "could not finish removing its marketplace" and the plugin stayed pending. The marketplace is now removed from every settings scope. A name also declared at another path is reported as a conflict and left in place.skillshare sync plugins -g - Skill and plugin name clashes are explained before install — Claude reads a skill folder that has a plugin manifest as
<name>@skills-dirand loads only one plugin per name, so adding a Claude plugin from the same repository as a synced skill made/pluginreport the skill as not loaded. The install preview now says Claude will load the plugin and skip that folder until one of them is renamed or removed.
[0.23.3] - 2026-10-01
Bug Fixes
Plugins
- Plugin marketplaces are named after their plugin — the local marketplace Skillshare registers for each Claude Code or Codex plugin was named
skillshare-<hash>, which said nothing in/pluginorcodex plugin marketplace list. New installs are namedskillshare-<plugin>-<hash>, such asskillshare-humanizer-322a2e01808560f4. Existing installs keep their names. - Excluding or removing a plugin removes its marketplace — the marketplace stayed registered after its plugin was excluded or removed, and for good when the plugin had already been uninstalled in the Agent or its first install had failed. Skillshare now removes the marketplace it registered in those cases too, and a failed cleanup runs again on the next sync. A marketplace with the same name at another path, and imported plugins' marketplaces, are left alone. An update registers a missing Skillshare marketplace again.
skillshare plugin disable humanizer --target claude -g
skillshare sync plugins -g - Imported plugins whose marketplace is gone are skipped with the reason — when an imported plugin's native marketplace was no longer registered, for example after synced settings dropped it, sync failed with "claude command failed". Sync and update now skip that Agent and say how to recover, and the plugin's other Agents still sync. Skillshare does not switch an imported plugin to its recorded source by itself.
- Plugin errors are translated and shown once — the Plugins page showed failed operations in English, and repeated the same message once per failed Agent.
[0.23.2] - 2026-10-02
New Features
Hooks
- Git config hooks — a hook entry can bind
gitto register named Git config hooks (Git 2.54+) globally or in a project. Skillshare writes the commands to its own include file, adds theinclude.pathline, and writes the helper scripts listed underfiles;{files}expands to their directory on each machine. Preview, sync, backups and restore work as they do for Agent hooks, and managing hooks never runs them. Linked worktrees share their project's hooks.bindings:
git:
commands:
project.check:
events: [pre-commit]
command: "{files}/check.sh"
files:
check.sh: |
#!/bin/sh
exec make checkWith Git older than 2.54 the files are still written, and the plan says why the hooks cannot run.skillshare hooks add git-check --file git-check.yaml -g --dry-run
skillshare hooks sync -gparallelneeds Git 2.55+. When the include target is a symlink or not writable, the plan prints the lines to add by hand. Thegitkey always means Git, so an account target namedgitreceives no hooks; the plan warns once an entry uses thegitbinding.
Doctor
- Check MCP servers, hooks, plugins and extras —
skillshare doctorand the dashboard's Doctor page now check these too, in global and project mode:- MCP: environment variables, commands, client rules and sync state, without DNS lookups or starting servers
- Hooks: what
hooks syncwould still change or refuse. Git hooks that cannot run, for example because Git is missing, are reported with the reason instead of as unsynced - Plugins: what
plugin syncwould change, without fetching sources, when a plugin is configured - Extras: config errors, broken links in targets, and drift as
diffreports it
skillshare doctor --json
MCP
- Pi 1.0 OAuth metadata URL —
piOptions.oauth.authServerMetadataUrl, which Pi 1.0 uses instead of discovering a server's authorization server, is checked when you save: it must use https, or http on localhost. Pi 1.0 keeps OAuth sign-ins per server name and URL, so after renaming a server or changing itsurl, sign in again in Pi.mcp:
servers:
example:
url: https://mcp.example.com/mcp
piOptions:
oauth:
authServerMetadataUrl: https://example.okta.com/.well-known/openid-configuration
Backups
- Backup limits and Delete all —
backup.max_countandbackup.max_size_mbin the global config set how many target folder snapshots to keep and their total size (defaults 10 and 500 MB,0= no limit).sync, the dashboard's sync andbackup --cleanupapply them; backups older than 30 days are still removed. The dashboard's Target folders tab shows the limits, edits them, and adds Delete all behind a confirmation. Project snapshots keep the defaults, and file, MCP and hooks backups are not affected.backup:
max_count: 20
max_size_mb: 1000
Dashboard
- Share several plugins as one command — Share on the Plugins page, in the header or a plugin's menu, lists the plugins added from an HTTPS source and copies one line that adds the ticked ones in order. Each add uses
--no-tui -g, so the plugins land in the recipient's global config without a picker per plugin; they choose Agents on the Plugins page afterwards. An option keeps the per-plugin Agent picker. Plugins added from a local directory are left out, since the path only exists on your machine.
[0.23.1] - 2026-10-01
New Features
Plugins
- Update Codex plugins —
plugin updatenow updates a Codex binding. Codex has no update command, so Skillshare refreshes the reviewed snapshot, adds the plugin again, which replaces the installed copy, and checks the installed version. A plugin disabled in Codex is skipped with the reason instead of being turned back on.skillshare plugin update review --target codex --no-tui - Run a compatible CLI for an account — an account target can set
cliso its plugin commands run a compatible executable instead of the Agent's own, such asomofor a Pi account. It takes a name onPATHor an absolute path. If the CLI is missing, the command fails; Skillshare does not fall back to the Agent's CLI.skillshare target add omo --agent pi --config-dir ~/.omo/agent --cli omo
Hooks
- Hooks for account targets — a global hook binding can name an account target declared with
agentandconfig_dir, such as a second Codex home. Claude, Codex and Pi accounts use their Agent's native binding format, and sync, import and backups keep the account name.targets:
codex-2:
agent: codex
config_dir: ~/.codex-2
hooks:
entries:
check:
bindings:
codex-2:
events:
Stop:
- hooks:
- type: command
command: "echo checked"
MCP
- Turn off a global server for Pi in one project — a
disabledentry for a project undermcp.projectsnow reaches Pi. Skillshare writes the global server'scommand, or itsurlwithout the query, withenabled: falseto that project's.pi/mcp.json; args, env and headers stay out of the file. This replaces the 0.23.0 change that removedpifrom the targets ofdisabledentries. If a 0.23.0 sync already removedpifrom such an entry, add it back totargets. A project's own config still cannot turn off a global server for Pi.mcp:
projects:
~/work/project01:
servers:
context7: # off in this project only
disabled: true - Turn a server off in Pi from the dashboard — Turned on in Pi in a server's Pi settings writes
enabled: falsewhen you clear it, so Pi keeps the server without connecting to it, and removes it when you check it again. It sits above Tool exposure and stays in step with the Other Pi settings JSON.
Dashboard
- Discard Git Sync changes — Discard changes restores tracked files in the source repository to the last commit and deletes untracked files and folders, after you confirm. Ignored files, nested repositories and the root
config.yamlare kept, and a dry run shows what would change. - Resolve Git pull conflicts across computers — when this computer and the remote both changed the same files, Git Sync no longer only stops with the merge undone. Review conflicts shows the local and remote version of each file side by side; keep one whole-file version per file, then Apply choices and pull. Both commit histories are kept, other files merge normally, and
.metadata.jsonconflicts still resolve automatically. If either side gets new commits before you apply, the dialog asks you to choose again. Binary files and files over 16 KiB can be chosen but have no preview. - Pull and merge, Commit and pull — when both computers have new commits, Pull becomes Pull and merge and the page explains that both histories are kept before you push. With uncommitted changes while the remote is ahead, Commit and push becomes Commit and pull.
Bug Fixes
Sync
- Sync no longer deletes skill links you made yourself — in merge mode, sync removed any link in a target that pointed into the skills source but was filtered out, including links you created by hand or with another tool, and the removed links could not be restored. A live link is now removed only when Skillshare created it, as recorded in
.skillshare-manifest.json, or with--force; other links are kept and counted as local. Links created before 0.15.0 that are now filtered out are kept as well; remove them by hand or with--force. - Agent and extra links to other places are kept — merge-mode sync and
extras --remove-target --pruneremoved every agent.mdlink or extra link that was not expected, including links to files outside the source. Now only broken links and links into the source are removed. A link whose file cannot be read, for example because of permissions, is no longer treated as broken. - Copy-mode agents keep your own files — in copy and extension modes, sync deleted every agent file in the target that did not match a source agent, including files you put there. Copies are now tracked in a
.skillshare-manifest.jsonin that agents folder, and sync removes only copies it wrote that you have not edited. Copies that were already orphaned before upgrading are kept; delete them by hand. - Failed agent prunes are reported — when sync could not delete an orphaned agent link or copy, it still counted it as pruned. It now shows a warning, and the other orphans are still removed.
Plugins
- One Agent no longer blocks a plugin update — a plugin installed on several Agents could not update anywhere when one of them could not take the update, such as a plugin disabled in Codex or Copilot, or an imported package. Those Agents are now skipped with the reason, the others update, and the skipped update stays pending. Imported Codex plugins now update through
codex plugin marketplace upgrade, and imported Pi packages in global mode throughpi update. A plugin whose Agents hold different versions shows each version. - Claude account targets list their plugins — a Claude account target could fail with "native plugin list contains an unsupported plugin identifier", for example when the dashboard ran from the home folder, because Claude also lists plugins of other scopes. Those entries are now ignored.
- Plugin results are translated — the dashboard's Plugins page showed last-action statuses and installation messages in English in every language.
Hooks
- Editing a hook from a target tab keeps account bindings — saving a hook from a target page dropped its bindings for account targets such as
codex-2, so the next sync removed that account's hook. - Hooks report config errors — when the global config failed to load,
skillshare hooksran without account targets and reportedunsupported Agent "codex-2"instead of the real error. - Missing account folders are explained — the dashboard's hook config view showed nothing for an account whose
config_diris missing. It now shows a warning for that target.
MCP
- Account shells keep the default home — when
CLAUDE_CONFIG_DIR,CODEX_HOMEorPI_CODING_AGENT_DIRpointed at a declared account'sconfig_dir, sync, import and the dashboard sent the plain Agent target to that account's home and could prune entries in its default home. The plain target now keeps its default home, and sync warns about the shadowed variable. - Project-mode MCP status is complete again — in project mode,
mcp check, the dashboard and the target list dropped pending syncs and conflicts, andmcp remove --keep-filesdid not stop managing a project's Claude off switch, so the next sync removed it anyway. - Pi 0.99.2 settings are kept — Pi 0.99.2's
auth: {provider: NAME}, which sends a provider's/logintoken to an HTTP server, was refused inpiOptionsas api-mcp-adaptersetting, and loading or importing a config dropped it, and the dashboard's Other Pi settings refused it too. It is now kept and checked: it needs an httpsurl, or http on localhost, and global mode, because Pi reads it only from its global file. Only the adapter's stringauthis still removed.oauth.clientNameis checked as text, anddescriptionpasses through.skillshare mcp add docs --url https://example.com/mcp --target pi --pi-options '{"auth":{"provider":"github"}}' --no-tui -g - Server names Pi reads as one are refused — Pi 0.99.2 reads names that differ only in
-and_, such asmy-docsandmy_docs, as one server and skips the second with a config error. Skillshare now refuses the second before writing it. - Pi's error says how to turn off a server — a
disabledentry for Pi that Skillshare cannot write now fails with a message pointing at a complete server withpiOptions: {"enabled": false}, instead of only listing the clients that support a switch. The MCP docs explain the same.
Dashboard
- Beautify keeps config.yaml in order — Beautify and save in Settings → Files now keep config sections in a consistent order with a blank line between them, and keep the
# yaml-language-server: $schema=…line at the top of the file, moving one that was saved in the wrong place.
Website
- Desktop app guide — a new Desktop App page covers installing Skillshare App on macOS, Windows and Linux, in all five documentation languages. The homepage, navigation and README now show the desktop app before the CLI installation. On Apple Silicon Macs:
brew tap runkids/tap
brew install --cask skillshare-app
[0.23.0] - 2026-10-01
New Features
Hooks
- Manage native hooks —
skillshare hookskeeps named hooks inhooks.entriesand writes them into each Agent's own hook configuration: Claude Code, Codex, Gemini CLI, Copilot CLI, Cursor, Factory Droid, Qwen Code, Antigravity (and its CLI,agy), Pi, Amp and OpenCode, in global and project scope. Each binding keeps that Agent's own event names and format; Skillshare does not translate between Agents. Sync previews every file it changes, keeps your other settings and hooks, reports a hook you edited by hand as a conflict, and backs files up before writing. It never runs a hook or changes an Agent's trust.skillshare hooks add check --file ./check.yaml
skillshare hooks sync --dry-run
skillshare hooks sync
skillshare sync --all # now includes hooks - Import the hooks you already have —
hooks import --from AGENTlists that Agent's existing hooks. Saving one takes over those registrations in place, so the next sync does not add a duplicate.skillshare hooks import --from claude - Disable, stop managing and restore —
hooks disablekeeps the definition and removes it from the Agents on the next sync.hooks remove --keep-filesstops managing a hook and leaves its entries in the Agent files as yours;hooks importoffers them again.hooks restorebrings back a backup of an Agent file without touching unrelated later edits.skillshare hooks disable check --sync
skillshare hooks remove check --keep-files
skillshare hooks restore BACKUP_ID --dry-run - Project hooks from the global config —
hooks.projectsholds hooks for other project folders, so one sync from the global config reaches each of them. - Removal cleans up after itself — removing a hook deletes a hook file Skillshare created once nothing else is left in it, together with the folders it created that are now empty. Files and folders that existed before, and anything you added, stay.
MCP
- Tool policy per server —
tools.allowandtools.denysay which of a server's tools reach the model. Write them once; sync translates them into Pi'stoolExposure, Codex'senabled_toolsanddisabled_tools, and Copilot'stools. Parts an Agent cannot hold, such as the whole policy for OpenCode and Kilo Code, are named in the sync plan and bymcp checkinstead of being dropped.skillshare mcp add github --target pi --target codex --tools-allow 'get_*,search_code' --tools-deny get_secret -- github-mcp
skillshare mcp edit github --tools-allow '' # clear the allow list
Dashboard
- Hooks page — add and edit hooks by picking each target's documented events, copy commands from another target's tab, or edit the native JSON with completion and checks. Every sync shows a diff of each file it changes. Import lists each target's hooks that Skillshare does not manage yet. Hooks also appear on target and project pages, on the Sync page and in Settings → Backups.
- Clear remove choices — removing a hook offers Remove and sync, Remove from source only and Stop managing; hovering or focusing a button explains what it does to the target files. In the hook and MCP remove dialogs, Remove and sync names the other pending hooks or servers that go out with it.
- Tools in the MCP server dialog — load a server's tool list with the dialog's current settings, even before saving, and tick the tools the model gets. The dialog says which selected Agents follow the policy fully, partly or not at all.
- Plan notices before an MCP sync — the MCP sync dialog and the Sync page list the plan's notices, such as Pi's built-in MCP needing Pi 0.99.0, before you sync.
- Open config.yaml at the right place — the config.yaml button in the Hooks and MCP page headers opens Settings → Files at the
hooks:ormcp:section. The field panel there explains everyhookskey.
Bug Fixes
- Script installs no longer need administrator access —
install.shnow installs to~/.local/binby default;INSTALL_DIRstill overrides the location. When that folder is not on your PATH, or an olderskillsharesuch as/usr/local/bin/skillsharecomes first, the installer says so and prints the PATH line to add. Remove the old copy (sudo rm /usr/local/bin/skillshare) so the new one runs. - Stop managing an MCP server works in the dashboard — Stop managing in the MCP remove dialog always failed with a "changed since preview" error. It now succeeds, and its message says the entries stay in the Agent files.
- Beautify unfolds one-line YAML — in Settings → Files, Beautify left a section squeezed onto one line, such as
servers: {docs: {url: …}}, unchanged and said there was nothing to tidy. It now unfolds nested one-line sections; short lists such astargets: [claude, codex]stay on one line.
Breaking Changes
Pi MCP
- Pi uses only its built-in MCP — Skillshare now writes Pi's servers only to Pi's own
mcp.json(~/.pi/agent/mcp.json, or.pi/mcp.jsonin a project). It no longer writes forpi-mcp-adapterorpi-mcp-extension, and thepiExtensionchoice is gone. The first sync after upgrading moves your servers: entries Skillshare wrote tomcp-adapter.jsonare removed and written tomcp.json, andpi-mcp-extensionentries are rewritten in place. Entries you added tomcp-adapter.jsonyourself are left alone, andmcp import --from pistill reads them. - Needs Pi 0.99.0 or later — Pi added its built-in MCP in 0.99.0. On older Pi the moved servers stop loading until you update Pi. Skillshare does not check Pi's version; the sync that moves servers prints a warning.
- Remove the old extension from Pi — if
pi-mcp-adapterorpi-mcp-extensionis still installed in Pi, uninstall it. Pi's docs say an installed extension that registers/mcpreplaces the built-in MCP, andpi-mcp-adapter3.0.0 and later no longer readmcp.json. - Adapter-only server options are dropped — Pi's built-in MCP does not read these
piOptionsfields, so the next sync removes them from your config:approveTools,auth,bearerToken,bearerTokenEnv,bearerTokenStore,caFile,debug,exposeResources,idleTimeout,inheritEnv,lifecycle,protocolVersion,requestHeadersCommand,requestTimeoutMs,searchKeywords,socket,tasks,toolPrefix,trace. - No per-project off switch for Pi — Pi cannot turn off one global server in one project. The next sync removes
pifrom the targets ofdisabledentries, so that server is on again in that project. To keep a server off for Pi, setpiOptions: {enabled: false}on a complete entry. directToolsbecomes Pi's exposure —directTools: truebecomespiOptions.exposure: direct,"search"becomesdeferred, and a list of tool names becomespiOptions.toolExposurewith those toolsdirect.mcp.directToolsand a project's default are copied into each Pi server that sets none.piOptions.includeTools/excludeToolsbecometools.allow/tools.deny.- Removed flags —
--pi-extension,--direct-toolsand--pi-options-prunenow fail with a message saying what to use. Use--pi-options '{"exposure":"direct"}'or--pi-options '{"toolExposure":{"TOOL":"direct"}}'instead of--direct-tools. Sync always removes unchanged Pi fields Skillshare wrote earlier, so--pi-options-pruneis no longer needed. - Your config is updated on the first sync — the old config still loads, and
sync mcp --dry-runnames each retired setting. The firstsync mcp,sync --allor dashboard sync savesconfig.yaml(or thesources.mcpfile) without them, keeping the previous version in the file history.
[0.22.2] - 2026-09-30
New Features
MCP
- Check servers before an Agent starts them —
skillshare mcp checktells you whether each server will work as synced: afromEnvvariable that is unset, acommandnot found onPATH, a remote host that does not resolve, a server an Agent's rule refuses, and an Agent entry that conflicts with the source or is not synced yet. It starts nothing, writes nothing and never prints variable values. It exits 1 when it finds an error, so it fits in scripts. In the global config it also checks the servers undermcp.projectsand names their project.skillshare mcp check
skillshare mcp check docs github --json
skillshare mcp check --no-dns # skip the DNS lookup of remote hosts - Probe servers live —
mcp check --livealso starts each local server, or sends one request to each remote server, reports its name, version, protocol version and number of tools, and stops it again. A server that needs sign-in is a warning; Skillshare never signs in. Each probe gets 10 seconds, or--timeout, and configured values are removed from every message.skillshare mcp check --live --timeout 30s - Pi built-in MCP — Pi 0.99.0 includes MCP, and
piExtension: builtinsyncs servers into~/.pi/agent/mcp.json(.pi/mcp.jsonin a project) with no extension to install.piOptionstakes Pi's per-server fields such asexposureandtoolExposure, and import keeps them. A new server that goes to Pi without a mode now usesbuiltin; before,mcp add --target piwithout--pi-extensionfailed. Existing servers keep their mode.skillshare mcp add docs --url https://example.com/mcp --target pi --pi-options '{"exposure":"deferred"}' --no-tui - Remove cleared Pi settings — clearing a Pi setting stops managing it and leaves its value in Pi.
--pi-options-prune, or Remove cleared settings from Pi in the dashboard, removes the fields Skillshare wrote that nobody has changed since.skillshare mcp edit docs --pi-options '{}' --pi-options-prune --no-tui
Dashboard
- Check MCP servers — the MCP page and each project's MCP tab have a Check button in the Sync box once there are servers to check. It runs the same check as
mcp checkwithout--live, with a summary above the list and each problem under its server. - See every file Sync writes for a server — View what each Agent gets lists the Skillshare source and every target Agent's file, with its path and format (JSON, JSONC, TOML, YAML), and shows the one you pick with syntax highlighting. It counts the files Sync writes and names the scope: global, or the project.
- Pi settings in the server dialog — a Pi server chooses its Pi MCP mode, built-in by default, its tool exposure, other Pi settings as JSON, and Remove cleared settings from Pi. When a pasted snippet holds one server, the paste tab shows the same Pi settings.
- Tidier MCP page — the header keeps only Import from a target and Add server; Check and Backups and restore moved into the Sync box. Each server row shows its command next to its name and the Agents it goes to as chips below, and the Pi chip shows the Pi mode. Project MCP tabs use the same rows, and the MCP dialogs are wider.
Bug Fixes
- Shell completion matches the CLI — completion offered commands that did not work:
backup restorebacked up a target namedrestore,extras modeonly printed help,install --sourcefailed as an unknown option, andhub index --audit-skillswas rejected. Those are gone. bash, zsh, fish, PowerShell and Nushell now completemcp checkwith--live,--timeoutand--no-dns, subcommands such asbackup filesandaudit rules, and flags no shell offered before. - SSH failures say why — installing or loading a hub over SSH that failed showed only "Could not read from remote repository.". The message now keeps SSH's reason, such as
Permission denied (publickey),Host key verification failedor an unresolved host, and a denied key suggestsssh -T user@host. - Dashboard target links open the target — target rows on the dashboard, the Playful pin notes and the "needs attention" entries opened the target list. They now open that target's page.
- Chinese dashboard says 目標 and 目标 — buttons and messages such as "從 target 匯入" mixed the English word into Traditional and Simplified Chinese. They now say 目標 and 目标.
- Hubs page opens on the default hub — with no default hub saved, the Hubs page opened with nothing selected and Skillshare Hub had no default star, although
search --hubalready falls back to it. The page now stars Skillshare Hub in that case and opens on the default hub when you have no hub of your own. - Find skills no longer installs when it finds nothing — in the Install dialog, Find skills on a source with no skills or agents went on to install the whole source as one skill without a
SKILL.md, and so did Install on such a search result. The dialog now says nothing was found and installs nothing. - MCP restore preview keeps its size — switching backups resized the restore dialog while the preview loaded. It now stays the same size.
[0.22.1] - 2026-09-30
Bug Fixes
- Dashboard file editor no longer crashes — opening a file tab on a target page, such as
APPEND_SYSTEM.mdonpi, showed "Something went wrong — Unrecognized extension value in extension set". The dashboard bundled two copies of its code editor library; it now bundles one.
[0.22.0] - 2026-09-30
New Features
Dashboard
- Richer markdown preview — skill and file previews now render HTML such as
<details>, GitHub alerts,:::containers, emoji shortcodes,==mark==,++ins++,^sup^and~sub~, and footnote links resolve. HTML goes through a sanitizer, since previews show skills from anyone. Tables no longer squeeze short columns until words break, file previews keep single line breaks as the tool reads them, a leading---block counts as frontmatter only when it is YAML, and outside links open in a new tab. - Failed sync targets listed first — when a dashboard sync loses a target, the Sync page now lists each failed target with its part (Skills, Agents, Extras or Config) and error above the other warnings, marks it in the change list, and shows a warning toast instead of Sync complete. Each failure gets a plain-language explanation for common causes (a symlink pointing elsewhere, permission denied, a read-only disk, a file where a folder belongs, a missing path, invalid target settings). A skills symlink that points elsewhere offers Turn on Force. The Last sync card names the failed targets, and the project sync dialog shows the same list instead of a success note.
Bug Fixes
Sync
- Dashboard sync keeps going after a target fails — the first skills target that failed stopped a dashboard sync with an error, leaving every later target unsynced and agents, extras and MCP not run. Like
skillshare sync, the failed target is now reported as<target>: sync failed: <err>and the rest still sync; the operation log records it aspartial. - Invalid target settings fail only that target — one target with invalid settings, such as a path that is a file instead of a folder, or a project target without a path, stopped the whole
sync,sync -pand dashboard sync before anything ran. That target is now skipped with its error and the others still sync. - Project dashboard works with a target that has no path —
skillshare ui -pwould not start, and a running project dashboard failed every request, when a custom target had noskills.path. It now starts with a warning, and its sync lists that target as failed. sync -p agentschecks settings and is logged — it synced agents into targets with invalid settings and left no entry inskillshare log. It now skips those targets, exits non-zero, and logs the run likesync agents.- Dashboard sync reports every failed target when all fail — when every skills target failed, the dashboard showed only the first error, and agents, extras and MCP were not synced. It now lists every failed target the same way as a partial failure.
- Agent failures counted in the operation log — a target whose agents failed to sync was left out of the sync entry's
targets_failed, so a partly failed sync could be logged asok. The entry now counts it and listsfailed_targets. - Prune failures reported — when removing orphaned skills or agents from a target failed,
syncand the dashboard said nothing and stale links stayed behind. They now show<target>: agents prune failed: <err>(orprune failedfor skills) along with the prune's own warnings. - Dashboard respects symlink conflicts — in symlink mode, a target folder linked somewhere else was replaced by a dashboard sync without the conflict message
skillshare syncshows. Without Force it now fails withconflict - symlink points to X (use --force to override). sync --allexits non-zero when an extras target fails — it printed a warning and exited 0, and with--jsonignored extras errors entirely. It now fails in text and JSON, global and project, and the dashboard's operation log records extras failures aspartialinstead ofok.- An extras failure no longer stops a dashboard sync — the first failed extras target ended the run: the skills result and warnings already on screen were dropped, MCP was never written, and the error named neither the extra nor the target. The sync now finishes and lists every failed extras target.
- Missing extras source is skipped, not created — global
syncand the dashboard created an empty source folder for an extra whose source did not exist, which hid a misconfigured path. Every sync now skips that extra and saysSource directory does not exist: <path>. - Dashboard skips extras targets the agents sync writes — like the CLI, a dashboard sync no longer writes the
agentsextra into a target folder that the agents sync already manages, so the two stop fighting over it. - Context-cost warnings name the right target — the dashboard's sync warnings showed
{target}instead of a name, and when several targets tied, listed offenders from a different target than the one named. They now name the target, and ties go to the alphabetically first one with its own offenders.
Tracked repositories
- Unreadable git status no longer treated as clean — when skillshare could not read a tracked repo's git status (for example, a corrupt index),
updatepulled over it,uninstallmoved it to trash after a warning, andstatusandlistshowed it as up to date.updateanduninstallnow fail that repo withfailed to check git status: <err>unless--force, while other items in the batch still run;statusandlistshow it as unknown with a warning, andstatus --jsonreports"status": "unknown". The error now includes what git printed, not justexit status 128.skillshare update --all --force # pull even when git status cannot be read - Dashboard checks private repos with your token — the dashboard's update check fetched without the HTTPS token, so private tracked repos and skills without a pinned branch reported errors that
skillshare checkdid not. It now uses the same check as the CLI.
Project mode
- Project uninstall reports the real problem — every name that could not be resolved was reported as "not found", even when it matched several nested skills or pointed at a file. Project mode now gives the same specific errors as global.
- Project uninstall logs like global — the operation log recorded
--help, dry runs and declined prompts as uninstalls, always with zero succeeded. It now records one entry when the uninstall ran, with the real count, and uninstalls from the projectlistview are logged too. logs/,trash/andbackups/stay out of your project's.gitignore— in projects created before 0.17.3, project uninstall added them to the project's own.gitignoreinstead of.skillshare/.gitignore.
CLI
searchshows mixed-case skill names — skills named likeMySkill, whichinstallaccepts, never appeared insearchresults. Search now uses the same name rule as install.
Dashboard
- Revert on ignore-file tabs — on the
.skillignoreand.agentignoretabs of the Config page, Revert resetconfig.yamland left the ignore file's edits in place. It now resets the file the tab has open. - Install dialog marks the right skills as installed — the dialog matched installed skills by name only, so a skill with the same name from another repo showed as Installed. It now matches by source.
- Path overlap warning translated — the Sync page showed the overlap warning in English in every language. It is now translated and has a button that opens Health Check.
- Target-only resources grouped by target — the Sync page's list of resources that exist only in targets was one comma-joined line. Each target now has its own group with its logo and count.
- Failed target settings no longer reported as saved — batch target updates reported success even when saving the settings failed, so an override could disappear on the next reload. They now show the error.
- Sync page in Chinese, Japanese and Korean — the Playful theme's handwritten note on the Sync page repeated the subtitle and, with no CJK glyphs in its font, showed as stray large text. It has been removed.
- Selected tool in Add target — the picked tool now uses the same highlighted row as the collect and install dialogs, instead of an inset ring.
Breaking Changes
updateanduninstallstop on an unreadable git status — a tracked repo whose git status cannot be read now fails instead of being treated as clean. Scripts that runupdate --allunattended should expect a non-zero exit for such a repo, or pass--forceto pull anyway.sync --allexits non-zero when an extras target fails — it used to warn and exit 0.sync --jsonalso reports the failure.sync -p agentsexits non-zero for a target with invalid settings — it used to sync agents into that target and exit 0.- Missing extras sources are no longer created — sync used to create an empty source folder for an extra whose source did not exist. Create the folder yourself or fix the path in the config.
POST /api/syncreturns 200 when every target fails — the dashboard API used to answer 500 with the first error. It now returns the usual result with every failed target infailed; check that list instead of the status code.
[0.21.17] - 2026-09-29
New Features
Dashboard
- Edit Pi's APPEND_SYSTEM.md on its target page — the
piandomptarget pages have an APPEND_SYSTEM.md tab next to the instruction file, so you can edit the text Pi appends to its system prompt without leaving the dashboard. + adds a tab for any other file a tool reads, including files in subfolders; the dashboard saves them under the target'sfiles. Three tabs show at a time and the rest move to a menu; removing a tab doesn't delete the file. Refs: #301.Paths stay inside the tool's folder (targets:
pi:
files:
- SYSTEM.md
- prompts/review.md~/.pi/agentfor pi,.piin a project). Share with Extras on a tab opens Add extra filled in with the file's folder and name, so one file can be shared across tools.
Extras
- Single-file extras named after their file — in Add extra, a single file's Name follows its file name without the extension (
APPEND_SYSTEM.mdgivesAPPEND_SYSTEM) until you type one, and the hint suggests using the file name. Refs: #300.
Bug Fixes
- Ticking an Agent after importing from it takes its entry over — importing an MCP server from an Agent without ticking that Agent, then ticking it later, left the Agent's entry unmanaged: no sync was offered, nothing was recorded in
state.json, and unticking the Agent removed nothing. The preview now lists the entry as Take over; sync records it as managed without changing the file, and unticking the Agent afterwards removes it. A server you turned off in the Agent itself is still never claimed. Refs: #303. - MCP tab for
antigravity-cli— theantigravity-clitarget page now has an MCP tab, showing the~/.gemini/config/mcp_config.jsonfile it shares with Antigravity. - Dialogs keep focus on their first field — dialogs that focus a field when they open, such as Add extra, moved focus to the close button instead.
- Pi's logo in its brand colors — Pi now shows its coral, blue and yellow logo instead of a black mark.
- Sync page lists you can scan — the expanded targets in sync list was one comma-separated line mixing global targets with
<project>@<tool>ones. It now shows logo chips, global targets apart from each project's. The ignored list is grouped by.skillignoreand.agentignoreand by folder, so a prefix such assecurity/is written once.
[0.21.16] - 2026-09-29
New Features
Sync
- Targets that undo each other's sync — when two targets sync skills into the same folder with different include or exclude filters, each sync adds what one wants and removes what the other filters out, so
synckeeps showing the same changes.sync,doctorand the dashboard's Sync page now name both targets and the folder and suggest keeping one (universalwhen it is one of them); the Sync page has a button that stops syncing skills for the other.Targets with the same filters in one folder are not reported.skillshare target codex --skills=false # let universal alone write ~/.agents/skills
Dashboard
- Plugin version and logo without an Agent — a plugin added without picking an Agent now shows its version, and the logo from its Codex manifest (
interface.logo, up to 1MB) in the Plugins list and the add preview, instead of the default icon.
Bug Fixes
- No false "also reads" note for a shared folder — a target sharing its skills folder with another, such as
codexanduniversalboth on~/.agents/skills, was told it also reads the other's skills and sees each one twice. It holds one copy, so the note no longer appears. - Duplicate skills described accurately — the dashboard and docs said each skill "shows up twice" when a tool reads two skills folders. Pi keeps the first and warns, and Gemini and others pick one, so they now say the tool finds each skill twice.
