Detect your stack. Recommend the right skills. Author portable skills. Verify what you install. Materialize once for the agents you actually use.
Quick start · Author skills · Security · Supported agents · Architecture · Contributing
AunoSkills is a CLI-first package manager, authoring toolkit, and trust layer for SKILL.md-based AI coding skills.
It can inspect a project and recommend skills, resolve and materialize them reproducibly, verify registry provenance and artifact integrity, and now take a skill author through a deterministic init → validate → inspect → pack → verify → publish workflow.
npx aunoskillsAunoSkills is designed around three principles:
| Principle | What it means |
|---|---|
| Intelligence | Recommendations come from project evidence and remain explainable. |
| Trust | Relevance, author claims, provenance, integrity, signer state, and policy are evaluated separately. |
| Control | No silent execution, no silent trust elevation, and project mutations are transactional. |
Current release:
v0.4.0— skill authoring, deterministic.aunoskillartifacts, independent verification, publication submissions, and the existing secure registry/release trust pipeline.
npx aunoskillsWith no subcommand, AunoSkills behaves like init:
scan project
↓
build evidence graph
↓
recommend relevant skills
↓
resolve versions + trust policy
↓
verify registry / bundle integrity
↓
write manifest + lockfile
↓
materialize skills for selected agents
Inspect before changing anything:
npx aunoskills detect
npx aunoskills recommend
npx aunoskills explain typescript-qualityInstall reproducibly:
npx aunoskills install
npx aunoskills install --frozen-lockfile
npx aunoskills restore --offline--yes can skip ordinary confirmation. It does not bypass trust, signature, integrity, path-safety, or capability policy.
Reusable AI-agent instructions are becoming common, but discovery, authoring, trust, versioning, portability, updates, rollback, and CI reproducibility are still fragmented.
AunoSkills puts those concerns behind deterministic contracts.
| Problem | AunoSkills |
|---|---|
| “Which skills does this repo actually need?” | Evidence-based scanner + recommendation engine |
| “Why was this skill recommended?” | Explainable evidence and confidence model |
| “How do I create a portable skill correctly?” | skill init, source validation, inspection, capability inference |
| “Can I package the same bytes on every OS?” | Canonical .aunoskill container + cross-platform golden digest |
| “Is this artifact structurally valid?” | Independent artifact verification |
| “Can I trust this package?” | Trust tiers, hashes, Ed25519 signatures, provenance, signer state |
| “Will this work across my agents?” | Adapter-based materialization for six coding agents |
| “Can CI reproduce my local setup?” | Human manifest + deterministic lockfile + frozen installs |
| “What if an update goes wrong?” | Transactional writes, crash recovery, doctor, rollback |
| “Can a downloaded skill execute code silently?” | Capability-aware policy; authoring checks never execute skill code |
| “Can I use private registries?” | Custom registry support with explicit trust anchors and env-based auth |
AunoSkills v0.4 adds a first-class author workflow without creating a hosted marketplace or weakening the registry trust boundary.
skill source
↓
init
↓
validate
↓
inspect
↓
pack
↓
verify
↓
publish submission / workspace
↓
registry review + signing
npx aunoskills skill init acme/security-reviewThe default source remains standard-first:
security-review/
├── SKILL.md
└── auno.json
SKILL.md is the agent-facing source of truth. auno.json carries package-manager metadata such as package identity, version, publisher, compatibility, capabilities, and skill dependencies.
For v0.4, auno.json.id is the package ID and the runtime name is derived from its final path segment:
acme/security-review
└──────┬──────┘
runtimeName
npx aunoskills skill validate ./security-review
npx aunoskills skill inspect ./security-review
npx aunoskills skill inspect ./security-review --jsonValidation covers metadata, portable identity, semver, source paths, secret-like files, symlinks, dependencies, compatibility, capability declarations, and security findings.
Capability inference is intentionally explainable and conservative. It can flag evidence such as network URLs, shell/process instructions, environment-variable reads, Git mutation, filesystem writes, and possible secret access. Inference is a review signal — never permission to execute.
npx aunoskills skill pack ./security-review --output ./dist/security-review.aunoskill.aunoskill v1 is a canonical JSON distribution container with exact file bytes encoded as base64.
