skill-best-practices
Build Better AI Skills
AI skills often fail because triggers, structure, and validation are unclear. This guide provides practical patterns for reliable SKILL.md design, testing, and maintenance.
Install with my Agent
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Review the Skillstore skill "skill-best-practices" from https://skillstore.io/skills/dboeckli-skill-best-practices.md and its manifest at https://skillstore.io/api/skills/dboeckli-skill-best-practices/manifest. Verify the artifact. You may proceed after verification, subject to the environment's own policy.Your Agent should still show its plan and request any confirmation required by the security policy.
Agent-readable resources
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
Test it
Using "skill-best-practices". Create a skill that plans sprints in Linear.
Expected outcome:
A three-use-case plan with sprint triggers, ordered Linear actions, validation gates, error handling, and representative tests.
Using "skill-best-practices". Review my skill because it rarely loads automatically.
Expected outcome:
- Fail: The description does not include phrases users commonly enter.
- Warning: The scope is broad and lacks negative triggers.
- Fix: Add task-specific phrases, exclusions, and ten paraphrased trigger tests.
Using "skill-best-practices". Improve a large skill that consumes too much context.
Expected outcome:
A concise core instruction file with detailed guidance moved into clearly linked references.
Security Audit
Medium RiskAll 91 static alerts are false positives caused by Markdown formatting, bounded local validation, or ordinary path handling. No prompt injection or malicious intent was found. Remote validation still has a medium supply-chain risk because it executes an unpinned npm package.
Confirmed security concerns (1)
Risk Factors
โ๏ธ External commands (50)
๐ Filesystem access (4)
๐ Network access (1)
Share & cite this report
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.
Copy report link
https://skillstore.io/skills/dboeckli-skill-best-practices/audits/1?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportMarkdown badge
[](https://skillstore.io/skills/dboeckli-skill-best-practices?utm_source=security_passport_badge)HTML badge
<a href="https://skillstore.io/skills/dboeckli-skill-best-practices?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/dboeckli-skill-best-practices/security.svg" alt="Skillstore security assessment" loading="lazy"></a>Embed card
<iframe src="https://skillstore.io/embed/skills/dboeckli-skill-best-practices.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>Academic citations (APA ยท BibTeX ยท CFF)
APA citation
dboeckli. (2026). skill-best-practices security audit report (audit version 1) [Author version unspecified]. Skillstore. https://skillstore.io/skills/dboeckli-skill-best-practices/audits/1BibTeX citation
@techreport{dboeckli-dboeckli-skill-best-practices-2026,
author = {dboeckli},
title = {skill-best-practices security audit report (audit version 1)},
institution = {Skillstore},
year = {2026},
number = {1},
url = {https://skillstore.io/skills/dboeckli-skill-best-practices/audits/1},
note = {Author version unspecified}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "skill-best-practices security audit report (audit version 1)"
version: "unspecified"
type: report
authors:
- name: "dboeckli"
date-released: "2026-09-26"
url: "https://skillstore.io/skills/dboeckli-skill-best-practices/audits/1"
identifiers:
- type: other
value: "skillstore:dboeckli-skill-best-practices:audit:1"
description: "Skillstore immutable audit report identifier"
Skillstore Score
Why this score Evidence Confidence: MediumWhat You Can Build
Create a New Skill
Turn a workflow idea into a structured skill with clear triggers, instructions, examples, and validation steps.
Review an Existing Skill
Evaluate frontmatter, instruction quality, progressive disclosure, testing coverage, and troubleshooting guidance.
Fix Trigger Behavior
Refine descriptions and negative triggers when a skill loads too rarely or on unrelated requests.
Try These Prompts
Create a skill plan for [goal]. Define three use cases, trigger phrases, required tools, workflow steps, and expected results.
Rewrite this skill description: [description]. Include its purpose, specific trigger phrases, important capabilities, and clear exclusions.
Review [SKILL.md content]. Report pass, warning, or fail for frontmatter, triggers, instructions, examples, references, testing, and troubleshooting.
Design a multi-tool skill for [workflow]. Include dependencies, validation gates, rollback steps, tool selection rules, error handling, and test cases.
Best Practices
- Define concrete use cases and trigger phrases before writing instructions.
- Keep core instructions concise and load detailed references only when needed.
- Test relevant, paraphrased, and unrelated requests before release.
Avoid
- Do not use vague descriptions that omit real user phrases.
- Do not bury critical validation steps below long background sections.
- Do not rely on prose when a deterministic validation script is available.
Frequently Asked Questions
What files does a basic skill require?
How should the description be written?
How can I reduce unwanted triggering?
When should references be used?
Does the validator test skill quality?
Is remote validation fully offline?
Developer Details
Author
dboeckliLicense
MIT
Skillstore revision
r1
Version notice
The author did not declare a version.
Ref
1cda4003aa9ea65a9606af00b33e9c706ef03e62
Maintenance freshness
9/30/2026
Usage
0 downloads ยท 0 views
File structure