- Antigravity no longer counted as reading
~/.agents/skills— Antigravity documents only~/.gemini/config/skillsas the desktop app's global skills folder, so switching its skills off no longer claims it still seesuniversal's skills.
[0.21.15] - 2026-09-29
New Features
Targets
- Switch skills off for a target — a target can now stop syncing skills while skillshare keeps managing its agents, MCP servers and instructions. Use it for a tool that also reads another target's folder, such as Pi reading
~/.agents/skillsofuniversal, so each skill no longer shows up twice. Turning skills off savesskills.enabled: falseand removes only the links into your source: your own skills stay, copies from copy mode are kept and listed apart, and a folder another enabled target writes to is left alone.sync,diff,statusanddoctorthen skip the target's skills, andanalyzecounts what the folder still holds.Turn skills back on withskillshare target pi --skills=false --dry-run # preview what is removed
skillshare target pi --skills=false
skillshare target add gemini ~/.gemini/skills --no-skills--skills=true; the nextskillshare syncsyncs them again. Works in project mode with-p. - 10 more targets —
autohand-code,fx,jazz,kimchi,kimi-code,ona,posit-assistant,qoder-cn,reasonixandzcode, with the folders each tool also reads recorded so the dashboard can tell you when two targets overlap. - More vendor logos — more targets show their vendor's colored logo instead of a letter.
Dashboard
- Stop syncing skills from the target page — Stop syncing skills on a target's Skills tab lists what will be removed and what stays before anything changes, and warns when other tools read the same folder and would lose those skills. The dashboard's target list shows such targets as Skills off.
- See who else reads a skills folder — a target's Skills tab names the targets that stopped syncing skills and read its folder instead, and the other folders a tool also reads, so you can spot skills that load twice.
- Adding a target shows what it writes — the add dialog pins
universalas the shared folder when it is not configured yet, and for the picked tool lists every place skillshare will write: the skills folder (with a switch to add it with skills off), the agents folder, the MCP config and the instruction file. - Where a target's AGENTS.md comes from, in one card — the AGENTS.md tab now shows one card with the shared file the target follows or imports, the other targets using it, and the actions for it. Change switches the target to another shared AGENTS.md in place; Edit opens the shared file. The tab opens in Preview when the file has content, Show all expands it to its full length, and Save appears once there is something to save.
Extras
- Several single-file extras in one source folder — in the Add extra dialog, a single file's Source file is one path: the source folder, then the file name. The folder defaults to the extra's name; click a folder another single-file extra uses, or type a new one, and each extra syncs its own file from it. Project extras now accept
--sourcetoo, relative to the project root, so a project can share a folder the same way. Removing an extra keeps files the others still use. Refs: #300.skillshare extras init review -p --source .skillshare/extras/prompts --file review.md --target .pi
skillshare extras init append -p --source .skillshare/extras/prompts --file append.md \
--target .pi --as APPEND_SYSTEM.md
Bug Fixes
- Windows paths of single-file extras use backslashes throughout — the Extras page showed paths such as
~\.pi\agent/APPEND_SYSTEM.md, with a slash before the file name. Refs: #300. - Kilo Code's AGENTS.md location — the dashboard suggested
~/.kilocode/AGENTS.md, a folder Kilo never reads. Thekilocodetarget now uses~/.config/kilo/AGENTS.mdglobally andAGENTS.mdin a project, as Kilo documents; Change location on its AGENTS.md tab sets another path such as~/.kilo/AGENTS.md. Refs: #302.
Breaking Changes
- The
zencodertarget moved to.agents/skills—~/.agents/skillsglobally and.agents/skillsin a project, because Zencoder now documents that location and reads.zencoder/skillsonly for backward compatibility. A global config stores full paths, so an existing one keeps its path. A project config stores target names only, so it follows the new default on its nextsync -p, which also removes the links skillshare left in the old folder; folders you made by hand there are kept. replitis project-only — Replit documents only the project.agents/skillsfolder, so the target no longer has a global default path. An existing globalreplittarget keeps the path in your config.
[0.21.14] - 2026-09-29
New Features
Install
- Pin a skill to a tag or commit from its web URL — the branch, tag or commit SHA after
tree/orblob/in a GitHub URL (-/tree/on GitLab,src/on Bitbucket) is now the install ref, so a pasted URL installs the version it names.skillshare updatekeeps the pin. A ref the remote no longer has, such astree/master/after a rename tomain, fails the install instead of falling back to the default branch. Branch names containing/are matched against the remote's branches and tags,tree/HEAD/links use the default branch, and--branchstill overrides the URL. Refs: #293.Skills installed earlier from askillshare install github.com/team/skills/tree/v1.2.0/skills/footree/<ref>/URL got the default branch, andupdateandskillshare installfrom config keep them there. - Pin hub entries — a hub index entry whose
sourcenames a ref installs that revision for everyone, fromskillshare search --huband the dashboard's Hubs page. Move the pin by editing the ref in the index. Pinned skills from one repo and ref still share one clone. Refs: #293.{ "name": "reviewer", "source": "github.com/owner/repo/tree/v1.2.0/skills/reviewer" }
Extras
- Sync any single file —
skillshare extras inittakes--fileto sync one file from the source folder instead of the whole folder, and--asto give it a different name at the targets. Use--add-target <path> --as <name>for a different name per target.initonly writes the config: it does not create the source file or sync. Refs: #300.In global mode, several single-file extras can share oneskillshare extras init pi-prompt --source ~/dotfiles/prompts --file system.md \
--target ~/.pi/agent --as APPEND_SYSTEM.md--sourcefolder, each syncing only its own file.extras listshows the full source and target file paths, and theextras initwizard asks whether to sync a folder or a single file. - Single files on the dashboard — the first Extras tab is now Folders & files and lists every extra except shared AGENTS.md files. Add extra can create a single file, with a file name per target and
merge,copyorimportmode.
Dashboard
- One Hubs page for browsing and building — browsing a hub and building your own are now the same page: your hub is shown the way others will see it and edited in place. Entries can be added from any repository URL, with a branch or tag picked from the remote, and skills added from installed ones keep the version they were installed from.
- Backups grouped by day — Settings → Backup groups folder backups by day with one compact row per backup. Opening a row lists each folder with its file count and size, and its own Restore button. The page says what it is doing while backups load and while Back up now runs.
Docs site
- llms.txt for AI tools — the docs site now serves
llms.txt, an index of every page, andllms-full.txt, the full English docs in one file, so you can point an AI assistant at the docs. Both are linked from the site footer.
Bug Fixes
Dashboard
- Previewing your own hub shows it — previewing a draft from the hub builder opened an empty "pick a hub" page instead of the draft.
- Counts of one read correctly — labels such as "1 skills", "1 of 1 targets" and "1 backups" now use the singular in every language.
- The dashboard no longer looks stuck after an upgrade — restarting after
skillshare upgradedeleted the UI files the upgrade had just downloaded, so the server fetched them from GitHub again. On a slow connection that outlasted the reconnect wait. - The project-mode note no longer says Backup is hidden — Settings → Backup appears in project mode, scoped to the project.
Performance
- The Backup page opens faster — each snapshot folder is read once for its size and file count, instead of twice.
[0.21.13] - 2026-09-28
New Features
Dashboard
- Choose how each tool gets a shared AGENTS.md — on Extras → AGENTS.md, every connected tool now has a mode dropdown:
importadds one@importline and keeps your own lines,symlinklinks the file, andcopywrites a copy. Saving the shared file in the dashboard updates the copies right away. Switching back toimportbrings back your own content, including edits you made while inimportmode. Refs: #299.skillshare ui - See what a restore puts back before it happens — turning a tool off, or Restore all, first shows the file the tool will have afterwards, with a diff against what it has now.
- Move a tool's instruction file — Change location on a target's AGENTS.md tab sets a custom path and file name for any supported tool, not only custom targets. A folder is refused, and the option is off while a shared file is connected.
- Put a shared AGENTS.md in any folder — under Other locations, Add location writes the shared file into a folder that is not in the targets list, under its own name or another one such as
instructions.md, assymlink,copyorimport. Each location has its own mode, and Remove shows the restore preview first. In a project, shared files move from the Folders tab to the AGENTS.md tab, with the same locations relative to the project root. Refs: #299. - Preview everywhere, and Cmd/Ctrl+S on the target page — every box that shows an AGENTS.md has Preview and Source (or Edit) tabs, long lines wrap, and the shared file's card opens in Preview. The target page editor saves with Cmd/Ctrl+S and asks before you leave with unsaved edits.
- Update progress — the Updates tab on Skills and Agents shows a progress bar, marks the row being updated, and moves blocked or failed updates into their own section with a one-line reason.
Backups
- Manage every backup from Settings → Backup — the tab now has three sections. Target folders lists snapshots with a filter by target or agents, and can delete one. Files lists each AGENTS.md, CLAUDE.md or shared-file location skillshare backed up before rewriting it, with each version's reason (converted,
@AGENTS.mdadded, edited, collected, overwritten…), a diff preview, and restore. MCP lists MCP config backups by agent and what each changed. The tab now appears in project mode too, scoped to the project. Refs: #299.skillshare backup files # files with backups
skillshare backup files show ~/.claude/CLAUDE.md
skillshare backup files restore ~/.claude/CLAUDE.md <id>
skillshare backup --delete 2026-09-28_10-52-00skillshare backup filesis now a subcommand; to back up a target namedfiles, useskillshare backup -t files. In a project,backup --list -pandbackup --cleanup -pwork on the project's agent snapshots.
Extras
- Attach a single-file extra under another name —
--add-targettakes--asto pick the file name in the target folder, such asinstructions.mdin a notes folder.skillshare extras <name> --helpnow prints that extra's options.skillshare extras personal --add-target ~/work/notes --as instructions.md --mode symlink
Bug Fixes
Windows
- AGENTS.md no longer shows up as a folder — single files were linked with directory junctions, which tools read as a folder. Files are now linked with file symlinks, and when Windows can't create them (Developer Mode off and not an administrator), skillshare writes copies and keeps them up to date instead. The dashboard marks
symlinkas unavailable and explains why. Refs: #299. - Junctions are recognized as links again — since Go 1.23, a junction is no longer reported as a symlink, so skills synced as junctions could be reported as local folders by
status,doctor,syncand the dashboard. - The AGENTS.md tab shows the file name on Windows — a target's instructions tab was labeled with the whole Windows path instead of its file name, such as
CLAUDE.md.
Extras
- One shared file per linked or copied tool — a tool whose file is a link to, or a copy of, one shared file could also be connected to another shared file. The import line was then written through the link into the other shared file, and every tool reading it picked it up. The dashboard, Connect all,
--add-target,--modeandsync extrasnow refuse this and name the file that holds the tool. - Your files are kept in more cases — an instruction file that is a link into your dotfiles is left as it was after restore; a missing end marker no longer duplicates the managed block; replacing a link you pointed elsewhere is reported and recorded; and the managed block follows the file's CRLF line endings.
- Project imports use relative paths — in project mode the
@importline written into a committedCLAUDE.mdpointed at an absolute path in your home folder. It is now relative to the file, so it works for everyone and after the project moves. - Clearer status for single-file extras —
extras list -pno longer reports correctly synced relative links as drift; an edited copy showsmodifiedand can be collected from the dashboard; an invalidmodeinconfig.yamlis no longer shown as healthy; andsync extras --dry-runsays when an edit would be backed up and replaced. sync extras --jsonexits with an error when a target fails — it used to exit 0 while the plain output exited 1.
Dashboard
- Agents backups can be restored from the dashboard — restoring a
<target>-agentssnapshot failed with "target not found". - Messages about shared AGENTS.md files are translated — warnings and errors from mode changes, connecting, moving and restoring used to appear in English in every language.
- Empty rules folders are left out of the read order — a target's AGENTS.md tab listed
~/.claude/rules/even when it held no rule files.
CLI
NO_COLORis honored everywhere —status,doctor,extras listand about twenty other commands still printed colors withNO_COLORset.
[0.21.12] - 2026-09-28
New Features
Dashboard
- Edit the instruction files of tools that get skills through universal — Codex, Gemini CLI, Pi and other tools read skills from
~/.agents/skills, but none of them reads~/.agents/AGENTS.md, so with onlyuniversalas a target their own files, such as~/.codex/AGENTS.md, had no page. Universal's AGENTS.md tab now has a dropdown with each of these tools that is installed and isn't a target of its own; pick one to see and edit its file. They also appear in the shared AGENTS.md list under Extras, so a shared file can be connected to them. Cline and the Warp Agent CLI read~/.agents/AGENTS.mditself, and are now shown as sharing universal's file.skillshare ui
Bug Fixes
Targets
- Removing a target no longer takes skills away from another target in the same folder —
codexanduniversalboth write to~/.agents/skills. Removing one of them turned the other's synced skills into local copies that skillshare no longer managed. The folder is now left alone while another target still uses it, andtarget removesays so, including with--dry-run.skillshare target remove codex --dry-run
Upgrade
- A skill left owned by root now says how to fix it — an upgrade run with sudo before v0.21.10 wrote the built-in skill as root, and every later upgrade failed with only
permission denied. The error now includes thechowncommand that gives the skills folder back to you.
[0.21.11] - 2026-09-27
New Features
Dashboard
- More tools' instruction files are filled in — the instruction file tab on a target page now knows the file 22 more targets read, instead of asking you for its path. For example,
universalreads~/.agents/AGENTS.md,pireads~/.pi/agent/AGENTS.md,copilotreads~/.copilot/copilot-instructions.mdandqwenreads~/.qwen/QWEN.md. A file you already have at that path shows up with no setup. The full list is in Share one AGENTS.md across your tools.skillshare ui
Bug Fixes
Dashboard
- Reloading a page other than the first one no longer hangs — opening or refreshing an address such as
/targets/claudeasked for the page's scripts in the wrong folder, so it stayed on its loading placeholder and the browser console showedFailed to load module scripterrors.
Plugins
- Opening a plugin no longer downloads its source again — expanding a plugin to see which other Agents can take it cloned its whole repository every time, which could take tens of seconds. Skillshare now reads the copy it reviewed when the plugin was added, and downloads the source only if that copy was changed.
- Clearer messages while a plugin source is read — when a source can't be reached over the network, or the repository or branch doesn't exist, the dashboard now says which, instead of a general git failure. It also says when you are offline, and when reading a source or asking an Agent's CLI is taking a while. For example,
codex plugin listcan wait on Codex's remote marketplace; Skillshare waits up to 90 seconds for each Agent.
[0.21.10] - 2026-09-27
New Features
Dashboard
- Share one AGENTS.md across your tools — the Extras page has a new AGENTS.md tab. Create a shared
AGENTS.mdand choose which targets read it. Claude has no user-levelAGENTS.md, so it gets an@import in~/.claude/CLAUDE.mdand keeps its own content; Codex, Gemini and other targets get a link in place of their file, which is backed up first. Several shared files can sit side by side, such as one for personal and one for work, and targets that follow@imports can use more than one. Restore asks first, then puts back exactly what the target had before it was attached.skillshare ui - Edit each tool's instruction file — every target page has a tab named after the file that tool reads, such as CLAUDE.md, GEMINI.md or AGENTS.md. It shows the read order, an editor, and warnings such as Windsurf reading only the first 6,000 characters. Convert… moves the content of
CLAUDE.mdintoAGENTS.mdby import, rename or copy, and backs up the file first. AGENTS.mdin projects — in project mode the tab shows whether each target reads./AGENTS.md, and adds a small fix for tools that only read their own file, such as@AGENTS.mdinCLAUDE.md.- Tools skillshare doesn't know — a custom target can say which instruction file it reads, in the Custom target dialog when you add it or later from the same tab. The setting is saved as
instructionson the target:targets:
myagent:
path: ~/.myagent/skills
instructions:
path: ~/.myagent/AGENTS.md
import: true # the tool follows @path lines - See which projects a skill reaches — on the Skills page, the Targets column shows your global tools as icons, followed by a folder badge with the number of projects the skill is synced into. Before, each project repeated its tools' icons, so
claudeplus two projects showed three Claude icons. Hover to see the global tools and each project's tools, including projects the skill does not reach. The Target filter now groups global tools and projects, with one entry per project, and in the tree view the Targets row shows where the selected skill actually goes. Refs: #297.
Extras
- Single-file extras — an extra with
filesyncs one file instead of a whole folder,asrenames it per target, and the newimportmode writes an@line into the target's own file instead of replacing it.extras listshowsmodifiedwhen a linked target was replaced by a different file, andextras removeputs back what each target had before the first sync.extras:
- name: personal
file: AGENTS.md
targets:
- path: ~/.codex
- path: ~/.claude
as: CLAUDE.md
mode: import
Bug Fixes
Git sync
- A pull that fails midway no longer leaves the remote's files behind — when git could not finish a pull, for example because a file in the source folder was owned by root, the files it had already written showed up as local changes. The dashboard then blocked the next pull and suggested committing them, which would have pushed stale content back. A failed pull now restores those files and leaves your own edits alone, and a permission failure shows the
chowncommand that gives the source folder back to you.
Upgrade
- Upgrading with sudo no longer leaves root-owned files in your home — when the binary lived in a root-owned folder,
upgraderan entirely under sudo, so the built-in skill, dashboard assets and logs were written as root and a latergit pullof the skills source failed withPermission denied. Only the binary replacement now runs with sudo.skillshare upgrade
MCP
- Pi servers load again with
pi-mcp-adapter3.0 — the adapter stopped reading Pi'smcp.jsonand now readsmcp-adapter.jsonin the same folder, so servers synced for it were ignored. Skillshare now writes them to~/.pi/agent/mcp-adapter.json,.pi/mcp-adapter.jsonin a project, ormcp-adapter.jsonin a Pi account's folder. The next sync removes the entries Skillshare had written tomcp.jsonand leaves your own there. If you already renamed the file as Pi's warning suggests, Skillshare keeps managing the entries you moved.pi-mcp-extensionstill usesmcp.json. Refs: #298.skillshare sync mcp
[0.21.9] - 2026-09-26
New Features
Dashboard
- Turn a whole folder or tracked repo on or off — the tree view on the Skills and Agents pages now shows the folders on the left and what you selected on the right. Selecting a folder or tracked repo gives one switch that enables or disables everything inside it, and each skill is listed with its own switch. Cmd/Ctrl-click adds to the selection and Shift-click selects a range, so the same switch works on any set of skills. A disabled skill is marked with a power-off icon in place of its usual one. The divider between the two sides can be dragged. Refs: #295.
- Targets for skills in tracked repos — setting targets on a tracked repo, one of its subfolders or a single skill in it used to be refused. It now works, and the setting is kept outside the cloned repo, so the repo stays clean and
skillshare updatekeeps it. Refs: #295. - Filter and group by folder — the list and cards views have a Folder filter, and grouping has a Folder option, so skills installed into a folder can be seen one folder at a time or side by side. A tracked repo counts as one folder, and skills at the top of the source are grouped under Root.
skillshare install ~/my-skill --into frontend - A shorter toolbar on the Skills and Agents pages — the Source, Status, Target and Folder filters are now chips that show only their name until set; a set filter shows its value and a button to clear it. Grouping and sorting share one menu, and expand all / collapse all in the tree view is one button.
Bug Fixes
Sync
- Skills under a dot folder are no longer reported missing — a source skill in a folder such as
.system/syncs to a target entry starting with a dot, which target scans skipped.diff,doctor,statusand the dashboard reported these synced skills as missing, andsyncdid not prune them after the source skill was deleted. Refs: #294.
Dashboard
- One Agent's plugin error no longer breaks the Plugins page — when an Agent's plugin list could not be read, for example OpenCode with both
opencode.jsonandopencode.jsonc, the whole Plugins page failed to load. That Agent now shows its error and the other Agents work as usual. Refs: #296. - The dashboard server no longer risks crashing under overlapping requests — changing a skill while another request was being handled could crash the server.
[0.21.8] - 2026-09-25
New Features
Git sync
- See what the remote has before you push — opening the Git Sync page fetches from the remote, and Pull shows how many commits are waiting, such as Pull 2 commits, so a machine that is behind finds out before a push is refused.
.metadata.jsonconflicts resolve themselves — every install or update rewrites.metadata.json, so pulling after two machines had both installed or updated skills almost always conflicted there.pullnow merges that file skill by skill; when both machines changed the same skill, the one installed later wins. A conflict in any other file stops the pull, undoes the merge and names the files, so the repository is never left half-merged.skillshare pull
Bug Fixes
Git sync
- Pulling after both machines committed — once this machine and the remote each had commits the other lacked,
pullfailed withNeed to specify how to reconcile divergent branches, in the terminal and on the Git Sync page, and the only way out was git in a terminal.pullnow merges the two histories.skillshare updatedoes the same for a tracked repository with local commits. - A refused push offers Pull — when the remote had newer commits, Push on the Git Sync page showed git's raw
rejectedmessage. It now says to pull first and puts a Pull button next to the error.
[0.21.7] - 2026-09-24
New Features
Extras
- Pull target edits back with
extras collect --force—collectskipped every file that already existed in source, so an edit made directly in a copy-mode target could not be brought back. With--force, the target's version overwrites the source file. Files whose content already matches are still skipped, and withflatten, a second target file with the same name is reported instead of overwriting the first.Refs: #291.skillshare extras collect rules --force
Bug Fixes
Extras
- Collecting from a copy-mode target keeps its files —
extras collect, in the terminal and in the extras list, replaced each collected file in the target with a symlink, even when the target usesmode: copy. Copy-mode targets now keep their files. Refs: #291. --fromfinds the target however its path is written —extras collect --fromonly matched a target written exactly as inconfig.yaml, so/Users/me/.claude/rulesor a trailing slash did not match~/.claude/rules, and the target'smode,flattenand extension settings were ignored. Paths are now compared after expanding~. Refs: #291.
[0.21.6] - 2026-09-23
New Features
Targets
- MCP servers on each target's page — a target whose Agent has an MCP config file now has an MCP tab with one row per server: its endpoint, whether this Agent gets it, and whether a change is waiting to be synced. Clicking a row adds the server to that Agent or takes it out, saved right away. As on the MCP page, this only changes the source; Sync all targets then writes the MCP files of every target at once. Adding and importing servers, resolving conflicts and restoring backups stay on the MCP page. The Targets list also counts the MCP servers each Agent gets, next to its skills.
- A project's MCP on its targets in project mode — with
skillshare ui -p, the tab lists the project's servers, which go to its own files such as.mcp.json. For Claude Code, OpenCode, Kilo Code and Pi, it also lists the switches that turn a global server off in this project.
Sync
- MCP and project sync dialogs look like the Skills one — the dialogs behind Sync MCP and Sync project show one row per target instead of one line per item, as the Skills sync dialog does. An MCP row names the project of the Agent file and the servers that change, with counts such as 1 to add or 1 to turn off. Sync project still says which MCP entry is in conflict and why. The Sync page keeps the item-by-item list.
Bug Fixes
MCP connections
- Quick clicks on Agent toggles no longer undo each other — ticking two Agents in quick succession on the MCP page or a project's MCP tab could fail with an error and untick the first one again. Each toggle now waits until the previous one is saved.
- Turning a server off in a project for another Agent is saved — on the MCP page of
skillshare ui -p, ticking an Agent on a server that is off in this project also listed the project's other Agents, including ones that cannot turn a server off, such as Cursor, so the save was refused. Only Agents that can turn a server off in a project are listed now.
[0.21.5] - 2026-09-22
New Features
Targets
- A second account of Claude Code, Codex or Pi as its own target — when you run an Agent with a second config folder, such as a work account started with
CLAUDE_CONFIG_DIR=~/.claude-work, add that folder as a target and Skillshare works out where its skills and agents go. Codex (CODEX_HOME) and Pi (PI_CODING_AGENT_DIR) work the same way. In the dashboard, choose Add target → Another account; in the terminal:Inskillshare target add claude-work --agent claude --config-dir ~/.claude-workconfig.yamlthe target only records the folder:Refs: #289.targets:
claude-work:
agent: claude
config_dir: ~/.claude-work - Accounts receive MCP servers and plugins too — an account's name works wherever an Agent's does in
mcp.targets, a server'stargets,--targetand--from. Servers are written into the account's own file (.claude.json,config.tomlormcp.jsonin its folder), and plugins are installed with the Agent's CLI pointed at that folder, so one account can have a server or plugin the other does not.skillshare mcp import --from claude-workreads that account's servers. A Pi account needspiExtension: pi-mcp-adapter, sincepi-mcp-extensionalways reads~/.pi/agent/mcp.json. Refs: #289. - Removing an account says where MCP still names it —
skillshare target removeand the dashboard remove the target, then warn whenmcp.targetsor a server'stargetsstill lists it, since the next MCP sync would fail. Refs: #289.
Sync
- Sync one part from its own page — Skills, Agents and MCP each have a sync button that previews and writes only that part, and a project page has Sync project, which writes that project's skills, agents and MCP without touching global targets or other projects. The sync prompts after an update, uninstall or collect open the same dialog. Refs: #289.
MCP connections
- Stop managing a server without touching Agent files — removing a server always cleared its entries from the Agents on the next sync. Stop managing drops it from Skillshare and leaves the entries where they are, so the Agent keeps using it. It is the third choice in the dashboard's remove dialog and in the remove wizard:
Refs: #290.
skillshare mcp remove context7 --keep-files - Servers added to an Agent directly are pointed out — the MCP page and each project's MCP tab say which Agent files hold servers Skillshare does not manage, and Import opens on that file. Refs: #290.
- Pi adapter settings show on the server row — Direct tools are listed on a line under the endpoint instead of only on hover. Other adapter settings only say that they are set. Refs: #289.
Bug Fixes
MCP connections
- Importing a project's conflict uses that project's files — Import from an Agent on a project's conflict read the Agent's global file and wrote to the global source, so the project's own entry could never be taken over. Refs: #290.
- Pi adapter settings survive unticking Pi — unticking every Agent dropped Direct tools and
piOptions, so ticking Pi again reset the adapter. Refs: #289. - The MCP page no longer crashes on a cold load.
Dashboard
- Skill and agent pages list their projects — the Skills and Agents lists counted project targets, but the detail page only showed global ones. It now lists each project the skill or agent syncs to, with a link.
- Skills and Agents sync previews match the Sync page — they showed changes on targets that were already in sync.
CLI
- Global setup errors say they are about the global config —
skillshare ui -gwith a missing source folder said "source directory not found" and suggestedskillshare init, which then said Skillshare was already initialized. The error now says it is the global source, names the config, and tells you to create the folder or pointsources.skillsat an existing one.
[0.21.4] - 2026-09-22
New Features
Plugins
- Add a plugin without choosing Agents yet — leave every Agent unticked in Add plugin to keep the plugin in Skillshare without installing it anywhere. Its row shows No Agents yet; tick an Agent there when you want it, and the install preview uses the source as it is then. In the terminal, leave out
--target, or confirm the picker with nothing selected:A plugin added this way stays managed when its last Agent is removed.skillshare plugin add ./my-plugin --no-tui # keep it in Skillshare; choose targets laterskillshare plugin remove NAMEwithout--targetremoves it from Skillshare. - Versions are easier to see — each plugin's version is now a tag next to its name. After Check updates, a plugin whose source has a new version shows
1.0.0 → 1.1.0in the list and in the preview.
MCP connections
- Keep a server without sending it to any Agent — untick every Agent in the server dialog to keep a server in Skillshare while no Agent receives it, for example to take it out of use for a while without losing its settings. The next sync removes the entries it had, and ticking an Agent brings it back. Project servers work the same way. In the terminal, use
--target none; inconfig.yaml, an empty list:Refs: #289.skillshare mcp edit context7 --target none # stays in Skillshare, written to no Agent - Set other
pi-mcp-adapterfields from Skillshare — the adapter has per-server fields that Skillshare has no setting for, such asexcludeToolsandapproveTools. Put them underpiOptionsand they are written into the server's entry in Pi's file as given. The server dialog has a JSON box for them under Direct tools, which checks that the text is a JSON object before saving. In the terminal:A field removed fromskillshare mcp edit github --pi-options '{"excludeTools":["*emulator*"]}'piOptionsstays in Pi's file until you delete it there. Refs: #289.
Upgrade
skillshare upgradeshows download progress — on a slow connection the release download can take minutes, and the spinner alone made the upgrade look stuck. In a terminal it now shows how much has been downloaded, for the CLI and for the dashboard assets:Downloading v0.21.4... 3.2 MB / 9.1 MB
Bug Fixes
Plugins
- Pi and OpenCode are no longer blocked by a scoped npm name — a
package.jsonnamed like@owner/pkgmade both Agents show the plugin as blocked, although they install it by path. - Pi packages whose
package.jsonhas no name can be installed — they were blocked for Pi even when another manifest named the plugin.
Config
- Installing a plugin no longer reindents
config.yaml— saving a plugin rewrote the whole file with 4-space indentation. Every YAML file Skillshare writes, including skill and agent frontmatter andaudit-rules.yaml, now uses 2 spaces.
MCP connections
- An entry left behind by a deleted configuration can be taken over — when the Skillshare configuration that owned an Agent's MCP entry was moved or deleted, the conflict still said the entry was managed by another configuration and named a file that is no longer there, leaving no way forward in the dashboard. Such a conflict now reports the entry as left over, and Import from the Agent or Replace with source takes it over, in the terminal and from the conflict in the dashboard. A configuration that only cannot be read, such as one on a drive that is not mounted, still counts as present. Refs: #288.
- OpenCode project settings kept in
.opencode/are used — OpenCode also readsopencode.jsonandopencode.jsoncfrom a project's.opencode/folder. A file kept there was ignored, and sync created a second one at the project root. It is now the file Skillshare writes to; a new file is still created at the root. Refs: #289. - Turning a global server off in a project follows the project's Agents — the dashboard saved the switch with every Agent the global server reaches, including Agents the project does not use, and the list went stale when the project's targets changed. The switch now stores no Agent list and applies to the Agents the project uses that have a per-project switch. The row shows those Agents as logos and says which of the project's Agents still load the server. An entry saved by an earlier version shows Match the project to update it. Refs: #289.
- The Sync page says when a change only turns a server off — a project's switch for Claude Code is kept in
~/.claude.json, and it read like the global server being added or removed there. Such a change now says it turns the server off or back on, and names the project. A conflict on a switch offers only Replace with source, since importing reads the Agent's global file. Refs: #289.
Dashboard
- Agent logos show on Windows machines that report the wrong type for SVG files — a few larger logos, Antigravity among them, appeared as broken images on some Windows machines while every other logo was fine. Refs: #289.
- Going back to the global targets asks first — switching a project's MCP targets back to Same as global saved at once and dropped the project's own list.
- Status labels and Kilo Code messages follow the dashboard language — enabled on the Skills page, In sync on the Extras page, the Kilo Code project warning and the error for an unreadable pasted snippet stayed in English. Refs: #289.
[0.21.3] - 2026-09-21
New Features
Dashboard
- Analyze only the skills Skillshare manages — when a target also holds skills you added by hand, an Only skillshare-managed switch on the Analyze tab hides them, and the always-loaded and on-demand totals follow the switch. The dashboard remembers your choice. Local skills now show their folder name instead of an internal
synced/…path; the full path appears on hover and in the skill's details.
Bug Fixes
Plugins
- One bad entry no longer blocks a whole marketplace — a marketplace failed to load when one entry used an external source, pointed at a missing folder, or had an invalid or duplicate name. Such an entry is now marked in its own row with the reason, in your language, and the rest of the marketplace can be installed. When one catalog points a plugin at an external source and another at a folder inside the repository, the folder is used.
- Claude Code plugins without
plugin.jsoncan be installed — Claude Code does not require the manifest. Such a plugin is now read from its marketplace entry and its default folders, and aSKILL.mdat the plugin root counts as its only skill. Definitions in the entry, such asstrict: false,skillsandlspServers, and its version, are carried into the install. - Entries that share one folder install their own skills — when several entries in a marketplace pointed at the same folder and each listed its own
skills, every one of them installed the same content. - Plugins whose marketplace name differs from their manifest install in Claude Code — Claude Code installs such a plugin under the marketplace name, so it is no longer blocked there. Codex refuses the mismatch, so other Agents still show it as blocked.
- Each Agent installs from its own folder — when a marketplace ships a separate copy of a plugin for each Agent, every Agent now gets the copy made for it instead of the first one found.
- Broken links no longer block a plugin source — a single broken symlink anywhere in a repository, or one that pointed outside it, made every plugin in it fail. Such links are now left out of the install and listed in a warning. They are still never followed.
- Add plugin no longer preselects a plugin that cannot be installed — when the only plugin in a source was blocked, the dialog chose it for you.
- Pi's version is shown — Pi prints its version to stderr, so the plugin list showed it without one.
MCP connections
- View what each Agent gets shows a spinner while it loads — an empty dialog gave no sign whether the preview was still coming.
