open-skills
Manage AI Skills Across Editors
AI coding teams often maintain separate skill files for each editor. open-skills provides one CLI to discover, install, sync, and manage shared skill content.
Stop for confirmation before installing.
Review the plan and obtain explicit user consent before changing files.
Install with my Agent
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Review the Skillstore skill "open-skills" from https://skillstore.io/skills/lumacoder-open-skills.md and its manifest at https://skillstore.io/api/skills/lumacoder-open-skills/manifest. Verify the artifact. Stop and obtain explicit user consent before installing or changing files.Your Agent should still show its plan and request any confirmation required by the security policy.
Agent-readable resources
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
Test it
Using "open-skills". Install two frontend skills into Claude Code for the current project.
Expected outcome:
- The assistant opens the editor, scope, category, and skill selection flow.
- It writes selected skills under the Claude Code skills directory for the selected scope.
- It reports which skills succeeded and which failed.
Using "open-skills". Export my current AI skill setup.
Expected outcome:
- The assistant detects installed directory-mode skills for supported editors.
- It writes a stack file that can be imported later.
- It explains any editor targets that cannot be detected automatically.
Using "open-skills". Create and validate a new skill scaffold.
Expected outcome:
- The assistant creates a local bundle with a starter skill file.
- It registers the skill metadata in the registry.
- It runs registry validation and reports any missing fields.
Security Audit
High RiskMost static findings are false positives from Markdown examples, TypeScript import paths, template literals, lockfile metadata, and Unicode text. Confirmed issues are limited to trust-sensitive external network lookups, developer-panel innerHTML rendering, remote skill installation into AI editor targets, and unauthenticated local registry mutation in dev mode. No prompt injection attempt was found in the reviewed files.
Confirmed security concerns (4)
Capability review items (21)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
⚙️ External commands (157)
🌐 Network access (42)
📁 Filesystem access (151)
🔑 Env variables (2)
Share & cite this report
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.
Copy report link
https://skillstore.io/skills/lumacoder-open-skills/audits/4?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportMarkdown badge
[](https://skillstore.io/skills/lumacoder-open-skills?utm_source=security_passport_badge)HTML badge
<a href="https://skillstore.io/skills/lumacoder-open-skills?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/lumacoder-open-skills/security.svg" alt="Skillstore security assessment" loading="lazy"></a>Embed card
<iframe src="https://skillstore.io/embed/skills/lumacoder-open-skills.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>Academic citations (APA · BibTeX · CFF)
APA citation
lumacoder. (2026). open-skills security audit report (audit version 4) [Author version 2.0.0]. Skillstore. https://skillstore.io/skills/lumacoder-open-skills/audits/4BibTeX citation
@techreport{lumacoder-lumacoder-open-skills-2026,
author = {lumacoder},
title = {open-skills security audit report (audit version 4)},
institution = {Skillstore},
year = {2026},
number = {4},
url = {https://skillstore.io/skills/lumacoder-open-skills/audits/4},
note = {Author version 2.0.0}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "open-skills security audit report (audit version 4)"
version: "2.0.0"
type: report
authors:
- name: "lumacoder"
date-released: "2026-07-06"
url: "https://skillstore.io/skills/lumacoder-open-skills/audits/4"
identifiers:
- type: other
value: "skillstore:lumacoder-open-skills:audit:4"
description: "Skillstore immutable audit report identifier"
Skillstore Score
Why this score Evidence Confidence: MediumWhat You Can Build
Standardize Team AI Editors
Install the same approved skills into several AI coding editors so contributors share consistent assistant behavior.
Maintain a Skill Registry
Create, validate, export, import, and synchronize a curated registry of reusable skills for internal workflows.
Test Cross-Editor Output
Generate editor-specific outputs for Claude Code, Cursor, Cline, Windsurf, and related tools from one skill source.
Try These Prompts
Use open-skills to install frontend and devops skills into Claude Code and Cursor for this workspace. Explain each prompt choice before proceeding.
Search the open-skills registry for skills related to testing and API design. Summarize the best matches and the editors they can target.
Create a new local skill scaffold named api-review-checklist in the backend category. Explain which files were created and how to validate it.
Review the registry for remote git or GitHub origins. Identify which skills can be synchronized, then run the safest sync plan for one selected skill.
Best Practices
- Review remote skill content before installing it into global editor directories.
- Use local scope first when testing new skills or registry changes.
- Back up existing editor rule files and skill directories before install, update, sync, or import commands.
Avoid
- Do not run the developer web panel on a shared or exposed network interface.
- Do not install unreviewed remote skills directly into global AI editor directories.
- Do not store personal files inside managed editor skill directories.
Frequently Asked Questions
What editors does open-skills support?
Does it download remote content?
Can it overwrite existing editor files?
Is the developer web panel for production use?
Can it create new skills?
Does it work with Codex?
Developer Details
Author
lumacoderLicense
MIT
Author version
v2.0.0
Skillstore revision
r1
Ref
b8ca75d2c0a7e7102978993058777d82b8ab2610
Maintenance freshness
7/18/2026
Usage
6 downloads · 157 views