mujiehaskillwharf

skillwharf

One manifest and lockfile for the agent skills your team shares.

npm i -g skillwharf
skillwharf on npm

Node 22.12 or later, on macOS and LinuxVersion 0.1.1Release notes

skillwharf in 28 seconds: why skills get copied everywhere, go unpinned and go unused; then init, add pinned to a full commit sha, sync, doctor and usage in a terminal; who it is for: one developer, a small team, a company; and the install command, npm i -g skillwharf

At a glance

Requires
Node 22.12 or later
Tested on
macOS and Linux, with Node 22 and 24
Licence
MIT, free to use
Works with
Claude Code, Codex and Cursor
Network
Fetches skills from GitHub when you add, sync or update them, and a registry’s index when you search
Telemetry
None, and no account

skillwharf is a command-line tool for agent skills: folders with a SKILL.md that teach a coding agent a task, such as filling in PDFs, building an MCP server, or your team’s release checklist. They are easy to write and easy to lose track of. The same skill ends up copied into every agent’s folder and onto every teammate’s machine, and the copies drift. Nothing pins them, so a fresh clone of your project can get a different skill from the one you tested with, or none at all. And nobody knows which ones are actually used.

skillwharf treats skills the way a package manager treats dependencies. skillwharf.json says which skills a project wants, and skillwharf.lock.json pins each one to a full commit sha and a content hash. One copy lives in .skillwharf/skills, and each agent’s folder gets a link to it: by default .claude/skills for Claude Code and .agents/skills, which Codex and Cursor read.

What it does

  • add installs a skill from GitHub or a local path and pins it.
  • sync, run after a git clone, gives a teammate exactly the same skills. It refuses a lockfile it cannot verify.
  • doctor reports broken links, drift from the lockfile, folders skillwharf did not create, and skills nobody has used lately.
  • usage reads Claude Code’s local session logs to show which skills actually fire.
  • update re-fetches from source, refreshes the lockfile and reports what changed.

Who it’s for

One developer: skillwharf -g keeps your personal skills in ~/.skillwharf and links them into the agents’ global folders, so every project on your machine sees the same versions. A small team: commit the two files next to your code, and everyone who clones the repository runs skillwharf sync. A company with several teams: keep shared skills in repositories of your own, private ones too as long as each person’s git can already clone them, and let each team pin the versions it uses.

What goes over the network

There is no telemetry and no account. GitHub sources are fetched with git clone --depth 1. search reads a registry’s index.json; the default one is mujieha/skillwharf-registry, a starter list that is schema-checked, not reviewed. usage reads Claude Code’s logs on your machine, and nothing from them leaves it.

What it does not do

It does not review a skill’s content. Coding agents read skills as instructions, so installing one is like installing a dependency: read a SKILL.md before installing it, as you would a shell script. A compromised upstream at the ref you asked for is faithfully installed, so read what skillwharf update reports before trusting the result.

Usage tracking covers Claude Code only; Codex and Cursor do not write comparable local logs. On Windows without Developer Mode, symlinks fall back to copies, and doctor flags them.

How it keeps what lands there exact

skillwharf checks every path component before using it, including values read back from the manifest and lockfile, and never writes through a symlink inside the project. It drops symlinks from fetched skills, never replaces files it did not create unless you pass --force, and treats registries as untrusted data: plain http:// registries are refused and redirects are not followed. The security policy has the full threat model.

Install

npm i -g skillwharf
skillwharf init
skillwharf add github:anthropics/skills/skills/mcp-builder

It needs Node 22.12 or newer. After a fresh git clone of a project that uses it, run skillwharf sync.

Source code: github.com/mujieha/skillwharf