[0.21.2] - 2026-09-21
New Features
Projects
-
Manage many project folders from the global config — a
projects:key declares a folder once, with the tools used there.syncthen treats each one as a<project>@<tool>target with its own mode and filters, so you no longer list every project skills folder as a custom target or run project mode in each repo.# ~/.config/skillshare/config.yaml
projects:
~/work/project01:
targets: [claude, codex]
skills:
mode: copy
include:
- myskill-*
agents: {}skillshare sync --dry-run # preview
skillshare syncTools that share a project skills folder are written once. A project whose folder is missing is skipped with a warning instead of failing the sync, and
collectandtargetleave project targets alone. Refs: #286. -
MCP servers for many projects in one place —
mcp.projectslists project roots, each with its owntargets,serversanddirectTools. Onesync mcpplans the global files and every root together, and removing a root cleans up what was written there.# ~/.config/skillshare/config.yaml
mcp:
projects:
~/work/project01:
targets: [opencode, pi]
servers:
context7: # off in this project only
disabled: truemcp.projectsis refused in a project config. Adisabledentry works for Claude Code, OpenCode, Kilo Code and Pi withpi-mcp-adapter. For Claude Code the switch is written to~/.claude.json, where it keeps its per-project off list, and the server definitions in that file are left as they are. Codex is refused, because a switch for a server its global config lacks stops Codex loading its config at all. Refs: #286. -
Projects page in the dashboard — in global mode, a Projects page lists each project with Skills, Agents and MCP tabs. Adding a project takes a folder and its targets, and an ordinary target that already points inside a project can be converted. On a project's MCP tab, every global server has a switch that turns it off for that project.
Install
-
Project lockfile — project mode now writes
.skillshare/skills.lock.jsonnext toconfig.yaml. The config records which skills the project wants; the lockfile records the exact commit each one resolved to. Commit both, andskillshare install -pgives every teammate the same commit even after upstream moves on.skillshare install github.com/team/skills --all -p # writes the lockfile
git add .skillshare/ && git commit -m "Add team skills"
skillshare install -p # a teammate gets the locked commits
skillshare update --all -p # moves the pins forward; commit the lockfile againTracked repos are pinned too and stay on their branch, so they can still be updated.
update -pand the dashboard move a pin only for skills whose commit changed, a tracked repo with uncommitted changes is left alone, anduninstall -pdrops the pin. -
Pin an install to a tag or a commit —
--branchnow accepts a tag or a commit SHA as well as a branch name.checkresolves tags and skips the network for full SHAs, which can never move.skillshare install github.com/team/skills --branch v1.2.0 --all
skillshare install github.com/team/skills --branch 8f14e45fceea167a5a36dedd4bea2543ce848564 --all--trackis refused with a tag or a SHA, in the CLI and the dashboard, because a tracked repo needs a branch to pull. Refs: #281. -
Gitea and CNB sources — skills install from Gitea (gitea.com and self-hosted) and CNB (cnb.cool), including subdirectories and web URLs. Private repos use
GITEA_TOKENandCNB_TOKEN, and self-hosted instances are listed undergitea_hostsandcnb_hostsin the config, or inSKILLSHARE_GITEA_HOSTSandSKILLSHARE_CNB_HOSTS. Subdirectory installs download through each platform's contents API and fall back to a git clone. Refs: #168.
MCP connections
-
directToolsfor Pi —pi-mcp-adaptercan register a server's tools as individual Pi tools. Set it per server, as a default undermcp, or per project. It acceptstrue,false,search, or tool names separated by commas.skillshare mcp add docs --url https://example.com/mcp --target pi --pi-extension pi-mcp-adapter --direct-tools search --no-tui -
Edit MCP defaults in the dashboard — a Defaults section on the Servers tab edits
mcp.targetsandmcp.directTools, which could only be changed by hand before.
Analyze
analyzemeasures what each target actually loads — a symlink target exposes the whole source folder, so skills disabled in.skillignoreare now counted for it and flaggeddisabled. For merge and copy targets, skills you dropped into the target folder by hand are counted and flaggedlocal. Token estimates charge one token per wide character, so Chinese, Japanese and Korean text is no longer undercounted by roughly four times. The CLI, the TUI, the dashboard and the sync summary now report the same numbers.
Targets
-
antigravity-cliis its own target — the Antigravity CLI reads~/.gemini/antigravity-cli/skillsand never the app's folder, so as an alias ofantigravityit received skills in a folder it does not read. A path-lessantigravity-cli:entry in the config is now valid. -
Convert agents for a tool that reads a different format — an
extension:on a target'sagentsblock converts each agent while it syncs, reusing the extension mechanism of extras. The new built-inopencode-agentsturns Claude-style agents into OpenCode agents. It keeps only the fields OpenCode documents and addsmode: subagentwhen missing. It refuses agents that limit their tools (tools,disallowedTools,permissionMode), because dropping those would give the OpenCode agent every tool.codex-agentsworks here too and writes.tomlfiles. Converted targets are never collected back into your source. The dashboard sets the extension from the target's Agents tab, and the targets list tags a target that uses one. Refs: #267, #241.targets:
opencode:
agents:
extension: opencode-agents
Dashboard
- Beautify button in the config editor — reformats
config.yamlin the editor, keeping comments, so the result is visible and revertable before you save. - Expand the config editor — an Expand button opens the same editor and assistant panel in a near-fullscreen dialog, for files too long to read in the inline row. The dialog ignores backdrop clicks and Escape, so an edit in progress is never dismissed by accident.
- The install dialog opens on the URL tab — installing from a known repo URL is the common path. A
?install=searchlink still opens the search tab. - Copy the config path from the sidebar — a copy button appears on hover next to the truncated path.
- Analyze follows the target in the URL — target and project pages link straight into the analysis of that target, and project targets are listed after your own with their tool icon.
Documentation
- The docs site is available in four more languages — Traditional Chinese, Simplified Chinese, Japanese and Korean, at full parity with the English docs. The README is available in the same languages.
Bug Fixes
- A skill installed into a group reaches the project config —
install <git source> --into <group> -p, and installing a config entry that hasgroup:, wrote the skill's metadata into the group folder. The skill was then missing fromconfig.yaml, so teammates runninginstall -pdid not get it. Config installs were affected in global mode too. doctorsuggests removing the right target for a discovery overlap — it pointed at the target that owns the shared folder, such asuniversal, and removing that hides skills from every tool reading the folder. It now suggests removing the scanning target, such ascodex. Refs: #135.- Overlap warnings match each tool's documentation — the list of extra folders each tool scans covered nine targets and had drifted. Kimi no longer gets a false warning for
~/.agents/skills, and OpenCode, Goose, Copilot, Crush, Droid, Pi, Cline, Command Code, Deep Agents, Kilo Code, OpenClaw, OpenHands and Kode now get a warning when paired with a target whose folder they also read. Refs: #135. - The dashboard's Update now no longer hangs waiting for a password — when the binary lives in a root-owned folder, the upgrade waited up to ten minutes for a
sudoprompt nobody could see. It now fails at once and names the terminal command to run. Cached credentials andNOPASSWDsetups still upgrade. The release download also has a timeout. - A rejected target save in the dashboard changes nothing — when one field was invalid, such as a malformed include pattern, fields sent in the same save were still applied in memory and written by the next successful save.
- The Gitea token stays on the API host — a download URL on another origin is refused and the install falls back to a git clone, so a hostile server cannot collect
GITEA_TOKEN.
Breaking Changes
- The
codex,gooseandopenhandstargets moved to.agents/skills—~/.agents/skillsglobally and.agents/skillsin a project, because each tool now documents that location and reads its old folder only for backward compatibility. Withuniversalalso configured, the old default showed every skill twice. A global config stores full paths, so an existing one keeps its path and itsdoctoroverlap warning. A project config stores target names only, so it follows the new default on its nextsync -p, which also removes the links Skillshare left in the old folder; folders you made by hand there are kept. A freshinitsets up onlyuniversalfor Codex. Refs: #135.
[0.21.1] - 2026-09-20
New Features
MCP connections
-
Turn off a global MCP server in one project — a server in an Agent's global config loads in every project. In project mode, add an entry with the same name and mark it
disabledto stop it loading in that project only. The Agent keeps the command or URL from its global entry.cd my-project
skillshare mcp add company-docs --disabled --target claude --target opencode
skillshare sync mcp# .skillshare/config.yaml
mcp:
servers:
company-docs:
disabled: true
targets: [claude, opencode]Works with Claude Code, OpenCode, Kilo Code, and Pi with
pi-mcp-adapter. OpenCode, Kilo Code and Pi get a lone switch in their project file. Claude Code takes a whole entry from one scope, so Skillshare adds the name to that project's off list in~/.claude.json, the one the/mcppanel edits; a name you turned off yourself is never claimed or removed. Other clients are refused, because a lone switch would replace the server instead of turning it off. In the dashboard, open it from the project folder, choose Add server and pick Off in this project. Refs: #286. -
Kilo Code is an MCP client —
kilocodejoins the supported clients, in global and project scope. It uses OpenCode's format; Skillshare writes to whicheverkilo.jsoncorkilo.jsonalready exists and createskilo.jsoncwhen there is none. Kilo ignores a project config that holds an environment reference, sofromEnvandbearerTokenare refused for Kilo in project mode before anything is written. Refs: #287. -
Claude Code local scope servers are reported — a server added with
claude mcp addand no--scopewins, whole, over one of the same name in.mcp.jsonor the user scope. In project mode the plan and the dashboard now point out such a server next to the entry it hides, with the command that removes it. The sync is not blocked. -
Limits of each client are caught before the write — Claude Code skips the reserved names
workspace,claude-in-chromeandcomputer-use, and reads its own credentials such asANTHROPIC_API_KEYas empty in a remote server'surlandheaders; both are now refused for Claude with a message that says what to do. The dashboard's config preview refuses the same things saving would.
Dashboard
- Manual only skills are visible — a skill with
disable-model-invocation: truecarries a manual only tag in the skills list, on its tile and on its detail page, matching the badge the list TUI shows afterM. Refs: #283. - Add field explains each frontmatter field — the skill editor's Add field menu shows what each field does under its name, instead of bare keys such as
contextandshell. - Agent icons in the MCP import picker — the Agent dropdown in Import from a target shows each Agent's logo. Factory, LM Studio, Kilo Code and Claude Desktop now have their own icons.
Bug Fixes
- The MCP page detects Agents that have no MCP file yet — detection looked only for the MCP file, so a fresh Claude Code install showed as not detected. An Agent's own settings folder now counts. In project mode the page listed every Agent as detected; it now lists those with a project MCP file or a global install.
- Cline's MCP settings are found again — Cline moved its settings to
~/.cline/data/settings/, shared by the VS Code extension, the CLI and the SDK. Skillshare now writes there and honorsCLINE_MCP_SETTINGS_PATH,CLINE_DATA_DIRandCLINE_DIR. The old VS Code extension path is still used while it is the only one that exists. - An MCP entry owned by a deleted config can be taken over — an entry managed by a Skillshare config that was later moved or deleted stayed blocked forever as "managed by another Skillshare config". An explicit import or replace now takes it over, and the conflict names the owning file.
--disabledis refused where it does nothing — onlymcp adduses the flag, but the othermcpcommands andsync mcpaccepted it and ignored it.- A relative
XDG_CONFIG_HOMEis ignored for MCP paths — as the XDG specification requires, instead of producing a path relative to the current directory. - Skill detail and new skill pages — the file viewer no longer leaves a gap above it when it sticks while scrolling, and the info column beside a long
SKILL.mdstays in view.
Breaking Changes
- The
kilocodeskills target moved to.kilo/skills— from.kilocode/skills, in both global and project scope, because that is the only location Kilo Code's documentation lists now. Runskillshare synconce to write skills to the new location.
[0.21.0] - 2026-09-19
New Features
MCP connections
-
Define an MCP server once, sync it into each Agent's own config — a server lives in
config.yaml(or a separatemcp.yaml) as a portable definition, andsync mcpwrites it in the format each client expects: JSON, JSONC, TOML or YAML, under that client's own key. Nothing is started or proxied; Skillshare only manages the settings.skillshare mcp add # guided: URL, command, or pasted JSON
skillshare mcp add docs --url https://example.com/mcp --target claude --target cursor
skillshare mcp import docs --from claude --sync # adopt what an Agent already has
skillshare sync mcp --dry-run # preview every file that would change
skillshare sync mcpSupported clients: Claude Code, Codex, Cursor, VS Code, OpenCode, Grok CLI, Antigravity, Amp, Claude Desktop, Cline, Copilot CLI, Factory, Gemini CLI, Goose, Junie, Kiro, LM Studio, Warp, Windsurf and Pi. Global and project scope are both supported where the client has them.
skillshare mcpwithout arguments opens a TUI for browsing, editing and syncing. -
Secrets stay out of the files — headers and environment values are written as
{fromEnv: VARIABLE}references and rendered in each client's own reference syntax. On import, literal tokens and values carrying a URL password, such as database DSNs, are turned into references, and credential-like arguments are flagged. -
Only entries Skillshare wrote are ever changed — ownership is tracked per entry. An entry you wrote by hand is left alone even when it matches the source, and stays that way until you
importit. A managed entry edited in the Agent is reported as a conflict instead of being overwritten, Agent-only fields such as timeouts survive a sync, and previews stay valid while an Agent rewrites unrelated settings in the same file. -
Backups and restore — every write backs up the Agent file first, keeping the newest 20 per file.
skillshare mcp restore BACKUP_ID --dry-run
skillshare mcp restore BACKUP_ID -
Pasted snippets are recognised by shape —
mcp import --fileand the add wizard pick the client format from the top-level key, so VS Codeserversand OpenCodemcpsnippets copied from a provider's docs import without naming a client. TOML still needs--from, because Codex and Grok share the format. -
Pi through a chosen extension — Pi has no built-in MCP support, so a server targeting Pi names the third-party package that reads the file,
pi-mcp-adapterorpi-mcp-extension. Install one in Pi yourself; Skillshare only writes its configuration.skillshare mcp add docs --url https://example.com/mcp --target pi --pi-extension pi-mcp-adapter --no-tui -
sync --allincludes MCP — it syncs skills, agents, extras and MCP settings together, and--jsonreports the MCP plan alongside the rest.
Plugins
-
Install a complete plugin and choose which tools receive it — a plugin bundles skills, hooks, MCP settings and scripts that only work together.
pluginkeeps that package intact and installs it through each Agent's own CLI, so native formats and unrelated installations are untouched.skillshare plugin add # guided: source, plugin, targets, review
skillshare plugin add owner/repo --target claude --target codex --no-tui
skillshare plugin import review@team --from claude # adopt an existing native installation
skillshare plugin disable review --target codex # save the selection only
skillshare sync plugins --dry-run # then install or remove on sync
skillshare plugin check review
skillshare plugin update review --target claudeInstall targets: Claude Code, Codex, Cursor, Antigravity Desktop, Antigravity CLI, GitHub Copilot CLI, Pi and OpenCode. Grok Build supports import and removal, with install and trust handled in Grok. Sources can be a local folder,
owner/repoor an HTTPS Git URL, pinned with--source-ref. Plugins are synced withsync pluginsand are not part ofsync --all.
Dashboard
- Redesigned in two styles — the dashboard now comes in Clean and Playful, each in light and dark, switched from the theme menu. Skills and Agents are separate pages that hold their own install, search, updates and trash, and General, Backup, Log, Health, Extensions and Files are collected into one Settings page. Old routes redirect.
- MCP page — one row per server with its Agents as toggles. Add a server from a URL, a command, a pasted snippet or a file, or import what an installed Agent already has. Conflicts explain their cause and offer Import or Replace, backups are grouped by day with a preview before restoring, and View what each Agent gets shows exactly what each Agent would receive, including edits you have not saved yet. MCP settings are only served when the dashboard is opened through
localhostor an IP address. - Plugins page — one row per plugin with its Agents as toggles, the same as MCP. Expanding a row also lists the other Agents the source supports, so ticking one previews an install there. View files opens a read-only browser of the local copy Skillshare reviewed.
- Hubs page — browse a hub and install from it, or assemble your own index from installed skills, validate it and export it, all at
/hubs. A draft can be browsed straight away, before it is hosted anywhere. - Filter skills and agents by target, and a Remote source filter for skills from GitLab, Gitea, self-hosted and SSH sources, which previously matched no filter. Refs: #278.
- Config editors explain themselves — the Files tab and the audit rules editor keep a panel beside the YAML showing what the field under the cursor does and the unsaved changes. Audit rules also get a Test tab that runs a rule's regex against pasted lines.
- Dashboard source counts link to their pages, and plugins are counted alongside the other kinds.
Audit
- Findings accepted with
--forceare remembered — a skill that legitimately quotes attack strings, such as a security scanner or red-team notes, no longer has to be forced on everyupdate --all. The accepted findings are recorded for that skill, and later updates treat the same rule matching the same text as acknowledged. Any new finding, or the same rule matching different text, still blocks. Refs: #279.
List TUI
- Press
Mto make a skill manual only — togglesdisable-model-invocationin the selected skill'sSKILL.md, so the skill stays installed and can be invoked by name but is no longer loaded by the model on its own. The detail panel shows a manual only badge. For a tracked or installed skill the TUI asks first, because the edit counts as a local change; pressingMagain restores the file exactly. Refs: #283.
Bug Fixes
sync --dry-run agentsandsync -g extrasno longer sync skills — the resource kind was only recognised as the first argument, so putting a flag before it silently synced skills instead. The kind now matches in any position.- A mistake in the
mcpsection no longer breaks every command — an invalid MCP setting is reported by MCP commands and the config editor, whilesync,install,listand the dashboard keep working. - Web UI: saving the config keeps flow-style YAML — a hand-written
targets: [claude, codex]is no longer expanded into a block list on every save. Indentation is still normalised and comments are preserved.
[0.20.29] - 2026-09-11
Bug Fixes
install -pno longer removes the skills it just installed fromconfig.yaml— a project install driven byconfig.yamlreconciled against the metadata it had read before installing, so a skill that arrived as a plain copy — any source pointing at a subdirectory, which has no.gitto fall back on — looked absent and its entry was pruned from the declarative list. The install itself reported success and the skill and its metadata landed correctly, but the entry was gone fromconfig.yaml, which broke theinstall -p && syncflow for anyone setting the project up from a clean checkout. Metadata is now re-read from disk before reconciling, which also covers project-mode installs made throughsearch. Refs: #280.
[0.20.28] - 2026-09-09
New Features
-
Visible
skillshare/project directory — repositories that treat skills as reviewable content, rather than tool state, can now use a visibleskillshare/directory instead of the hidden.skillshare/.skillshare init -p --visible # create skillshare/ instead of .skillshare/Everything lives inside whichever directory is in use:
config.yaml,skills/,agents/,extras/, and the operationaltrash/,backups/andlogs/. Detection checks.skillshare/config.yamlfirst andskillshare/config.yamlsecond, so existing projects are unaffected and.skillshare/wins when both exist.init -pwithout the flag still creates.skillshare/. To move an existing project, runmv .skillshare skillsharefollowed byskillshare sync -pto repair target symlinks, and update anysourcespaths inconfig.yamlthat name.skillshare/explicitly. Refs: #256.
Bug Fixes
.skillignorematches again when the file uses CRLF line endings — rules were compiled with a trailing carriage return that could never equal a path segment, so a.skillignoresaved on Windows silently ignored nothing whilestatusstill reported its patterns as loaded. Editing patterns was affected the same way: existing entries were not found, adding one duplicated it, and removing one failed. A regression since v0.17.4. Refs: #275.- A directory symlink inside a skill no longer discards every file hash — hashing stopped at the first entry that could not be read as a file and threw away the hashes computed so far, which left installed skills without the metadata used to detect local edits. Directory symlinks are skipped; file symlinks are still hashed, and real failures such as broken links still surface. Refs: #272.
[0.20.27] - 2026-09-02
New Features
-
Agents can declare which targets they belong to — a
targetslist in an agent's frontmatter now restricts that agent to the listed tools, the same waymetadata.targetsworks for skills. Agent files are copied verbatim and Claude Code, OpenCode, Cursor and Copilot read different frontmatter fields, so this lets you keep a per-tool variant of the same agent side by side. Agents without the field still sync everywhere; target aliases such asclaude-codematchclaude. Applies tosync agents, the dashboard,doctorand the target summary. Refs: #267.# ~/.config/skillshare/agents/reviewer.md
---
targets: [claude]
tools: Read, Write, Bash(git log)
---
# ~/.config/skillshare/agents/reviewer-opencode.md
---
targets: [opencode]
mode: subagent
permission: { read: allow, write: allow, bash: ask }
---
Bug Fixes
update --allno longer deletes a skill when the audit blocks its update — when several skills from one repository were updated together, the existing skill directory was removed before the new content was copied in, and an audit block then cleaned up the new content as well, leaving nothing on disk and a stale metadata entry that later updates could not find. Grouped updates now stage the new content in a temporary directory, run the audit there, and only swap it into place once the audit passes, matching whatupdate <name>already did. If a skill was already lost this way,skillshare update <name> --forcereinstalls it. Refs: #271.- Batch updates and the web UI follow the branch a skill was installed from —
update --allcloned the remote default branch for skills installed with-b <branch>, so they were reported stale or downgraded, and--prunemoved them to trash. The dashboard's check and update did the same, comparing against the remote HEAD instead of the installed branch. All of these now group by repository and branch and fetch from the installed branch. Refs: #268. - Windows drive-letter paths install as local skills —
skillshare install D:\skills\my-skillfailed withunrecognized source formatbecause only paths starting with/,~,./or../were treated as local. Drive-letter paths (D:older,C:/Users/...) and backslash-relative paths (.\skill) are now recognised in the CLI and the dashboard install page. Refs: #269. - Dashboard labels non-GitHub git sources as Remote — skills installed from Gitea, GitLab, self-hosted or SSH sources showed a Local badge because only GitHub metadata types were recognised. Any non-local git source now shows Remote, matching
skillshare list. Tracked repos and GitHub sources keep their existing badges. Refs: #270.
[0.20.26] - 2026-08-27
Bug Fixes
-
update --forcecan override the security audit again — when an update was blocked by an audit finding, the error told you to pass--force, but the flag never reached the audit gate. Update stages new content in a temporary directory and had to leave its internal overwrite flag off to keep the gate active, which discarded your--forcealong with it, so a flagged update could not be applied short of--skip-audit— which turns scanning off entirely.--forcenow reaches the gate on every update path: regular skills, tracked repos, agents, and the web UI's Force Retry button.skillshare update my-skill --force # apply despite audit findings
skillshare update my-skill --skip-audit # skip scanning entirelyAudit scan failures stay fail-closed regardless of
--force: accepting findings you have seen is not the same as proceeding when the scanner could not run. -
install --jsonno longer bypasses the security audit —--jsonset the internal overwrite flag so installs could run non-interactively, and the audit gate read that same flag, so JSON-mode installs silently accepted content that would have been blocked interactively. -
Grouped batch updates are covered by the audit gate — updating several skills from a single repository inherited the same overwrite flag and skipped the block threshold.
-
Web UI: Force Retry only appears where it can help — a failure such as
failed to remove existing skill: ... permission deniedoffered a Force Retry button that retried with force and failed identically, with no hint of what would actually fix it. The button now shows for audit blocks and for pulls the server would retry with force, and is hidden elsewhere. -
Web UI: update errors no longer quote CLI flags — messages ending in
Use --force to override or --skip-audit to bypass scanningwere rendered verbatim in the dashboard, where there is no command line to type them into.
Breaking Changes
- A
--forceat install time no longer exempts later updates from the audit gate —--forceis a per-command decision. A skill installed with--forceis scanned again on its nextupdate, and needs--force(or--skip-audit) again to apply findings at or above the block threshold.
[0.20.25] - 2026-08-10
Bug Fixes
- Batch updates no longer mark skills under target dot-directories as stale — skills installed from subdirectories such as
.claude/skills/...or.codex/skills/...were skipped by discovery during batch updates and reported as deleted upstream, which could incorrectly suggest--prune. Batch update now resolves the requested subdirectory directly before declaring it missing. Refs: #261. - Explicit target dot-directory installs discover their requested content — commands such as
skillshare install user/repo/.claudeno longer return zero results just because.claudeis normally excluded from repository-wide discovery. Explicitly requested roots are scanned for both skills and agents, while repository-root scans continue to skip synced target copies. - Project commands preserve existing projects when
config.yamlis missing — when.skillshare/already contains skills or agents but.skillshare/config.yamlhas disappeared, project-mode commands now stop with recovery guidance instead of silently re-initializing an empty config, dropping target configuration, and leaving stale links. Fresh projects and shared repositories that intentionally gitignoreconfig.yamlstill initialize automatically. - Windows can uninstall nested skills again — uninstalling a skill stored under a folder no longer passes Windows backslashes into the trash-name validator and fails with
trash name must not contain backslash. Nested skill names are normalized to slash-separated paths in global and project mode without weakening traversal checks. Refs: #264.
[0.20.24] - 2026-08-03
Bug Fixes
-
Gemini CLI and Antigravity are separate targets again —
geminihad been folded intoantigravityas an alias, but the two runtimes read different global skill directories, so one of them was always pointed at the wrong path. Antigravity now resolves to~/.gemini/config/skills(global) and.agents/skills(project);geminiis a target of its own resolving to~/.gemini/skillsand.gemini/skills, with~/.agents/skillsand.agents/skillsstill scanned as fallbacks. Aliases:gemini-clifor Gemini CLI,antigravity-clifor Antigravity. Refs: #255.skillshare target add gemini # Gemini CLI
skillshare target add antigravity # Antigravity
skillshare syncAntigravity's skill scanner also skips symlinked skill directories entirely — silently on macOS and Linux, and as
Incorrect functionon Windows. The troubleshooting docs now cover this along with its two workarounds: switch the target tocopymode, or point Antigravity at your skillshare source directory via its Skill Custom Paths setting. -
doctor's symlink compatibility hint is deterministic — the hint chose its example target by iterating a map, so the same config produced a different suggestion on each run, and it could name a target whose runtime handles symlinks fine — telling users to switch something that was not broken. The example is now drawn only from the targets known to skip symlinked skill directories, in a fixed order. The sync docs are also corrected: the hint is printed bydoctor, notsync.
Breaking Changes
geminino longer resolves to the Antigravity target — configs that usedgemini(orgemini-cli) to reach Antigravity now sync to Gemini CLI's own directory instead. Useantigravityfor Antigravity. Existingantigravitytargets change global path from~/.gemini/skillsto~/.gemini/config/skills; runskillshare syncafter upgrading.
[0.20.23] - 2026-07-30
New Features
-
list --statusfilters enabled or disabled entries outside the TUI — the enabled/disabled filter previously existed only inside the list TUI (skey,status:search tag), so scripts had to know thatdisabledis omitted for enabled entries and filter the JSON themselves.--statuscombines with the pattern and--typeusing AND semantics, and works in project mode and for agents.skillshare list --status disabled
skillshare list --status enabled --json--status allis the default and produces output identical to omitting the flag. Refs: #244.
Bug Fixes
- Backups no longer copy your source, and old snapshots are pruned automatically — pre-sync backups followed merge-mode skill symlinks and copied the resolved content, so every snapshot duplicated the source directory, including files kept out of Git but still present on disk such as model weights,
.venv, and browser profiles. Retention only ran whenbackup --cleanupwas invoked by hand, so nothing removed the accumulating snapshots; backup directories could reach hundreds of gigabytes untilsyncfailed withno space left on device. Snapshots now capture only local target content, and the existing retention policy (10 snapshots, 30 days, 500 MB) runs after every automatic backup. Refs: #252. backup --cleanupkeeps the newest snapshot when it exceeds the size cap — a single snapshot larger than the 500 MB cap previously removed every backup including the most recent one, leaving no restore point at all.- Backup previews and cleanup now agree —
backup --cleanup --dry-runno longer reports that it will delete an oversized newest snapshot when the actual cleanup keeps it. Retention also counts only snapshots that remain after cleanup, avoiding unnecessary deletion of older snapshots that still fit. - Failed backups are discarded instead of appearing as restore points — if a file cannot be copied, the partial snapshot is removed and cannot consume the newest retention slot. Automatic cleanup failures are now shown as warnings instead of being silently ignored.
- Targets holding only symlinks no longer produce empty snapshots — an empty restore point consumed a retention slot and evicted older snapshots that did have content.
doctorhandles linked target directories correctly — in project symlink mode the valid link../.skillshare/skillswas reported as pointing to the wrong location, because relative links were resolved against the current working directory instead of the link's parent. Symlink-mode targets no longer report every source skill as a duplicate target-local copy, while copy-mode targets reached through a symlink still report real duplicate copies. Refs: #251.
Breaking Changes
- Backups capture local target content only — merge-mode skill symlinks are skipped, so restoring a target recovers its local skills and then needs
skillshare syncto recreate symlinks for synced skills. Copy-mode targets are unaffected because they hold real files. The documented backup location is also corrected to~/.local/share/skillshare/backups/(the XDG data directory), which had been listed under~/.configin some places.
[0.20.22] - 2026-07-21
New Features
-
Grok CLI target — added xAI's Grok CLI as a built-in target, syncing skills to
~/.grok/skills(global) and.grok/skills(project), with legacy fallback to~/.agents/skills. Aliases:xai,grok-cli.skillshare target add grok
skillshare sync
Bug Fixes
collect --jsonno longer forces overwrites — JSON mode previously implied--force, silently overwriting existing skills and agents in the source. It now still skips confirmation prompts but keeps the overwrite guard, so existing resources are preserved unless--forceis passed.uninstall --jsonno longer bypasses the uncommitted-changes guard — JSON mode previously implied--force, removing tracked skills that had uncommitted changes without warning. Dirty repositories now return a structured error unless--forceis passed.- Batch uninstall explains all-dirty failures — uninstalling multiple tracked skills where every repository has uncommitted changes now reports why nothing was removed instead of failing without explanation.
- Editing a skill's source no longer rewrites the source directory's Git remote — in the dashboard, changing a nested skill's source URL could overwrite the
originof the skills source directory itself when that directory is a Git repository (for example, backed by Git Sync). Source edits now only affect a tracked skill's own repository. - Freshly installed skills show their correct source instead of "Local" — after installing a skill from the dashboard, the resource now immediately shows its GitHub source and type, rather than appearing as a local skill with an empty source until the server was restarted.
[0.20.21] - 2026-06-29
Bug Fixes
- Copy-mode sync respects file ignore patterns —
syncincopymode now skips configuredignore:artifacts, plus default.DS_Store,.git/, and__pycache__/files, across CLI sync, diff, and dashboard sync/diff paths. This prevents ignored cache and build artifacts from being copied into targets or changing copy-mode checksums. - Global sync uses the default skills source when source is omitted — global configs that only define targets now work with
skillshare sync --global, using the default~/.config/skillshare/skillssource instead of failing withsource path is empty. Refs: #238.
[0.20.20] - 2026-06-19
Bug Fixes
- Self-managed GitLab URLs with deep project paths install correctly — generic HTTPS sources such as
https://domain.com/dir1/dir2/dir3/dir4now retry deeper repository boundaries when the initialdir1/dir2clone is not a Git repository, so nested GitLab projects can install without adding.gitor configuringgitlab_hosts. Authentication, SSL, branch, and network errors still fail directly instead of retrying unrelated paths.
[0.20.19] - 2026-06-17
Bug Fixes
initshows shared skills directories as a single universal target — when a detected CLI uses the shared~/.agents/skillsdirectory,skillshare initnow presents the shared directory guidance instead of listing each matching CLI target separately.- Trash restore handles nested entries and current-directory restores again — nested trashed skills returned by
skillshare trash listcan be restored with their slash-separated names, and restoring to.no longer fails the path safety check while sibling-prefix escapes are still rejected.
[0.20.18] - 2026-06-16
Bug Fixes
- Dashboard project-root installs are rejected before copying into themselves — the web dashboard now rejects project-mode installs where the local source resolves to the project root, matching
skillshare install ./ -pand returning the same "install a specific skill subdirectory" guidance instead of recursively copying.skillshare/skillsinto itself. - Trash operations reject traversal-style names — moving skills or agents to trash, restoring from trash, and automatic trash cleanup now validate trash-relative names and destination paths before filesystem writes or removals. Traversal segments, absolute paths, backslashes, NUL-containing names, and empty names are rejected while safe nested names like
org/team-skillanddemo/my-agentcontinue to work.
[0.20.17] - 2026-06-15
Bug Fixes
update --allno longer crashes on unreadable metadata — when.metadata.jsonis corrupt or unreadable, update now reports a metadata warning and continues scanning local skills instead of panicking with a stack trace.- Project root installs are rejected before copying into themselves —
skillshare install ./ -pnow fails with a clear message telling users to install a skill subdirectory, preventing.skillshare/skillsfrom recursively copying into itself on Windows.
[0.20.16] - 2026-06-15
Bug Fixes
- Repository subdir installs reject traversal paths — source parsing now rejects repository subdirectories with absolute paths,
./..segments, backslashes, NUL/control characters, or encoded traversal before install and download flows use them. Inputs such asgithub.com/owner/repo/../../etc/passwdand unsafe blobSKILL.mdpaths now fail instead of resolving outside the repository boundary. Refs: #224. - Metadata files stay readable after atomic saves — install and update operations now write
.metadata.jsonwith0644permissions, so Git and other tooling can read metadata after Skillshare replaces the file.