Its artifact identity excludes volatile host metadata:
normalized POSIX paths
+ lexical file ordering
+ exact file bytes
+ per-file SHA-256
+ canonical metadata
- timestamps
- uid / gid
- host absolute paths
- platform path separators
= deterministic artifact SHA-256
The repository locks one normalized fixture to the same golden artifact digest across Ubuntu, macOS, and Windows.
npx aunoskills skill verify ./dist/security-review.aunoskill
npx aunoskills skill verify ./dist/security-review.aunoskill --jsonVerification treats the artifact as untrusted input and independently checks container schema, paths, duplicate/case-colliding entries, canonical base64, file sizes/hashes, manifest correspondence, embedded auno.json, SKILL.md, dependencies, and capabilities.
Important:
artifactValid: truedoes not mean registryverified. Artifact validity and registry trust are separate security properties.
Create a deterministic registry submission:
npx aunoskills skill publish ./security-review --output submission.jsonOr publish into an explicitly writable local registry workspace:
npx aunoskills skill publish ./security-review \
--registry-workspace ../registry-workspacePublication is immutable by version: identical existing bytes are idempotent; different bytes at the same package/version are rejected.
Authoring does not mint official registry signatures, store private signing keys, or assign verified trust. The registry still performs independent review, validation, signing, and publication.
See packages/authoring/README.md for the package boundary and artifact format.
AunoSkills separates project intelligence from package resolution and filesystem mutation.
Project Scanner
│
▼
Evidence Graph
│
▼
Recommendation Engine
│
▼
Policy-aware Resolver
│
▼
Registry / Trust / Integrity
│
▼
Content-addressed Store
│
▼
Agent Adapter Planner
│
▼
Transactional Materialization
A normal project uses two committed contracts:
aunoskills.json # human-authored project intent
skills-lock.json # exact resolved, reproducible state
Machine-local state remains separate:
.aunoskills/state/ # transactions / ownership / diagnostics
~/.aunoskills/cache/ # content-addressed bundles
~/.aunoskills/registries/<name>/ # verified registry metadata cache
AunoSkills v0.4 targets six coding-agent ecosystems.
| Agent | Portable project target | Native specialization when needed |
|---|---|---|
| OpenAI Codex | .agents/skills/ |
.agents/skills/ |
| Claude Code | .claude/skills/ |
.claude/skills/ |
| Cursor | .agents/skills/ |
.cursor/skills/ |
| Windsurf | .agents/skills/ |
.windsurf/skills/ |
| GitHub Copilot | .agents/skills/ |
.github/skills/ |
| OpenCode | .agents/skills/ |
.opencode/skills/ |
Portable skills are shared where agent conventions overlap. Native fan-out is used only when an extension actually requires it.
AunoSkills separates relevance, author claims, artifact validity, registry trust, authenticity, integrity, and requested capability.
Authoring operations never execute skill code. Publishable inventories reject symlinks and block common credential-like files such as .env, private-key files, SSH keys, credential JSON, and service-account files.
.aunoignore can exclude additional content, but cannot re-include security-blocked paths.
| Trust tier | Meaning |
|---|---|
verified |
Registry-v2 verification succeeds against an explicit/pinned trusted anchor. |
community |
Known source/integrity metadata without verified-registry endorsement. |
untrusted |
Local, arbitrary, author-produced, or otherwise unverified source. |
A skill cannot become verified by putting that word in auno.json, a .aunoskill artifact, or a publication submission.
configured / pinned trust anchor
↓
signed trust.json
↓
signed index.json
↓
manifest SHA-256 + Ed25519 signature
↓
bundle SHA-256
A registry cannot bootstrap its own trust with an unknown self-signed key. Rotations and revocations require authorization from an already trusted active key.
npx aunoskills doctor --check
npx aunoskills audit --registry
npx aunoskills audit --fail-on highA revoked signer is a CRITICAL finding.
For the complete security model and disclosure guidance, see SECURITY.md.
Long-lived root authority is separated from routine release signing:
offline root private key
↓ signs trust.json
pinned root public key
↓ delegates
release public key(s)
↓ sign index + manifests
registry v2
Release tooling is explicitly staged:
npm run registry:unsigned
npm run registry:sign
npm run registry:verify
npm packThe protected GitHub release workflow uses a release environment and verifies public output before packaging.
