Showcase · Plugin marketplace · Markdown / JSON

Agent skills

A Claude Code plugin marketplace for the reusable skills, guardrails and workflow habits I use across my projects.

Covers 3 projects

Repository

The problem it exists for

An agent reads its instruction files and does what they say, so those files behave like code. Copied from one repository to the next, they drift. Accept them from strangers, and anyone can hide an instruction inside one.

So the habits behind How I work live in one place, a public plugin marketplace: 66 skills across 8 plugins, plus 5 subagents and 21 commands, installable into Claude Code or Codex. Versioning is where it bit first: before it was automated, one plugin shipped nothing to anyone for six weeks, because its version number never moved.

How it works

One folder per plugin, one catalogue

Each plugin is a folder with an owner and a version of its own, and a single catalogue lists them all. You add the marketplace once and install the plugins you want.

A security gate on every change

Every merge request runs a shared security check over the skills. It fails a change on hidden characters (zero-width or Trojan Source tricks), on an invalid manifest or skill header, and on leaked secrets, and it warns on instruction patterns that look like an injection. Two more checks make sure a skill is declared the same way for Claude and for Codex, and that the prose doesn’t carry the usual AI tells. The scanners are cicd’s skill-security component, so any repository of skills or agent instruction files can include the same gate, and the pipeline keeps them current. The marketplace I had to defend from my own attack surface is why.

skillup: versions that can’t stall

A plugin’s version number is what delivers its update. Claude Code caches each plugin under its version and never looks at a git branch or tag, so in the words of its own docs, users only receive updates when that field changes. A version that doesn’t move doesn’t delay a change. It withholds it, with no error and nothing in CI to notice.

skillup is the tool that keeps every version moving. It treats each plugin in the marketplace as a segment with its own version, and it has four jobs:

  • plan shows what each segment’s next version should be, and changes nothing.
  • apply writes those versions into the manifests and does nothing else: no commit, no tag, no push. The contributor commits the bump alongside the change that earned it, so a plugin’s content and its version never disagree on the main branch.
  • check is the gate. It fails a merge request when any segment has fallen behind, and it also reports a plugin the catalogue doesn’t list (so nobody can install it) or a catalogue version that contradicts the plugin’s own.
  • tag adds a tag per segment at the commit that set each version, after the fact if need be.

The trick is where it starts counting from. Release tools usually take the last git tag as the baseline, which makes tags something a person has to keep cutting on time, forever. skillup takes each segment’s baseline from the history of its own manifest, the commit where its version last changed. So it’s correct on a repository that has never been tagged, a late tag costs nothing but visibility, and tags can be added afterwards because the history still says where every version was set.

Its rules are the cautious ones. A change counts towards a segment by the files it touches, not by the label on the commit. It never lowers a version, because commit messages under-describe some changes (removing a skill breaks its users, but tends to land as a refactor), and reaching 1.0 is the author’s promise to make, not a sum. Below 1.0 a breaking change is a minor bump. It edits the version and nothing else in the file, rather than rewriting the JSON and turning a one-character change into an eighteen-line diff. And running it twice before committing doesn’t bump twice.

It’s a go-tool-base tool, and all its git work goes through go/repo, so there’s no git binary to shell out to (git and forges). It runs as a gate on GitLab or GitHub, with a setup guide for each, and Your first run with skillup walks through one.

docscheck

docscheck is a smaller sibling, checking that the commands a tool’s docs show you are commands the tool can actually run. krites runs it on every merge request through cicd’s docs-verify component, which runs a project’s own docs check with no change detection at all, because a docs gate that only wakes up for docs changes misses the code changes that break the docs.

Decisions and what they cost

  • Version from history, not tags. skillup reads each plugin’s manifest history instead of the last git tag. The existing tools were tried first: one had no monorepo support, one was GitHub-only, one bumped every file to a single version, and the closest fit took its baseline from tags. The tag-based tools proposed 0.1.0 for every plugin on an untagged repository, and gave two different states of the main branch the same version (the spike). What it cost: about 600 lines of Go to maintain, repeating parsing other tools already do.
  • CI checks, people bump. The pipeline only checks the version; the contributor runs the bump and commits it. A pipeline that pushed its own bump would start no new pipeline, leaving the merge request waiting forever. What it cost: a manual step on every change.
  • Deep members decide. The research panel puts one question to two “deep” agents, who give the verdict, and one “broad” agent, who only steers, each working on a throwaway copy of the files inside a sandbox (spec 0002). What it cost: one of the three tools has no read-only mode, and on macOS the sandbox can’t keep a member’s own state apart.
  • A clock the agent can’t ignore. The timebox skill comes with hooks that read the real clock and stop an agent quitting before its time (spec 0001), because a skill alone relies on remembering to look. What it cost: Codex gets the skill without the hooks.

Proof in use

  • It’s what this estate’s own agent sessions run on. The marketplace has had 292 commits since June 2026, and its plugins version on their own: the common plugin, the biggest, is at 0.46.
  • skillup gates every merge request to the marketplace, pinned at v0.3.1.
  • docscheck checks krites’ docs: 57 files and 97 documented commands, every real error caught and no false alarms.

Use it when, and when not to

Borrow it if you work with AI coding agents and want your habits written down once, installed everywhere, and safe to accept changes to. The general skills don’t assume my projects.

skillup only understands Claude Code plugin marketplaces, writes no changelogs, and needs the full git history (a shallow clone gives an answer that’s quietly wrong). docscheck checks command paths only, not flags or prose. The review panel needs a second agent tool with quota to spare, and falls back to one agent, visibly, without it. Hooks don’t carry over to Codex, and output styles are Claude-only.

Where it’s going

Rust and Terraform skills, a checker for skills that have drifted from their own repositories, and the panel and timebox findings deferred from their first release.

What it covers

The story in posts

Last reviewed .