skill-publish — security grade SAFE, quality 71/100

Security audit verdict: SAFE · quality 71/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by hashgraph-online · Codex Skill · ★ 165

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is skill-publish safe to install? View the security audit →

About skill-publish

skill-publish Instead of sharing mutable URLs or copy/paste blobs, each release is recorded on Hedera (HCS) and exposed via references. That immutability is the value: the published artifact is tamper-evident, reproducible, and audit-friendly. Immutability gives you: Version pinning: consumers can depend on an exact . Reproducible retrieval: the same canonical references resolve later (not “whatever is at this URL today”). Audit trail: topic IDs, job IDs, and optional repo+commit stamping connect releases back to source. A skill package starts with . is optional metadata; when it is absent, synthesizes it during validate, quote, and publish flows. By default, excludes hidden files and directories, env files, lockfiles, build output, local databases, and key/certificate material

claudeclicodexgithub-actionprovenanceskillsverification

Quick Facts

Stars165
Forks2
LanguageJavaScript
CategoryCodex Skill
Quality Score70.5531107212759/100
Open Issues1
Last Updated2026-04-13
Created2026-02-16
Platformsclaude-code, cli, codex, node
Est. Tokens~28k

Compatible Skills

These tools work well together with skill-publish for enhanced workflows:

  • agentshield — semantic(0.25)+complementary+similar_pop+shared_platform (49%)
  • mcp-evals — semantic(0.22)+complementary+similar_pop+shared_platform (48%)
  • github-topics-trending — semantic(0.18)+complementary+similar_pop+shared_platform (46%)

skill-publish alternative? Top 6 similar tools

Looking for a skill-publish alternative? If you're comparing skill-publish with other codex skill tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • agnix by agent-sh · ⭐ 421

    The missing linter and lsp for AI coding assistants. Validate CLAUDE.md, AGENTS.md, SKILL.md, hooks, MCP. Plug

  • skillport by gotalab · ⭐ 406

    Bring Agent Skills to Any AI Agent and Coding Agent — via CLI or MCP. Manage once, serve anywhere.

  • claude-skills-journalism by jamditis · ⭐ 397

    Claude Code skills for journalism, media, and academia - verification, FOIA, data journalism, academic writing

  • ClaudeR by IMNMV · ⭐ 337

    Connect RStudio to Claude Code, Codex, Gemini, and other LLM agents via MCP. Multi-agent orchestration, automa

  • swarm-orchestrator by moonrunnerkc · ⭐ 106

    A coding agent whose claims about its own work resolve to machine-captured evidence: an append-only hash-chain

  • mcpick by spences10 · ⭐ 94

    Vendor-neutral MCP configuration manager — one CLI to add, toggle, and audit MCP servers and skills across eve

More Codex Skill Tools

Explore other popular codex skill tools:

View all Codex Skill tools →

Popular JavaScript Agent Tools

Frequently Asked Questions

What is skill-publish?

skill-publish is GitHub Action and CLI to validate, monitor, and publish verifiable skills (SKILL.md) via Registry Broker. It is categorized as a Codex Skill with 165 GitHub stars.

What programming language is skill-publish written in?

skill-publish is primarily written in JavaScript. It covers topics such as claude, cli, codex.

How do I install or use skill-publish?

You can find installation instructions and usage details in the skill-publish GitHub repository at github.com/hashgraph-online/skill-publish. The project has 165 stars and 2 forks, indicating an active community.

What are the best alternatives to skill-publish?

The top alternatives to skill-publish on Agent Skills Hub include agnix, skillport, claude-skills-journalism. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse Codex Skill tools