skillock 🔒
Security-first package manager for AI agent skills.
Like npm for skills — with audit built into install.
Features
- 🔒 Scan-before-install — 19 security rules (9 P0, 6 P1, 4 P2) check every file
- 🔐 Supply-chain integrity — TOML lockfile with SHA-256 of every file
- 🚫 Zero trust — P0 rules block install; P1 prompts; P2 notes only
- 🔄 Symlink deploy — clean, reversible installation into agent directories
- 🏷️ Pinned versions — resolves tags/commits/branches to immutable SHA
- 🧩 Multi-agent — supports Claude, Codex, Agents, Cursor (or
--agents all) - 📦 Zero runtime deps — Python ≥3.11, stdlib only (
tomllib,hashlib,subprocess,pathlib) - 🛡️ MIT licensed
Install
# one-off (no install needed)
uvx skillock add owner/repo --skill my-skill --agents claude,codex
# or install globally
uv tool install skillock
Commands
| Command | Description |
|---|---|
add owner/repo[@tag] |
resolve → clone → scan → gate → deploy → lock |
list |
installed skills, pinned refs, scan verdicts |
update [skill] |
rescan + unified diff of every changed file, then upgrade |
remove <skill> |
delete symlinks, store copy, lock entry |
audit |
re-scan everything + verify SHA-256 of every installed file |
What Gets Blocked (P0 — Install Refused)
- curl-pipe-shell —
curl ... | sh,wget ... | bash - destructive-rm —
rm -rf /,rm -fr,rm -Rf - sudo / privilege escalation —
sudo,su,doas - code execution —
eval(),exec(),Function(),os.system(),subprocess(..., shell=True) - pickle deserialization —
pickle.load(),pickle.loads() - credential reads —
.env,~/.ssh/,AWS_SECRET,GH_TOKEN, etc. - hardcoded secrets — API keys, tokens, passwords in source
P1 warns and asks for confirmation; P2 prints notes only.
Full rule table: docs/spec.
Quick Demo
# This skill reads .env and uses exec() — BLOCKED (18 P0 findings)
uvx skillock add obra/superpowers --skill brainstorming --agents agents --yes
# Clean skill — installs successfully
uvx skillock add obra/superpowers --skill test-driven-development --agents agents --yes
How It Works
- Resolve — GitHub repo + tag/commit/branch → pinned commit SHA
- Clone — shallow clone at pinned ref
- Scan — every file checked against 19 security rules (9 P0, 6 P1, 4 P2)
- Gate — P0 blocks install; P1 prompts; P2 notes
- Deploy — symlinks into agent directories (
~/.claude/skills/,~/.codex/agents/, etc.) - Lock — TOML lockfile with SHA-256 of every file for integrity verification
Supported agents: claude, codex, agents, cursor (or --agents all)
Why
Real incidents show skills are untrusted code:
- A polars skill shipped adversarial instructions (K-Dense-AI/claude-scientific-skills)
- A hallucinated npm package spread to 200+ repos via copy-pasted skills
Skills are prompts your agent executes — treat them like untrusted code.
Architecture
- Zero runtime dependencies — Python ≥3.11, stdlib only (
tomllib,hashlib,subprocess,pathlib) - POSIX — Linux, macOS, WSL
- MIT license
Links
- GitHub: https://github.com/ruslanlap/skillock
- PyPI: https://pypi.org/project/skillock/
- Security policy: SECURITY.md
- Contributing: CONTRIBUTING.md
- Changelog: CHANGELOG.md (if exists)
Badges
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file skillock-0.1.3.tar.gz.
File metadata
- Download URL: skillock-0.1.3.tar.gz
- Upload date:
- Size: 35.0 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via:
twine/7.0.0 CPython/3.13.5
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
ba517674524fa13fda312589e40ee4fedc48e23d7f1d484ba358b2571fa11b10
|
|
| MD5 |
f11c5c0bac5e74e046b7a2dd701bb53f
|
|
| BLAKE2b-256 |
344c294c62e97fbc973c0fcaec5f31e876d9453ffd101e5efbf238728357eee3
|
File details
Details for the file skillock-0.1.3-py3-none-any.whl.
File metadata
- Download URL: skillock-0.1.3-py3-none-any.whl
- Upload date:
- Size: 12.2 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via:
twine/7.0.0 CPython/3.13.5
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
9ecfe28bb62dd82bd5d53ab10691130f5068a273b92156b9d6d8d6bf7f65be4f
|
|
| MD5 |
c5eec98a44ea92e75bd363689593cf4b
|
|
| BLAKE2b-256 |
8ab6dbcaf04db940fc5c9ba495b60d945ace04448a32d06677bae2423b120a61
|