[0.20.15] - 2026-06-14
Bug Fixes
- Git branch refreshes now fail visibly when fetch fails — the dashboard no longer serves stale remote branches or continues a checkout after
git fetchfails. Branch listing and checkout requests now report the fetch failure so users can fix connectivity, authentication, or remote problems before switching branches. - Source URL edits keep metadata and remotes in sync — updating a tracked skill or agent source now updates the Git remote before saving metadata. If the remote update fails, the API returns an error and leaves the existing source metadata unchanged instead of reporting success with an old on-disk remote.
- Target removal preserves config when cleanup fails — removing a target from the dashboard now stops if Skillshare cannot inspect the target, remove the target symlink, remove the target manifest, or clean managed symlinks. The target remains configured so users can fix the filesystem issue and retry instead of losing the target entry.
- Version checks handle release tag formats correctly — update checks now accept versions with a leading
vprefix while still rejecting malformed version segments. Local metadata builds only advertise a release version when built from a clean exact tag; non-release builds stay indevmode so update checks do not compare against commit-describe strings. - JSON-mode automation stays clean during cleanup warnings — temporary Git clone cleanup failures are still logged for human-readable flows, but cleanup warnings no longer leak into
--jsonstderr output. - Skill linting reports rule load failures instead of panicking — malformed embedded lint rules now return explicit errors through analysis/discovery paths, and repeated lint runs keep the load error instead of losing it after the first attempt.
- Audit finding severity dots are vertically centered — severity indicators in the dashboard Audit findings list now align with their badges and messages.
[0.20.14] - 2026-06-13
Bug Fixes
- Push failures redact token-auth URLs without losing diagnostics — failed Git push flows now sanitize credential-bearing error output before it reaches CLI/API/UI callers, while still preserving useful Git and pre-push hook diagnostics. Refs: #214.
[0.20.13] - 2026-06-11
New Features
Web Dashboard
- Rehydrate missing tracked repos from the dashboard — the Updates page now shows a warning banner listing tracked repos declared in
.metadata.jsonwhose clone directories are missing on disk, with a one-click Rehydrate button that re-clones them from metadata. The Dashboard's Update All also warns about missing repos and points to rehydrate, instead of reporting that there is nothing to update. Refs: #212.
Bug Fixes
update --allreports missing tracked repos in batch and project mode — reporting a missing tracked repo previously only worked when it was the single update target; whenupdate --allcovered multiple items (the common case) the batch path skipped missing repos silently, and project mode (-p) never detected them at all. Both now surface each missing repo with a warning and a one-shot rehydrate hint:skillshare update --all # ! _team-skills clone directory absent
skillshare install # rehydrate from metadataupdate --all --jsonnow carries an aggregatedmissing_tracked_repossummary (names + hint), and the per-item error is the conciseclone directory absent. Refs: #212.
[0.20.12] - 2026-06-11
New Features
- Droid syncs custom droids as agents — the
droidtarget now distributes custom droids (.mdfiles with YAML frontmatter) alongside skills, mapping them to~/.factory/droids(global) and.factory/droids(project) through the existing agents sync. The target also acceptsfactoryas an alias:Refs: #213.skillshare target add factory # same as: skillshare target add droid
skillshare sync agents
Bug Fixes
- Project-mode agent symlinks are now relative —
skillshare sync agentscreated absolute symlinks in project mode, which broke when the repository was moved or checked out on another machine. Agent symlinks now use relative paths, matching how project skill symlinks already work. - Factory alias syncs Droid agents correctly — adding the Droid target by its
factoryalias now also resolves the built-in agents path, soskillshare sync agentswrites custom droids to~/.factory/droidsor.factory/droidsinstead of skipping the target as agentless. - Web UI sync respects agent filters — syncing from the dashboard now honors target-level
agents.includeandagents.excludefilters, matching the CLI. Agents that become excluded are pruned from target directories on the next sync. Refs: #211.
[0.20.11] - 2026-06-10
Bug Fixes
- Grouped tracked repositories rehydrate at the correct path — when
.metadata.jsoncontains tracked repos installed with--track --into <group>,skillshare installnow restores the missing clone at the original grouped path instead of applying the group twice and failing on paths likeanthropics/anthropics/_skills. Refs: #212.
[0.20.10] - 2026-06-10
Bug Fixes
- Missing tracked repositories are no longer silently ignored — when
.metadata.jsondeclares a tracked repo but the local_repo/clone is missing (common after a fresh clone on another machine),status,check,update --all, anddoctornow report it as missing instead of showing no tracked repos. The message points to the existing recovery path:skillshare install
skillshare syncupdate --all --jsonnow counts the missing repo as skipped and includes an item explaining the recovery step. Refs: #212.
[0.20.9] - 2026-06-05
New Features
- Batch enable/disable in the web dashboard — the Resources page now has a selection mode. Click Select, tick multiple skills or agents across the grid, folder, or table view (folders offer a select-all checkbox), then enable or disable them all at once from the bottom action bar. Enabling applies immediately; disabling asks for confirmation first. Works for both skills (
.skillignore) and agents (.agentignore). Refs: #203.
Bug Fixes
- Fixed
enabled: falsebeing ignored for tier and cross-skill audit rules — disabling one of these rules inaudit-rules.yamlmarked it disabled in the rule listing, but the scan still fired it at full severity. Both the per-skill and single-file scan paths now honor the disabled rule. Refs: #204.
[0.20.8] - 2026-06-05
Bug Fixes
- SSH GitHub Enterprise hub entries inherit the hub SSH login — when an SSH hub returns same-host GitHub or GitHub Enterprise domain-prefixed sources, search results now install them over SSH using the hub username and host. For example, a hub loaded from
acme@acme.ghe.com:Org/skills.git//hubs/team.jsoncan returnacme.ghe.com/Org/skills/skills/reviewer, and Skillshare installs it asacme@acme.ghe.com:Org/skills.git//skills/reviewer. Explicit HTTPS/SSH sources, cross-host entries, local paths, and in-memory indexes keep their existing behavior. Refs: #196. - SSH skill previews can read private hub results — previews for SSH GitHub/GHE sources now fall back to a shallow clone when no token is available or the Contents API rejects the request, so the dashboard can show full
SKILL.mdcontent for SSH-only private hub results instead of only index metadata.
Performance
- Faster
.skillignoreglobstar matching — repeated**patterns no longer trigger exponential backtracking, so commands that scan ignored skills stay responsive with complex ignore rules.
[0.20.7] - 2026-06-03
Bug Fixes
- Fixed single-skill uninstall for disabled skills in the dashboard — a skill hidden by
.skillignorestill appeared on the Resources page, but uninstalling it from the item menu or detail page could return "skill not found". Single-resource uninstall now resolves disabled skills the same way the list and batch uninstall flows do.
Performance
- Trash page virtualization — the dashboard Trash page now renders long trash lists incrementally, so large skill or agent trash folders stay responsive instead of rendering every trashed item at once.
[0.20.6] - 2026-06-03
New Features
- Clearer hub errors in the web dashboard — when a hub fails to load, the Search page now names the failing hub and explains the likely cause (malformed URL, missing index file, authentication required, or invalid JSON) instead of showing a bare
HTTP 400.
Bug Fixes
- Fixed the skill preview showing only index metadata (name, description, tags) for skills from non-github.com hubs — the web dashboard always fetched
SKILL.mdviaapi.github.com, so GitHub Enterprise, GitLab, and other sources never rendered their full content. The preview now reads from the source's own host (the GHE Contents API, or a shallow clone for other platforms), and degrades with a clear notice when a source genuinely can't be fetched. - Fixed the hub selector dropdown being clipped behind the search box on the dashboard's Search page.
- Fixed
skillshare auditignoring.skillignoreinside tracked hub repos — skills excluded via a tracked repo's.skillignorewere still scanned and reported. Audit now skips those skills, matching how sync and the rest of the CLI treat them.
[0.20.5] - 2026-06-03
New Features
- Zed editor target —
zedis now a supported sync target. Add it, then sync; skills go to~/.agents/skills(global) and.agents/skills(project):skillshare target add zed
skillshare sync
Bug Fixes
- Fixed disabled skills failing to uninstall from the web dashboard — a skill disabled via
.skillignorestill appeared in the dashboard list but couldn't be removed, reporting "skill not found". Uninstall now resolves disabled skills the same way the list does. The CLI was unaffected.
[0.20.4] - 2026-06-02
New Features
SSH hub sources
- Fetch a hub index over SSH —
skillshare search --hubandskillshare hub addnow accept SSH URLs, so a shared hub index can live in a private or GitHub Enterprise repo that teammates reach over SSH without cloning it first. Skillshare shallow-clones the repo with your SSH keys and reads the index from it:The index path inside the repo comes from theskillshare search react --hub git@ghe.corp.com:team/skills.git
skillshare hub add git@ghe.corp.com:team/skills.git//hubs/team.json --label ghe//pathsuffix and defaults toskillshare-hub.jsonat the repo root. Both scp-style (git@host:org/repo.git) and scheme-style (ssh://git@host/org/repo.git) URLs work. In the web dashboard, SSH hub sources must be saved first — the server only clones saved hubs.
Extras per-target management
- Add or remove a single target on an existing extra —
extras <name> --add-targetand--remove-targetmanage one target without recreating the whole extra. Both update config only; runskillshare sync extrasafterward to apply:Removing a target leaves already-synced files in place by default. Addskillshare extras rules --add-target ~/.cursor/rules --mode copy
skillshare extras rules --remove-target ~/.cursor/rules--pruneto also delete the skillshare-managed files under that target — in merge mode only symlinks are removed, so your own files are preserved. Removing the last remaining target is rejected (useextras remove <name>for the whole extra). The web dashboard's Extras page gains matching per-target add/remove controls.
Bug Fixes
- Fixed extension downloads in the web dashboard's Config page clearing each other's progress — starting a second download no longer wipes the first one's loading spinner; each download now tracks its own state.
Breaking Changes
- Removed the
extras modesubcommand — change a target's sync mode or flatten setting with theextras <name>shorthand instead (same behavior, one less command):skillshare extras rules --mode copy --target ~/.claude/rules
skillshare extras agents --flatten
[0.20.3] - 2026-06-01
New Features
- Copilot CLI agents — agents now sync to Copilot CLI alongside skills. Copilot uses the same
.agent.mdformat Skillshare already manages, soskillshare sync agentssymlinks your agents into~/.copilot/agents(global) and.github/agents(project) with no conversion:skillshare sync agents # now includes copilot
Bug Fixes
- Installing a specific skill no longer drags in every agent — when installing from a repo that contains both skills and agents,
-s/--skillnow installs only the named skills (no agents), and-swith-a/--agentinstalls only the named agents. An unknown-aname fails the whole command up front, so automation never sees a half-completed install.--all/--yesstill install everything.
[0.20.2] - 2026-05-31
New Features
Doctor remediation suggestions
skillshare doctornow suggests how to fix what it flags — when doctor detects targets writing to a shared path, or one target's runtime discovering another target's skills, it prints a remediation suggestion next to the warning instead of only reporting the overlap. Suggestions are also included indoctor --jsonunder a newsuggestionsfield.- Suggestions point at a ready-to-run target removal command — overlap suggestions now include the exact command to preview removing a duplicate target:
skillshare target remove <name> --global --dry-run - Health Check page surfaces suggestions — the dashboard Health Check page renders each check's remediation suggestions inside its expandable detail block, localized across all supported languages.
Bug Fixes
- GitHub Enterprise Cloud data residency hosts are now recognized — repositories on
*.ghe.comtenants are detected as GitHub over both HTTPS and SSH, and the GitHub API base is resolved ashttps://api.<tenant>.ghe.com, so installing and updating from data residency accounts works. - SSH remote URLs with a custom username now work — clone URLs such as
acme@acme.ghe.com:org/repo.git(any username, not onlygit) are parsed and normalized correctly when installing and updating.
[0.20.1] - 2026-05-31
Bug Fixes
- Codex agent transforms reject incomplete agents — the bundled
codex-agentsextension now fails clearly when the resolvedname,description, or Markdown body is blank. Missingnamestill falls back to the source filename, and the extension docs link to Codex's custom agent schema for the required fields. - Dashboard Extras sync shows extension errors — when an extras transform fails, the Extras page toast now shows the first file-level error instead of only an error count, so users can fix the specific source file without opening logs.
[0.20.0] - 2026-05-30
New Features
Git scope control (git_root)
git_rootscope — choose which directoryskillshare commit,push, andpullversion. The default stays your skills source, but you can point git atagents,extras, orroot(skills + agents + extras together in a single repo). Set it during init, or switch later on an existing setup:Askillshare init --git-root root # version skills, agents, and extras in one repo
skillshare init --git-root agents # switch scope headlessly laterroot-scope repo automatically keepsconfig.yamlout of version control (it holds machine-specific paths), and nested git repositories are detected and blocked before they would upload as empty submodules. Ifgit_rootpoints to a scope whose directory has no repo,commit/push/pullprint a "Git root mismatch" error with the exact commands to fix it.- Switch scope from the dashboard — the Git Sync page can change the
git_rootscope, set the git remote during the switch, and offers a one-click action when the scoped directory isn't a repository yet.
Extras extension transforms
extensionfield on extras targets — convert Markdown into a tool's native format during sync, for tools that don't read Markdown. Reference extensions ship for Gemini CLI (TOML commands) and Codex CLI (TOML agents):Transforms run source → target only (extras:
- name: commands
targets:
- path: .gemini/commands
extension: gemini-commands # transforms .md → .toml during syncextras collectskips them), usecopysemantics, and never overwrite a local file or directory without--force. The Codex agents extension mapsname,description, andmodelfrom frontmatter.- Manage extensions from the dashboard — the Config page lists installed extensions with descriptions and guards against removing one that is still in use; the Extras page and Add Extra modal include a per-target extension picker.
List filtering
- Filter skills by enabled/disabled status — press
sin thelistTUI to cycle All → Enabled → Disabled, or use thes:enabled/s:disabledtag to combine status with other filters. The dashboard Resources page gains the same status filter.
Bug Fixes
- Hardened git remote handling — remote URLs beginning with
-(which git could misinterpret as a flag) are now rejected when setting or adding a remote, including viaskillshare init --remote. - Dashboard pull keeps skill paths correct with scoped git roots — pulling from a
root,agents, orextrasgit scope no longer causes the follow-up sync to flatten paths such asskills/foointo the wrong skill name. - Transformed extras no longer show false drift — dashboard diff/status checks now compare transformed filenames (for example
.md→.toml) consistently, and missing extension definitions surface as warnings instead of silently falling back. - Safer reference transforms — bundled TOML transforms now escape control characters correctly and stop hung transform commands instead of blocking sync indefinitely.
[0.19.24] - 2026-05-27
New Features
Local skill checkpoints
skillshare commit— create a local git commit for source skills without pushing to the remote. This is useful when iterating locally and wanting a restore point before you are ready to share changes across machines. It stages all source changes and commits them with the provided message, and it works even when no git remote is configured.skillshare commit -m "Update writing skill"
skillshare commit --dry-run- Dashboard local commit action — the Git Sync page now has a Commit locally button alongside Push and Pull. It uses the same commit message and dry-run preview area, but only creates the local commit and never pushes.
Bug Fixes
- Dashboard update results stay current after updating — after updating skills from the dashboard, successfully updated or already-current items are now marked Up to date and keep their latest check status instead of falling back to Unchecked.
[0.19.23] - 2026-05-26
Bug Fixes
- Nested GitHub-installed skills stop reappearing as updateable after update —
skillshare updateand the dashboard Update page now refresh the stored metadata for skills installed under a subdirectory, so items such astools/agent-browserno longer keep showing Update available immediately after a successful update - Dashboard Update checks are remembered between visits — the Update page now keeps the last completed check status in browser storage and shows the previous check time, so returning to the page no longer resets every item to Unchecked
[0.19.22] - 2026-05-26
Bug Fixes
- Web UI install now handles mixed-track repos — installing a repository that contains both skills and agents with Track enabled (for example
github/awesome-copilot) used to fail with atracked install is ambiguous; pass --kind skill or --kind agenterror toast and no way forward. The dashboard now opens a kind picker showing skill and agent counts; choose Skills or Agents and the install proceeds with the chosen--kind. Refs: #167
Performance
- One fewer clone when recovering from a mixed-track install — the install API now reports skill/agent counts in the ambiguity error itself, so the dashboard no longer re-clones the repository via
/api/discoverbefore showing the kind picker
[0.19.21] - 2026-05-24
Bug Fixes
- Update page checks now finish for nested GitHub-installed skills — the dashboard now matches check results by relative path as well as display name, so items such as
tools/agent-browserno longer stay stuck onCheckingafter Check All completes - Update Selected now targets nested GitHub-installed skills correctly — selecting an item installed under a subdirectory now sends its relative path (for example
tools/agent-browser) to the update endpoint instead of the flattened display name - Remote update checks no longer wait indefinitely on Git prompts — lightweight
git ls-remoteprobes now disable interactive credential prompts and time out after 15 seconds, surfacing an error in the UI/CLI instead of leaving the update check spinner running forever
[0.19.20] - 2026-05-24
New Features
Web UI process management
skillshare ui start/skillshare ui stop— run the web dashboard as a managed background process instead of holding a foreground shell. Re-runningstartreuses the existing healthy process;stopshuts it down using the remembered host/port. The legacy foregroundskillshare uiand the--no-open &shell-backgrounding workaround keep working unchanged.skillshare ui start # start in background, return to shell
skillshare ui start --clear-cache # clear cached UI assets, then start
skillshare ui stop # stop the background server--appflag —skillshare ui start --appopens the dashboard in a Chromium app-mode window (Chrome, Edge, Brave) so it gets its own Dock/taskbar entry and chrome-less frame on macOS, Windows, and Linux.
In-place upgrade from the dashboard
- Update without leaving the browser — the Update dialog and the Doctor page's Version card now show an Update now button. The dashboard runs
skillshare upgradeon the host, restarts the local UI server, then auto-reloads the page once the new server reports healthy. Two new endpoints back this flow:If the dashboard cannot reconnect on its own, it surfaces a message asking you to runPOST /api/upgrade # run skillshare upgrade in place
POST /api/restart # restart the UI server (optional { "clearCache": true })skillshare ui startto bring the background server back up. - Doctor Version card redesign — the version section now leads with a state-coloured icon (blue when an update is available, green when up to date), shows the version delta as
current → latest, and hides the Update now button when there is nothing to upgrade.
Installable as a Progressive Web App
- PWA support — the dashboard now ships a
site.webmanifest, app icons (192px / 512px), and a minimal service worker. Browsers that support it (Chrome, Edge, Safari, Brave) let you install Skillshare as a standalone desktop app from the address bar; offline cache covers the static shell so the dashboard opens even before the local server is reachable.
[0.19.19] - 2026-05-23
Bug Fixes
- Tracked root-level
SKILL.mdrepos now get integrity hashes —skillshare install <repo> --trackfor single-skill repos withSKILL.mdat the repo root now writesfile_hashesinto.metadata.json, soskillshare doctorcan verify them instead of warning that integrity checks are unavailable. Runningskillshare update _repoalso backfills hashes for already-installed tracked root-skill repos that were created by v0.19.18. Refs: #165
[0.19.18] - 2026-05-22
Bug Fixes
- Tracked repos with a root-level
SKILL.mdare fully supported — installing a single-skill repo with--track(whereSKILL.mdsits at the repo root, not nested) used to reportFound 0 skill(s), skip metadata persistence, and omit the repo fromskillshare statusandskillshare list. Now the install reports the correct count, writes the tracked entry to.metadata.json, and the repo appears in status output withskill_count: 1. Cross-machine recovery via metadata works again for this layout. The misleadingRun skillshare sync to distribute skillsnext-step hint is also suppressed when the install produced zero skills or agents. Refs: #163 - GitLab SSH URLs with nested subgroups now produce a clean tracked-repo name —
skillshare install git@gitlab.example.com:org/subgroup/my-skills.git --trackpreviously stored the repo under a directory name containing the subgroup path; the resolved name is now justmy-skills, matching the existing HTTPS subgroup behavior
[0.19.17] - 2026-05-22
New Features
doctorwarns on overlapping skill paths —skillshare doctornow flags two classes of duplicate-skill problems before they reach the runtime picker. Refs: #135The first warning fires when two enabled targets resolve to the same primary path. The second fires when an enabled target's runtime also scans a directory another enabled target writes to (e.g. Codex Desktop reads! Shared path ~/.agents/skills ← universal, warp
! codex will see content from: universal
~/.agents/skills ← universal~/.agents/skillsin addition to~/.codex/skills). Both checks are pure metadata — no filesystem probing, no runtime calls.skillshare syncalso prints a one-line hint when overlap is detected, pointing back todoctorfor the full breakdown:! Skill path overlap across 2 target(s) — run `skillshare doctor` for details
Bug Fixes
clinetarget path reverted to~/.cline/skills— the cline target was briefly pointing at the shared~/.agents/skillsroot, which doesn't match the official cline documentation. Restored to the brand-specific~/.cline/skills(global) and.cline/skills(project). If you synced cline between v0.19.14 and v0.19.16, re-runskillshare syncto move skills to the correct location
[0.19.16] - 2026-05-21
New Features
- Global config
sources:map — global mode now accepts the samesources:map shipped for project mode in v0.19.15. Override skills, agents, or extras source directories from a single place:Each key is optional. Existing top-level# ~/.config/skillshare/config.yaml
sources:
skills: ~/work/skills
agents: ~/work/agents
extras: ~/work/extrassource:/agents_source:/extras_source:fields continue to work unchanged; when both formats are set,sources.<key>wins. Freshskillshare init -gwrites the newsources:shape; existing configs are never auto-rewritten
Behavior Changes
extras initno longer silently backfillsextras_source:— runningskillshare extras init <name>on a global config without an explicit extras source used to write the derivedextras_source:path back into yourconfig.yaml. The runtime now resolves the extras parent on the fly, so the legacy field stays empty unless you set it yourself. Same change applies to the equivalent server endpoint (POST /api/extras)extras source <path>writes to whichever field the user already configured — ifsources.extrasis already set, the command updates that key; otherwise it falls back to the legacyextras_sourcefield. This prevents the new value from being silently shadowed bysources.extras
[0.19.15] - 2026-05-20
New Features
- Custom project source directories — project mode can now read skills, agents, and extras from any directory in your repo. Useful for co-locating skill content with existing project documentation. Refs: #153, #162
Each key is optional — omit to fall back to
# .skillshare/config.yaml
sources:
skills: ./docs/skills
agents: ./docs/agents
extras: ./docs/extras
targets:
- claude.skillshare/<type>/. Paths are resolved from the project root; absolute paths and~work too.skillshare init -pstill seeds the default.skillshare/directories. Trash, backups, and operation logs always stay under.skillshare/regardless ofsourcessettings
Behavior Changes
- Project commands fail closed on malformed
config.yaml—uninstall,new,enable/disable, andchecknow returnfailed to load project configinstead of silently falling back to.skillshare/skills. With customsources, the old fallback could have operated on the wrong directory. Fix any YAML errors (e.g.targets: {}→targets: []) and the command will succeed - Sync rejects source/target path overlap —
skillshare sync -perrors whensources.skillsorsources.agentsaliases or nests with a target path. Without this check,sync --forcecould delete the configured source directory. Common safe layout:sources.skills: ./docs/skillswith aclaudetarget (no overlap)
[0.19.14] - 2026-05-20
Refactoring
- Unified Gemini and Antigravity targets — the standalone
geminitarget has been merged intoantigravity. The shared skill path~/.gemini/skillsis now served by theantigravitytarget. Old namesgemini,gemini-cli, andantigravity-clicontinue to work as aliases
Bug Fixes
- Audit: Swift files are now scannable —
.swiftfiles are included in security audit scans alongside.go,.py,.ts, and other source files - Audit: reduced false positives — tightened publisher-claim extraction to avoid flagging ordinary phrases like "from CSV data" as organization claims. Bracket placeholders like
[Count] ([Percentage]%)no longer trigger dangling-link warnings. Common documentation domains (MDN, Apple Developer, etc.) are excluded from external-link findings - Audit: uppercase URI schemes no longer flag as dangling links — custom URI schemes like
VSCode://are now correctly recognized as external links
[0.19.13] - 2026-05-17
Bug Fixes
- Tracked skills now retain custom name and branch from config — previously,
skillshare updateon a tracked repo re-derived the directory name from the clone URL (e.g._owner-repo), ignoring any customname:set inconfig.yaml. Now the resolution priority is:--nameflag > configname:> URL-derived name. Similarly, a non-defaultbranch:in config is now respected during clone and update. Refs: #158
[0.19.12] - 2026-05-14
Bug Fixes
- Project
skills:in config.yaml no longer stripped — previously, project-mode commands silently removed theskills:section from.skillshare/config.yamlduring an internal migration, leaving no committable record of remote skill dependencies. Nowskills:stays inconfig.yamlas the declarative source of truth. Teammates can clone the repo and runskillshare install -pto install all listed skills. Refs: #157# .skillshare/config.yaml — committed to git
targets:
- claude
- cursor
skills:
- name: pdf
source: anthropic/skills/pdf
- name: review
source: github.com/team/skills/code-review
group: frontendskillshare install <source> -pautomatically adds the skill toconfig.yaml.skillshare uninstallremoves it. Runtime metadata (hashes, timestamps) stays in.metadata.json(gitignored)
[0.19.11] - 2026-05-14
New Features
preserve_tilde_on_save— opt-in config flag that folds$HOMEprefixes back to~when savingconfig.yaml. Keeps the on-disk config portable across machines when shared via dotfiles (stow, chezmoi, yadm, bare git repo). Refs: #155Non-home absolute paths (e.g.preserve_tilde_on_save: true/opt/shared/skills) are passed through unchanged. The in-memory config is unaffected —Load()still expands~as usual
Bug Fixes
- Fixed
skillshare init -pnot gitignoring.skillshare/backups/— backup artifacts from project-mode agent sync could be accidentally committed
[0.19.10] - 2026-05-12
Bug Fixes
- Fixed
skillshare update --allcreating duplicate.metadata.jsonentries with../../...relative-path keys when the skills source directory is a symlink or custom location. Existing metadata keys such asbrowser/agent-browsernow stay stable during update. Refs: #152
[0.19.9] - 2026-05-11
New Features
- Context cost summary after sync —
skillshare syncnow displays a one-line token cost summary showing always-loaded and on-demand context usage per target. Targets with identical token counts are grouped on a single line. Refs: #150✔ Synced 47 skill(s) to 4 target(s) in 312ms
Context: ~12.4K always-loaded · ~58.2K on-demand (claude, cursor, codex, opencode) - Configurable budget warnings — set token budget thresholds in
config.yaml. Whensyncoranalyzedetects a target exceeding the budget, a warning shows the top 3 offenders by token countDefaults to 10K always-loaded / 100K on-demand. Set tocontext_budget:
warn_always_loaded_tokens: 10000 # default; 0 = disabled
warn_on_demand_tokens: 100000 # default; 0 = disabled0to disable --quiet/-qflag for sync — suppresses the token summary and budget warnings. JSON output (--json) always includescontext_costregardless of--quiet- Context cost in Web UI — the Sync page now displays token cost groups and budget violation warnings after each sync
Bug Fixes
- Fixed
skillshare installfailing withhttp://protocol URLs (contributed by @eekryuos)
[0.19.8] - 2026-05-08
New Features
- Shell completion — new
skillshare completioncommand generates tab-completion scripts for bash, zsh, fish, PowerShell, and Nushell. Supports--installto auto-write the script to the correct platform path. Refs: #148Covers all commands, subcommands, and per-command flags. Bash, zsh, and PowerShell scripts auto-detect aliases (e.g.skillshare completion bash --install # one-line setup
skillshare completion zsh --install
skillshare completion fish --install
skillshare completion powershell --install
skillshare completion nushell --installalias ss=skillshare) and register completions for them
[0.19.7] - 2026-05-05
New Features
- Azure DevOps Server (on-premises) support — added
azure_hostsconfig parameter for self-hosted Azure DevOps Server instances on custom domains. Previously, onlydev.azure.comand*.visualstudio.comwere recognized; custom-domain URLs would fail with an incorrect.gitsuffix in the clone URL. Refs: #147azure_hosts:
- azuredevops.mycompany.comWorks in both global and project configs. For CI/CD, use theskillshare install https://azuredevops.mycompany.com/Org/Project/_git/RepoSKILLSHARE_AZURE_HOSTSenvironment variable (comma-separated, merged with config file values)
[0.19.6] - 2026-05-05
New Features
- 8 new agent targets — added AiderDesk, CodeArts Agent (Huawei), Code Studio (Syncfusion), Devin for Terminal (Cognition), Dexto, ForgeCode, Rovo Dev (Atlassian), and Tabnine CLI. Total built-in targets: 64+
- Cursor project path updated to
.agents/skills— Cursor officially supports.agents/skillsas a project-level skill path alongside.cursor/skills. The project path now uses the ecosystem-standard.agents/skillsconvention, matching Cursor's official documentation. The global path (~/.cursor/skills) and agents paths are unchanged - Automatic target inference from directory structure — skills organized under a target's project path are now automatically scoped to that target during sync, without needing
targets:in SKILL.md frontmatter. For example, placing a skill at.cursor/skills/my-skill/in the source directory automatically restricts it to thecursortargetInference matches against the project paths defined insource/
.cursor/skills/browse/ → syncs only to cursor
.factory/skills/bench/ → syncs only to droid
openclaw/skills/investigate/ → syncs only to openclaw
shared/my-tool/ → syncs to all targets (no inference)targets.yaml. When multiple targets share the same path (e.g.universal,codex,ampall use.agents/skills), the skill is correctly scoped to all of them
Bug Fixes
- Fixed host path inference only returning the canonical target name when multiple targets share the same project path —
.agents/skills/skills now correctly infer all sharing targets instead of justuniversal - Fixed
skillshare updatefailing for skills originally installed at the repo root of an orchestrator (multi-skill) repository — the update now correctly detects the repo layout and re-applies subdirectory extraction
[0.19.5] - 2026-04-23
New Features
Search Experience
-
Skill preview modal — clicking a search result card or table row now opens a preview modal that renders the remote
SKILL.mdso you can read the full content before installing. The Install button has moved inside the modalskillshare ui # open Search, click any resultBacked by a new
GET /api/preview?source=owner/repo/pathendpoint that fetchesSKILL.mdfrom the GitHub Contents API with a Git Tree fallback for hub sources, plus a 5-minute in-memory cache. If the fetch fails but hub metadata exists, the modal falls back to showing the description and tags instead of an error. Refs: #141 -
Higher-quality search results — the scoring formula that ranked search hits was dominated by name matches (45%) while stars — the strongest quality signal — only contributed 5%, so zero-star personal experiments often outranked well-known skill repos. Weights are now rebalanced (name 30%, description 20%, stars 25%, source 25%), with a better star-count curve in the 5–50 range where most useful skills live
-
Low-quality result filtering — search now filters out 0-star non-preferred repos, results with very short descriptions, and known spam orgs, and boosts preferred hubs like
anthropics/skillsandvercel-labs/skills. Results are also deduplicated when the same skill appears from multiple sources -
Repo-scoped search queries — you can now search inside a specific repo (or subdirectory) using
owner/repoorowner/repo/subdirpatterns -
Frontmatter validation — search results without valid
SKILL.mdfrontmatter are filtered out, so non-skill.mdfiles no longer appear in results
Skill Detail Editor
- Editable source URL on skill detail page — the skill editor now exposes a Source URL field so you can correct or reassign the upstream URL without touching disk
For tracked repos, updating one skill's source URL updates every sibling skill from the same repo and rewrites the git remote origin to match. Saving source-URL-only changes skips the diff review dialog
skillshare ui # open any skill's detail page → edit Source URL - Backed by a new
PATCH /api/resources/{name}/sourceendpoint
Bug Fixes
- Fixed a skill lookup collision when a standalone skill and a tracked-repo skill shared the same base name — detail-page requests now prefer an exact
FlatNamematch before falling back to the base name, so the correct skill is always returned - Fixed spurious frontmatter diffs when only the body or source URL changed — the YAML serializer now preserves the original formatting (quote style, line wrapping) unless a field's value actually changed
- Fixed
IntersectionObserveron the Search page not reconnecting after "load more", so infinite scrolling now continues to fire as you reach the bottom of the list - Fixed background page scrolling when a modal was open —
DialogShellnow locks body scroll for all modal dialogs
Improvements
- Keyboard-accessible search results — search result cards and table rows now have
role="button"withtabIndex=0and respond to Enter/Space, so the preview modal can be opened without a mouse - Bounded preview cache — the preview cache is now capped at 200 entries with TTL purge plus a full reset on overflow to prevent unbounded memory growth on long-running UI sessions
- Shared input components in the frontmatter editor — the editor now uses the same
Input/Textareaprimitives as the rest of the UI (with a newsize="sm"variant) for visual consistency, and the editor header now uses the sharedKindBadge/SourceBadgecomponents
[0.19.4] - 2026-04-22
Bug Fixes
- UI install no longer deletes local source files — installing a skill from a local path via the Web UI would permanently delete the original source directory after discovery. The cleanup logic now only removes temporary directories created by git clones, leaving user directories untouched. CLI installs were unaffected. Refs: #139
Improvements
$ARGUMENTStokens highlighted on detail page — skill detail pages in the Web UI now render$ARGUMENTSplaceholders with the same warning-badge style used in the editor, making them easier to spot when reviewing a skill's content
[0.19.3] - 2026-04-18
New Features
Web-Based Skill Editor
-
Edit skills directly in the Web UI — the resource detail page now has an Edit action that opens a full in-browser editor, replacing the previous read-only view. Changes are saved back to the source
SKILL.mdthrough a newPOST /api/resources/:name/contentendpointskillshare ui # then open any skill and click Edit -
Two-pane Markdown editor — side-by-side textarea and live preview with synced scrolling. A mode toggle in the status bar switches between Edit / Split / Preview (
⌘Pcycles), and⌘Ssaves whileEsccancels. An outline drawer lets you jump to any heading, and the status bar shows token / word / line / file counts with a 5K-character budget warning -
Structured frontmatter editor — all 13 official SKILL.md fields are grouped into Identity / Invocation / Execution / Metadata sections with field-appropriate controls: switch toggles for booleans, segmented control for enums, and chip inputs for list-valued fields. A shared 1,536-character budget is enforced across
description+when_to_use. A raw YAML mode is also available, and round-trips cleanly with the Fields view. Legacy root-leveltargets:is automatically migrated tometadata.targetson load -
Diff review before save — saving opens a side-by-side diff modal so you can confirm every change before writing to disk. The YAML serializer emits plain scalars when safe, so the diff no longer shows spurious quote wrapping for values containing
:,*,#, or" -
Open in local editor — a new
POST /api/resources/:name/openendpoint opens the skill file in your preferred local editor (via$EDITOR), useful when you prefervim/ VS Code over the browser editor -
Targets visible in detail sidebar — the resource detail sidebar now shows a Targets row when
metadata.targetsis set, so you can see at a glance which targets a skill is scoped to
Web UI Localization
- 11 languages in the Web UI — every page is now fully translated. Pick your language from the language switcher in the top navigation bar; the preference is saved to your browser and auto-detected on first visit from
navigator.languages- Supported: English, 中文, 日本語, 한국어, Español, Français, Deutsch, فارسی, Português (BR), Bahasa Indonesia
- Persian (فارسی) automatically switches the layout to right-to-left
[0.19.2] - 2026-04-14
New Features
-
Local agent count in Targets — the Targets page and
skillshare target --jsonnow show how many local (non-source) agents exist per target alongside the linked/expected counts. The Collect button appears for targets with local agents and routes directly to the Collect page with the correct scope pre-selectedskillshare target --json # agentLocalCount field in each target -
Richer
target list --jsonoutput — each target entry now includestargetNaming(effective naming strategy, e.g.flat),sync(skill sync summary), andagentSync(agent sync summary), making JSON output more useful for scripted workflows and external toolingskillshare target list --json # targetNaming, sync, agentSync per target
Bug Fixes
- Fixed batch uninstall for agents — selecting multiple agents from the same tracked repo on the Uninstall page sent only the repo name instead of individual agent names, causing all uninstalls to fail with "agent not found". The confirmation dialog now correctly lists each agent and the API receives individual names
- Fixed empty state messages on the Resources and Uninstall pages — switching to the Agents tab with no agents installed now shows "No agents installed" instead of the generic "No skills installed" text
- Fixed Health Check theme display — the Theme check on the Web UI always showed a warning with technical internals (
fallback-dark-no-tty,no_color: false) that users couldn't understand. Now the CLI and UI both show human-readable messages like "auto-detected from terminal" or "set via SKILLSHARE_THEME", and the UI no longer shows a false warning caused by the server subprocess lacking a terminal
[0.19.1] - 2026-04-13
Bug Fixes
-
Orchestrator repos no longer copy the entire repository — installing a multi-skill repo with a root
SKILL.md(e.g.skillshare install user/project) previously copied the entire repo root into the root skill directory, including source code, assets, CI configs, and build scripts. Now the root skill installs only itsSKILL.md, and each child skill installs as an independent flat directory. Refs: #124# Before: skills/MyProject/ contained the entire repo
# After:
skills/MyProject/SKILL.md ← root skill (SKILL.md only)
skills/child-a/... ← independent child
skills/child-b/... ← independent child -
Structured output no longer corrupted by update notices —
--json,-j, and--format json/sarif/markdownmodes could emit a trailing human-readable update notification into stdout, producing invalid JSON for downstream consumers. The update check is now skipped entirely in structured-output modes, and the notification itself writes to stderr as a safety net. Refs: #129
[0.19.0] - 2026-04-11
New Features
Agent Management
Agents are now a first-class resource type alongside skills. You can install, sync, audit, and manage agent files (.md) across agent-capable targets (Claude, Cursor, OpenCode, Augment) with the same workflow as skills.
