Skip to main content

Skill Install ++ wordmark

Audit-first skill and plugin management for Codex, Claude Code, and Copilot CLI.

Keep ~/.skills as the source of truth, export only the discovery surfaces each client should see, and repair drift without guessing hidden client state.

CI Release PyPI Python License

Repository: skill-install-plus-plus | Package: skillpp | CLI: skillpp

Table of Contents

Why This Exists

AI assistant skill setups drift quickly once you mix:

  • standalone local skill folders
  • Git-backed skill repositories
  • hybrid repositories that export skills plus bundle metadata
  • plugin bundles with manifests, agents, hooks, and runtime files

Copies go stale, links diverge, and it becomes unclear which files are managed versus accidental.

skillpp gives those assets one managed home under ~/.skills, then projects only the explicit SKILL.md surfaces into client discovery roots.

It is intentionally conservative: audit first, mutate second.

What Skillpp Manages

  • Standalone local skills normalized into ~/.skills/custom
  • Git-backed skill repositories stored under ~/.skills/repos/<owner>/<repo>
  • Plugin bundles stored under ~/.skills/plugins/<publisher>/<name>
  • Explicit skill exposures for Codex, Claude Code, and Copilot CLI
  • Non-destructive alignment when client discovery roots drift away from managed state

Highlights

  • One managed source-of-truth tree under ~/.skills
  • Supports standalone skills, Git-backed repos, hybrid repos, and plugin bundles
  • Audit-first workflow for drift, broken links, legacy copies, and missing exposures
  • Safe alignment that creates missing links without rewriting unrelated client state
  • Public Python CLI available through uvx, uv tool install, and pipx
  • GitHub Actions CI plus PyPI release automation via Trusted Publishing

Support Matrix

Client Status Discovery root Notes
Codex Supported ~/.agents/skills Respects existing aggregate custom exposures where already in place
Claude Code Supported ~/.claude/skills Injects explicit skill surfaces only
Copilot CLI Supported ~/.copilot/skills Injects explicit skill surfaces only

Install

Try it without installing

uvx skillpp audit

Persistent install with uv

uv tool install skillpp

Persistent install with pipx

pipx install skillpp

Quick Start

  1. Audit the current managed state:
skillpp audit
  1. Bootstrap the current project into the managed tree:
skillpp bootstrap --source .
  1. Install a skill from GitHub:
skillpp install --repo jackwener/OpenCLI --path skills/opencli-browser
  1. Install a plugin bundle:
skillpp install-plugin --publisher acme --name suite --repo acme/suite
  1. Create missing non-destructive exposures:
skillpp align --apply
  1. Refresh managed repositories and git-backed bundles:
skillpp update

Source-of-Truth Model

Everything managed by skillpp lives under ~/.skills:

~/.skills/
|- custom/
|- repos/<owner>/<repo>/
|- plugins/<publisher>/<name>/
`- registry.json

Client discovery roots stay separate:

  • Codex: ~/.agents/skills
  • Claude Code: ~/.claude/skills
  • Copilot CLI: ~/.copilot/skills

This keeps the managed tree explicit while preserving each client's discovery model.

Why Audit-First Matters

Blind installers are convenient until they overwrite something you needed.

skillpp treats that as a design problem, not a user problem. The tool:

  • inventories managed sources before mutating discovery roots
  • surfaces legacy copies and mismatched links explicitly
  • creates only safe missing links during alignment
  • avoids guessing undocumented client plugin registries

That boundary matters most for larger bundles where exported SKILL.md files are only one part of the package surface.

Development

Run the test suite:

uv run python -m unittest tests.test_manager tests.test_cli -v

Build the package:

uv run --with build python -m build

Check built artifacts:

uv run --with twine python -m twine check dist/*

Release Model

skillpp is PyPI-first.

Recommended usage modes:

  • uvx skillpp ... for ephemeral runs
  • uv tool install skillpp for persistent installs
  • pipx install skillpp as a familiar Python CLI alternative

There is no npm package or npx wrapper in v1.

Contributing

Contributions are welcome. Start with CONTRIBUTING.md for development workflow, test expectations, and contribution scope.

Security

Security reporting guidance lives in SECURITY.md.

License

MIT. See LICENSE.

Metadata

Release files for skillpp 0.1.2

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for skillpp 0.1.2
File Size Uploaded
skillpp-0.1.2.tar.gz 23.1 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for skillpp 0.1.2
File Interpreter ABI Platform
skillpp-0.1.2-py3-none-any.whl Python 3 none any Details

Total release size: 39.4 kB

Release files / skillpp-0.1.2.tar.gz

Download URL skillpp-0.1.2.tar.gz
Size 23.1 kB
Tags Source
SHA-256 checksum
How to use checksums
f509eb7a26da2505b71eb13b50bc0e09e9c3728e4928a41efa08df47e97b286b
BLAKE2b-256 checksum
How to use checksums
3fd36c4dfb44f9eadcebf63f6bdee16fd33b1b326b5ad7f9b9473b1ebda6dbb7
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.12

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Apr 14, 2026.

Transparency log

Release files / skillpp-0.1.2-py3-none-any.whl

Download URL skillpp-0.1.2-py3-none-any.whl
Size 16.3 kB
Tags Python 3
SHA-256 checksum
How to use checksums
93a04b4a24bae94cd72de0413af39baad897ccc8d058621610031e81989fffb0
BLAKE2b-256 checksum
How to use checksums
29f2c4ac26d4a58b98f30dd81ddf1b666371518c6390cda3837af322f2184e98
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.12

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Apr 14, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.1.2 This release

2 release files

0.1.1

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page