agentskills-fs
Local filesystem skill provider for the Agent Skills SDK.
Serves Agent Skills from a local directory tree. Each subdirectory containing a SKILL.md file is a skill.
Installation
pip install agentskills-fs
Requires Python 3.12 or newer. Installs agentskills-core and pyyaml as dependencies.
Expected Directory Layout
skills/
├── incident-response/
│ ├── SKILL.md # YAML frontmatter + markdown body
│ ├── references/ # supplementary docs (optional)
│ ├── scripts/ # executable scripts (optional)
│ └── assets/ # diagrams, data files (optional)
└── another-skill/
└── SKILL.md
Usage
from pathlib import Path
from agentskills_core import SkillRegistry
from agentskills_fs import LocalFileSystemSkillProvider
provider = LocalFileSystemSkillProvider(Path("./skills"))
registry = SkillRegistry()
await registry.register_all(provider) # every subdirectory holding a SKILL.md
skill = registry.get_skill("incident-response")
meta = await skill.get_metadata()
body = await skill.get_body()
script = await skill.get_script("page-oncall.sh")
Use registry.register("incident-response", provider) instead to take one named skill and ignore
the rest of the folder.
Blocking file I/O runs in a worker thread, so a slow or networked filesystem does not stall other coroutines.
SKILL.md content is cached per provider instance after the first read — a single skill is otherwise re-read up to five times in one agent session. Call invalidate() when skills change on disk.
provider.invalidate("incident-response") # forget one skill
provider.invalidate() # forget everything
Security
- Path-traversal protection - Skill IDs and resource names are validated to stay within the root directory. Attempts to escape (e.g.
../../etc/passwd) raiseSkillNotFoundErrororResourceNotFoundError. - File size limits - Files exceeding 10 MB (default) are rejected before reading into memory. Configure via the
max_file_bytesparameter. - Error-message sanitization - Error messages reference the
skill_idrather than full filesystem paths, preventing internal path leakage.
For the full security policy, see SECURITY.md.
API
LocalFileSystemSkillProvider(root, *, max_file_bytes=10_485_760)
| Parameter | Type | Default | Description |
|---|---|---|---|
root |
Path |
- | Path to the directory containing skill subdirectories |
max_file_bytes |
int |
10_485_760 (10 MB) |
Maximum allowed file size in bytes |
| Method | Returns | Description |
|---|---|---|
get_metadata(skill_id) |
dict[str, Any] |
Parsed YAML frontmatter from SKILL.md |
get_body(skill_id) |
str |
Markdown body after the frontmatter |
get_script(skill_id, name) |
bytes |
Raw content of a script file |
get_asset(skill_id, name) |
bytes |
Raw content of an asset file |
get_reference(skill_id, name) |
bytes |
Raw content of a reference file |
list_resources(skill_id) |
dict[str, list[str]] |
Resource filenames grouped by kind |
invalidate(skill_id=None) |
None |
Drop cached SKILL.md content for one skill, or all skills |
Resource Discovery
This provider sets supports_resource_listing = True and can enumerate a skill's bundled files:
listing = await provider.list_resources("incident-response")
# {"references": ["severity-levels.md"], "scripts": ["page-oncall.sh"], "assets": []}
All three keys are always present; unused categories are empty lists. Only regular files directly inside references/, scripts/ and assets/ are reported. Dotfiles, subdirectories, and symlinks resolving outside the skill root are skipped rather than raising, so one stray entry cannot make a whole skill unlistable — and listing can never offer a name that a subsequent read would reject.
License
MIT
Metadata
Release files for agentskills-fs 0.5.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| agentskills_fs-0.5.0.tar.gz | 6.1 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| agentskills_fs-0.5.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 13.7 kB
Release files / agentskills_fs-0.5.0.tar.gz
| Download URL | agentskills_fs-0.5.0.tar.gz |
|---|---|
| Size | 6.1 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
a9e16dfd7d8c047863e09e8a093fd71a4752bf019c1eb6039803136a9bc82d1e
|
|
BLAKE2b-256 checksum How to use checksums |
e4c12548c96ed7bb07a5211aef640e606505a61e2cc1ede7bb240fdb2556d32e
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 19, 2026.
Transparency logRelease files / agentskills_fs-0.5.0-py3-none-any.whl
| Download URL | agentskills_fs-0.5.0-py3-none-any.whl |
|---|---|
| Size | 7.6 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
4cbbf1c582db5c53ce26c8c8eeafb1be48fd8eb390028cf1c067740647889207
|
|
BLAKE2b-256 checksum How to use checksums |
6f07ae985d14f885af804d5111e03da5ef5bcfc9c7ffeba39ffd31daecef216d
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 19, 2026.
Transparency log