-
Agents source directory — agents live in
~/.config/skillshare/agents/(or.skillshare/agents/in project mode).skillshare initcreates the directory automatically, andagents_sourceis a new config field that can be customizedskillshare init # creates skills/ and agents/
skillshare init -p # same for project mode -
Positional kind filter — most commands accept an
agentskeyword to scope the operation to agents only. Without it, commands operate on skills (existing behavior is unchanged)skillshare sync agents # sync agents only
skillshare sync --all # sync skills + agents + extras
skillshare list agents # list installed agents
skillshare check agents # detect drift on agent repos
skillshare update agents --all # update every agent
skillshare audit agents # scan agents for security issues
skillshare uninstall agents foo # uninstall a single agent
skillshare enable foo --kind agent
skillshare disable foo --kind agent -
Install agents from repos —
installauto-detects agents in three layouts:agents/convention subdirectory- mixed-kind repos with both
SKILL.mdandagents/ - pure-agent repos (root
.mdfiles, noSKILL.md)
skillshare install github.com/team/agents # auto-detect
skillshare install github.com/team/repo --kind agent # force agent mode
skillshare install github.com/team/repo --agent cr # specific agentsConventional files (
README.md,LICENSE.md,CHANGELOG.md) are automatically excluded -
Tracked agent repos — agents can be installed with
--trackfor git-pull updates, including nested discovery.check,update,doctor, anduninstallall recognise tracked agent repos, and the--group/-Gflag filters by repo group -
Agent sync modes — merge (default, per-file symlink), symlink (whole directory), and copy are all supported.
skillshare sync agentsskips targets that don't declare anagents:path and prints a warning -
.agentignoresupport — agents can be excluded via.agentignoreand.agentignore.localusing the same gitignore-style patterns as.skillignore. The Web UI Config page now has a dedicated.agentignoretab -
Agent audit —
skillshare auditscans agent files individually against the full audit rule set, with Skills/Agents tab switching in both the TUI and Web UI. Audit results carry akindfield so tooling can filter by resource type -
Agent backup and restore — sync automatically backs up agents before applying changes, in both global and project mode. The backup TUI and trash TUI tag agents with an
[A]badge and route restores to the correct source directory -
Project-mode agent support — every agent command works in project mode with
-p. Agents are reconciled alongside skills into.skillshare/ -
JSON output for agents —
install --jsonandupdate --jsonnow emit agent-aware payloads and apply the same audit block-threshold gate as skills. Useful for scripted agent workflowsskillshare update agents --json --audit-threshold high -
Kind badges — TUI and Web UI surface
[S]/[A]badges throughout (list, diff, audit, trash, backup, detail, update, targets pages) so you can tell at a glance what kind of resource you're looking at
Unified Web UI Resources
-
/resourcesroute — the old/skillspage is now/resources, with Skills and Agents tabs. Tab state persists to localStorage, and the underline tab style follows the active theme (playful mode gets wobble borders) -
Targets page redesign — equal Skills and Agents sections, with a modal picker for adding targets. Filter Studio links include a
?kind=param so you jump directly to the right context -
Update page redesign — a new three-phase flow (selecting → updating → done) with skills/agents tabs, group-based sorting, and status cards. EventSource streaming is properly cleaned up on page change
-
Filter Studio agent support — agent filters can be edited via
PATCH /api/targets/:name(agent_include,agent_exclude,agent_mode) and via the CLI through new flags onskillshare target <name>:skillshare target claude --add-agent-include "team-*"
skillshare target claude --remove-agent-include "team-*"
skillshare target claude --agent-mode copy # merge | symlink | copyThe UI Filter Studio is a single-context view driven by
?kind=skill|agent -
Audit cache — audit results are now cached with React Query and invalidated on mutation. The audit card icon colour follows the max severity, and the count no longer mixes agent totals with finding counts
-
Collect page scope switcher — a new segmented control lets you collect skills or agents from targets
Theme System
internal/themepackage — unified light/dark terminal palette with WCAG-AA-compliant light colours and softened dark primary. Resolution order:NO_COLOR>SKILLSHARE_THEME> OSC 11 terminal probe > dark fallback. All TUIs, list output, audit output, and plain CLI output now route through the themeSKILLSHARE_THEME=light skillshare list
SKILLSHARE_THEME=dark skillshare auditskillshare doctorincludes a theme check to help debug unreadable colours
Install & TUI Polish
-
Explicit
SKILL.mdURLs resolve to one skill — pasting a directblob/.../SKILL.mdURL now installs only that skill, bypassing the orchestrator pack prompt. Previously, the URL would trigger the full multi-select picker even though the intent was clearskillshare install https://github.com/team/repo/blob/main/frontend/tdd/SKILL.mdRefs: #124
-
Radio checklist follows the cursor — the single-select TUI (used for orchestrator selection, branch selection, and similar flows) now auto-selects the focused row. No more confusing empty-selection state — pressing Enter always confirms the item your cursor is on
-
Diff TUI — single-line items with group headers instead of the old verbose-per-item layout. Agent diffs are shown with an
[A]badge -
List TUI — entries are now grouped by tracked repo root and local top directory, with a new
k:kindfilter tag for quick agent/skill filtering inside the fuzzy filter
Centralized Metadata Store
.metadata.jsonreplaces sidecar files andregistry.yaml— installation metadata is now stored in a single atomic file per source (~/.config/skillshare/skills/.metadata.json). This fixes long-standing issues with grouped skill collisions (e.g. two skills both nameddevin different folders) where the old basename-keyed registry would mix them up- Automatic migration — the first load after upgrade reads any existing
registry.yamland per-skill.skillshare-meta.jsonsidecars, merges them into.metadata.json, and cleans up the old files. Idempotent — safe to run repeatedly - Full-path keys — lookups use the full source-relative path, so nested skills never collide
- No user action required; existing installs continue to work
- Automatic migration — the first load after upgrade reads any existing
Bug Fixes
- Sync extras no longer flood when
agentstarget overlaps — targets that declare an extras entry calledagentsare now skipped automatically when agent sync is active, preventing duplicate file writes - Nested agent discovery —
check agentsnow uses the recursive discovery engine, so agents in sub-folders (e.g.demo/code-reviewer.md) are detected correctly - Doctor drift count excludes disabled agents — agents disabled via
.agentignoreno longer count toward the drift total reported byskillshare doctor - Audit card mixes counts — the Web UI audit card no longer mixes agent counts with finding counts, and excludes
_cross-skillfrom the card total (shown separately) - Audit scans disabled agents too — the audit scan walks every agent file regardless of
.agentignorestate, so hidden agents still get checked - List TUI tab bar clipping — the tab bar no longer gets cut off in the split-detail layout on narrow terminals
- Sync extras indent — removed the stray space between the checkmark and the path in
syncextras output; summary headers are now consistent across skills, agents, and extras - UI skill detail agent mode — the detail page hides the Files section for agents (single-file resources), remembers the selected tab via localStorage, and shows the correct folder-view labels
- Sync page layout — the stats row and ignored-skills grouping are now easier to scan
- Button warning variant — the shared
Buttoncomponent now supports awarningvariant that was already referenced by several pages - Check progress bar pop-in — removed the loading progress bar that caused layout shift on the Skills page
- Tracked repo check status — the propagated check status is now applied to every item within the repo, not just the root
- Target name colouring in doctor — only the status word is coloured in
doctortarget output, not the full line
Breaking Changes
audit --allflag removed — use the positional kind filter instead:The oldskillshare audit # skills (default, unchanged)
skillshare audit agents # agents only--allflag is gone because audit now runs per kind and the Web UI has dedicated tabs
[0.18.9] - 2026-04-07
New Features
- Relative symlinks in project mode —
skillshare sync -pnow creates relative symlinks (e.g.,../../.skillshare/skills/my-skill) instead of absolute paths. This makes the project directory portable — rename it, move it, or clone it on another machine and all skill symlinks continue to work. Global mode continues to use absolute paths. Existing absolute symlinks are automatically upgraded to relative on the next sync
Bug Fixes
- Status version detection —
skillshare statusno longer reports! Skill: not found or missing versionwhen the version is stored undermetadata.versionin the SKILL.md frontmatter. Previously, thestatuscommand used its own local parser that only checked for a top-levelversion:key, whiledoctor(fixed in v0.18.7) andupgradealready used the correct shared parser
[0.18.8] - 2026-04-06
Bug Fixes
- Sync no longer deletes registry entries for installed skills — running
skillshare sync(or project-modesync -p) would silently removeregistry.yamlentries for skills whose source files were not present on disk. This meant that installing a skill and then syncing could erase the installation record entirely. Sync now leaves the registry untouched — onlyinstallanduninstallmanage registry entries
[0.18.7] - 2026-04-04
New Features
Folder-Level Target Display & Bulk Editing
-
Folder target aggregation — the Skills page grouped view now shows aggregated target info on each folder row. If all skills share the same target, it shows that target; mixed targets show the union with a warning badge;
Allis shown when no targets are set- Compact display: folders with 4+ targets show
N targetswith full list in tooltip
- Compact display: folders with 4+ targets show
-
Bulk set target — right-click any folder to set or remove the target for all skills in that subtree at once
Right-click folder → Available in... → claudeWrites
metadata.targetsto every SKILL.md in the folder. SelectingAllremoves the field. Disabled skills are skipped -
Single skill target editing — right-click any skill in grouped or grid view, or use the inline
Available indropdown in table view, to change which targets receive that skill
Right-Click Context Menu
-
Context menu on all views — right-click skills in grouped, grid, or table view for quick actions:
- Available in... — submenu to set target (hover-expand with 180ms intent delay)
- View Detail — navigate to skill detail page
- Enable / Disable — toggle skill visibility
- Uninstall — with confirmation dialog
-
Folder context menu — right-click folders in grouped view for
Folder available in...(batch target) — only target actions, no uninstall -
Submenu pattern — top-level items with sub-options expand on hover. Future actions (e.g. Move, Rename) can be added as flat items alongside
Table View Improvements
- Inline target selector — the table now has an
Available incolumn with an inline dropdown for one-click target switching — no context menu needed - Actions column —
⋯button opens a flat menu with View Detail, Enable/Disable, and Uninstall - Simplified layout — reduced from 7 columns to 5 by merging Path and Source into the Name cell. Path shows as a subtitle when different from the name; source shows as a clickable globe icon linking to the repo
- Persistent page size — the selected page size (10/25/50) is remembered across sessions
UX Polish
- Right-click tip banner — a one-time dismissible tip appears on first visit, explaining that right-click is available for actions. Styled with playful theme support (wobble borders, paper-warm background, slight tilt)
- Optimistic updates — all mutations (set target, enable/disable, uninstall) update the UI instantly with automatic rollback on error
- Active item highlight — when a context menu is open, the targeted skill or folder gets a hover-matching highlight
Bug Fixes
-
Config page dashed border clipping — in playful theme, the Structure panel's dashed borders were cut off at the right edge because the panel wrapper kept
overflow-hiddenafter expanding. Now usesoverflow-visiblewhen expanded -
Tracked repos in project-mode dashboard — the Web UI dashboard now shows tracked repositories when running in project mode (
skillshare ui -p), with Update and Uninstall actions -
Nested tracked repo update and uninstall — repos installed with a nested path (e.g.
org/_team-skills) can now be updated and uninstalled from both the CLI and Web UI. Previously, the server failed to resolve nested repo paths for these operations -
Project-mode uninstall cleans correct
.gitignore— uninstalling a tracked repo in project mode now removes entries from.skillshare/.gitignoreinstead of the global source.gitignore. Previously, stale ignore rules were left behind -
Registry prune no longer affects sibling repos — uninstalling a nested tracked repo (e.g.
org/_team-skills) no longer accidentally removes registry entries belonging to a sibling with the same basename (e.g.dept/_team-skills) -
Nested trash lifecycle — trash, restore, cleanup, and listing now work correctly for nested tracked repo names. Parent directories are created on restore and cleaned up after expiry
-
Dashboard tracked repo row polish — status indicators (
clean/modified) moved next to the repo name as compact badges. Action buttons use a smallerxssize to reduce visual weight -
Bulk target folder matching — setting targets on a folder with a trailing slash (e.g.
frontend/) no longer silently skips all skills. The server now normalizes folder paths before matching -
Doctor version detection —
skillshare doctorno longer reports! Skill: missing versionwhen the version is stored undermetadata.versionin the SKILL.md frontmatter. Previously, the inline parser only checked for a top-levelversion:key -
Target display on Skills page — the Skills page now correctly shows saved targets for each skill. Previously, the API did not parse SKILL.md frontmatter, so targets always appeared as
Alleven after being set -
Target editing respects tracked repos — setting targets via the context menu or batch folder action now skips tracked-repo skills. Previously, writing to SKILL.md inside a tracked repo would make the repo dirty and block future updates. Audit hash integrity is also preserved after target edits
-
Uninstall Repo from context menu — right-clicking a tracked-repo skill now shows
Uninstall Repoinstead of the individualUninstallaction (which would always fail with an error) -
Enable/disable with glob patterns — enabling a skill that was disabled by a glob or directory pattern in
.skillignore(or.skillignore.local) now correctly returns an error with guidance, instead of silently showing a success toast while the skill stays disabled -
Disabled tracked skills stay in Tracked view — disabling a tracked-repo skill via
.skillignoreno longer removes it from the Tracked tab. The discovery engine now correctly preserves theisInRepoflag for all disabled skills
[0.18.6] - 2026-04-01
Bug Fixes
-
UI batch uninstall now removes nested skill registry entries — previously, uninstalling grouped skills (e.g.
frontend/vue/vue-best-practices) from the Web UI left stale entries inregistry.yamlbecause the flat name (__) didn't match the stored path name (/). Uninstall now tracks the exact resolved path for accurate cleanup -
Sync prunes stale registry entries —
skillshare syncand the Web UI Sync page now automatically removeregistry.yamlentries for skills that no longer exist in the source directory. Covers manual deletions, not justuninstall. Skills hidden by.skillignoreare preserved -
Uninstall page search works as substring match — typing
mattin the filter box now matchesmattpocock/tdd(substring search). Previously, only glob patterns like*matt*worked. Glob syntax (*,?) still works when present -
Uninstall page shows path format — the confirmation dialog and result summary now display
frontend/vue/vue-best-practicesinstead offrontend__vue__vue-best-practices -
Updates page removes redundant status line — the "0 repo(s) and 20 skill(s) already up to date" line no longer appears when everything is already current (the empty state already says this)
[0.18.5] - 2026-04-01
New Features
--helpfor all commands — every command now supports--help/-hto show usage info, flags, and examples. Previously, commands likepush,pull,sync,status,collect,doctor, anduiwould execute instead of showing help when--helpwas passedskillshare push --help # shows usage instead of pushing
skillshare sync -h # shows flags and examples
skillshare ui --help # shows port/host options
[0.18.4] - 2026-03-31
New Features
Branch Support (--branch / -b)
-
Install from a specific branch — new
--branch/-bflag lets you clone from any branch instead of the remote default:skillshare install github.com/team/skills --branch develop --all
skillshare install github.com/team/skills --track --branch frontend- Works with both tracked repos (
--track) and regular skill installs - Branch is persisted in metadata —
updateandcheckautomatically use the correct branch - Same repo on different branches: use
--nameto avoid collisions:skillshare install github.com/team/skills --track --branch frontend --name team-frontend
skillshare install github.com/team/skills --track --branch backend --name team-backend - Supported in project mode (
-p) and config-driven rebuild (skillshare installwith no args) registry.yamlstores the branch for cross-device reproducibility
- Works with both tracked repos (
-
Branch in Web UI — the Install form shows a Branch input field (inline with Source) when a git source is detected. Skills page shows a branch badge on cards, and the Skill Detail page includes branch in the metadata section
-
Branch in CLI list —
skillshare listdetail panel shows the tracked branch when non-default -
Branch-aware check —
skillshare checkcompares against the correct remote branch ref, not just HEAD. JSON output includes abranchfield for tracked repos
Sync Accuracy
-
Accurate skill counts on Targets page — the expected skill count now reflects what sync actually resolves (after name collision and validation filtering), instead of the raw source count. Previously, targets using
standardnaming could show39032/64075 sharedwhen all resolved skills were actually in sync -
Skipped skill visibility — when skills are excluded by naming validation or collisions, the Targets page and Sync page now show a summary (e.g. "12345 skill(s) skipped, 456 name collision(s)") instead of silently dropping them. Suggests switching to
flatnaming to include all skills
Target Naming Mode
-
target_namingconfig option — choose how synced skill directories are named in targets. Set globally or per-target:target_naming: standard # use SKILL.md name as directory name
targets:
claude:
skills:
target_naming: flat # override: keep flattened prefix (default)flat(default) — nested skills likefrontend/devbecomefrontend__devin targetsstandard— uses the SKILL.mdnamefield directly (e.g.dev), following the Agent Skills specification- Standard mode validates that SKILL.md names match their directory name, warns and skips invalid skills
- Name collisions (e.g. two skills both named
dev) are detected and both are skipped with a warning - Switching from
flattostandardautomatically migrates existing managed entries (symlinks and copies are renamed in place) - If a local skill already occupies the bare name, the legacy flat entry is preserved with a warning
target_namingis ignored insymlinkmode (the entire source directory is linked)
-
Collision output redesigned — name conflict warnings are now deduplicated across targets and displayed as a compact summary instead of repeating each collision per target
Folder Tree View (Web UI)
-
Skills folder tree — the second layout on
/skillsis now a true folder tree with multi-level expand/collapse, matching your actual directory structure from--into:- Click any folder to expand/collapse its children
- Expand All / Collapse All buttons in the toolbar
- Sticky folder header — scrolling through a long folder keeps the folder name pinned at the top; click it to jump back
- Search-aware — filtering or searching auto-expands all matching folders; clearing restores your previous collapse state
- Hover tooltip on skill rows shows path, source, and install date (follows cursor, 1.5s delay)
- Collapse state persists across page reloads via localStorage
- Virtualized rendering handles 10,000+ skills with no performance impact
-
Skill detail button layout — the Enable/Update/Uninstall buttons no longer wrap awkwardly on narrow screens
Agent Target Paths
- Agent-specific paths — targets that support agents (Claude, Cursor, OpenCode, Augment) now declare separate
agents:paths in their configuration. This is groundwork for upcoming agent sync support
GitHub Actions
setup-skillshareaction — install skillshare in CI with a single step:- uses: runkids/setup-skillshare@v1
Bug Fixes
- CLI sync output no longer floods terminal — targets with thousands of naming validation warnings (common with
standardnaming and large skill sets) now print a compact summary instead of one line per skipped skill - Target dropdown lag removed — changing sync mode or target naming in the Web UI Targets page now updates instantly via optimistic cache update, instead of waiting 2 seconds for the API round-trip
Performance
- Cached branch lookups —
skillshare listcachesgitbranch queries per tracked repo, so listing 500 skills from the same repo runs 1 git command instead of 500
[0.18.3] - 2026-03-29
New Features
Enable / Disable Skills
-
skillshare enable/skillshare disable— temporarily hide skills from sync without uninstalling them. Adds or removes patterns in.skillignore:skillshare disable draft-* # hide from sync
skillshare enable draft-* # restore
skillshare disable my-skill -p # project mode
skillshare disable my-skill -n # dry-run preview -
TUI toggle — press
Einskillshare listto toggle the selected skill's enabled/disabled state. The change is written immediately without leaving the TUI. Disabled skills show a red disabled badge in the detail panel and a[disabled]suffix in compact view -
Web UI toggle — the Skill Detail page now shows an Enable/Disable button. The REST API exposes
POST /api/skills/{name}/enableandPOST /api/skills/{name}/disableendpoints
Target Config — Skills Sub-Key
- Per-resource-type configuration — target configs now support a
skillssub-key with its ownpath,mode,include, andexcludesettings. Existing flat-field configs are auto-migrated on first load — no manual editing needed:targets:
claude:
skills:
path: ~/.claude/skills
mode: merge
Upgrade Improvements
- Auto-sudo for protected paths —
skillshare upgradenow auto-detects when the binary is in a write-protected directory (e.g.,/usr/local/bin) and transparently re-executes withsudo(#105)
Bug Fixes
- Fixed
diffshowing skills with unsupportedtargetsvalues (e.g.,targets: ["*"]) as "source only" pending items — these skills are now correctly filtered out, matching the behavior ofsync - Fixed
collectignoring inherited sync mode when a target's mode was set at the global level — the command now resolves the effective mode before deciding whether to scan for local skills - Fixed
collectusing a stale manifest after switching a target fromcopytomergemode - Fixed
pullinfo message referencinggit stashinstead ofgit stash -u - Fixed config migration writing directly to the config file — now uses atomic write-to-temp + rename to prevent corruption on disk errors
[0.18.2] - 2026-03-28
New Features
Update Page Improvements
-
Sticky progress bar — the Update page now shows a real-time progress bar during batch updates with percentage, completed/total count, and ETA. The bar stays pinned to the top while scrolling through the item list
-
Auto-scroll to active item — during batch updates, the page automatically scrolls to the item currently being updated so you can follow the progress without manual scrolling
-
Purge stale skills — when a skill fails to update because its subdirectory no longer exists in the repository, a Purge button appears instead of Force Retry. Clicking it removes the stale skill from your source directory
Analyze & Install UX
-
Install picker improvements — the skill picker modal in Install and Analyze pages now auto-focuses the search field, shows clearer skill descriptions, and handles keyboard navigation better
-
Tooltip enhancements — tooltips across the dashboard now follow the cursor and stay within viewport bounds
Bug Fixes
- Fixed analyze page crash when a target has no skills (null targets array from API)
- Fixed redundant path line showing in the skill detail dialog on the Analyze page
- Fixed install source field not clearing after a successful installation
[0.18.1] - 2026-03-27
New Features
Analyze — Filter & Token Budget
-
--filterflag — filter skills by name or group path with case-insensitive substring matching. Works across all output modes:skillshare analyze claude --json --filter frontend # JSON with filtered_summary
skillshare analyze --filter marketing # TUI with pre-populated filter -
Dynamic token subtotals — the TUI stats line and Web UI now show always-loaded, on-demand, and total token sums for the current filtered set. In the TUI, the format changes to
5/50 skillswhen a filter is active -
Web UI filtered summary bar — when searching or filtering on the Analyze page, a summary bar appears above the table with token counts per category. The bar slides in/out with a smooth animation
-
JSON
filtered_summary— when--filteris used with--json, the output includesfilter,matched_count,total_count, and afiltered_summaryobject withalways_loaded,on_demand, andtotaltoken counts
Registry Location
- Registry moved to source directory —
registry.yamlnow lives at~/.config/skillshare/skills/registry.yaml(inside the source directory) instead of~/.config/skillshare/registry.yaml. This meansgit syncautomatically includes the registry, so tracked skill metadata is preserved across machines. Migration is automatic on first run (#103)
Bug Fixes
init --remoteskips skill prompt — wheninit --remoteclones a repo that already contains skills, the interactive "choose skills to install" prompt is now skipped since the remote already defines the skill set (#102)
Improvements
- Analyze Web UI polish — improved empty state with icon and helper text, fixed table height to prevent layout jumps when filtering, lint filter badge now shows readable rule names (e.g., "No Trigger Phrase" instead of
no-trigger-phrase)
[0.18.0] - 2026-03-26
New Features
Analyze Command — Context Window & Skill Quality
-
skillshare analyze— new command that calculates context window token usage for each target's skills. Shows two layers of cost: "always loaded" (name + description, loaded every request) and "on-demand" (skill body, loaded when triggered). Token estimates usechars / 4:skillshare analyze # interactive TUI
skillshare analyze claude # single target (auto-verbose)
skillshare analyze --verbose # top 10 largest descriptions
skillshare analyze --json # machine-readable output
skillshare analyze -p # project mode -
Skill quality lint —
analyzeruns 7 built-in lint rules against every skill, checking SKILL.md structure and description quality:- Errors: missing
name, missingdescription, empty body - Warnings: description too short (<50 chars), too long (>1024 chars), near limit (900–1024), missing trigger phrases (e.g., "Use when…")
Lint issues appear in the TUI (✗ for errors, ⚠ for warnings) and in
--jsonoutput aslint_issuesper skill - Errors: missing
-
Interactive TUI — full-screen bubbletea TUI with left skill list and right detail panel. Features include:
- Color-coded dots (red/yellow/green by percentile) indicating relative token cost
- Tab/Shift+Tab to switch between targets; identical targets are merged into groups
/to filter skills,sto cycle sort (tokens↓ → tokens↑ → name A→Z → Z→A)- Quality section in detail panel showing all lint findings with icons
-
--no-tuiflag — disable the interactive TUI and print plain text summary
Web UI — Analyze Page
- Analyze dashboard — new page in the web dashboard showing per-target token usage with a chart, skill table with token breakdown, and lint issue indicators
- Skill detail token breakdown — the Skill Detail page now shows always-loaded and on-demand token counts
GET /api/analyzeendpoint — REST API returning per-target context analysis with lint issues, skill paths, tracked status, and descriptions
Web UI — Update Page Improvements
- Sticky search filter — the search input on the Update page now sticks to the top when scrolling, making it easy to filter skills in long lists
- SplitButton actions — Update page action buttons replaced with a SplitButton component for cleaner interaction
Improvements
- Unified dialog styling — all modal dialogs (Confirm, File Viewer, Hub Manager, Keyboard Shortcuts, Skill Picker, Sync Preview, Update) now share consistent styling via a shared
DialogShellcomponent
[0.17.11] - 2026-03-25
New Features
Extras — Flatten Option
-
flattenfor extras targets — whenflatten: trueis set on an extras target, all files from subdirectories are synced directly into the target root instead of preserving the directory structure. This is useful for AI tools (e.g., Claude Code's/agents) that only discover files at the top level:extras:
- name: agents
targets:
- path: ~/.claude/agents
flatten: true # source/curriculum/tactician.md → target/tactician.md -
--flattenflag forextras init— enable flatten when creating a new extra:skillshare extras init agents --target ~/.claude/agents --flatten -
--flatten/--no-flattenforextras mode— toggle flatten on existing targets:skillshare extras agents --flatten
skillshare extras agents --no-flatten -
Flatten in TUI wizard — the
extras initinteractive wizard now includes a "Flatten files into target root? (y/N)" step after mode selection (skipped for symlink mode) -
Filename collision handling — when flatten causes files from different subdirectories to share the same name (e.g.,
team-a/agent.mdandteam-b/agent.md), the first file wins (sorted alphabetically) and subsequent collisions are skipped with a warning -
Fflatten toggle in TUI — pressFin the extras list TUI to toggle flatten on/off for a target. Single-target extras toggle directly; multi-target extras show a target picker first
Web UI — Flatten Support
- Flatten checkbox — the Extras page shows a flatten checkbox per target, both when creating extras and on existing targets. Disabled when mode is symlink
- Config editor validation — the YAML config editor warns when
flatten: trueis combined withmode: symlink - Target name field docs — clicking a target name in the config editor (both
name: claudeand short-form- agents) now shows the correct "target name" documentation instead of unrelated field docs
[0.17.10] - 2026-03-24
New Features
- Update notification in Web UI — a dialog appears on first visit when a newer CLI or skill version is available. Shows current and latest versions with a copyable
skillshare upgradecommand. Dismissed once per browser session
Bug Fixes
- Skill cards equal height — skill cards on the Skills page now stretch to equal height within each row
- Tour step target fix — the skill-filters tour step now correctly highlights its target element
[0.17.9] - 2026-03-20
New Features
- Force toggle on Extras page — a new Force button in the Extras page header lets you overwrite existing files when the sync mode has changed. Hover for a tooltip explaining what it does. Previously, skipped files could only be force-synced via the CLI (
skillshare sync extras --force)
Bug Fixes
- Config page assistant panel now scrollable — the right-side Structure/Diff panel now has a fixed 500px content area matching the editor height, enabling vertical scrolling when the YAML structure is long
- Removed false "Unknown target" warnings — the config editor no longer flags custom target names as unknown. Target names are user-defined and freely configurable — any name is valid
- Audit rules assistant panel scrollable — same fixed-height scrolling fix applied to the Audit Rules page's assistant panel
- Extras sync API response key — fixed the JSON response key from
resultstoextras, which prevented the Extras page from displaying sync results
Improvements
- Richer
targetsfield docs — thetargetsfield documentation example now shows all sub-fields (path,mode,include,exclude) with multiple targets - Filter Studio virtual scrolling — the skill preview list now uses virtual scrolling for smooth performance with large skill collections
- Force auto-resets after sync — the Force option on both the Sync and Extras pages automatically disables after a successful sync, preventing accidental overwrites on subsequent runs
- Smarter skip toast — when extras files are skipped, the toast suggests "enable Force to override" instead of a CLI command. If Force is already enabled, the hint is omitted
[0.17.8] - 2026-03-19
New Features
Extras — Configurable Source Paths
-
Custom extras source directory — extras source paths are now configurable instead of hardcoded. Add
extras_sourcetoconfig.yamlto set a global default, or use per-extrasourcefor individual overrides:extras_source: ~/my-extras # all extras default to here
extras:
- name: rules
source: ~/company-shared/rules # this one overrides extras_source
targets:
- path: ~/.claude/rules
- name: commands # uses extras_source (~/my-extras/commands/)
targets:
- path: ~/.cursor/commandsResolution priority: per-extra
source>extras_source> default (~/.config/skillshare/extras/<name>/) -
--sourceflag forextras init— specify a custom source directory when creating an extra:skillshare extras init rules --target ~/.claude/rules --source ~/company-shared/rules -
Source input in TUI wizard — the
extras initinteractive wizard now includes a source directory step between name and target input. Leave empty to use the default -
extras sourcecommand — show or set the globalextras_sourcedirectory from the CLI instead of editingconfig.yamlmanually:skillshare extras source # show current value
skillshare extras source ~/company-shared/extras # set new value -
--forceflag forextras init— overwrite an existing extra without needing toextras removefirst:skillshare extras init rules --target ~/.cursor/rules --force -
--sourcerejected in project mode —extras init --sourcenow returns a clear error in project mode instead of silently ignoring the flag. Project mode always uses.skillshare/extras/<name>/ -
source_typein JSON output —extras list --jsonandGET /api/extrasnow include asource_typefield (per-extra,extras_source, ordefault) indicating which level resolved the source path
Web UI — Extras Source
- Source type badge — the Extras page shows a
(per-extra)or(extras_source)badge next to non-default source paths - Source input in Add Extra modal — optional "Source path" field when creating extras from the dashboard
- API accepts
sourcefield —POST /api/extrasnow accepts an optionalsourcefield in the request body
Web UI — Config Editor Assistant Panel
- Context-aware assistant panel — the Config page now has a right-side panel that shows relevant information as you edit
config.yaml:- Field docs — move your cursor to any field and see its description, type, allowed values, and an example snippet. Covers all 28+ config fields (source, mode, targets, extras, audit, hub, log, tui, gitlab_hosts, and sub-fields)
- Structure tree — visual outline of your YAML structure with line numbers. Click any node to jump to that line in the editor
- Real-time validation — inline error markers for YAML syntax errors. Schema validation warns about unknown target names (with typo suggestions), invalid sync modes, and invalid audit settings
- Diff preview — see what changed since last save, with colored add/remove lines. Includes a "Revert All" button to reset to the last saved version
- The panel auto-switches between views by priority (errors → field docs → structure), or lock to Structure/Diff via the bottom bar
- Collapse the panel with the toggle button or
Cmd+B; save withCmd+S
- Empty config guide — when the editor is empty, the panel shows all available top-level fields as a quick reference
.skillignorepanel — the.skillignoretab shows a simplified panel with change count and the list of currently ignored skills (from all sources, including tracked repos)
Web UI — Audit Rules Assistant Panel
- YAML editor assistant panel — the Audit Rules page's YAML editor now has the same assistant panel as the Config page:
- Field docs — cursor-aware documentation for all audit rule fields (id, severity, pattern, message, regex, exclude, enabled) with allowed values and examples
- Regex tester — move your cursor to a
regex:field and the panel auto-switches to an inline regex tester. Paste test lines and see match results instantly with highlighted matches. Supports(?i)flag conversion from Go to JavaScript - Real-time validation — warns about invalid severity values, uncompilable regex patterns (with Go-specific syntax detection), and YAML syntax errors
- Structure tree + Diff preview — same as Config editor
- Three bottom-bar locks: Structure / Diff / Test
- Save button in header — the Save button is now in the page header (top-right) for better visibility
Bug Fixes
.skillignoresave no longer shows sync preview banner — the "Preview Sync" prompt after save is now only shown forconfig.yamlchanges, not.skillignore- Tracked repo ignores visible without root
.skillignore— previously, if the root.skillignorefile didn't exist, the API returned no ignore stats at all, hiding tracked repos' own.skillignoreentries. Now always reports all ignored skills regardless of whether a root file exists - Dirty state guard on tab switch — switching between
config.yamland.skillignoretabs with unsaved changes now shows a confirmation dialog instead of silently discarding edits
[0.17.7] - 2026-03-19
New Features
Web UI — Uninstall Skills Page
- Batch uninstall from the dashboard — a new "Uninstall Skills" page lets you remove multiple skills at once with filtering and multi-select. Filter by group directory, glob pattern (
*react*,frontend/*), or type (Tracked / GitHub / Local), then check the skills you want to remove and confirm:- Group dropdown narrows to a specific directory
- Glob pattern input with real-time matching (supports
*and?) - Type filter tabs with counts (matching the Skills page style)
- Select All / Deselect All for the current filtered view
- Tracked repos auto-escalate — selecting any skill inside a tracked repo selects the entire repo, with a force option for uncommitted changes
- Results show per-item success/failure with a "Run sync" reminder
- Batch uninstall API —
POST /api/uninstall/batchaccepts multiple skill names in a single request with skip-and-continue semantics. Includes registry cleanup, config reconciliation, and.gitignorebatch removal — matching the CLI's behavior
TUI — Target Remove Action
- Remove targets with
Rkey — the target list TUI (skillshare list --targets) now supports pressingRto remove a target from your config
Bug Fixes
- Sidebar no longer shifts on long skill lists — fixed a layout issue where scrolling to the bottom of the Skills page caused the sidebar to shift horizontally
[0.17.6] - 2026-03-19
Bug Fixes
- Sync auto-creates missing target directories with notification — v0.17.5 introduced a strict check that blocked sync when a target directory didn't exist (e.g.,
~/.claude/skillson a fresh Claude Code install). This prevented first-time users from syncing without manually creating directories (#87). Sync now auto-creates missing directories and shows what it did:Dry-run mode previews which directories would be created without actually creating them✓ claude: merged (99 linked, 0 local, 0 updated, 0 pruned)
ℹ Created target directory: ~/.claude/skills skillshare initcreates target directories — wheninitdetects an installed CLI tool (e.g.,~/.claude/exists) but the skills subdirectory is missing, it now creates it automatically instead of leaving it as "not initialized"
Web UI
- Sync Preview shows directory creation — the Config → Preview Sync modal and the Sync page now display a "directory created" or "directory will be created" badge per target when a target directory is auto-created
- Sync Preview stays open after sync — the Config → Preview Sync → Sync Now flow now shows sync results in the modal with a "Sync Complete" banner instead of immediately closing. This gives you time to review what changed before dismissing
[0.17.5] - 2026-03-18
New Features
Config Save Validation
- Semantic validation on config save —
PUT /api/confignow validates config semantics before writing, not just YAML syntax. Invalid configs return HTTP 400 with a descriptive error instead of saving silently and failing at sync time:- Source path must exist and be a directory
- Sync mode must be
merge,symlink, orcopy(global and per-target) - Target paths must exist and be directories
- CLI validation before sync —
skillshare syncvalidates config before starting. Invalid source path or sync mode exits immediately with a clear error instead of a cryptic filesystem error mid-sync - Config save warnings — when saving config with non-fatal issues, the API returns
{ success: true, warnings: [...] }. The Config page shows a warning toast with details
Sync Safety — No Auto-Create
- Sync no longer auto-creates target directories — previously,
syncwould silentlymkdir -pany missing target path. This masked typos (e.g.,~/.cusor/skillsinstead of~/.cursor/skills). Now sync fails fast with a clear error:This applies to all sync modes (merge, copy, symlink conversion) and also toError: target directory does not exist: /home/user/.cusor/skills--dry-run - Dry-run path validation —
sync --dry-runnow detects missing target paths and reports errors, matching the behavior of a real sync. Previously dry-run skipped existence checks
Web UI — Sync Warnings
- Sync pre-check warnings — the sync API response now includes a
warningsfield surfacing issues like empty source directories or missing target paths. Warnings appear as a yellow banner on the Sync page and in the Sync Preview modal - Dashboard full paths — the Source Directory card on the Dashboard now shows the full absolute path instead of abbreviating with
~/
Web UI — Config Save → Sync Preview
- Preview Sync from Config page — after saving
config.yamlor.skillignore, a banner appears above the editor offering to preview what sync will do. Click "Preview Sync" to open a modal showing a dry-run per target — which skills will be linked, updated, or pruned — before committing to the real sync:The banner auto-dismisses when you start editing again. Handles edge cases: no targets configured, everything already in sync, API errors with retry, and a refresh button to re-run the dry-runSave config → Banner: "Config updated — preview what sync will do?"
