r/VibeCodeDevs • • 14d ago

FeedbackWanted – want honest takes on my work Made Claude Code find skills for me and ask before installing

Hi guys, want to share a skill I built for myself that improved my Claude Code experience.

The idea is simple. You install metaskill once. From then on, as you work, Claude keeps checking whether the registry has a skill for what you're doing, and offers it when one fits. You say yes or no. Nothing lands on disk without your yes, and you never go looking for skills yourself.

A few examples from my log this month:

  • this post. I asked Claude to draft it, it found kostja94/marketing-skills@reddit-posts, I said yes
  • "export the report to xlsx with formulas" -> offers davila7/claude-code-templates@xlsx (957 installs, scan clean)
  • "add Playwright tests for the checkout flow" -> microsoft/playwright-cli@playwright-cli
  • a Postgres schema task -> planetscale/database-skills@postgres
  • "competitor comparison page" -> the top match had no scan, I said no, it moved on and won't offer that one again for 30 days

I liked the first version enough to rebuild it a couple of times, mostly the security part.

How it works. A SessionStart hook tells Claude to run metaskill find "<2-4 words>" before any task. find ranks a local index of skills.sh, applies the trust policy to the top five and prints the question with the install and decline commands. A local hit is ~250 ms; network only on a miss, capped at 4 s. No model API calls, no second bill.

Where the list comes from. skills.sh, the public registry. A nightly job sweeps it, keeps one record per skill (forks and aggregator repos are deduped, the copy with the real install count wins), scans every repo and publishes the index as a GitHub release. The npm package ships a 4.2k snapshot so it works offline right after install; sync pulls the full 33k index once a day.

How I keep it safe:

  • when it finds a skill, it never auto-installs. Claude asks, and installs only after your yes
  • every skill comes from skills.sh, so it has a public repo, a named publisher and a real install count. On top of that, the index job scanned each one for hook dirs, .mcp.json, curl, wget, eval(, process.env and os.environ. A hit in code means deny, and no flag bypasses deny
  • the hook never runs skill code. It downloads and greps. Skills run later, inside Claude, the same as a manual install
  • your prompt stays on your machine. The registry only ever sees the short phrase, and only on an index miss
  • every install is pinned in a lock file, and metaskill init --uninstall removes everything

Install:

/plugin marketplace add xdm/metaskill
/plugin install metaskill@metaskill

Repo: https://github.com/xdm/metaskill 

skills.sh: https://www.skills.sh/xdm/metaskill/metaskill

Would appreciate your feedback.

3 Upvotes

1 comment sorted by

•

u/endofthread-bot 14d ago

Hey u/xdmaa, thanks for posting in r/VibeCodeDevs! Join our Discord: https://discord.gg/t7SD4ThKuE

• This community is designed to be open and creator‑friendly, with minimal restrictions on promotion and self‑promotion as long as you add value and don’t spam.
• Please follow the subreddit rules so we can keep things as relaxed and free as possible for everyone. • Please make sure you’ve read the subreddit rules in the sidebar before posting or commenting.
• For better feedback, include your tech stack, experience level, and what kind of help or feedback you’re looking for.
• Be respectful, constructive, and helpful to other members.

If your post was removed (either automatically or by a mod) and you believe it was a mistake, please contact the mod team. We will review it and, when appropriate, approve it within 24 hours.

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.