No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by hashgraph-online · Codex Skill · ★ 165
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is skill-publish safe to install? View the security audit →
skill-publish Instead of sharing mutable URLs or copy/paste blobs, each release is recorded on Hedera (HCS) and exposed via references. That immutability is the value: the published artifact is tamper-evident, reproducible, and audit-friendly. Immutability gives you: Version pinning: consumers can depend on an exact . Reproducible retrieval: the same canonical references resolve later (not “whatever is at this URL today”). Audit trail: topic IDs, job IDs, and optional repo+commit stamping connect releases back to source. A skill package starts with . is optional metadata; when it is absent, synthesizes it during validate, quote, and publish flows. By default, excludes hidden files and directories, env files, lockfiles, build output, local databases, and key/certificate material
| Stars | 165 |
| Forks | 2 |
| Language | JavaScript |
| Category | Codex Skill |
| Quality Score | 70.5531107212759/100 |
| Open Issues | 1 |
| Last Updated | 2026-04-13 |
| Created | 2026-02-16 |
| Platforms | claude-code, cli, codex, node |
| Est. Tokens | ~28k |
These tools work well together with skill-publish for enhanced workflows:
Looking for a skill-publish alternative? If you're comparing skill-publish with other codex skill tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.
The missing linter and lsp for AI coding assistants. Validate CLAUDE.md, AGENTS.md, SKILL.md, hooks, MCP. Plug
Bring Agent Skills to Any AI Agent and Coding Agent — via CLI or MCP. Manage once, serve anywhere.
Claude Code skills for journalism, media, and academia - verification, FOIA, data journalism, academic writing
Connect RStudio to Claude Code, Codex, Gemini, and other LLM agents via MCP. Multi-agent orchestration, automa
A coding agent whose claims about its own work resolve to machine-captured evidence: an append-only hash-chain
Vendor-neutral MCP configuration manager — one CLI to add, toggle, and audit MCP servers and skills across eve
Explore other popular codex skill tools:
skill-publish is GitHub Action and CLI to validate, monitor, and publish verifiable skills (SKILL.md) via Registry Broker. It is categorized as a Codex Skill with 165 GitHub stars.
skill-publish is primarily written in JavaScript. It covers topics such as claude, cli, codex.
You can find installation instructions and usage details in the skill-publish GitHub repository at github.com/hashgraph-online/skill-publish. The project has 165 stars and 2 forks, indicating an active community.
The top alternatives to skill-publish on Agent Skills Hub include agnix, skillport, claude-skills-journalism. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: