Skip to content
Skillcrew

Your team's AI skills.Every agent.Always in sync.

One Git repository for your whole team. Skills stay up to date in every agent, with no action from developers.

brew install yoanbernabeu/tap/skillcrew
Read the docs →
acme/skills · main · just now
skillsecurity:review · v2
  • Claude Codesynced
  • Codexsynced
  • Cursorsynced
  • Copilotsynced
  • Gemini CLIsynced
One skill from the acme/skills registry, synced to five agents.

01 / The problem

Agent Skills work everywhere. Keeping a team's copies straight does not.

  1. 01

    Skills copied by hand drift.

    Versions diverge, and a fix never reaches everyone.

  2. 02

    Every agent reads its own folder.

    A team on five agents maintains five copies, or none.

  3. 03

    Nobody knows who has what.

    No way to require the security review skill, or to pull a bad one.

02 / How it works

One repository in, every agent out.

  1. Administrator

    Step 1: Create the registry

    One Git repository with the Claude Code marketplace layout and a skillcrew.yaml. Push it to your Git host.

    terminal
    $ skillcrew registry init --org acme
    Created a new Skillcrew registry.
      + .claude-plugin/marketplace.json
      + .github/workflows/validate.yml
      + plugins/example/skills/hello-world/SKILL.md
      + skillcrew.yaml
  2. Developer, once

    Step 2: Join with one command

    Clones the registry, adds a session-start hook to each agent it finds and an hourly timer, then syncs.

    terminal
    $ skillcrew init github.com/acme/skills --team backend
    Joined organization acme (registry https://github.com/acme/skills.git, branch main).
      ✓ claude-code: session-start hook installed
      ✓ codex: session-start hook installed
      ✓ fallback timer installed (every 1h0m0s)
    Synced registry 7f396e1a9c2d:
      + review (installed)
  3. Everyone, from then on

    Step 3: Merge a pull request. Every machine gets it.

    The next agent session, or the timer within the hour, runs the sync. Nobody types anything.

    terminal
    $ skillcrew sync      # hooks and the timer run it
    Synced registry 9b1c4e2a7d30:
      ~ review (updated)
      + conventional-commits (installed)
      - risky (removed: blocked by your organization)
How Skillcrew syncs skillsThe registry is fetched by skillcrew sync, which runs on every agent session start (hooks) and every hour (timer). Sync writes real copies to ~/.agents/skills and symlinks to them in ~/.claude/skills.REGISTRYacme/skills · skillcrew.yamlsession-start hooksevery agent sessionhourly timerlaunchd · systemdskillcrew sync~/.agents/skillsreal copiesCodex · Copilot · Cursor · Gemini~/.claude/skillssymlinks to the copiesClaude Codegit fetch

Syncs are debounced and atomic. Offline, agents keep the last fetched skills. How syncs work

03 / Governance

Five statuses, per organization and per team.

A team can harden a status, never soften the organization's. Developers turn off what is only recommended; nobody installs what is blocked.

required
Installed automatically, kept up to date, restored if removed or edited. Cannot be disabled.
recommended
Installed by default. Developers can turn it off with skillcrew disable.
available
In the catalog. Developers add it with skillcrew install.
deprecated
Stays where installed, never reaches new machines, shows its replacement.
blocked
The kill switch: removed from every machine at the next sync.

Statuses · Resolution rules

skillcrew.yaml, at the root of the registry

yaml
org: acme
default: available            # skills not listed below

skills:
  security:review: required
  git:commit-msgs: recommended
  quality:old-linter:
    status: deprecated
    replaced_by: quality:lint-rules
  misc:risky: blocked         # kill switch

teams:
  backend:
    skills:
      data:db-migrations: required

04 / Works with your agents

One copy on disk, read by every agent.

Skills land in ~/.agents/skills, with symlinks for Claude Code. Here is what we have tested for real.

  • Claude Codeverifiedskills and session-start hook
  • OpenCodeverifiedskills, synced by the hourly timer
  • Codex CLIskills listedhook not verified yet; trust it once with /hooks
  • Gemini CLIskills listedhook not tested yet
  • GitHub Copilotnot tested yetreads ~/.agents/skills
  • Cursornot tested yetreads ~/.agents/skills

As of 2026-10-11. Any agent that reads ~/.agents/skills gets the skills; skillcrew doctor reports what it finds on each machine.

05 / Safe by design

It writes to every developer machine, so it trusts one thing only.

  • The registry is the root of trust.

    Every change is a reviewed pull request, checked by skillcrew validate in CI.

  • Pins cannot be hijacked.

    sha is a full commit id, ref is a tag; neither ever resolves to a branch.

  • Skillcrew executes nothing from the registry.

    It copies files, atomically, and keeps working offline.

  • No secrets stored.

    Git uses your existing SSH keys and credential helpers; URLs with passwords are refused.

Read the security model

06 / FAQ

Questions

More in the documentation FAQ.

What happens to my local edits to a team skill?
They are backed up in ~/.skillcrew/backups/<skill>/ (last 5 versions) and the team version is restored. skillcrew propose <skill> turns them into a pull request.
What if I already have a personal skill with the same name?
It is backed up (and never pruned) and replaced by the team skill; skillcrew uninstall puts it back. Rename yours to keep both.
Can a skill be pinned?
Yes: ref (a tag) or sha (a full commit id). Otherwise skills follow the registry branch.
What about project-specific skills?
Commit them in the project (.agents/skills/, .claude/skills/): Git already distributes them. Skillcrew manages user-level skills.
How do I uninstall?
skillcrew uninstall lists what it removes, then removes hooks, the timer, team skills and ~/.skillcrew. Personal skills that team skills replaced are restored when their name is free, and backups of your local changes are kept. Then brew uninstall skillcrew or delete the binary.

Type to search the documentation.