→ Modal shows dry-run results per target (compact badge view)
→ "Sync Now" to confirm, or Cancel to walk away
Web UI — Base Path for Reverse Proxy
--base-pathflag — serve the Web UI under a sub-path behind a reverse proxy (e.g., Nginx, Caddy):Also configurable viaskillshare ui --base-path /skillshare # UI at http://host/skillshare/SKILLSHARE_UI_BASE_PATHenvironment variable. All API routes, static assets, and client-side navigation automatically adjust to the base path
Skill Design Patterns — skillshare new Wizard
-
Design pattern templates —
skillshare newnow offers five structural design patterns for your skills, each with a tailored SKILL.md template and recommended directory structure:Pattern Description tool-wrapperTeach agent how to use a library/API generatorProduce structured output from a template reviewerScore/audit against a checklist inversionAgent interviews user before acting pipelineMulti-step workflow with checkpoints -
Interactive wizard — running
skillshare new my-skillwithout flags launches a TUI wizard that guides you through pattern, category, and directory scaffolding. Esc goes back to the previous step:skillshare new my-skill # Interactive wizard
skillshare new my-skill -P reviewer # Skip wizard, use reviewer pattern directly
skillshare new my-skill -P none # Plain template (previous behavior) -
Category tagging — optionally tag your skill with a use-case category (library, verification, data, automation, scaffold, quality, cicd, runbook, infra) stored as a
category:frontmatter field -
Scaffold directories — when using a pattern, the wizard offers to create recommended subdirectories (
references/,assets/,scripts/) with.gitkeepplaceholders. Auto-created when using-P
Web UI — New Skill Wizard
- Create skills from the dashboard — the Skills page now has a "+ New Skill" button that opens a step-by-step wizard at
/skills/new:The wizard dynamically skips steps based on your choices — selecting "none" pattern goes straight to confirm. Pattern and category selection use card grids with descriptions. Scaffold directories are toggle cards (all on by default). On success, navigates to the new skill's detail pageName → Pattern → Category → Scaffold → Confirm GET /api/skills/templates— new endpoint returning available patterns and categories. Used by the wizard, also available for custom integrationsPOST /api/skills— new endpoint to create a skill with name, pattern, category, and scaffold directories. Validates name format, checks for duplicates (409), and validates scaffold dirs against the pattern's allowed list
.skillignore.local — Local Override
.skillignore.local— a local-only override file that works alongside.skillignore. Place it in the same directory (source root or tracked repo root) to override patterns without modifying the shared.skillignore:Patterns from# _team-repo/.skillignore blocks private-*
# _team-repo/.skillignore.local un-ignores your own:
echo '!private-mine' > _team-repo/.skillignore.local
skillshare sync # private-mine is now discovered.skillignore.localare appended after.skillignore, so!negationrules naturally override the base file. Works at both the source root and repo level- CLI indicators —
sync,status, anddoctorshow.local activewhen a.skillignore.localis in effect. JSON output includes.localfile paths in thefilesarray
metadata.targets — Ecosystem-Aligned Frontmatter
metadata.targets— thetargetsfield in SKILL.md can now be placed under ametadata:block, aligning with the emerging agent skill ecosystem convention used across 30+ AI CLI tools:The top-level---
name: claude-prompts
description: Prompt patterns for Claude Code
metadata:
targets: [claude]
---targets:format continues to work. If both are present,metadata.targetstakes priority. This is a backward-compatible change — existing skills require no modification
New Target: Hermes Agent
- Hermes Agent — Nous Research's CLI is now a built-in target (56+ total). Global:
~/.hermes/skills, Project:.hermes/skills
[0.17.4] - 2026-03-17
New Features
Doctor JSON Output
doctor --json— structured JSON output for CI pipelines and automation. Returns per-check results with status, message, and details:Exit code 1 when errors are found, 0 for warnings-only or all-passskillshare doctor --json
skillshare doctor --json | jq '.summary' # Quick summary
skillshare doctor --json | jq -e '.summary.errors == 0' # CI gate
Web UI — Health Check Page
- Health Check page — new dashboard page at
/doctorshowing environment diagnostics with summary cards (pass/warnings/errors), filter toggles, expandable check details, and version info. Access from the sidebar under "System → Health Check" GET /api/doctor— new API endpoint returning the same structured JSON asdoctor --json
Root-Level .skillignore
- Root-level
.skillignore— place a.skillignorefile in the source root (e.g.~/.config/skillshare/skills/.skillignore) to hide skills and directories from all commands. Previously.skillignoreonly worked inside tracked repos (_repo/.skillignore); now it works at both levels:# ~/.config/skillshare/skills/.skillignore
draft-* # Hide all draft skills
_archived/ # Hide entire directory - SkipDir optimization — directories matching
.skillignorepatterns are now skipped entirely during discovery (not entered), improving performance for large source trees
Full Gitignore Syntax for .skillignore
-
Gitignore-compatible pattern matching —
.skillignorenow supports the full gitignore syntax instead of just exact names, prefixes, and trailing*. New supported features:Pattern Example Behavior ****/testMatch at any directory depth ??.mdMatch a single character [abc][Tt]estCharacter class !pattern!importantNegation — un-ignore a previously ignored skill /pattern/root-onlyAnchored to the .skillignore location pattern/build/Match directories only \#,\!\#fileEscaped literal characters # .skillignore — now supports gitignore syntax
**/temp # Ignore "temp" at any depth
test-* # Ignore all test- prefixed skills
!test-important # But keep test-important
vendor/ # Ignore vendor directories only
[Dd]raft* # Character class matching -
Parent directory inheritance — if a directory is ignored, all its contents are automatically ignored too.
vendorin.skillignorewill excludevendor/lib/deep/skillwithout needingvendor/** -
Safe directory skipping with negation — when negation patterns (
!) are present, skillshare avoids skipping parent directories prematurely, ensuring negated skills inside ignored directories are still discovered
.skillignore Visibility
statusshows .skillignore info — when a.skillignorefile exists,statusnow displays an extra line below the source path showing active pattern count and ignored skill count:Source: ~/.config/skillshare/skills (12 skills)
.skillignore: 5 patterns, 3 skills ignoredstatus --jsonincludes skillignore field — thesourceobject in JSON output now includes askillignorefield withactive,files,patterns,ignored_count, andignored_skillsdoctor --jsonskillignore check — a newskillignorecheck appears in the doctor output. Showspasswith pattern/ignored counts when.skillignoreexists, orinfostatus when absentinfostatus in doctor — new fourth status alongsidepass/warning/errorfor informational checks that are neither passing nor failing. Does not count toward errors or warnings
Web UI — .skillignore Editor
- Config page tabs — the Config page now has two tabs:
config.yamland.skillignore, switchable via the same pill toggle used on the Skills and Doctor pages. Each tab has independent save state .skillignoreeditor — full CodeMirror text editor for.skillignorewith live stats showing how many skills are currently ignored. Below the editor, an "Ignored Skills" summary shows which skills are excludedGET/PUT /api/skillignore— new API endpoints for reading and writing the.skillignorefile with ignore statistics
Web UI — Doctor Page Unification
- SegmentedControl filter — the Doctor page filter toggles (All/Error/Warning/Pass) now use the same
SegmentedControlcomponent as the Skills page, replacing the previous hand-styled buttons for visual consistency
Sync — .skillignore Ignored Skills
syncshows ignored skills — after sync completes, the CLI now lists skills excluded by.skillignorewith a source hint showing whether ignores come from the root-level file, repo-level files, or both:7 skill(s) ignored by .skillignore:
• _team/vendor/lib
• _team/feature-radar
• draft-wip
(from root .skillignore + 1 repo-level file)sync --jsonincludesignored_countandignored_skills— JSON output now includes the full list of ignored skills for automation and scriptingdoctorshows skillignore status — the Checking Environment section now displays.skillignorepattern count and ignored skill count (was previously JSON-only)- Web UI Sync page — a collapsible "Ignored by .skillignore" card appears on the Sync page showing which skills were excluded and whether the ignores come from root or repo-level files. An "ignored" badge also appears in the pending changes summary
Doctor Output Readability
- Visual spacing in
doctoroutput — config directory paths, source/environment checks, and skill validation checks are now separated by blank lines for easier scanning - Duplicate skill names truncated — when targets have overlapping skills isolated by filters,
syncnow shows only the first 5 names instead of dumping all (e.g., 14000+) on a single line
Bug Fixes
.skillignorerespected in all discovery paths —.skillignorepatterns were not applied during source discovery, causingdoctorto report false "unverifiable (no metadata)" warnings for intentionally excluded directories (e.g.,.venv/inside tracked repos). Discovery now consistently honors.skillignoreacross all commands (#83).skillignoredirectory-only patterns during install — patterns with trailing slash (e.g.,demo/) now correctly match directories duringskillshare installdiscovery, not just during sync- Quieter integrity checks —
doctorno longer warns about locally-created skills missing metadata (this is expected). Only installed skills with incomplete metadata are flagged, with skill names listed for easy identification - Doctor check labels — the web UI Health Check page shows human-readable labels ("Source Directory", "Sync Status") instead of raw identifiers (
source,sync_drift) - Doctor global mode in web UI —
skillshare ui -gnow correctly passes-gto the doctor subprocess, preventing it from auto-detecting project mode when the server's working directory contains.skillshare/config.yaml
[0.17.3] - 2026-03-16
New Features
Centralized Skills Repo
--config localfor project init —skillshare init -p --config localgitignoresconfig.yamlso each developer manages their own targets independently. Skills are shared via git, config stays local:# Creator: set up shared skills repo
skillshare init -p --config local --targets claude
skillshare install <skill> -p && git push
# Teammate: clone and configure own targets
git clone <repo> && cd <repo>
skillshare init -p
skillshare target add myproject ~/DEV/myproject/.claude/skills -p- Smart shared repo detection — when a teammate clones a shared skills repo and runs
skillshare init -p, skillshare auto-detects the shared repo pattern (config.yaml in .gitignore) and creates an empty config with guided next steps. No--config localflag needed for cloners
Init Source Path Prompt
- Interactive source path customization —
skillshare initnow asks whether you want to customize the source directory path instead of silently using the default (~/.config/skillshare/skills/). Use--sourceto skip the prompt in scripts:skillshare init # Prompts for source path
skillshare init --source ~/my-skills # Skips prompt
Target List Interactive TUI
- Interactive target browser —
skillshare target listnow launches a full-screen TUI with a split panel layout (target list on the left, detail panel on the right). Includes fuzzy filtering via/and keyboard navigation:skillshare target list # Interactive TUI (default on TTY)
skillshare target list --no-tui # Plain text output - Mode picker — press
Mon any target to change its sync mode (merge, copy, symlink) without leaving the TUI. Changes are saved to config immediately - Include/Exclude editor — press
IorEto open an inline pattern editor for the selected target. Add patterns witha, delete withd— changes persist to config on each action
Web UI — Filter Studio
- Filter Studio page — new dedicated page for managing target include/exclude filters at
/targets/{name}/filters. Two-column layout: edit glob patterns on the left, see a live preview of which skills will sync on the right. Click any skill in the preview to toggle it between include/exclude:Dashboard → Targets → Customize filters → (Filter Studio opens) - Always-visible filter summary — every target card on the Targets page now permanently displays a skill count line (
All 18 skillsor12/18 skills) with filter tag previews (max 3 tags,+N morefor overflow). Replaces the hidden ghost "Filters" button that nobody noticed - Skill Detail — Target Distribution — the skill detail sidebar now shows a "Target Distribution" card listing which targets this skill syncs to, with status indicators (synced, excluded, not included, SKILL.md targets mismatch). Links to Filter Studio for editing
- Live preview with search — Filter Studio's preview panel includes a search box to quickly find skills in the list, and updates in real-time (500ms debounce) as you add or remove patterns
GET /api/sync-matrix— new API endpoint returning the authoritative skill × target sync matrix with status and reason for each entry. Supports?target=filter.POST /api/sync-matrix/previewaccepts draft patterns for what-if preview without saving- Auto-commit on blur —
FilterTagInputnow automatically adds the typed pattern when the input loses focus, preventing the common mistake of typing a pattern but forgetting to press Enter
Web UI — Skill Detail Styling
- Post-it sidebar cards — Metadata, Files, Security, Target Distribution, and Target Sync cards in the skill detail sidebar now use semantic pastel backgrounds in playful theme (yellow, green, blue, cyan) with thumbtack pin decorations. Clean theme uses white backgrounds
- Hand-drawn manifest block — the SKILL.md manifest area uses a sketchy dashed border with tape decoration in playful theme
- Unified input borders — all text inputs, textareas, selects, and tag inputs now use consistent
border-2 border-mutedstyling withfocus:border-pencilacross the dashboard
Bug Fixes
- Web UI network error guidance — the web dashboard now shows a clear "restart
skillshare ui" message when the API server is unreachable, instead of a generic "Failed to fetch" error init --helpcompleteness —skillshare init --helpnow shows the--subdirflag and lists flags in the same order as the documentation- Project trash gitignore —
skillshare init -pnow automatically addstrash/to.skillshare/.gitignore, preventing soft-deleted skills from being accidentally committed. Existing projects are patched on the nextuninstallrun - Web UI target filter persistence — target include/exclude filters set via the web dashboard are now correctly persisted; previously, in-memory state could drift from disk after saving, causing subsequent page loads to show stale filter values
- Web UI extras list empty state — the extras list page now renders correctly when no extras are configured, fixing a missing tour target in the empty state
- Partial init repair auto-select —
skillshare init -pnow automatically selects all detected targets when repairing a partial initialization (.skillshare/exists butconfig.yamlis missing), instead of prompting you to pick from a checklist - Target list TUI help bar — scroll hints (
Ctrl+d/u) and help bar key ordering now follow the same convention as other TUIs (navigate → filter → scroll → actions → quit) - Web UI server stability — fixed a potential crash when concurrent API requests (e.g., multiple browser tabs) hit the dashboard while target config was being modified
[0.17.2] - 2026-03-14
New Features
Web UI Git Sync Enhancements
- Repository Info Card — the Git Sync page now displays a card showing the current repository URL, branch, and latest commit at the top of the page
- Branch switcher — switch between git branches directly from the Git Sync page without leaving the web dashboard
Web UI Backup & Sidebar
- Backup page restore UX — improved restore flow with clearer action buttons and confirmation dialogs
- Collapsible sidebar tools — sidebar tool sections can now be collapsed/expanded to reduce visual clutter
CLI TUI Improvements
- Trash TUI split panel — the trash list now uses the same left-right split panel layout as other TUIs, with a detail panel showing item info alongside the list
Bug Fixes
- Backup command spinner —
skillshare backupnow shows a progress spinner during backup operations instead of appearing frozen - Git Sync footer layout — Push/Pull action buttons are now pinned to the bottom of the page and no longer shift when content changes
Performance
- Restore TUI async size calculation — backup version sizes are now computed asynchronously in the background instead of blocking the TUI. Large backups with many versions no longer freeze the interface when browsing or selecting versions. Detail panel I/O is capped at 20 skills to prevent lag on large backups
[0.17.1] - 2026-03-13
New Features
Web UI Theme System
- Multi-theme support — the web dashboard now offers two visual styles and three color modes, switchable via the Theme button in the sidebar:
- Styles:
Clean(professional, minimal) andPlayful(hand-drawn borders, organic shapes) - Modes:
Light,Dark, andSystem(follows OS preference) - Preferences persist in localStorage across sessions. Default: Playful + Light
- Styles:
Init Source Subdirectory
- Subdirectory prompt during init —
skillshare initnow prompts whether to store skills in a subdirectory instead of the repository root. Useful when embedding skills inside a dotfiles or monorepo:This sets the source path toskillshare init --remote git@github.com:you/dotfiles.git --subdir skills~/.config/skillshare/skills/skills/, keeping the repo root free for README, CI config, and other non-skill files
Bug Fixes
- Collect skips
.git/directories —skillshare collectnow excludes.git/when copying skills from target to source. Previously, collecting a git-cloned repo (e.g.,obra/superpowersin~/.cursor/skills/) could produce only empty directories becausefilepath.Walkwould abort on.git/pack files - Actionable git error messages —
skillshare installandskillshare updatenow show context-specific guidance instead of raw exit codes when git operations fail:- Authentication failures suggest token env vars (
GITHUB_TOKEN,GITLAB_TOKEN, etc.), SSH URLs, orgh auth login - SSL certificate errors suggest custom CA bundle, SSH, or
GIT_SSL_NO_VERIFY - Token rejections distinguish between missing auth and expired/invalid tokens
- Divergent branch conflicts show the
fatal:line instead of justexit status 128
- Authentication failures suggest token env vars (
[0.17.0] - 2026-03-11
Breaking Changes
- Extras directory structure — extras source files are now stored under
extras/<name>/instead of directly under the config root. Existing directories are auto-migrated on firstsync extrasrun. No manual action required
New Features
First-Class Extras Command Group
Extras (non-skill resources like rules, prompts, commands) are now a first-class feature with their own command group:
extras init— create a new extra with interactive TUI wizard or CLI flags:skillshare extras init rules --target ~/.claude/rules --target ~/.cursor/rules
skillshare extras init prompts --target .claude/prompts --mode copy -pextras list— view all configured extras with sync status (synced,drift,not synced,no source). Interactive TUI with split-pane detail view, or--json/--no-tuioutputextras mode— change sync mode of an extra's target from CLI, TUI (Mkey), or Web UI:skillshare extras rules --mode copy # single target auto-resolved
skillshare extras mode rules --target ~/.claude/rules --mode copyextras remove— remove an extra from config (source files and synced targets are preserved)extras collect— reverse-sync local files from a target back into the extras source directory:skillshare extras collect rules --from ~/.claude/rules --dry-run- Project mode — all extras commands support
--project/-pfor.skillshare/scoped extras
Extras Integration with Existing Commands
status— shows extras file count and target count per extradoctor— checks that extras source directories exist and target parent directories are reachablediff --extras— per-file diff for extras targets;diff --allshows combined skills + extras diffsync extras --json— structured JSON output for programmatic consumptionsync --all -p— project-mode--allnow includes extras sync
Web UI Redesign
The web dashboard (skillshare ui) received a complete visual overhaul — replacing the hand-drawn aesthetic with a clean, minimal design:
- Redesigned design system — new DM Sans typography, clean border-radius, streamlined color palette with proper dark mode support
- Table view with pagination — skills and search results now offer a table view alongside the existing card/grouped views, with client-side pagination for large collections
- Sticky search and filters — SkillsPage toolbar stays pinned at the top while scrolling, with grouped view sticky headers
- Keyboard modifier shortcuts — press
?to see available shortcuts, with an on-screen HUD overlay showing active modifiers - Sync progress animation — visual feedback during sync operations
- Onboarding tour — step-by-step spotlight tour for first-time users, highlighting key features
- Shared UI components — new DialogShell, IconButton, Pagination, and SegmentedControl components for consistent interactions across pages
Web UI Extras Page
- New Extras page in the web dashboard with list, sync, remove, add-extra modal, and inline mode dropdown per target
- Dashboard card showing extras count, total files, and total targets
- REST API:
GET /api/extras,GET /api/extras/diff,POST /api/extras,POST /api/extras/sync,PATCH /api/extras/{name}/mode,DELETE /api/extras/{name}
Custom GitLab Domain Support
-
JihuLab auto-detection — hosts containing
jihulabin the name (e.g.,jihulab.com) are now automatically detected alongsidegitlab, so nested subgroup URLs work without any config -
gitlab_hostsconfig — declare self-managed GitLab hostnames so skillshare treats URLs with nested subgroup paths correctly. Hosts containinggitlaborjihulabin the name are detected automatically; this config is for other custom domains likegit.company.com:# ~/.config/skillshare/config.yaml (or .skillshare/config.yaml)
gitlab_hosts:
- git.company.com
- code.internal.io# With config above, full path is treated as repo (not owner/repo + subdir)
skillshare install git.company.com/team/frontend/uiWithout config, append
.gitas a workaround:git.company.com/team/frontend/ui.git -
SKILLSHARE_GITLAB_HOSTSenv var — comma-separated list of GitLab hostnames for CI/CD pipelines that don't have a config file:SKILLSHARE_GITLAB_HOSTS=git.company.com,code.internal.io skillshare install git.company.com/team/frontend/uiWhen both the env var and config file are set, their values are merged (deduplicated). Invalid entries in the env var are silently skipped
Bug Fixes
- GitLab subgroup URL parsing —
skillshare installnow correctly handles GitLab nested subgroup URLs with arbitrary depth. Previously, URLs likegitlab.com/group/subgroup/projectwere misinterpreted as repogroup/subgroupwith subdirproject. Now the entire path is treated as the repo path:To specify a subdir within a multi-segment repo, use# These all work now (previously failed)
skillshare install gitlab.com/group/subgroup/project
skillshare install onprem.gitlab.internal/org/sub1/sub2/project
skillshare install https://gitlab.com/group/subgroup/project.git.gitas the explicit boundary:Non-GitLab hosts (GHE, Gitea, etc.) retain the original# Clone group/subgroup/project, install from skills/my-skill subdir
skillshare install gitlab.com/group/subgroup/project.git/skills/my-skillowner/repo+ subdir behavior. GitLab web URLs with/-/tree/and Bitbucket/src/markers continue to work as before.--trackmode generates correct names for subgroup paths (e.g.,group-subgroup-project) - HTTPS fallback on non-GitLab hosts — fixed platform-aware HTTPS URL parsing that could misroute GitHub Enterprise and Gitea URLs with subdirectory paths
- Skill discovery in projects —
skillshare installnow skips known AI tool config directories (.claude/,.cursor/, etc.) when scanning a project directory for skills, preventing circular discovery and false duplicates - Sync collision message —
skillshare syncnow shows both duplicate skill names in collision warning messages for easier troubleshooting - Extras mode switch without
--force— changing an extra's sync mode (e.g., frommergetocopy) and re-syncing now automatically replaces old symlinks. Previously, leftover symlinks from the old mode were treated as conflicts requiring--force
[0.16.14] - 2026-03-09
New Features
Terminal Rendering Improvements
- SGR dim for consistent gray text — all dim/gray text across CLI and TUI now uses the SGR dim attribute (
\x1b[0;2m) instead of bright-black (\033[90m) or fixed 256-color grays. This adapts to any terminal theme — dark, light, or custom — instead of rendering too dark or invisible on certain configurations - Progress bar counter visibility — the file counter (e.g.
