From legal-skills
Manages Claude Code Skills and Commands: installs via symlinks from local paths or git clones from GitHub repos/subdirs, tracks versions/sources/install times in JSON, lists/removes/updates/checks for updates.
npx claudepluginhub cat-xierluo/legal-skills --plugin minimax-image-understandThis skill uses the workspace's default tool permissions.
管理 Claude Code Skills 和 Commands 的安装、同步、卸载和列表查看。
Installs, updates, lists, and removes Claude Code skills from GitHub repos/subdirs or .skill zips. Supports user-global and project-local locations.
Installs Claude skills from GitHub repositories via URL parsing, skill browsing, user selection, content fetching, and automated security scanning for malicious code, backdoors, and vulnerabilities.
Create, update, and manage Claude Code skills including SKILL.md files, slash commands, directory structures, frontmatter, substitutions, and invocation controls.
Share bugs, ideas, or general feedback.
管理 Claude Code Skills 和 Commands 的安装、同步、卸载和列表查看。
.claude/skills/ 和 .claude/commands/ 目录的权限# 单个 skill 目录
skill-manager install ~/skills/pdf-tool
# 单个 command 文件
skill-manager install ~/commands/deepresearch.md
# 包含多个 skills 的目录(批量安装)
skill-manager install ~/skills/external-skills/
# 包含多个 commands 的目录(批量安装)
skill-manager install ~/commands/
skill-manager install https://github.com/owner/skill-repo
skill-manager install owner/skill-repo
# 完整 URL 到子目录
skill-manager install https://github.com/jgtolentino/insightpulse-odoo/tree/main/docs/claude-code-skills/community
# 简写格式:owner/repo/branch/path/to/skills-directory
skill-manager install jgtolentino/insightpulse-odoo/main/docs/claude-code-skills/community
git clone --depth 1 浅克隆.backup,然后安装新版本# 使用脚本安装
scripts/install.sh <source>
# 示例
scripts/install.sh ~/dev/my-skills/pdf-tool
scripts/install.sh ~/dev/my-commands/deepresearch.md
scripts/install.sh ~/dev/my-skills/
scripts/install.sh ~/dev/my-commands/
scripts/install.sh https://github.com/anthropics/claude-code
scripts/install.sh jgtolentino/insightpulse-odoo/main/docs/claude-code-skills/community
scripts/list.sh
显示 .claude/skills/ 和 .claude/commands/ 目录下所有已安装的 items 及其类型(符号链接或克隆)。
scripts/remove.sh <name>
删除指定的 skill 或 command(自动识别类型)。
scripts/update.sh [name]
scripts/check.sh
检查所有已安装 Skills 的最新版本,对比当前安装版本,显示:
每次安装和更新都会自动记录到 data/skill-registry.json。
python3 scripts/record.py list
显示所有已安装 Skills 的详细记录,包括:
一个目录被视为有效的 skill 目录,如果它包含:
SKILL.md 文件(标准 skill)skill.md 文件(变体).claude 子目录.md.md 文件# ========== 安装 ==========
# 安装本地单个 skill
skill-manager install ~/dev/my-skills/pdf-tool
# 批量安装本地目录下的所有 skills
skill-manager install ~/dev/my-skills/
skill-manager install ../other-project/.claude/skills/
# 从 GitHub 仓库根目录安装
skill-manager install https://github.com/anthropics/claude-code
skill-manager install anthropics/claude-code
# 从 GitHub 子目录安装
skill-manager install https://github.com/jgtolentino/insightpulse-odoo/tree/main/docs/claude-code-skills/community
skill-manager install jgtolentino/insightpulse-odoo/main/docs/claude-code-skills/community
# ========== 查看与管理 ==========
# 列出已安装的 skills
skill-manager list
# 卸载 skill
skill-manager remove pdf-tool
# ========== 更新与检查 ==========
# 检查所有 skills 的更新
skill-manager check
# 更新所有 git 克隆的 skills
skill-manager update
# 更新指定 skill
skill-manager update claude-code
# 查看安装记录
python3 scripts/record.py list
从 GitHub 安装 skill 时,会自动进行安全检查(本地安装不检查)。
| 类别 | 说明 |
|---|---|
| 危险代码模式 | 命令执行、敏感文件访问、数据外泄、代码混淆、权限提升等 |
| Skill 特有风险 | 安装钩子、MCP 服务器配置等 |
| 提示词安全 | 提示注入、数据收集指令、执行指令、欺骗性描述等 |
| 硬编码凭证 | API Key、Token、密码等敏感信息 |
skill-manager/
├── SKILL.md # 本文件
├── CHANGELOG.md # 变更日志
├── CLAUDE.md # AI 开发助手说明
├── LICENSE.txt # 许可证
├── scripts/
│ ├── install.sh # 安装脚本
│ ├── list.sh # 列表脚本
│ ├── remove.sh # 卸载脚本
│ ├── update.sh # 更新脚本
│ ├── check.sh # 更新检查脚本
│ ├── record.py # 记录管理模块
│ └── security.py # 安全检查模块
└── assets/ # 资源文件
├── skill-registry.json # Skill 安装记录(运行时生成)
└── skill-registry.example.json # 注册表示例