/agent skills.
Concepts
Default Registries
ChatCLI ships with three registries:
New default registries are automatically added after upgrades — no need to edit config manually.
skills.sh
skills.sh is the open agent skills directory, compatible with 30+ agents (Claude Code, Cursor, Codex, Gemini CLI, etc.). Skills hosted on GitHub are indexed with installation metrics and security audits. ChatCLI consumes 3 skills.sh APIs:- Search API — fuzzy search with install counts
- Download API — pre-packaged snapshots with all skill files
- Audit API — partner security assessments (ATH, Socket, Snyk)
/skill Commands
Search Skills
(214K installs)— install count (skills.sh)[installed](green) — skill installed from that registry[installed from other source](yellow) — same-name skill exists from another source[SUSPICIOUS]/[BLOCKED]— moderation flags
Install Skill
--from resolves the ambiguity:
Uninstall Skill
List Installed Skills
Skill Info
--from, prioritizes the registry with richest data (skills.sh with installs and security). With --from, queries only that registry.
Manage Registries
Source Preferences
Pin Skills for the Session (/skill pin)
When you want a skill considered on every turn of the conversation — regardless of whether the message matches its triggers: or paths: — pin it with /skill pin. The skill stays injected in the system prompt until you /skill unpin it or end the session.
Measure What a Skill Does (/skill stats)
Every agent and coder run is credited to the skills injected into it — pinned, auto-activated by trigger, or authored by the self-evolve engine — with its turns, tool calls and cost, next to a baseline of every run. /skill stats puts the two side by side, per run, so a skill can be judged by what it changes rather than by how often it fires: a negative percentage means the runs that used it were shorter or cheaper than the baseline, a learned skill that stays positive is a candidate for pruning. The ledger lives in ~/.chatcli/skills/.skill-stats.json and is provider-neutral: turns and tool calls come from the run registry, cost from the tracker, both of which every provider feeds. Each row also says whether the skill was used, not only activated: for a skill that declares allowed-tools, a run counts as used when one of those tools executed after the injection (tools used in 3 of 4 runs); a skill that declares no tools reads tool use not declared, because guessing would be worse than not knowing.
- Injects the skill into a dedicated
# Pinned Skillsblock in the system prompt, before the# Auto-loaded Skillsblock. Onmodel:/effort:hint conflicts, pinned beats auto-activation (but loses to a manual/<skill-name>invocation). - The pinned block carries
cache_control: ephemeral— the provider keeps the cache warm across turns as long as the pinned set doesn’t change. - Auto-activation still runs: if a skill is pinned and matches by
triggers:/paths:, it’s injected exactly once (deduplicated by name). - Skills uninstalled/renamed during the session silently drop from the set on the next turn (re-resolved through the persona manager).
/skill listshows[pinned]next to pinned skills.
- Skills with
disable-model-invocation: truecannot be pinned — the flag exists precisely to forbid automatic injection. Use manual/<skill-name>for those. - The pinned set is session-scoped; it does not persist across chatcli runs (by design — pinning expresses current-session intent).
How to Activate a Skill: Three Modes
model:/effort: hint precedence when multiple modes fire on the same turn:
Skill Injection Budget
Injected skill bodies respect a per-block character budget:CHATCLI_SKILL_INJECT_BUDGET (default 24000, 0 = unlimited/legacy). On top of it, a per-run budget of 2× that value caps the cumulative skill bytes an agent/coder run may inject (startup + mid-loop); once spent, later activations still announce themselves but their bodies degrade the same way. Skills are rendered in their stable order; every entry now carries a Source: <path> line, and once a budget is spent, later skills keep their header and description but the body degrades to a read-on-demand pointer at the skill’s source file:
Skill lifecycle: aging, cooldown and drip (agent/coder)
Mid-loop skill injections no longer ride the window for the whole run. Three mechanisms bound their footprint:- Aging: a mid-loop skill block older than
CHATCLI_SKILL_AGE_TURNSturns (default6) collapses to a one-line stub — the full guidance is archived and recoverable via@recall, and the stub names the skills plus theirSource:paths so nothing is unreachable. - Cooldown + re-trigger: a collapsed skill leaves the run’s dedup set. If its trigger fires again after the cooldown (same number of turns), the skill re-injects fresh — aging is eviction, not amnesia.
- Drip cap: at most 3 new skills per mid-loop injection; a burst of matches drips across turn boundaries instead of landing as one giant block (the capped-out skills re-candidate on the next boundary, none are dropped).
Why this exists: a single prompt can auto-activate a burst of skills (e.g. nine ServiceNow skills matching one question), adding tens of KB to every subsequent request. Behind a corporate proxy/WAF with a body-size cap, that alone can push the session over the rejection threshold — see Context Recovery. The default is generous: typical sessions inline every activated skill untouched.
/config agent (token efficiency section) — CHATCLI_SKILL_INJECT_BUDGET and CHATCLI_SKILL_AGE_TURNS.
Help
Namespace and Collisions
How Skills Are Stored on Disk
Registry skills use qualified names to avoid collisions:-- separator is safe because the agentskills.io spec forbids consecutive hyphens in skill names.
Users Never Need to Type Qualified Names
Daily usage is transparent:Configuration
Registries File
~/.chatcli/registries.yaml controls the registries:
Preferences File
~/.chatcli/skill-preferences.yaml stores source preferences:
/skill prefer — no manual editing needed.
Environment Variables
Security and Moderation
Moderation Flags
Security Audits (skills.sh)
For skills.sh skills,/skill info shows security assessments from three partner providers:
Data is fetched from
https://add-skill.vercel.sh/audit with a 3-second timeout — failures are silent (advisory data, never blocks).
Atomic Installation
Skills are installed using atomic writes:- Content downloaded to temporary directory (
.tmp-*) - YAML frontmatter validated
- Moderation flags checked
- Scripts receive executable permission
sourceandsnapshot_hashfields injected into frontmatter- Directory atomically renamed to final destination
- On failure, temporary directory is automatically removed
Search Cache (Trigram)
ChatCLI implements a trigram-based fuzzy cache to reduce network calls:
The cache is automatically invalidated after installing or uninstalling a skill, and recreated when enabling/disabling a registry.
Architecture
Packages
Next Steps
- Customizable Agents — How to create and use agents with skills
- Command Reference — Complete list of all commands
- Configuration (.env) — Available environment variables