How we choose and review skills
This catalog is curated, not crawled. Here is what that means, and where the checks stop.
Updated
Who curates it
The catalog is curated by Santiago Gómez de la Torre, who also wrote the 327 skills built here. It is an independent project: it is not made by, or affiliated with, Anthropic.
Santiago Gómez de la Torre · github.com · linkedin.com · instagram.com
What is in it
478 skills in 9 sections: 327 written in this repository and 151 vendored from 20 community repositories. Every figure about the catalog is computed from the catalog when the site is built.
What gets in
- Built here: one task per skill, clear steps, and it detects the project's language and framework instead of assuming one.
- Community: only skills whose license lets us redistribute them with the original notices; currently MIT, Apache-2.0.
- A skill whose upstream has no license, or an (A)GPL one, is used privately and never published on this site.
How permissions are declared and checked
Each of the 327 skills built here carries a permissions block in its frontmatter: what it reads, what it writes, which commands it runs, whether it uses the network and whether it can destroy data. The catalog build fails if a skill has no block, so a skill without one cannot appear here.
Two scripts run in CI on every change to a skill. One checks structure, the manifest, dangerous patterns (such as piping curl into a shell) and trigger quality. The other cross-checks the manifest against the text: a skill that mentions destructive or network commands must declare them. These are pattern-based checks. They catch mismatches, not intent, so read the source before you run anything you do not know.
Community skills have no manifest. Their page says so and links to the source at the exact commit we vendored.
How community skills are synced
Community skills live in the repository under external/. A manifest (external/sources.txt) names each upstream repository, branch or tag and path, and a sync script (scripts/sync-external.sh) copies them in and pins the exact upstream commit. Each copy records that commit, its date and the upstream license in its own UPSTREAM.md and LICENSE files. A vendored copy is never edited by hand: the next sync would overwrite it. A weekly CI job reports which copies have fallen behind upstream.
Licenses
The 327 skills built here are MIT. The 151 community skills keep their upstream license: 134 MIT, 17 Apache-2.0. Every skill page shows its license and its original author.
Dates and updates
The date on a skill is when its file last changed in git (built here) or the date of the vendored upstream commit (community). The date on the home page and on each section is the newest date among its skills, never the build time.
Upstream drift is checked every week by CI. Updates are pulled in when the curator syncs them.
What this does not prove
Automated checks verify structure and declared permissions. They do not prove that a skill produces the right result for your case, and we do not review every line of every community skill. Treat a skill like any other code that runs on your machine.
Report a problem
Found a wrong claim, a missing permission or a broken skill? Tell us on GitHub.