Publish
Create a skill directly or import it from a Git repository.
- SKILL.md
- checklist.md
- rules/owasp.md
Skills for agents, managed like packages
Create, version, secure, and distribute reusable skills across your entire engineering team. One source of truth for Claude Code, Codex, Cursor, Gemini CLI — 70+ coding agents in total.
No credit card required · Set up in minutes · Keep your skills private
Your team already shares code through Git and packages through registries.
MasterSkills lets you manage agent skills the same way.
$ ✔ resolved @acme-corp/[email protected]✔ access verified · security, platform✔ installed → Claude CodeOne registry. Every team. Every coding agent.
The distribution problem
As teams create more agent skills, distribution becomes the real problem. MasterSkills gives every skill an owner, version, access policy, and reliable installation path.
~/.claude/skillsinfra-tools/promptssecure-code-reviewv2.4.1release-workflowv1.9.0company-architecturev3.1.2How it works
Create a skill directly or import it from a Git repository.
Assign access to organisations, workspaces, teams, projects, or individual users.
Let developers install the approved skill with one command.
$ masterskills add@acme-corp/secure-code-reviewNow available in
Agent-operated
MasterSkills ships as a skill your agent reads once. After that you ask in plain language — it packages the files, picks the version, applies your access rules, and publishes. Installing on the next machine works the same way.
“Publish the skills we just wrote.” That is the entire interface.
skill.md carries every command, flag, and guard rail — so the agent never guesses.
Access, approvals, and version pinning stay with people, in the registry.
Read https://masterskills.dev/masterskills/docs/skill.md and follow the instructions to use MasterSkillsWe just wrote a review checklist. Publish it to MasterSkills for the security team.
Reading skill.md from masterskills.dev…
SKILL.md, checklist.md, rules/owasp.mdv1.0.0acme-corp/secure-code-reviewPublished. Anyone with access can pull it now — I will keep it in sync from here.
Set it up on the new laptop too.
Running masterskills add @acme-corp/secure-code-review — done, v1.0.0 active.
Capabilities
Everything you already expect from a package registry — applied to the skills your agents run on.
Your internal workflows, architecture rules, and company knowledge remain inside your organisation.
Publish releases, review changes, pin versions, and roll back when needed.
Give each team access only to the skills relevant to their work.
Import and synchronise skills from GitHub, GitLab, or any Git repository.
Distribute the same organisational knowledge everywhere your team codes — Claude Code, Codex, Cursor, Gemini CLI, Copilot, Windsurf, and the rest of the ecosystem.
Search, install, update, and remove skills using a lightweight CLI.
Developers can browse approved skills instead of asking where the latest prompt or workflow lives.
Understand which skills are installed, maintained, outdated, or no longer used.
| Skill | Version spread | State |
|---|---|---|
secure-code-review | current | maintained |
release-workflow | mixed | update available |
legacy-prompt-pack | stale | unused |
The registry
Search, filter, and inspect any skill — this is a working slice of the product. Try it.
No skills match that search. Try review, migration, or infra.
acme-corp/secure-code-review
Security · updated 2 days ago
Reviews diffs against the internal security checklist, flags secret handling, authz gaps, and unsafe deserialisation before review is requested.
$ masterskills add @acme-corp/secure-code-reviewVersion history
Changelog — v2.4.1
· Added SSRF and SSTI checks to the network rules · Split rules/owasp.md into per-category files · Fixed false positives on generated migration files
Documentation preview
gh pr create. Reads the diff, applies rules/*.md, and returns findings grouped by severity with file:line anchors.Distribution layer
Your company knowledge should not be locked to a single AI tool. MasterSkills gives teams a consistent distribution layer while allowing each developer to use the agent they prefer.
@acme-corp/secure-code-reviewv2.4.1adapters per agent formatMasterSkills is the management and distribution layer. Each agent consumes the package through its own format adapter — 70+ coding agents are supported today. Not every agent supports every capability, and the registry makes those differences explicit.
Who it is for
Distribute infrastructure standards, deployment workflows, and security policies.
Share architecture conventions, feature workflows, and code-generation standards.
Maintain separate skill collections and access policies for each client.
Turn repeatable internal workflows into governed, reusable agent capabilities.
Control
Skills encode how your company builds software. MasterSkills treats them with the same care as your private packages: scoped, versioned, and traceable.
Enterprise security and deployment options can be tailored to your organisation.
Nothing leaves your organisation boundary by default.
Owner, maintainer, and consumer roles per registry.
Scope any skill to the teams and projects that need it.
Every release retained, comparable, and restorable.
Who changed what, when, and which version they shipped.
Scoped tokens, read-only sync, revocable at any time.
EnterpriseRuns inside your own network — docker compose plus a license key.
Plans
For trying MasterSkills with a small team.
$0forever
Hosted registry, ready immediately
Start for freeFor engineering teams standardising how agents work.
$20/month
Flat for the whole organisation — not per seat
Hosted registry with team workspaces
Start team workspaceFor companies that run the registry inside their own network.
Custom
Talk to us for a quote
Hosted, if you prefer us to run it
Talk to usOne flat price per organisation — never per seat. Prices in USD; billing runs on Paddle.
FAQ
A packaged, reusable instruction set your coding agent loads to perform a specific task the way your organisation wants it done — a review checklist, a release procedure, an architecture description. It is content plus metadata: files, a version, an owner, and the agents it is compatible with.
70+ coding agents — Claude Code, Codex, Cursor, Gemini CLI, GitHub Copilot, Windsurf, Zed, and the rest of the ecosystem. The full agent registry ships with the CLI: one install links a skill into every agent detected on the machine, and tools that adopt the shared .agents/skills convention are covered automatically. Because packaging and distribution are separate from the agent format, a new agent is an adapter rather than a rewrite of your skills.
No. MasterSkills ships as a skill your agent reads once — hand it Read https://masterskills.dev/masterskills/docs/skill.md and follow the instructions to use MasterSkills and it learns every command, flag, and guard rail. After that you ask in plain language: “publish the skills we just wrote”, “install the approved review skill here”. The CLI stays available for people who want it; it is not a prerequisite for anyone.
Yes. Point MasterSkills at a GitHub, GitLab, or generic Git repository and it imports the skill and keeps it synchronised. Read-only, scoped tokens; revocable at any time.
Private by default. A skill is visible only inside your organisation, and only to the workspaces, teams, projects, or users you grant access to. There is no public listing unless you deliberately publish one.
That is the core of the access model. Grant a skill to a whole organisation, a workspace, a team, a project, or named individuals, with read or write roles — so the data team never sees the client-specific skills an agency workspace holds.
Yes. Every release is retained. Teams can pin to an exact version, follow a range, or roll back to a previous release with one command — and the registry records who changed what.
No. Git remains ideal for source control. MasterSkills adds discovery, packaging, permissions, version distribution, installation, and organisation-wide governance for agent skills.
Yes — on the Enterprise plan: the registry ships as a docker compose deployment with a license key and runs inside your own network. The license check never hard-fails — a 30-day offline grace keeps your registry working even if the license endpoint is unreachable. Enterprise is arranged directly — talk to us.
Turn scattered prompts, workflows, and internal knowledge into reusable capabilities your entire team can trust.
Start free. Invite your team when you are ready.