Official registry status: the bundled
aunostarter registry remainslegacy-awaiting-production-trustuntil authentic production public root/trust material is externally provisioned. No fixture private key or fake production root is committed.
npx aunoskills registry add company https://registry.example.com
npx aunoskills registry add company https://registry.example.com \
--auth-env AUNOSKILLS_COMPANY_TOKEN
npx aunoskills registry trust company root-2026 BASE64_SPKI_PUBLIC_KEY
npx aunoskills registry refresh companyOnly the credential environment-variable name is stored; token values are read at request time and are not persisted in project/lock/user registry config.
npx aunoskills detect
npx aunoskills recommend
npx aunoskills explain <skill>
npx aunoskills add <skill>
npx aunoskills install
npx aunoskills update
npx aunoskills restore
npx aunoskills rollbacknpx aunoskills skill init <publisher>/<skill>
npx aunoskills skill validate <dir>
npx aunoskills skill inspect <dir>
npx aunoskills skill pack <dir>
npx aunoskills skill verify <artifact>
npx aunoskills skill publish <dir>npx aunoskills list
npx aunoskills outdated
npx aunoskills doctor
npx aunoskills audit
npx aunoskills registry list
npx aunoskills cache status
npx aunoskills config listMachine-readable JSON output is available across the command surface through the existing versioned envelope.
The AunoSkills repository itself dogfoods its manifest/lockfile and verifies the full project on:
| Operating system | Node 22 | Node 24 |
|---|---|---|
| Ubuntu | ✅ | ✅ |
| macOS | ✅ | ✅ |
| Windows | ✅ | ✅ |
Release gates include:
format
→ typecheck
→ compiled build
→ unit/contract tests
→ authoring tests
→ security fixtures
→ E2E lifecycle
→ cross-platform authoring determinism
→ deterministic registry rebuild
→ registry diff gate
AunoSkills keeps authoring, installation, trust, and agent rendering behind focused boundaries.
┌──────────────────────┐
│ apps/cli │
└──────────┬───────────┘
│
┌──────────────────┴──────────────────┐
│ │
▼ ▼
packages/authoring packages/core
init/validate/inspect detect/recommend/resolve
pack/verify/publish transact/materialize
│ │
└──────────────┬──────────────────────┘
▼
schema / security / registry
store / adapters / shared
Boundary rules:
- CLI parses arguments and renders structured results; authoring business logic lives in
packages/authoring. - Scanner knows projects, not skill packages.
- Recommender consumes evidence, not the filesystem directly.
- Resolver behavior is deterministic.
- Registry trust/signing remains outside authoring.
- CAS objects are immutable.
- Adapters plan materialization; Core owns filesystem mutation.
- Failed verification never mutates the project.
Design documents:
Requirements:
- Node.js
>=22 - npm
10.xor compatible behavior - Windows, macOS, or Linux
npm install --ignore-scripts
npm run verifyIndividual gates:
npm run format:check
npm run typecheck
npm run build
npm test
npm run test:security
npm run test:e2e
npm run benchmarkRebuild the compatibility registry deterministically:
npm run registry:buildContributions are welcome across authoring, the CLI, project detection, recommendation, agent adapters, security tooling, registry infrastructure, tests, documentation, and starter skills.
Before opening a pull request:
npm install --ignore-scripts
npm run verify
npm run registry:build
git diff --exit-code -- registry/index.json registry/blobsRead CONTRIBUTING.md for repository workflow. Report sensitive security issues through the process in SECURITY.md.
- Explainable project detection and skill recommendations
- Deterministic version resolution and lockfiles
- Six-agent materialization
- Transactional install/update/remove/restore/rollback
- Content-addressed caching, doctor, and audit
- Ed25519 verified-registry v2 support with rotation/revocation primitives
- Root/release secure publishing infrastructure
- Portable skill initialization, validation, and inspection
- Deterministic
.aunoskillpacking and independent artifact verification - Immutable publication submissions/local registry workspaces
- Cross-platform CI and golden authoring artifact determinism
- AunoSkills Cloud
- Hosted marketplace or private-registry service
- Publisher/team dashboard
- SSO / enterprise RBAC / billing
- Transparency log
- Private signing-key manager
- Kernel-level sandboxing
- Fake or fixture production official-registry trust material
See CHANGELOG.md for release history.
AunoSkills CLI/core, authoring toolkit, schemas, adapters, registry tooling, and bundled original starter skills are licensed under Apache-2.0.
AunoSkills is a clean-room implementation. The source code, schemas, registry/artifact formats, security model, CLI architecture, starter skills, documentation, and branding are written independently; third-party non-compatible source/assets are not incorporated into the repository.
AunoSkills · Intelligence · Trust · Control
Security · Authoring · Contributing · Changelog · License