Find Skills
Discover published Agent Skills before writing one, and install them only after
their provenance survives inspection. The npx skills CLI resolves a name
against the public skills.sh registry, which is a different surface from the
local jeo-skills catalog — mixing the two is the most common routing mistake
here.
Third-party skills run with full agent permissions. Treat every search result as untrusted input until its source is verified: an install is a code-execution decision, not a bookmark.
Adapted from vercel-labs/skills commit
435076e78988e1e6ec40d00b0b1d76bdbbc5419a (2026-08-18), MIT, © 2026 Vercel,
Inc. The upstream notice ships as LICENSE.upstream.txt.
When to use this skill
- Check whether a published skill already solves the user's problem.
- Search the registry by keyword, or scope a search to a GitHub owner.
- Triage candidates on install count, source reputation, and repo stars.
- Install, update, or remove a skill from the public ecosystem.
- Decide between installing an existing skill and authoring a new one.
Do not use this skill for neighboring jobs:
- Browse, filter, or install from the local jeo-skills catalog: use
jeo-skill. - Rank and load an already-installed skill for a task: use
openspace. - Author a new skill from scratch: use
write-a-skill. - Validate a
SKILL.mdagainst the Agent Skills spec: useskill-standardization. - Improve a weak skill against a benchmark: use
skill-autoresearchorupskill.
Instructions
Step 0: Confirm the user means the public ecosystem
find-skills searches skills.sh. jeo-skill searches this repository. If the
user says "our catalog", "the jeo skills", or names a skill already in
.agent-skills/, hand off rather than searching the public registry.
Step 1: Turn the request into a search
Identify the domain, the specific task, and whether it is common enough that a published skill plausibly exists. Then check the skills.sh leaderboard before running a CLI search — it ranks by total installs and usually surfaces the battle-tested option first.
npx skills find <query>
npx skills find <query> --owner <owner>
Use specific keywords (react testing beats testing) and try synonyms
(deploy → deployment → ci-cd) before concluding nothing exists.
Step 2: Triage before recommending — never recommend from search rank alone
| Signal | Green | Yellow | Red |
|---|---|---|---|
| Install count | 1K+ | 100–1K | <100 |
| Source | vercel-labs, anthropics, other official | known community author | unknown author |
| Repo stars | 100+ | 20–100 | <20 |
| Recency | pushed recently | stale months | abandoned |
A skill is executable instruction text that your agent will follow. Before
recommending, open its SKILL.md and check that the described behavior matches
its name, that it does not request credentials without cause, and that any
bundled script is inspectable. Report a mismatch instead of installing.
Step 3: Present options, do not auto-install
Give the user: what the skill does, install count and source, the exact install command, and the skills.sh link. Then stop and let them choose.
Step 4: Install only on explicit confirmation
npx skills add <owner/repo@skill> # project-level
npx skills add <owner/repo> --skill <name> # explicit skill selection
npx skills add <owner/repo@skill> -g -y # global, no prompts
Flag semantics that change blast radius:
-g/--globalwrites to the user-level skill directory, affecting every project. Confirm separately from the install itself.-y/--yesskips confirmation prompts, including the CLI's own security summary. Do not pass it on a first install from an unfamiliar source.--agent <runtime>targets one runtime instead of every detected one.--copyvendors files instead of linking — the copy will not track upstream.
The CLI prints a security assessment before installing. Read it; do not suppress
it with -y and then report the install as verified.
Step 5: Resolve names by frontmatter, not folder
The registry resolves --skill <name> against the name: in a skill's YAML
frontmatter, which need not match its directory. A name absent from the
repository tree can still install correctly. Verify against the installed file
rather than concluding the command is wrong.
Step 6: Maintain and remove
npx skills update # update installed skills
npx skills init <name> # scaffold your own
Removal is a filesystem operation on the target skill directory. Know whether
the install was project-level, global, or --copy before deleting.
Step 7: When nothing fits
Say so plainly, offer to do the task directly, and only then suggest authoring.
Route authoring to write-a-skill; do not improvise a SKILL.md here.
Examples
Example 1: Ambiguous catalog
Request: "Find me a skill for React performance."
Ask nothing if context is clear, but pick the right surface: if the user is
working inside jeo-skills, react-best-practices already exists locally — route
to jeo-skill. Otherwise search skills.sh.
Example 2: Low-reputation result
A search returns a skill with 40 installs from an unknown author. Report the counts, state that it falls below the recommendation threshold, and offer either a higher-install alternative or doing the work directly. Do not install it because it was the top hit.
Example 3: Global install request
Request: "Just install it everywhere, skip the prompts."
Confirm once, explicitly, that -g -y writes user-level and bypasses the
security summary — then run it. Do not treat an earlier "install it" as consent
for both flags.
Best practices
- Separate the two catalogs — skills.sh is public; jeo-skills is local.
- Leaderboard before CLI search — it answers most queries in one step.
- Never recommend on rank alone — installs, source, and stars first.
- Read the skill before running it — it executes with full permissions.
- Treat
-gand-yas separate approvals — scope and prompt-bypass are different risks. - Verify by frontmatter name — a missing folder is not a missing skill.
- Prefer an existing skill over a new one — author only after searching.