0/63947) now appears at a fixed position right after the percentage, preventing it from being pushed off-screen by long titles on narrow terminals:■■■■■■■■■■■■・・・・・ 69% 0/63947 Updating files - Progress bar accent color — progress bar now uses cyan (the project accent color) instead of orange, matching spinners, titles, and other interactive elements
Bug Fixes
- Fixed progress bar getting stuck at 99% on large scans (e.g. 63k+ skills) — parallel scan workers could race past the final frame, leaving the bar one tick short of 100%
- Fixed skill path segments (e.g.
security/insecurity/sarif-parsing) rendering as fixed 256-color gray in TUI list and audit views — now uses theme-adaptive dim
[0.16.13] - 2026-03-06
New Features
TUI Grouped Layout
- Grouped skill list —
skillshare listTUI now groups skills by tracked repo with visual separators. Each group shows the repo name and skill count. Standalone (local) skills appear in their own section. When only one group exists, separators are omitted for a cleaner view── runkids-my-skills (42) ──────────────
✓ security/skill-improver
! security/audit-demo-debug-exfil
── standalone (27) ─────────────────────
! react-best-practices - Grouped audit results —
skillshare auditTUI uses the same grouped layout. Panel height dynamically adjusts based on footer content, maximizing visible rows - Structured filter tags — filter skills precisely with
key:valuetags in the/filter input:Available tags:t:tracked g:security audit
→ type=tracked AND group contains "security" AND free text "audit"t:/type:(tracked/remote/local/github),g:/group:(substring),r:/repo:(substring). Multiple tags use AND logic. Tracked skills now show a repo-name badge so they remain identifiable even in filtered results without group headers
New Targets
- 3 new AI agent targets — Warp, Purecode AI (
purecode), and Witsy, bringing supported tools to 55+
Bug Fixes
- Fixed long skill names wrapping to multiple lines in list and audit TUIs — names now truncate with
…when exceeding column width - Fixed items at the bottom of the audit TUI list being hidden behind the footer
- Fixed detail panel showing duplicate information (installed date, repo name repeated across sections)
- Reduced color noise in audit CLI and TUI output — non-zero counts use semantic severity colors, zero counts are dimmed
- Fixed devcontainer wrapper not suppressing redirect banner for
-jshort flag
[0.16.12] - 2026-03-06
New Features
Structured JSON Output
--jsonflag on 8 more commands — structured JSON output for agent and CI/CD consumption, bringing total coverage to 12 commands:- Mutating:
sync,install,update,uninstall,collect - Read-only:
target list,status,diff
skillshare status --json # overview as JSON
skillshare list --json | jq '.[].name' # extract skill names
skillshare sync --json | jq '.details' # per-target sync details
skillshare install github.com/user/repo --json # non-interactive install- For mutating commands,
--jsonimplies--force(skips interactive prompts) - Fully silent: no spinners, no stderr progress — only pure JSON on stdout
- Previously supported:
audit --format json,log --json,check --json,list --json
- Mutating:
status --project --json— project-mode status now supports--jsonoutput
Bug Fixes
- Fixed
--jsonmode leaking spinner and progress text to stderr, breaking2>&1 | jq .pipelines - Fixed non-zero exit codes being swallowed in
--jsonerror paths - Fixed
status --jsonshowing hardcoded analyzer list instead of actual active analyzers - Fixed argument validation being skipped in
status --projectmode
Performance
- Parallelized git dirty checks —
status --jsonnow runs git status checks concurrently across tracked repos
[0.16.11] - 2026-03-05
New Features
Supply-Chain Trust Verification
- Metadata analyzer — new audit analyzer that cross-references SKILL.md metadata against the actual git source URL to detect social-engineering attacks:
publisher-mismatch(HIGH): skill claims an organization (e.g., "by Anthropic") but repo owner differsauthority-language(MEDIUM): skill uses authority words ("official", "verified") from an unrecognized source
skillshare audit # metadata analyzer runs by default
skillshare audit --analyzer metadata # run metadata analyzer only
Hardcoded Secret Detection
- 10 new audit rules (
hardcoded-secret-0throughhardcoded-secret-9) detect inline API keys, tokens, and passwords embedded in skill files:- Google API keys, AWS access keys, GitHub PATs (classic + fine-grained), Slack tokens, OpenAI keys, Anthropic keys, Stripe keys, PEM private key blocks, and generic
api_key/passwordassignments - Severity: HIGH — blocks installation at default threshold
skillshare audit # hardcoded secrets detected automatically
skillshare audit rules --pattern hardcoded-secret # list all secret rules - Google API keys, AWS access keys, GitHub PATs (classic + fine-grained), Slack tokens, OpenAI keys, Anthropic keys, Stripe keys, PEM private key blocks, and generic
Skill Integrity Verification
doctorintegrity check — verifies installed skills haven't been tampered with by comparing current file hashes against stored.skillshare-meta.jsonhashes:✓ Skill integrity: 5/6 verified
⚠ _team-repo__api-helper: 1 modified
⚠ Skill integrity: 1 skill(s) unverifiable (no metadata)
Web UI Streaming & Virtualization
- Real-time SSE streaming — all long-running web dashboard operations (audit, update, check, diff) now stream results via Server-Sent Events with per-item progress bars instead of waiting for the full batch
- Per-skill audit — audit individual skills directly from the skill detail page
- Virtualized scrolling — audit results and diff item lists now use virtual scrolling for smooth performance with large datasets (replaces "Show more" pagination)
Improvements
- SSL error guidance —
skillshare installnow detects SSL certificate errors and shows actionable options (custom CA bundle, SSH, or skip verification) - Cleaner TUI layout — removed detail panel box borders in list/log views for a cleaner, less cluttered appearance
[0.16.10] - 2026-03-04
New Features
Sync Extras
sync extrassubcommand — sync non-skill resources (rules, commands, memory files, etc.) from your config directory to arbitrary target paths:Each extra supports per-target sync modes (skillshare sync extras # sync all configured extras
skillshare sync extras --dry-run # preview without changes
skillshare sync extras --force # overwrite existing filessymlink,copy, ormerge). Configure inconfig.yaml:extras:
- name: rules
targets:
- path: ~/.claude/rules
- path: ~/.cursor/rules
mode: copysync --allflag — run skill sync and extras sync together in one command:skillshare sync --all
TUI Preferences
tuisubcommand — persistently enable or disable interactive TUI mode:When disabled, all commands fall back to plain text output. Setting is stored inskillshare tui # show current setting
skillshare tui off # disable TUI globally
skillshare tui on # re-enable TUIconfig.yaml.
Bug Fixes
- Fixed TUI detail panel bottom content being clipped in list view
Documentation
- Added sync extras documentation to website, built-in skill, and README
- Split monolith audit page into focused sub-pages for easier navigation
[0.16.9] - 2026-03-03
New Features
Audit Rules Management
audit rulessubcommand — browse, search, disable, enable, and override severity for individual rules or entire patterns:skillshare audit rules # interactive TUI browser
skillshare audit rules --format json # machine-readable listing
skillshare audit rules disable credential-access-ssh-private-key
skillshare audit rules disable --pattern prompt-injection
skillshare audit rules severity my-rule HIGH
skillshare audit rules reset # restore built-in defaults
skillshare audit rules init # create starter audit-rules.yaml- Audit Rules TUI — two-level interactive browser with accordion pattern groups, severity tabs (ALL/CRIT/HIGH/MED/LOW/INFO/OFF), text filter, and inline disable/enable/severity-override actions
- Pattern-level rule overrides —
audit-rules.yamlnow supports pattern-level entries (e.g.,prompt-injection: disabled: true) that apply to all rules under a pattern
Security Policy & Deduplication
--profileflag — preset security profiles that set block threshold and deduplication mode in one flag:Profiles:skillshare audit --profile strict # blocks on HIGH+, global dedupe
skillshare audit --profile permissive # blocks on CRITICAL only, legacy dedupedefault(CRITICAL threshold, global dedupe),strict(HIGH threshold, global dedupe),permissive(CRITICAL threshold, legacy dedupe)--dedupeflag — control finding deduplication:global(default) deduplicates across all skills using SHA-256 fingerprints;legacykeeps per-skill behavior- Policy display — active policy (profile, threshold, dedupe mode) shown in audit header, summary box, and TUI footer
Analyzer Pipeline
--analyzerflag — run only specific analyzers (repeatable):static,dataflow,tier,integrity,structure,cross-skill:skillshare audit --analyzer static --analyzer dataflow- Finding enrichment — JSON, SARIF, and Markdown outputs now include
ruleId,analyzer,category,confidence, andfingerprintfields per finding - Category-based threat breakdown — summary now shows threat counts by category (injection, exfiltration, credential, obfuscation, privilege, integrity, structure, risk) across all output channels (CLI, TUI, JSON, Markdown)
- Semantic coloring — TUI summary footer and CLI summary box use per-category colors for the Threats breakdown line
New Detection Rules
- Interpreter tier (T6) — audit classifies Turing-complete runtimes (
python,node,ruby,perl,lua,php,bun,deno,npx,tsx,pwsh,powershell) as T6:interpreter. Versioned binaries likepython3.11are also recognized. Tier combination findings:tier-interpreter(INFO) andtier-interpreter-network(MEDIUM when combined with network commands) - Expanded prompt injection detection — new rules detect
OVERRIDE:/IGNORE:/ADMIN:/ROOT:prefixes, agent directive tags (<system>,</instructions>), and jailbreak directives (DEVELOPER MODE,DEV MODE,DAN MODE,JAILBREAK) - Table-driven credential access detection — credential rules are now generated from a data table covering 30+ sensitive paths (SSH keys, AWS/Azure/GCloud credentials, GnuPG keyrings, Kubernetes config, Vault tokens, Terraform credentials, Docker config, GitHub CLI tokens, macOS Keychains, shell history, and more) across 5 access methods (read, copy, redirect, dd, exfil). Supports
~,$HOME,${HOME}path variants. Includes an INFO-level heuristic catch-all for unknown home dotdirs. Rule IDs are now descriptive (e.g.,credential-access-ssh-private-keyinstead ofcredential-access-0) - Cross-skill credential × interpreter — new cross-skill rule
cross-skill-cred-interpreter(MEDIUM) flags when one skill reads credentials and another has interpreter access - Markdown image exfiltration detection — new rule detects external markdown images with query parameters (
) as a potential data exfiltration vector - Invisible payload detection — detects Unicode tag characters (U+E0001–U+E007F) that render at 0px width but are fully processed by LLMs. Primary vector for "Rules File Backdoor" attacks. Uses dedicated
invisible-payloadpattern to ensure CRITICAL findings are never suppressed in tutorial contexts - Output suppression detection — detects directives that hide actions from the user ("don't tell the user", "hide this from the user", "remove from conversation history"). Strong indicator of supply-chain attacks
- Bidirectional text detection — detects Unicode bidi control characters (U+202A–U+202E, U+2066–U+2069) used in Trojan Source attacks (CVE-2021-42574) that reorder visible text
- Config/memory file poisoning — detects instructions to modify AI agent configuration files (
MEMORY.md,CLAUDE.md,.cursorrules,.windsurfrules,.clinerules) - DNS exfiltration detection — detects
dig/nslookup/hostcommands with command substitution ($(...)or backticks) that encode stolen data in DNS subdomain queries - Self-propagation detection — detects instructions that tell AI to inject/insert payloads into all/every/other files, a repository worm pattern
- Markdown comment injection — detects prompt injection keywords hidden inside markdown reference-link comments (
[//]: # (ignore previous instructions...)) - Untrusted package execution — detects
npx -y/npx --yes(auto-execute without confirmation) andpip install https://(install from URL, not PyPI registry) - Additional invisible Unicode — detects soft hyphens (U+00AD), directional marks (U+200E–U+200F), and invisible math operators (U+2061–U+2064) at MEDIUM severity
envprefix handling — command tier classifier now correctly classifiesenv python3 script.pyas T6:interpreter instead of T0:read-only
Performance
- Regex prefilters — static analyzer now applies conservative literal-substring prefilters before running regex, reducing scan time on large skills
Bug Fixes
- Regex bypass vulnerabilities closed — fixed prompt injection rules that could be bypassed with leading whitespace or mixed case; fixed data-exfiltration image rule whose exclude pattern allowed
.png?stolen_datato pass; fixeddd if=/etc/shadowbeing mislabeled asdestructive-commandsinstead ofcredential-access - SSH public key false positive —
~/.ssh/id_rsa.puband other.pubfiles no longer trigger CRITICAL credential-access findings (only private keys are flagged) - Catch-all regex bypass — fixed heuristic catch-all rule that could be silenced when a known credential path appeared on the same line as an unknown dotdir
- Structured output ANSI leak —
audit --format json/sarif/markdownno longer leaks pterm cursor hide/show ANSI codes into stdout - Severity-only merge no longer wipes rules — editing only severity in
audit-rules.yamlno longer drops the rule's regex patterns - Profile threshold fallback — profile presets now correctly set block threshold when config has no explicit
block_threshold - TreeSpinner ghost cursor — fixed missing
WithWriterthat caused cursor hide/show codes to leak on structured output - TUI summary overflow — category threat breakdown now renders on a separate line to prevent horizontal overflow on narrow terminals
[0.16.8] - 2026-03-02
New Features
audit --format— new--formatflag supportstext(default),json,sarif, andmarkdownoutput formats.--jsonis now deprecated:skillshare audit --format sarif # SARIF 2.1.0 for GitHub Code Scanning
skillshare audit --format markdown # Markdown report for GitHub Issues/PRs
skillshare audit --format json # Machine-readable JSON- Analyzability score — each audited skill now receives an analyzability percentage (how much of the skill's content can be statically analyzed). Shown per-skill in audit output and as an average in the summary
- Command safety tiering (T0–T5) — audit classifies shell commands by behavioral tier: T0 read-only, T1 mutating, T2 destructive, T3 network, T4 privilege, T5 stealth. Tier labels appear alongside pattern-based findings for richer context
- Dataflow taint tracking — audit detects cross-line exfiltration patterns: credential reads or environment variable access on one line followed by network sends (
curl,wget, etc.) on a subsequent line - Cross-skill interaction detection — when auditing multiple skills, audit now checks for dangerous capability combinations across skills (e.g., one skill reads credentials while another has network access). Results are also exposed in the REST API (
GET /api/audit) - Audit TUI filter — the
/filter in the audit TUI now searches across risk level, status (blocked/warning/clean), max severity, finding pattern names, and file names — not just skill names - Pre-commit hook —
.pre-commit-hooks.yamlfor the pre-commit framework. Runsskillshare audit -pon every commit to catch security issues before they land:repos:
- repo: https://github.com/runkids/skillshare
rev: v0.16.8
hooks:
- id: skillshare-audit - AstrBot target — new target for AstrBot AI assistant (
~/.astrbot/data/skills) - Cline target updated — Cline now uses the universal
.agents/skillsproject path
Performance
- Cross-skill analysis O(N) rewrite — cross-skill interaction detection rewritten from O(N²) pair-wise comparison to O(N) capability-bucket approach, significantly faster for large skill collections
Bug Fixes
- TUI gray text contrast — improved gray text readability on dark terminals by increasing ANSI color contrast
- Spinner on structured output —
auditnow shows progress spinner on stderr when using--format json/sarif/markdown, so structured stdout remains clean for piping - SARIF line-0 region — SARIF output no longer emits an invalid
regionobject for findings at line 0
[0.16.7] - 2026-03-02
Bug Fixes
- Preserve external symlinks during sync — sync (merge/copy mode) no longer deletes target directory symlinks created by dotfiles managers (e.g., stow, chezmoi, yadm). Previously, switching from symlink mode to merge/copy mode would unconditionally remove the target symlink, breaking external link chains. Now skillshare checks whether the symlink points to the source directory before removing it — external symlinks are left intact and skills are synced into the resolved directory
- Symlinked source directory support across all commands — all commands that walk the source directory (
sync,update,uninstall,list,diff,install,status,collect) now resolve symlinks before scanning. Skills managed through symlinked~/.config/skillshare/skills/(common with dotfiles managers) are discovered correctly everywhere. Chained symlinks (link → link → real dir) are also handled - Group operation containment guard —
uninstall --groupandupdate --groupnow reject group directories that are symlinks pointing outside the source tree, preventing accidental operations on external directories statusrecognizes external target symlinks —CheckStatusMergeno longer reports external symlinks as "conflict"; it follows the symlink and counts linked/local skills in the resolved directorycollectscans through external target symlinks —FindLocalSkillsnow follows non-source symlinks instead of skipping them, so local skills in dotfiles-managed target directories can be collectedupgradeprompt cleanup — upgrade prompts ("Install built-in skill?" and "Upgrade to vX?") no longer leave residual lines that break the tree-drawing layout
[0.16.6] - 2026-03-02
New Features
diffinteractive TUI — new bubbletea-based split-panel interface forskillshare diff: left panel lists targets with status icons (✓/!/✗), right panel shows categorized file-level diffs for the selected target. Supports fuzzy filter (/), detail scrolling (Ctrl+d/u), and narrow terminal fallback. Add--no-tuifor plain text outputdiff --patch— show unified text diffs for each changed file:skillshare diff --patchdiff --stat— show per-file change summary with added/removed line counts:skillshare diff --statdifffile-level detail — diff entries now include per-file data (added/removed/modified/renamed), source paths, modification times, and git-style status symbols (+/−/≠/→)diffstatistics summary — every diff run prints a summary line with total counts by category (e.g.,3 added, 1 modified, 2 removed)- Glob pattern matching —
install,update, anduninstallnow accept glob patterns (*,?,[...]) in skill name arguments; matching is case-insensitive:skillshare install repo -s "core-*"
skillshare update "team-*"
skillshare uninstall "old-??" trashinteractive TUI — bubbletea-based TUI with multi-select, fuzzy filter, and inline restore/delete/empty operations; includes SKILL.md preview in the detail panelrestoreinteractive TUI — two-phase TUI: target picker → version list with left-right split panel, showing skill diffs and descriptions in the detail panel. Add--helpflag and delete-backup action from TUIbackupversion listing —backupnow lists available backup versions per target and correctly follows top-level symlinks in merge-mode targets- Homebrew-aware version check — Homebrew users no longer see false "update available" notifications;
doctorand post-command checks now querybrew infoinstead of the GitHub Release API when installed via Homebrew - Devcontainer skill — new built-in skill that teaches AI assistants when and how to run CLI commands, tests, and debugging inside the devcontainer
- Red destructive confirmations — all destructive action confirmations (delete, empty, uninstall) now render in red across trash, restore, and list TUIs
Fixed
backup/restoremode flags —-gand-pflags now work correctly; previously-gwas misinterpreted as a target namediffhides internal metadata —.skillshare-meta.jsonis no longer shown in file-level diff outputdiff --statimplies--no-tui—--statnow correctly skips the TUI and prints to stdout
[0.16.5] - 2026-02-28
New Features
- Web UI: Dark theme — toggle between light and dark mode via the sun/moon button; persists to localStorage and respects
prefers-color-scheme - Web UI: Update page — dedicated page for batch-updating tracked skills with select-all, per-item progress tracking, and result summary
- Web UI: Security overview card — dashboard now shows a risk-level badge and severity breakdown; highlights critical findings with an accent card
- Web UI: Sync mode selector — change a target's sync mode (merge/symlink) directly from the Targets page dropdown
- Web UI: Install skill picker — skill descriptions from SKILL.md frontmatter are now shown inline in the picker modal; search also matches descriptions
upgradeversion transition —skillshare upgradenow shows clear before/after versions:Works for Homebrew, direct download, and skill installsUpgraded v0.16.3 → v0.16.5
Fixed
- Custom targets flagged as unknown —
checkanddoctorno longer warn about user-defined targets in global or project config (fixes #57) - Web UI: Modal scroll-away — clicking checkboxes in the skill picker no longer causes content to scroll out of view (replaced
overflow-hiddenwithoverflow-clip) - Web UI: Subdir URL discovery — install form now correctly discovers skills from git subdirectory URLs
- Web UI: Accessibility — added
aria-labels,htmlFor, focus trap for modals, andErrorBoundaryfor graceful error recovery
New Targets
- omp — oh-my-pi (
~/.omp/agent/skills,.omp/skills; alias:oh-my-pi) - lingma — Lingma (
~/.lingma/skills,.lingma/skills)
[0.16.4] - 2026-02-28
New Features
- Cross-path duplicate detection —
installnow detects when a repo is already installed at a different location and blocks the operation with a clear hint:skillshare install runkids/feature-radar --into feature-radar
# later...
skillshare install runkids/feature-radar
# ✗ this repo is already installed at skills/feature-radar/scan (and 2 more)
# Use 'skillshare update' to refresh, or reinstall with --force to allow duplicates - Same-repo skip — reinstalling a skill from the same repo now shows a friendly
⊘ skippedindicator instead of an error; skipped skills are grouped by directory with repo label in the summary - Web UI install dedup — the Web UI install endpoints enforce the same cross-path duplicate check as the CLI, returning HTTP 409 when duplicates are found
- 5 new audit rules — the security scanner now detects 36 patterns (up from 31):
fetch-with-pipe(HIGH) — detectscurl | bash,wget | sh, and pipes topython,node,ruby,perl,zsh,fiship-address-url(MEDIUM) — URLs with raw IP addresses that bypass DNS-based security; private/loopback ranges excludeddata-uri(MEDIUM) —data:URIs in markdown links that may embed executable content
- Unified batch summary —
install,uninstall, andupdatenow share a consistent single-line summary format with color-coded counts and elapsed time
Performance
- Batch gitignore operations —
.gitignoreupdates duringinstallreconciliation anduninstallare now batched into a single file read/write instead of one per skill; eliminates hang when.gitignoregrows large (100K+ lines) update --allgrouped skip — skills from the same repo are now skipped when installed metadata already matches remote state (commit or tree-hash match), avoiding redundant reinstall/copy; on large repos this eliminates the majority of workupdate --allbatch speed — removed a fixed 50ms per-skill delay in grouped batch iteration that dominated runtime on large skill sets (~90 min at 108K skills → seconds)update --allprogress visibility — batch progress bar now advances per-skill instead of per-repo, so it no longer appears stuck at 0% during large grouped updates; a scanning spinner and phase headers ([1/3] Pulling N tracked repos...) show which stage is runningstatusanddoctorat scale — both commands now run a single skill discovery pass instead of repeating it per-section (status: 7× → 1×, doctor: 5× → 1×); target status checks are cached so drift detection reuses the first result;doctoroverlaps its GitHub version check with local I/O; a spinner is shown during discovery so the CLI doesn't appear frozencollectscan speed — directory size calculation is no longer run eagerly during skill discovery; deferred to the Web UI handler where it is actually needed
Fixed
universaltarget path — corrected global path from~/.config/agents/skillsto~/.agents/skills(the shared agent directory used by multiple AI CLIs)initauto-includesuniversal—initandinit --discovernow automatically include theuniversaltarget whenever any AI CLI is detected; labeled as "shared agent directory" so users understand what it isuniversalcoexistence docs — added FAQ section explaining how skillshare andnpx skillscoexist on the same~/.agents/skillspath, including sync mode differences and name collision caveats--forcehint accuracy — the force hint now uses the actual repo URL (not per-skill subpath) and includes--intowhen applicableupdateroot-level skills — root-level skill repos (SKILL.md at repo root) no longer appear as stale/deleted during batch update; fixedSubdirnormalization mismatch between metadata ("") and discovery (".")pullproject mode leak —pullnow forces--globalfor the post-pull sync, preventing unintended project-mode auto-detection when run inside a project directorylistTUI action safety —audit,update, anduninstallactions in the skill list TUI now show a confirmation overlay before executing; actions pass explicit--global/--projectmode flags to prevent mode mismatch
Improvements
updatebatch summary — batch update summary now uses the same single-line stats format assyncwith color-coded counts- Command output spacing — commands now consistently print a trailing blank line after output for better terminal readability
[0.16.3] - 2026-02-27
Improvements
diffoutput redesign — actions are now labeled by what they do (add,remove,update,restore) with a grouped summary showing counts per action; overall summary line at the end- Install progress output — config and search installs now show tree-style steps with a summary line (installed/skipped/failed counts + elapsed time) and real-time git clone progress
- Web UI log stats bar — Log page now shows a stats bar with success rate and per-command breakdown
- Hub batch install progress — multi-skill installs from
search --hubnow show real-time git clone progress (cloning 45%,resolving 67%) instead of a static "installing..." label; only the active install is shown to keep the display compact - Hub risk badge colors — risk labels in hub search results are now color-coded by severity (green for clean, yellow for low, red for critical) in both the list and detail panel
- Hub batch failure output — failure details are classified by type (security / ambiguous / not found) with distinct icons; long audit findings and ambiguous path lists are truncated to 3 lines with a "(+N more)" summary
Performance
- Batch install reconcile — config reconciliation now runs once after all installs complete instead of after each skill, eliminating O(n²) directory walks that caused batch installs of large collections to appear stuck
- Repo-grouped cloning — skills from the same git repo are now cloned once and installed from the shared clone, reducing network requests for multi-skill repos
Fixed
- Race condition in
sync— targets sharing the same filesystem path no longer produce duplicate or missing symlinks - Race condition in
syncgroup key — canonicalized group key prevents non-deterministic sync results - Web UI stats on "All" tab — dashboard now computes stats from both ops and audit logs, not just ops
- Web UI last operation timestamp — timestamps are compared as dates instead of strings, fixing incorrect "most recent" ordering
log --stats --cmd audit— now correctly reads fromaudit.loginstead ofoperations.loglog max_entries: 0— setting max_entries to 0 now correctly means unlimited instead of deleting all entries- Oplog data loss — rewriteEntries now checks for write errors before truncating the original file
- TUI content clipping — detail panels in
listandlogTUIs now hard-wrap content and account for padding, preventing text from being clipped at panel edges - TUI footer spacing — list and log TUI footers have proper breathing room between action hints
- Copy mode symlink handling —
syncin copy mode now dereferences directory symlinks instead of copying broken link files; prevents missing content in targets like Windsurf that use file copying uninstall --allstale summary — spinner and confirm prompt now show correct noun type after skipping dirty tracked repos; added skip count message ("1 tracked repo skipped, 2 remaining"); fixed unnatural pluralization ("2 group(s)" → "2 groups")- Empty
list/logTUI —listandlogno longer open a blank interactive screen when there are no skills or log entries; they print a plain-text hint instead installquiet mode — tracked config dry-run messages are now suppressed in quiet mode
New Targets
- Verdent — added Verdent AI coding agent (
verdent)
[0.16.2] - 2026-02-26
New Features
diffcommand — new command to preview whatsyncwould change without modifying anything; parallel target scanning, grouped output for targets with identical diffs, and an overall progress bar:skillshare diff # all targets
skillshare diff claude # single target
skillshare diff -p # project mode- Interactive TUI for
audit—skillshare auditlaunches a bubbletea TUI with severity-colored results, fuzzy filter, and detail panel; progress bar during scanning; confirmation prompt for large scans (1,000+ skills) (skillshare audit --no-tuifor plain text) - Tree sidebar in
listTUI — detail panel now shows the skill's directory tree (up to 3 levels) with glamour-rendered markdown preview; SKILL.md pinned at top for quick reading - Log TUI: delete entries — press
spaceto select entries,dto delete with confirmation; supports multi-select (ato select all) - Log
--statsflag — aggregated summary with per-command breakdown, success rate, and partial/blocked status tracking:skillshare log --stats - Azure DevOps URL support — install from Azure DevOps repos using
ado:shorthand, full HTTPS (dev.azure.com), legacy HTTPS (visualstudio.com), or SSH v3 (ssh.dev.azure.com) URLs:skillshare install ado:myorg/myproject/myrepo
skillshare install https://dev.azure.com/org/proj/_git/repo
skillshare install git@ssh.dev.azure.com:v3/org/proj/repo AZURE_DEVOPS_TOKENenv var — automatic HTTPS token injection for Azure DevOps private repos, same pattern asGITHUB_TOKEN/GITLAB_TOKEN/BITBUCKET_TOKEN:export AZURE_DEVOPS_TOKEN=your_pat
skillshare install https://dev.azure.com/org/proj/_git/repo --trackupdate --prune— remove stale skills whose upstream source no longer exists (skillshare update --prune)- Stale detection in
check—skillshare checknow reports skills deleted upstream as "stale (deleted upstream)" instead of silently skipping them - Windows ARM64 cross-compile —
make build-windows/mise run build:windowsproduces Windows ARM64 binaries
Performance
- Parallel target sync — both global and project-mode
syncnow run target syncs concurrently (up to 8 workers) with a live per-target progress display - mtime fast-path for copy mode — repeat syncs skip SHA-256 checksums when source directory mtime is unchanged, making no-op syncs near-instant
- Cached skill discovery — skills are discovered once and shared across all parallel target workers instead of rediscovering per target
Improvements
- Batch progress for hub installs — multi-skill installs from
searchnow show per-skill status (queued/installing/done/error) with a live progress display - Log retention — operation log auto-trims old entries with configurable limits and hysteresis to avoid frequent rewrites
- Partial completion tracking —
sync,install,update, anduninstallnow log"partial"status when some targets succeed and others fail, instead of a blanket"error" - Unified TUI color palette — all bubbletea TUIs share a consistent color palette via shared
tcstruct
Fixed
upgradespinner nesting — brew output and GitHub release download steps now render cleanly inside tree spinners instead of breaking the layout
[0.16.1] - 2026-02-25
Improvements
- Async TUI loading for
list— skill list now loads inside the TUI with a spinner instead of blocking before rendering; metadata reads use a parallel worker pool (64 workers) for faster startup - Unified filter bar across all TUIs —
list,log, andsearchnow share the same filter UX: press/to enter filter mode,Escto clear,Enterto lock; search TUI suppresses action keys while typing to avoid accidental checkbox toggles - Colorized audit output — severity counts (CRITICAL/HIGH/MEDIUM/LOW/INFO), risk labels, and finding details are now color-coded by severity level
- Improved install output — single-skill and tracked-repo installs show inline tree steps (description, license, location) instead of a separate SkillBox; description truncation increased to 100 characters with visible ellipsis (
…) - Parallel uninstall discovery —
uninstall --alluses parallel git dirty checks (8 workers) for faster execution
Fixed
- Frozen terminal during
checkandupdate— header and spinners now appear immediately before filesystem scans, so users see feedback instead of a blank screen - Spinner flicker during
installclone — eliminated visual glitch when transitioning between clone and post-clone phases - Large operation log files crash
logTUI — JSONL parser now uses streamingjson.Decoderinstead of reading entire lines into memory, handling arbitrarily large log entries
[0.16.0] - 2026-02-25
Performance
- Per-skill tree hash comparison for
check—skillshare checknow uses blobless git fetches (~150-200 KB) and compares per-skill directory tree hashes instead of whole-commit hashes; detects updates to individual skills within monorepos without downloading full history (#46) - Parallel checking with bounded concurrency —
checkandcheck --allrun up to 8 concurrent workers; deduplicatesls-remotecalls for repos hosting multiple skills; progress bar now shows skill count instead of URL count (#46) - Sparse checkout for subdir installs —
install owner/repo/subdirusesgit sparse-checkout(git 2.25+) to clone only the needed subdirectory with--filter=blob:none; falls back to full clone on older git versions (fixes #46) - Batch update progress —
update --allnow shows a progress bar with the current skill name during batch operations
New Features
- Interactive TUI for
list—skillshare listlaunches a bubbletea TUI with fuzzy search, filter, sort, and a detail panel showing description, license, and metadata; inline actions: audit, update, and uninstall directly from the list (skillshare list --no-tuifor plain text) - Interactive TUI for
log—skillshare loglaunches a bubbletea TUI with fuzzy filter and detail panel for browsing operation history (skillshare log --no-tuifor plain text) - Interactive TUI for
search—skillshare searchresults now use a bubbletea multi-select checkbox interface instead of survey prompts - Interactive TUI for
init— target selection inskillshare initnow uses a bubbletea checklist with descriptions instead of survey multi-select - Skill registry separation — installed skill metadata moved from
config.yamltoregistry.yaml;config.yamlremains focused on user settings (targets, audit thresholds, custom targets); silent auto-migration on first v0.16.0 run — no user action required - Project-mode skills for this repo —
.skillshare/skills/ships 5 built-in project skills for contributors:cli-e2e-test,codebase-audit,implement-feature,update-docs,changelog; install withskillshare sync -pin the repo - Restore validation preview — Web UI restore modal now shows a pre-restore validation with conflict warnings, backup size, and symlink detection before committing (
POST /api/restore/validate) - Expanded detail panel in
listTUI — detail view now includes word-wrapped description and license field
Changed
- CLI visual language overhaul — all single-item operations (install, update, check) now use a consistent hierarchical layout with structured labels (
Source:,Items:,Skill:) and adaptive spinners; audit findings section only appears when findings exist checksingle-skill output — single skill/repo checks now use the same hierarchical tree layout asupdatewith spinner and step results instead of a progress barchecksummarizes clean results — up-to-date and local-only skills are now shown as summary counts (e.g., "3 up to date, 2 local") instead of listing each one individually- Symlink compat hint moved to
doctor— per-target mode hints removed fromsyncoutput;doctornow shows a universal symlink compatibility notice when relevant targets are configured - Web UI migrated to TanStack Query — all API calls use
@tanstack/react-querywith automatic caching, deduplication, and background refetching; Skills page uses virtual scrolling for large collections - Deprecated
openclaudetarget removed — replaced byopenclaw; existing configs usingopenclaudeshould update toopenclaw
Fixed
- Infinite loop in directory picker for large repos — bubbletea directory picker now handles repos with many subdirectories without hanging
