No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by SpaceZephyr · Codex Skill · ★ 70
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is skilldeck safe to install? View the security audit →
SkillDeck · 可视化 Skill 控制台(技控台) 把本地一堆 Skill(自动扫描 Codex 和 Claude Code 两处,可能上百个)变成一面卡片墙:搜索、按分类筛选,挑一张点「使用」,复制口令粘到 Codex 就能跑。还能把相关 Skill 打包成专家(如「内容创作专家」「配图设计专家」),让 Codex 在整段对话里按你的关键词自动挑用。支持深色 / 浅色皮肤。 「deck」一语双关:一副技能卡组 + 控制台(control deck)。 首次使用(独立 web 版,推荐先跑这个) 零依赖,只需要 Node ≥ 18。 启动 Skill 从哪来(自动扫描,不用手填路径) 启动时 SkillDeck 会自动扫描本机两个默认位置,扫到什么左侧栏就列什么: 每个来源右边的数字是扫到的 Skill 数量。目录不存在就标 未安装 并置灰,目录在但一个 都没有就显示 ,点进去是空态页,页面上直接给一个「手动选择目录」的按钮。 想加别的目录,点左下角 添加本地目录(macOS 原生选择框),选完自动加进列表并切过去。自定义目录 hover 时右边有个 可以从列表移除(只是从列表里去掉,本地文件不动)。两个内置来源不能删。 界面层级是两级: 切来源时技能和专家一起换,专家是按目录隔离的,Codex 下建的专家不会串到 Claude Code 里。顶栏右上角的刷新按钮可以重新扫描(新装了 Skill 之后点一下)。 SkillDeck 会读每个子文件夹里的 ,解析名称/描述并自动分类成卡片。 用一个 Skill 点任意卡片的「使用」→ 填写具体任务(可留空)→ 选口令类型 → 点「复制口令」→ 粘贴到 Codex 对话框发送。 路径口令(默认,推荐):。口令短,Codex 按地址自己读说明书,不依赖它有没有装这个 Skill。 完整口令:把整篇 注入口令里。换机器 / Codex 读不到那个路径时用。 本地运行:不复制,直接让 SkillDeck 后端调用本机 / 跑,结果在右侧抽屉回显。 打包成专家 切到顶栏「专家」: 让 Codex / Claude Code 自动分类:SkillDeck 不接任何大模型 API,不需要配 key。 点一下会生成一段口令(里面装着完整 Skill 清单 + 聚类要求 + 一条回传命令),复制粘到 Codex 或 Claude Code 发送,它
| Stars | 70 |
| Forks | 9 |
| Language | JavaScript |
| Category | Codex Skill |
| Quality Score | 56.396831709006/100 |
| Last Updated | 2026-07-31 |
| Created | 2026-07-23 |
| Platforms | browser, codex, node |
| Est. Tokens | ~7k |
These tools work well together with skilldeck for enhanced workflows:
Explore other popular codex skill tools:
skilldeck is SkillDeck · 可视化 Skill 控制台:把本地 Skill 变成卡片墙,一键把命令发送到 Codex 会话执行(Codex 原生 widget 插件 + 独立 web 版). It is categorized as a Codex Skill with 70 GitHub stars.
skilldeck is primarily written in JavaScript.
You can find installation instructions and usage details in the skilldeck GitHub repository at github.com/SpaceZephyr/skilldeck. The project has 70 stars and 9 forks, indicating an active community.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: