skillmeld
Describe what you want to do, point skillmeld at your repo, and it finds existing community skills for the job, security-scans them, and merges the best two or three into one coherent skill set tailored to your project — instead of writing one from scratch.
It runs on your own Claude in Claude Code, grounds in your repo, and shows you what it pulled, what it found, and why before anything is installed. It builds on the existing skills ecosystem (the open standard, community marketplaces, and registries) rather than replacing it.
What makes it different
skillmeld composes; it does not generate. Every line in a merged skill traces byte-for-byte back to a source skill — a deterministic verifier enforces this, so the tool can never invent an instruction. The hard, mechanical work (parsing, security scanning, deduplicating, conflict detection, packaging) runs as deterministic Python that makes zero model calls. Your Claude supplies the judgment; the engine supplies the guarantees.
Composition tools are appearing on other layers too: AgentSkillOS retrieves skills from a large pool and chains them into runtime workflows, and SkillComposer has a model generate and evolve its own skills. skillmeld's job is different: it merges skills other people wrote — untrusted input — into one reviewed, deduplicated set before anything runs, with a security verdict on every source and a byte trace on every line.
How it works
A Claude Code skill drives a bundled Python engine through one pipeline:
intake -> ground -> discover -> select (<=3) -> fetch -> security gate -> merge -> eval -> emit
- intake normalizes the request and says when it is too thin to act on.
- ground scans your repo into a use-case profile, locally.
- discover syncs a signed catalog of community skills (Ed25519-verified, hash-pinned, cached locally) and your Claude ranks the shortlist.
- select takes at most three candidates, a separate cap from the three-skill output.
- fetch downloads only the chosen bundles and checks every file against the hash the catalog pinned.
- security gate scans every candidate (PASS / REVIEW / BLOCK) before you see it, and again after merge. REVIEW is the normal outcome for a skill that calls the network or reads files: the findings are named for you to decide on, and a BLOCK is never overridable.
- merge parses each skill into byte-exact atoms, deduplicates, resolves conflicts, prunes to your use case, and partitions the result into at most three skills behind a thin routing orchestrator. A verifier proves every output atom traces to a source.
- eval scores the set with no model calls: structural quality, byte-traceability, held-out trigger routing and a leakage check; every description edit is gated on it.
- emit packages the result for Claude Code, a claude.ai zip, the API, or a Claude Code plugin marketplace, with a provenance record (
PROVENANCE.md, orPROVENANCE-<set>.mdbeside a Claude Code skills tree) of where every part came from.
Install
Two ways in, one engine. The plugin path needs uv on your PATH; the command-line path needs uv or pipx.
As a Claude Code plugin, the /skillmeld skill, with no clone:
/plugin marketplace add ifylab/skillmeld
/plugin install skillmeld@ifylab
Claude Code fetches the repository into its plugin cache, and the skill runs the engine from there.
As a command-line tool, from PyPI:
uv tool install skillmeld # or: pipx install skillmeld
skillmeld --help
The command line runs the deterministic stages one at a time, which suits scripts and CI. The judgment steps (completing the profile, ranking candidates, adjudicating conflicts, authoring descriptions) belong to the skill, driven by your Claude.
Quickstart
As a skill, describe the use case inside the project it is for:
/skillmeld I review pull requests for a Python service and want one consistent code-review routine
Or exercise individual stages directly from the CLI. Each line stands alone and prints JSON;
ground prints a partial profile whose summary and tasks you complete before discover reads
it. From the package root of a clone, uv run skillmeld is the same command:
skillmeld catalog sync # fetch and verify the hosted catalog
skillmeld ground . # scan a repo into a profile
skillmeld scan path/to/skill --license # security- and license-scan a bundle
skillmeld merge --bundles a/ b/ --profile profile.json
The full pipeline — intake, discover, select, fetch, the eval loop, and every JSON contract these
commands exchange — is walked step by step in skills/skillmeld/SKILL.md.
Offline, skillmeld dev-catalog builds the same signed catalog locally from repos you name. Two build-time
scouts feed the curated source list: skillmeld skillsmp-scout searches the SkillsMP registry
and skillmeld awesome-scout reads a curated awesome-list; both print candidates, and membership stays a
hand-made decision.
What it isn't
- Not a generator. It assembles existing skills; it never authors new instructions. A convention no source skill covers is yours to add, not a gap skillmeld fills.
- Not a catalog. It composes from community marketplaces and registries rather than being one.
- Not a model. The engine makes zero LLM calls; the judgment comes from your own Claude, on your tokens.
Acknowledgements
skillmeld stands on the open Agent Skills ecosystem — the skill format, the community marketplaces, and the registries that publish and share skills. It composes that work; it does not replace it. Security scanning leans on bandit, with optional semgrep, gitleaks and NVIDIA SkillSpector when present.
Status
In active development, built in the open one piece at a time. The discovery, security, merge, evaluation, and packaging stages are implemented and tested, and discovery runs against a hosted signed catalog rebuilt weekly by CI — every published skill is crawled at a pinned commit and pre-scanned into an advisory verdict index. The curated AEC corpus is coming next. See the changelog.
Stack
Python 3.12, managed with uv. Ruff for lint and format, ty for type-checking, pytest for tests.
uv run ruff check . && uv run ruff format --check . && uv run ty check && uv run pytest
Contributing
Issues and pull requests are welcome — see CONTRIBUTING.md. Contributions are accepted under the project's Apache 2.0 license (inbound = outbound); no separate contributor agreement is required.
License
Metadata
Release files for skillmeld 0.4.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| skillmeld-0.4.0.tar.gz | 139.0 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| skillmeld-0.4.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 253.8 kB
Release files / skillmeld-0.4.0.tar.gz
| Download URL | skillmeld-0.4.0.tar.gz |
|---|---|
| Size | 139.0 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
8ca293f96b8802afd040a18718b862829c49552943a9b0458f8f1dbc2d0865c9
|
|
BLAKE2b-256 checksum How to use checksums |
851bde33aa72b5c27805624f4f9308559c8fe93f9b5a0c1d043a6974c650fbdd
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
uv/0.12.19 {"installer":{"name":"uv","version":"0.12.19","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|
Release files / skillmeld-0.4.0-py3-none-any.whl
| Download URL | skillmeld-0.4.0-py3-none-any.whl |
|---|---|
| Size | 114.8 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
f8ed97b4bb68ea2df3f5bfae92c6a0b8027083842ca4752d0cbf8cbf048edb8f
|
|
BLAKE2b-256 checksum How to use checksums |
74b25424887a09dadd30b674de9dd8e6bc7487175765a6472553cf8874241261
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
uv/0.12.19 {"installer":{"name":"uv","version":"0.12.19","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|