- Leading slash in subdir path breaks tree hash lookup —
checknow normalizes//skills/footoskills/foofor consistent path matching update --allin project mode skipped nested skills — recursive skill discovery now enabled for project-modeupdate --all- Batch update path duplication —
update --allnow uses caller-provided destination paths to prevent doubled path segments file://URL subdir extraction —install file:///path/to/repo//subdirnow correctly extracts subdirectories via the//separator- Git clone progress missing in batch update — progress output now wired through to batch update operations
- Backup restore with symlinks —
ValidateRestorenow usesos.Lstatto correctly detect symlink targets instead of following them
[0.15.5] - 2026-02-23
Added
init --modeflag —skillshare init --mode copy(or-m copy) sets the default sync mode for all targets at init time; in interactive mode (TTY), a prompt offers merge / copy / symlink selection;init --discover --mode copyapplies the mode only to newly added targets, leaving existing targets unchanged (closes #42)- Per-target sync mode hint — after
syncanddoctor, a contextual hint suggestscopymode for targets known to have symlink compatibility issues (Cursor, Antigravity, Copilot, OpenCode); suppressed when only symlink-compatible targets are configured uninstall --all— remove all skills from source in one command; requires confirmation unless--forceis set; works in both global and project mode
Changed
- Improved CLI output — compact grouped audit findings (
× Ndedup), structured section labels, lighter update headers
Fixed
- Orphan real directories not pruned after uninstall —
syncin merge mode now writes.skillshare-manifest.jsonto track managed skills; afteruninstall, orphan directories (non-symlinks) that appear in the manifest are safely removed instead of kept with "unknown directory" warnings; user-created directories not in the manifest are still preserved (fixes #45) - Exclude filter not removing managed real directories — changing
excludepatterns now correctly prunes previously-managed real directories (not just symlinks) from targets; manifest entries are cleaned up to prevent stale ownership - MultiSelect filter text cleared after selection — filter text is now preserved after selecting an item in interactive prompts (e.g.,
installskill picker)
[0.15.4] - 2026-02-23
Added
- Post-update security audit gate —
skillshare updatenow runs a security audit after pulling tracked repositories; findings at or above the active threshold trigger rollback/block; interactive mode prompts for confirmation, non-interactive mode (CI) fails closed; use--skip-auditto bypass - Post-install audit gate for
--track—skillshare install --trackand tracked repo updates now run the same threshold-based security gate; fresh installs are removed on block, updates are rolled back viagit reset; use--skip-auditto bypass - Threshold override flags on
update—skillshare updatenow supports--audit-threshold,--threshold,-T(including shorthand aliases like-T h) for per-command blocking policy --diffflag forupdate—skillshare update team-skills --diffshows a file-level change summary after update; for tracked repos, includes line counts viagit diff; for regular skills, uses file hash comparison to show added/modified/deleted files- Content hash pinning —
installandupdatenow record SHA-256 hashes of all skill files in.skillshare-meta.json; subsequentauditruns detect tampering (content-tampered), missing files (content-missing), and unexpected files (content-unexpected) source-repository-linkaudit rule (HIGH) — detects markdown links labeled "source repo" or "source repository" pointing to external URLs, which may be used for supply-chain redirect attacks- Structural markdown link parsing for audit — audit rules now use a full markdown parser instead of regex, correctly handling inline links with titles, reference-style links, autolinks, and HTML anchors while skipping code fences, inline code spans, and image links; reduces false positives in
external-linkandsource-repository-linkrules (extends link-audit foundation from #39) - Severity-based risk floor — audit risk label is now the higher of the score-based label and a floor derived from the most severe finding (e.g., a single HIGH finding always gets at least a
highrisk label) - Severity-based color ramp — audit output now uses consistent color coding: CRITICAL → red, HIGH → orange, MEDIUM → yellow, LOW/INFO → gray; applies to batch summary, severity counts, and single-skill risk labels
- Audit risk score in
updateoutput — CLI and Web UI now display the risk label and score (e.g., "Security: LOW (12/100)") after updating regular skills; Web UI toast notifications include the same information for all update types
Fixed
- Uninstall group directory config cleanup — uninstalling a group directory (e.g.,
frontend/) now properly removes member skill entries (e.g.,frontend/react,frontend/vue) fromconfig.yamlvia prefix matching - Batch
update --allerror propagation — repos blocked by the security audit gate now count as "Blocked" in the batch summary and cause non-zero exit code --skip-auditpassthrough — the flag is now consistently honored for both tracked repos and regular skills duringupdateandinstall- Server rollback error reporting — Web UI update endpoint now implements post-pull threshold gate with automatic rollback on findings at/above threshold
- Audit rollback error accuracy — rollback failures now report whether the reset succeeded ("rolled back") or failed ("malicious content may remain") instead of silently ignoring errors
- Audit error propagation — file hash computation now propagates walk/hash errors instead of silently skipping, ensuring complete integrity baselines
[0.15.3] - 2026-02-22
Added
- Multi-name and
--groupforaudit—skillshare audit a b cscans multiple skills at once;--group/-Gflag scans all skills in a group directory (repeatable); names and groups can be mixed freely (e.g.skillshare audit my-skill -G frontend) external-linkaudit rule (closes #38) — newexternal-link-0rule (LOW severity) detects external URLs in markdown links ([text](https://...)) that may indicate prompt injection vectors or unnecessary token consumption; localhost and loopback links are excluded; completes #38 together with dangling-link detection from v0.15.1 (supersedes #39)- Auth tokens for hub search —
search --hubnow automatically usesGITHUB_TOKEN,GITLAB_TOKEN,BITBUCKET_TOKEN, orSKILLSHARE_GIT_TOKENwhen fetching private hub indexes; no extra configuration needed
Changed
pullmerges by default — when both local and remote have skills on first pull,pullnow attempts a git merge instead of failing; if the merge has conflicts, it stops with guidance;--forcestill replaces local with remote- Parallel audit scanning —
skillshare audit(all-skills scan) now runs up to 8 concurrent workers for faster results in both CLI and Web UI
Fixed
auditresolves nested skill names —skillshare audit nested__skillnow correctly finds skills by flat name or basename with short-name fallback- CodeX SKILL.md description over 1024 chars (fixes #40) — built-in skill description trimmed to stay within CodeX's 1024-character limit
[0.15.2] - 2026-02-22
Added
--auditflag forhub index—skillshare hub index --auditenriches the index with per-skill risk scores (0–100) and risk labels so teammates can assess skill safety before installing;searchdisplays risk badges in hub results; schema stays v1 with optional fields (omitted when--auditis not used)
Changed
hub index --auditparallel scanning — audit scans now run concurrently (up to 8 workers) for faster index generation on large skill collections
Fixed
init --remotetiming — initial commit is now deferred to after skill installation, preventing "Local changes detected" errors on firstpull; re-runninginit --remoteon existing config handles edge cases with proper timeout and error recovery- Auth error messages for
push/pull— authentication failures now show actionable hints (SSH URL, token env vars, credential helper) instead of misleading "pull first" advice; includes platform-specific syntax (PowerShell on Windows,exporton Unix) and links to docs with required token scopes per platform (GitLab, Bitbucket) - Git output parsing on non-English systems —
push,pull, andinitnow setLC_ALL=Cto force English git output, preventing locale-dependent string matching failures (e.g. "nothing to commit" not detected on Chinese/Japanese systems) - Skill version double prefix — versions like
v0.15.0in SKILL.md frontmatter no longer display asvv0.15.0
[0.15.1] - 2026-02-21
Added
- Dangling link detection in audit —
skillshare auditnow checks.mdfiles for broken local relative links (missing files or directories); producesLOWseverity findings with patterndangling-link; disable viaaudit-rules.yamlwith- id: dangling-link/enabled: false
Fixed
push/pullfirst-sync and remote flow — overhauledinit --remote,push, andpullto handle edge cases: re-runninginit --remoteon an existing config, pushing/pulling when remote has no commits yet, and conflicting remote URLs- Partial project init recovery — if
.skillshare/exists butconfig.yamlis missing, commands now repair config instead of failing
[0.15.0] - 2026-02-21
Added
- Copy sync mode —
skillshare target <name> --mode copysyncs skills as real files instead of symlinks, for AI CLIs that can't follow symlinks (e.g. Cursor, Copilot CLI); uses SHA256 checksums for incremental updates;sync --forcere-copies all; existing targets can switch between merge/copy/symlink at any time (#31, #2) - Private repo support via HTTPS tokens —
installandupdatenow auto-detectGITHUB_TOKEN,GITLAB_TOKEN,BITBUCKET_TOKEN, orSKILLSHARE_GIT_TOKENfor HTTPS clone/pull; no manual git config needed; tokens are never written to disk - Better auth error messages — auth failures now tell you whether the issue is "no token found" (with setup suggestions) or "token rejected" (check permissions/expiry); token values are redacted in output
Fixed
diffnow detects content changes in copy mode — previously only checked symlink presence; now compares file checksumsdoctorno longer flags copy-managed skills as duplicatestarget removein project mode cleans up copy manifest- Copy mode no longer fails on stray files in target directories or missing target paths
updateandchecknow honor HTTPS token auth — private repo pull/remote checks now auto-detectGITHUB_TOKEN,GITLAB_TOKEN,BITBUCKET_TOKEN, andSKILLSHARE_GIT_TOKEN(same as install)- Devcontainer project mode no longer pollutes workspace root —
sskeeps caller working directory and redirects-pfrom/workspaceto demo project - Project mode auto-repairs partial initialization — if
.skillshare/exists butconfig.yamlis missing, commands repair config instead of failing with "project already initialized"
Changed
agentstarget renamed touniversal— existing configs usingagentscontinue to work (backward-compatible alias); Kimi and Replit paths updated to match upstream docsGITHUB_TOKENnow used for HTTPS clone — previously only used for GitHub API (search, upgrade); now also used when cloning private repos over HTTPS
[0.14.2] - 2026-02-20
Added
- Multi-name and
--groupforupdate—skillshare update a b cupdates multiple skills at once;--group/-Gflag expands a group directory to all updatable skills within it (repeatable); positional names that match a group directory are auto-detected and expanded; names and groups can be mixed freely - Multi-name and
--groupforcheck—skillshare check a b cchecks only specified skills;--group/-Gflag works identically toupdate; no args = check all (existing behavior preserved); filtered mode includes a loading spinner for network operations - Security guide — new
docs/guides/security.mdcovering audit rules,.skillignore, and safe install practices; cross-referenced from audit command docs and best practices guide
Changed
- Docs diagrams migrated to Mermaid SVG — replaced ASCII box-drawing diagrams across 10+ command docs with Mermaid
handDrawnlook for better rendering and maintainability - Hub docs repositioned — hub documentation reframed as organization-first with private source examples
- Docker/devcontainer unified — consolidated version definitions, init scripts, and added
sandbox-logstarget; devcontainer now includes Node.js 24, auto-start dev servers, and adev-serversmanager script
[0.14.1] - 2026-02-19
Added
- Config YAML Schema — JSON Schema files for both global
config.yamland project.skillshare/config.yaml; enables IDE autocompletion, validation, and hover documentation via YAML Language Server;Save()automatically prepends# yaml-language-server: $schema=...directive; new configs fromskillshare initinclude the directive out of the box; existing configs get it on next save (any mutating command)
[0.14.0] - 2026-02-18
Added
- Global skill manifest —
config.yamlnow supports askills:section in global mode (previously project-only);skillshare install(no args) installs all listed skills; auto-reconcile keeps the manifest in sync after install/uninstall .skillignorefile — repo-level file to hide skills from discovery during install; supports exact match and trailing wildcard patterns; group matching via path-based comparison (e.g.feature-radarexcludes all skills under that directory)--excludeflag for install — skip specific skills during multi-skill install; filters before the interactive prompt so excluded skills never appear- License display in install — shows SKILL.md
licensefrontmatter in selection prompts and single-skill confirmation screen - Multi-skill and group uninstall —
skillshare uninstallaccepts multiple skill names and a repeatable--group/-Gflag for batch removal; groups use prefix matching; problematic skills are skipped with warnings; group directories auto-detected with sub-skill listing in confirmation prompt groupfield in skill manifest — explicitgroupfield separates placement from identity (previously encoded asname: frontend/pdf); automatic migration of legacy slash-in-name entries; both global and project reconcilers updated- 6 new audit security rules — detection for
eval/exec/Functiondynamic code, Python shell execution,process.envleaking, prompt injection in HTML comments, hex/unicode escape obfuscation; each rule includes false-positive guards - Firebender target — coding agent for JetBrains IDEs; paths:
~/.firebender/skills(global),.firebender/skills(project); target count now 49+ - Declarative manifest docs — new concept page and URL formats reference page
Fixed
- Agent target paths synced with upstream — antigravity:
global_skills→skills; augment:rules→skills; goose project:.agents/skills→.goose/skills - Docusaurus relative doc links — added
.mdextension to prevent 404s when navigating via navbar
Changed
- Website docs restructured — scenario-driven "What do you want to do?" navigation on all 9 section index pages; standardized "When to Use" and "See Also" sections across all 24 command docs; role-based paths in intro; "What Just Happened?" explainer in getting-started
- Install integration tests split by concern — tests reorganized into
install_basic,install_discovery,install_filtering,install_selection, andinstall_helpersfor maintainability
[0.13.0] - 2026-02-16
Added
- Skill-level
targetsfield — SKILL.md frontmatter now accepts atargetslist to restrict which targets a skill syncs to;checkvalidates unknown target names - Target filter CLI —
target <name> --add-include/--add-exclude/--remove-include/--remove-excludefor inline filter editing; Web UI inline filter editor on Targets page - XDG Base Directory support — respect
XDG_CONFIG_HOME,XDG_DATA_HOME,XDG_STATE_HOME; backups/trash stored in data dir, logs in state dir; automatic migration from legacy layout on first run - Windows legacy path migration — existing Windows installs at
~\.config\skillshare\are auto-migrated to%AppData%\skillshare\with config source path rewrite - Fuzzy subdirectory resolution —
install owner/repo/skill-namenow fuzzy-matches nested skill directories by basename when exact path doesn't exist, with ambiguity error for multiple matches listgrouped display — skills are grouped by directory with tree-style formatting;--verbose/-vflag for detailed output- Runtime UI download —
skillshare uidownloads frontend assets from GitHub Releases on first launch and caches at~/.cache/skillshare/ui/<version>/;--clear-cacheto reset;upgradepre-downloads UI assets
Changed
- Unified project target names — project targets now use the same short names as global (e.g.
claudeinstead ofclaude-code); old names preserved as aliases for backward compatibility - Binary no longer embeds UI — removed
go:embedand build tags; UI served exclusively from disk cache, reducing binary size - Docker images simplified — production and CI Dockerfiles no longer include Node build stages
Fixed
- Windows
DataDir()/StateDir()paths — now correctly fall back to%AppData%instead of Unix-style~/.local/paths - Migration result reporting — structured
MigrationResultwith status tracking; migration outcomes printed at startup - Orphan external symlinks after data migration —
syncnow auto-removes broken external symlinks (e.g. leftover from XDG/Windows path migration);--forceremoves all external symlinks; path comparison uses case-insensitive matching on Windows
Breaking Changes
- Windows paths relocated — config/data moves from
%USERPROFILE%\.config\skillshare\to%AppData%\skillshare\(auto-migrated) - XDG data/state split (macOS/Linux) — backups and trash move from
~/.config/skillshare/to~/.local/share/skillshare/; logs move to~/.local/state/skillshare/(auto-migrated) - Project target names changed —
claude-code→claude,gemini-cli→gemini, etc. (old names still work via aliases)
[0.12.6] - 2026-02-13
Added
- Per-target include/exclude filters (merge mode) —
include/excludeglob patterns are now supported in both global and project target configs - Comprehensive filter test coverage — added unit + integration tests for include-only, exclude-only, include+exclude precedence, invalid patterns, and prune behavior
- Project mode support for
doctor—doctornow supports auto-detect project mode plus explicit--project/--global
Changed
- Filter-aware diagnostics —
sync,diff,status,doctor, API drift checks, and Web UI target counts now compute expected skills using include/exclude filters - Web UI config freshness — UI API now auto-reloads config on requests, so browser refresh reflects latest
config.yamlwithout restartingskillshare ui - Documentation expanded — added practical include/exclude strategy guidance, examples, and project-mode
doctorusage notes
Fixed
- Exclude pruning behavior in merge mode — when a previously synced source-linked entry becomes excluded,
syncnow unlinks/removes it; existing local non-symlink target folders are preserved - Project
doctorbackup/trash reporting — now uses project-aware semantics (backups not used in project mode, trash checked from.skillshare/trash)
[0.12.5] - 2026-02-13
Fixed
target removemerge mode symlink cleanup — CLI now correctly detects and removes all skillshare-managed symlinks using path prefix matching instead of exact name matching; fixes nested/orphaned symlinks being left behindtarget removein Web UI — server API now handles merge mode targets (previously only cleaned up symlink mode)
[0.12.4] - 2026-02-13
Added
- Graceful shutdown — HTTP server handles SIGTERM/SIGINT with 10s drain period, safe for container orchestrators
- Server timeouts — ReadHeaderTimeout (5s), ReadTimeout (15s), WriteTimeout (30s), IdleTimeout (60s) prevent slow-client resource exhaustion
- Enhanced health endpoint —
/api/healthnow returnsversionanduptime_seconds - Production Docker image (
docker/production/Dockerfile) — multi-stage build,tiniPID 1, non-root user (UID 10001), auto-init entrypoint, healthcheck - CI Docker image (
docker/ci/Dockerfile) — minimal image forskillshare auditin pipelines - Docker dev profile —
make dev-docker-upruns Go API server in Docker for frontend development without local Go - Multi-arch Docker build —
make docker-build-multiarchproduces linux/amd64 + linux/arm64 images - Docker publish workflow (
.github/workflows/docker-publish.yml) — auto-builds and pushes production + CI images to GHCR on tag push make sandbox-status— show playground container status
Changed
- Compose security hardening — playground:
read_only,cap_drop: ALL,tmpfswith exec; all profiles:no-new-privileges, resource limits (2 CPU / 2G) - Test scripts DRY —
test_docker.shaccepts--onlineflag;test_docker_online.shis now a thin wrapper - Compose version check —
_sandbox_common.shverifies Docker Compose v2.20+ with platform-specific install hints .dockerignoreexpanded — excludes.github/,website/, editor temp files- Git command timeout — increased from 60s to 180s for constrained Docker/CI networks
- Online test timeout — increased from 120s to 300s
Fixed
- Sandbox
chmodfailure — playground volume init now uses--cap-add ALLto work withcap_drop: ALL - Dev profile crash on first run — auto-runs
skillshare initbefore starting UI server - Sandbox Dockerfile missing
curl— added for playground healthcheck
[0.12.2] - 2026-02-13
Fixed
- Hub search returns all results — hub/index search no longer capped at 20;
limit=0means no limit (GitHub search default unchanged) - Search filter ghost cards — replaced IIFE rendering with
useMemoto fix stale DOM when filtering results
Added
- Scroll-to-load in Web UI — search results render 20 at a time with IntersectionObserver-based incremental loading
[0.12.1] - 2026-02-13
Added
- Hub persistence — saved hubs stored in
config.yaml(both global and project), shared between CLI and Web UIhub add <url>— save a hub source (--labelto name it; first add auto-sets as default)hub list— list saved hubs (*marks default)hub remove <label>— remove a saved hubhub default [label]— show or set the default hub (--resetto clear)- All subcommands support
--project/--globalmode
- Hub label resolution in search —
search --hub <label>resolves saved hub labels instead of requiring full URLssearch --hub teamlooks up the "team" hub from configsearch --hub(bare) uses the config default, falling back to community hub
- Hub saved API — REST endpoints for hub CRUD (
GET/PUT/POST/DELETE /api/hub/saved) - Web UI hub persistence — hub list and default hub now persisted on server instead of browser localStorage
- Search fuzzy filter — hub search results filtered by fuzzy match on name + substring match on description and tags
- Tag badges in search —
#tagbadges displayed in both CLI interactive selector and Web UI hub search results - Web UI tag filter — inline filter input on hub search cards matching name, description, and tags
Changed
search --hub(bare flag) now defaults to community skillshare-hub instead of requiring a URL- Web UI SearchPage migrated from localStorage to server API for hub state
Fixed
audit <path>no longer fails with "config not found" in CI environments without a skillshare config
[0.12.0] - 2026-02-13
Added
- Hub index generation —
skillshare hub indexbuilds askillshare-hub.jsonfrom installed skills for private or team catalogs--fullincludes extended metadata (flatName, type, version, repoUrl, installedAt)--output/-oto customize output path;--source/-sto override scan directory- Supports both global and project mode (
-p/-g)
- Private index search —
skillshare search --hub <url>searches a hub index (local file or HTTP URL) instead of GitHub- Browse all entries with no query, or fuzzy-match by name/description/tags/source
- Interactive install prompt with
sourceand optionalskillfield support
- Hub index schema —
schemaVersion: 1withtagsandskillfields for classification and multi-skill repo support - Web UI hub search — search private indexes from the dashboard with a hub URL dropdown
- Hub manager modal for adding, removing, and selecting saved hub URLs (persisted in localStorage)
- Web UI hub index API —
GET /api/hub/indexendpoint for generating indexes from the dashboard - Hub index guide and command reference in documentation
Fixed
hub indexhelp text referenced incorrect--index-urlflag (now--hub)- Frontend
SearchResultTypeScript interface missingtagsfield
[0.11.6] - 2026-02-11
Added
- Auto-pull on
init --remote— when remote has existing skills, init automatically fetches and syncs them; no manualgit cloneorgit pullneeded - Auto-commit on
git init—initcreates an initial commit (with.gitignore) sopush/pull/stashwork immediately - Git identity fallback — if
user.name/user.emailaren't configured, sets repo-local defaults (skillshare@local) with a hint to set your own - Git remote error hints —
push,pull, andinit --remotenow show actionable hints for SSH, URL, and network errors - Docker sandbox
--baremode —make sandbox-barestarts the playground without auto-init for manual testing - Docker sandbox
--volumesreset —make sandbox-resetremoves the playground home volume for a full reset
Changed
init --remoteauto-detection — global-only flags (--remote,--source, etc.) now skip project-mode auto-detection, soinit --remoteworks from any directory- Target multi-select labels — shortened to
name (status)for readability; paths shown during detection phase instead
Fixed
init --remoteon second machine no longer fails with "Local changes detected" or merge conflictsinit --remoteproduces clean linear git history (no merge commits from unrelated histories)- Pro tip message only shown when built-in skill is actually installed
[0.11.5] - 2026-02-11
Added
--intoflag for install — organize skills into subdirectories (skillshare install repo --into frontendplaces skills underskills/frontend/)- Nested skill support in check/update/uninstall — recursive directory walk detects skills in organizational folders;
updateanduninstallresolve short names (e.g.,update vuefindsfrontend/vue/vue-best-practices) - Configurable audit block threshold —
audit.block_thresholdin config sets which severity blocks install (defaultCRITICAL);audit --threshold <level>overrides per-command - Audit path scanning —
skillshare audit <path>scans arbitrary files or directories, not only installed skills - Audit JSON output —
skillshare audit --jsonfor machine-readable results with risk scores --skip-auditflag for install — bypass security scanning for a single install command- Risk scoring — weighted risk score and label (clean/low/medium/high/critical) per scanned skill
- LOW and INFO severity levels — lighter-weight findings that contribute to risk score without blocking
- IBM Bob target — added to supported AI CLIs (global:
~/.bob/skills, project:.bob/skills) - JS/TS syntax highlighting in file viewer — Web UI highlights
.js,.ts,.jsx,.tsxfiles with CodeMirror - Project init agent grouping — agents sharing the same project skills path (Amp, Codex, Copilot, Gemini, Goose, etc.) are collapsed into a single selectable group entry
Changed
- Goose project path updated from
.goose/skillsto.agents/skills(universal agent directory convention) - Audit summary includes all severity levels — LOW/INFO counts, risk score, and threshold shown in summary box and log entries
Fixed
- Web UI nested skill update now uses full relative path instead of basename only
- YAML block scalar frontmatter (
>-,|,|-) parsed correctly in skill detail view - CodeMirror used for all non-markdown files in file viewer (previously plain
<pre>)
[0.11.4] - 2026-02-11
Added
- Customizable audit rules —
audit-rules.yamlexternalizes security rules for user overrides- Three-layer merge: built-in → global (
~/.config/skillshare/audit-rules.yaml) → project (.skillshare/audit-rules.yaml) - Add custom rules, override severity, or disable built-in rules per-project
skillshare audit --init-rulesto scaffold a starter rules file
- Three-layer merge: built-in → global (
- Web UI Audit Rules page — create, edit, toggle, and delete rules from the dashboard
- Log filtering — filter operation/audit logs by status, command, or keyword; custom dropdown component
- Docker playground audit demo — pre-loaded demo skills and custom rules for hands-on audit exploration
Changed
- Built-in skill is now opt-in —
initandupgradeno longer install the built-in skill by default; use--skillto include it - HIGH findings reclassified as warnings — only CRITICAL findings block
install; HIGH/MEDIUM are shown as warnings - Integration tests split into offline (
!online) and online (online) build tags for faster local runs
[0.11.0] - 2026-02-10
Added
- Security Audit —
skillshare audit [name]scans skills for prompt injection, data exfiltration, credential access, destructive commands, obfuscation, and suspicious URLs- CRITICAL findings block
skillshare installby default; use--forceto override - HIGH/MEDIUM findings shown as warnings with file, line, and snippet detail
- Per-skill progress display with tree-formatted findings and summary box
- Project mode support (
skillshare audit -p)
- CRITICAL findings block
- Web UI Audit page — scan all skills from the dashboard, view findings with severity badges
- Install flow shows
ConfirmDialogon CRITICAL block with "Force Install" option - Warning dialog displays HIGH/MEDIUM findings after successful install
- Install flow shows
- Audit API —
GET /api/auditandGET /api/audit/{name}endpoints - Operation log (persistent audit trail) — JSONL-based operations/audit logging across CLI + API + Web UI
- CLI:
skillshare log(--audit,--tail,--clear,-p/-g) - API: log list/clear endpoints for operations and audit streams
- Web UI: Log page with tabs, filters, status/duration formatting, and clear/refresh actions
- CLI:
- Sync drift detection —
statusanddoctorwarn when targets have fewer linked skills than source- Web UI shows drift badges on Dashboard and Targets pages
- Trash (soft-delete) workflow — uninstall now moves skills to trash with 7-day retention
- New CLI commands:
skillshare trash list,skillshare trash restore <name>,skillshare trash delete <name>,skillshare trash empty - Web UI Trash page for list/restore/delete/empty actions
- Trash API handlers with global/project mode support
- New CLI commands:
- Update preview command —
skillshare checkshows available updates for tracked repos and installed skills without modifying files - Search ranking upgrade — relevance scoring now combines name/description/stars with repo-scoped query support (
owner/repo[/subdir]) - Docs site local search — Docusaurus local search integrated for command/doc lookup
- SSH subpath support —
install git@host:repo.git//subdirwith//separator - Docs comparison guide — new declarative vs imperative workflow comparison page
Changed
- Install discovery + selection UX
- Hidden directory scan now skips only
.git(supports repos using folders like.curated/and.system/) install --skillfalls back to fuzzy matching when exact name lookup fails- UI SkillPicker adds filter input and filtered Select All behavior for large result sets
- Batch install feedback improved: summary toast always shown; blocked-skill retry targets only blocked items
- CLI mixed-result installs now use warning output and condensed success summaries
- Hidden directory scan now skips only
- Search performance + metadata enrichment — star/description enrichment is parallelized, and description frontmatter is used in scoring
- Skill template refresh —
newcommand template updated to a WHAT+WHEN trigger format with step-based instructions - Search command UX — running
searchwith no keyword now prompts for input instead of auto-browsing - Sandbox hardening — playground shell defaults to home and mounts source read-only to reduce accidental host edits
- Project mode clarity —
(project)labels added across key command outputs; uninstall prompt now explicitly says "from the project?" - Project tracked-repo workflow reliability
ProjectSkillnow supportstracked: truefor portable project manifests- Reconcile logic now detects tracked repos via
.git+ remote origin even when metadata files are absent - Tracked repo naming uses
owner-repostyle (for example,_openai-skills) to avoid basename collisions - Project
listnow uses recursive skill discovery for parity with global mode and Web UI
- Privacy-first messaging + UI polish — homepage/README messaging updated, dashboard quick actions aligned, and website hero/logo refreshed with a new hand-drawn style
ConfirmDialogcomponent supportswideprop and hidden cancel button- Sidebar category renamed from "Utilities" to "Security & Utilities"
- README updated with audit section, new screenshots, unified image sizes
- Documentation links and navigation updated across README/website
Fixed
- Web UI uninstall handlers now use trash move semantics instead of permanent deletion
- Windows self-upgrade now shows a clear locked-binary hint when rename fails (for example, when
skillshare uiis still running) mise.tomlui:buildpath handling fixed socd uidoes not leak into subsequent build steps- Sync log details now include target count, fixing blank details in some entries
- Project tracked repos are no longer skipped during reconcile when metadata is missing
[0.10.0] - 2026-02-08
Added
- Web Dashboard —
skillshare uilaunches a full-featured React SPA embedded in the binary- Dashboard overview with skill/target counts, sync mode, and version check
- Skills browser with search, filter, SKILL.md viewer, and uninstall
- Targets page with status badges, add/remove targets
- Sync controls with dry-run/force toggles and diff preview
- Collect page to scan and pick skills from targets back to source
- GitHub skill search with one-click install and batch install
- Config editor with YAML validation
- Backup/restore management with cleanup
- Git sync page with push/pull, dirty-file detection, and force-pull
- Install page supporting path, git URL, and GitHub shorthand inputs
- Update tracked repos from the UI with commit/diff details
- REST API at
/api/*— Gonet/httpbackend (30+ endpoints) powering the dashboard - Single-binary distribution — React frontend embedded via
go:embed, no Node.js required at runtime - Dev mode —
go build -tags devserves placeholder SPA; use Vite on:5173with/apiproxy for hot reload internal/git/info.go— git operations library (pull with change info, force-pull, dirty detection, stage/commit/push)internal/version/skill.go— local and remote skill version checking- Bitbucket/GitLab URL support —
installnow strips branch prefixes from Bitbucket (src/{branch}/) and GitLab (-/tree/{branch}/) web URLs internal/utils/frontmatter.go—ParseFrontmatterField()utility for reading SKILL.md metadata- Integration tests for
skillshare uiserver startup - Docker sandbox support for web UI (
--host 0.0.0.0, port 19420 mapping) - CI: frontend build step in release and test workflows
- Website documentation for
uicommand
Changed
- Makefile updated with
ui-build,build-ui,ui-devtargets .goreleaser.yamlupdated to include frontend build in release pipeline- Docker sandbox Dockerfile uses multi-stage build with Node.js for frontend assets
[0.9.0] - 2026-02-05
Added
- Project-level skills — scope skills to a single repository, shared via git
skillshare init -pto initialize project mode.skillshare/directory withconfig.yaml,skills/, and.gitignore- All core commands support
-pflag:sync,install,uninstall,update,list,status,target,collect
- Auto-detection — commands automatically switch to project mode when
.skillshare/config.yamlexists - Per-target sync mode for project mode — each target can use
mergeorsymlinkindependently --discoverflag — detect and add new AI CLI targets to existing project config- Tracked repos in project mode —
install --track -pclones repos into.skillshare/skills/ - Integration tests for all project mode commands
Changed
- Terminology: "Team Sharing" → "Organization-Wide Skills", "Team Edition" → "Organization Skills"
- Documentation restructured with dual-level architecture (Organization + Project)
- Unified project sync output format with global sync
[0.8.0] - 2026-01-31
Breaking Changes
Command Rename: pull <target> → collect <target>
For clearer command symmetry, pull is now exclusively for git operations:
| Before | After | Description |
|---|---|---|
pull claude | collect claude | Collect skills from target to source |
pull --all | collect --all | Collect from all targets |
pull --remote | pull | Pull from git remote |
New Command Symmetry
| Operation | Commands | Direction |
|---|---|---|
| Local sync | sync / collect | Source ↔ Targets |
| Remote sync | push / pull | Source ↔ Git Remote |
Remote (git)
↑ push ↓ pull
Source
↓ sync ↑ collect
Targets
Migration
# Before
skillshare pull claude
skillshare pull --remote
# After
skillshare collect claude
skillshare pull
[0.7.0] - 2026-01-31
Added
- Full Windows support (NTFS junctions, zip downloads, self-upgrade)
searchcommand to discover skills from GitHub- Interactive skill selector for search results
Changed
- Windows uses NTFS junctions instead of symlinks (no admin required)
[0.6.0] - 2026-01-20
Added
- Team Edition with tracked repositories
--trackflag forinstallcommandupdatecommand for tracked repos- Nested skill support with
__separator
[0.5.0] - 2026-01-16
Added
newcommand to create skills with templatedoctorcommand for diagnosticsupgradecommand for self-upgrade
Changed
- Improved sync output with detailed statistics
[0.4.0] - 2026-01-16
Added
diffcommand to show differencesbackupandrestorecommands- Automatic backup before sync
Changed
- Default sync mode changed to
merge
[0.3.0] - 2026-01-15
Added
pushandpull --remotefor cross-machine sync- Git integration in
initcommand
[0.2.0] - 2026-01-14
Added
installanduninstallcommands- Support for git repo installation
target addandtarget removecommands
[0.1.0] - 2026-01-14
Added
- Initial release
init,sync,status,listcommands- Symlink and merge sync modes
- Multi-target support