Skip to main content

skillmeld

CI PyPI License: Apache-2.0 Python 3.12+

Describe what you want to do, point skillmeld at your repo, and it finds existing community skills for the job, security-scans them, and merges the best two or three into one coherent skill set tailored to your project — instead of writing one from scratch.

It runs on your own Claude in Claude Code, grounds in your repo, and shows you what it pulled, what it found, and why before anything is installed. It builds on the existing skills ecosystem (the open standard, community marketplaces, and registries) rather than replacing it.

What makes it different

skillmeld composes; it does not generate. Every line in a merged skill traces byte-for-byte back to a source skill — a deterministic verifier enforces this, so the tool can never invent an instruction. The hard, mechanical work (parsing, security scanning, deduplicating, conflict detection, packaging) runs as deterministic Python that makes zero model calls. Your Claude supplies the judgment; the engine supplies the guarantees.

Composition tools are appearing on other layers too: AgentSkillOS retrieves skills from a large pool and chains them into runtime workflows, and SkillComposer has a model generate and evolve its own skills. skillmeld's job is different: it merges skills other people wrote — untrusted input — into one reviewed, deduplicated set before anything runs, with a security verdict on every source and a byte trace on every line.

How it works

A Claude Code skill drives a bundled Python engine through one pipeline:

intake -> ground -> discover -> select (<=3) -> fetch -> security gate -> merge -> eval -> emit
  • intake normalizes the request and says when it is too thin to act on.
  • ground scans your repo into a use-case profile, locally.
  • discover syncs a signed catalog of community skills (Ed25519-verified, hash-pinned, cached locally) and your Claude ranks the shortlist.
  • select takes at most three candidates, a separate cap from the three-skill output.
  • fetch downloads only the chosen bundles and checks every file against the hash the catalog pinned.
  • security gate scans every candidate (PASS / REVIEW / BLOCK) before you see it, and again after merge. REVIEW is the normal outcome for a skill that calls the network or reads files: the findings are named for you to decide on, and a BLOCK is never overridable.
  • merge parses each skill into byte-exact atoms, deduplicates, resolves conflicts, prunes to your use case, and partitions the result into at most three skills behind a thin routing orchestrator. A verifier proves every output atom traces to a source.
  • eval scores the set with no model calls: structural quality, byte-traceability, held-out trigger routing and a leakage check; every description edit is gated on it.
  • emit packages the result for Claude Code, a claude.ai zip, the API, or a Claude Code plugin marketplace, with a provenance record (PROVENANCE.md, or PROVENANCE-<set>.md beside a Claude Code skills tree) of where every part came from.

Install

Two ways in, one engine. The plugin path needs uv on your PATH; the command-line path needs uv or pipx.

As a Claude Code plugin, the /skillmeld skill, with no clone:

/plugin marketplace add ifylab/skillmeld
/plugin install skillmeld@ifylab

Claude Code fetches the repository into its plugin cache, and the skill runs the engine from there.

As a command-line tool, from PyPI:

uv tool install skillmeld    # or: pipx install skillmeld
skillmeld --help

The command line runs the deterministic stages one at a time, which suits scripts and CI. The judgment steps (completing the profile, ranking candidates, adjudicating conflicts, authoring descriptions) belong to the skill, driven by your Claude.

Quickstart

As a skill, describe the use case inside the project it is for:

/skillmeld I review pull requests for a Python service and want one consistent code-review routine

Or exercise individual stages directly from the CLI. Each line stands alone and prints JSON; ground prints a partial profile whose summary and tasks you complete before discover reads it. From the package root of a clone, uv run skillmeld is the same command:

skillmeld catalog sync                   # fetch and verify the hosted catalog
skillmeld ground .                       # scan a repo into a profile
skillmeld scan path/to/skill --license   # security- and license-scan a bundle
skillmeld merge --bundles a/ b/ --profile profile.json

The full pipeline — intake, discover, select, fetch, the eval loop, and every JSON contract these commands exchange — is walked step by step in skills/skillmeld/SKILL.md. Offline, skillmeld dev-catalog builds the same signed catalog locally from repos you name. Two build-time scouts feed the curated source list: skillmeld skillsmp-scout searches the SkillsMP registry and skillmeld awesome-scout reads a curated awesome-list; both print candidates, and membership stays a hand-made decision.

What it isn't

  • Not a generator. It assembles existing skills; it never authors new instructions. A convention no source skill covers is yours to add, not a gap skillmeld fills.
  • Not a catalog. It composes from community marketplaces and registries rather than being one.
  • Not a model. The engine makes zero LLM calls; the judgment comes from your own Claude, on your tokens.

Acknowledgements

skillmeld stands on the open Agent Skills ecosystem — the skill format, the community marketplaces, and the registries that publish and share skills. It composes that work; it does not replace it. Security scanning leans on bandit, with optional semgrep, gitleaks and NVIDIA SkillSpector when present.

Status

In active development, built in the open one piece at a time. The discovery, security, merge, evaluation, and packaging stages are implemented and tested, and discovery runs against a hosted signed catalog rebuilt weekly by CI — every published skill is crawled at a pinned commit and pre-scanned into an advisory verdict index. The curated AEC corpus is coming next. See the changelog.

Stack

Python 3.12, managed with uv. Ruff for lint and format, ty for type-checking, pytest for tests.

uv run ruff check . && uv run ruff format --check . && uv run ty check && uv run pytest

Contributing

Issues and pull requests are welcome — see CONTRIBUTING.md. Contributions are accepted under the project's Apache 2.0 license (inbound = outbound); no separate contributor agreement is required.

License

Apache License 2.0 — see LICENSE and NOTICE.

Metadata

Release files for skillmeld 0.4.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for skillmeld 0.4.0
File Size Uploaded
skillmeld-0.4.0.tar.gz 139.0 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for skillmeld 0.4.0
File Interpreter ABI Platform
skillmeld-0.4.0-py3-none-any.whl Python 3 none any Details

Total release size: 253.8 kB

Release files / skillmeld-0.4.0.tar.gz

Download URL skillmeld-0.4.0.tar.gz
Size 139.0 kB
Tags Source
SHA-256 checksum
How to use checksums
8ca293f96b8802afd040a18718b862829c49552943a9b0458f8f1dbc2d0865c9
BLAKE2b-256 checksum
How to use checksums
851bde33aa72b5c27805624f4f9308559c8fe93f9b5a0c1d043a6974c650fbdd
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via uv/0.12.19 {"installer":{"name":"uv","version":"0.12.19","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

Release files / skillmeld-0.4.0-py3-none-any.whl

Download URL skillmeld-0.4.0-py3-none-any.whl
Size 114.8 kB
Tags Python 3
SHA-256 checksum
How to use checksums
f8ed97b4bb68ea2df3f5bfae92c6a0b8027083842ca4752d0cbf8cbf048edb8f
BLAKE2b-256 checksum
How to use checksums
74b25424887a09dadd30b674de9dd8e6bc7487175765a6472553cf8874241261
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via uv/0.12.19 {"installer":{"name":"uv","version":"0.12.19","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

Release history Release notifications | RSS feed

0.5.0

2 release files

This release

0.4.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page