Repository files navigation

skillview

A local-only web GUI for inspecting agent skills (SKILL.md format) across personal, project, plugin, cache, and marketplace sources.

npm versionlicense: MITstatus: stablenode >= 20.19local only

bunx @pc_style/skillview
skillview main interface — skill list with detail preview

Run it from the workspace you want to inspect. Skillview opens a browser and builds a provenance-aware inventory of the agent skills on your machine — the shared SKILL.md format used by Amp, Codex, Claude Code, and other coding agents. It reads native Amp/Codex directories, Claude directories and plugin registries, and explicitly exposed symlink targets.

Also works with npx @pc_style/skillview if you don't use Bun.

highlights

  • provenance-aware — the same skill can appear as an installed plugin copy, a cached version, and a marketplace source; each record keeps its source, plugin, marketplace, and version context
  • fast filtering — search by name, description, or path; filter by source and lifecycle
  • deep inspection — rendered Markdown, raw SKILL.md, file trees, and metadata for every skill
  • safe by design — read-mostly, localhost-only, no cloud sync
Instant search filtering skills by keywordMetadata tab showing plugin, marketplace, and version provenance
instant search across 100+ skillsfull provenance: plugin, marketplace, version

sources

Skillview discovers:

sourcewhere
Amp user~/.config/agents/skills, ~/.agents/skills, and ~/.config/amp/skills
Codex usershared skills in ~/.agents/skills
Claude userdirect skills in ~/.claude/skills
linkedvalid skill-directory symlinks explicitly exposed in a discovered user or project root
Amp / Codex project.agents/skills directories beneath the selected workspace
Claude project.claude/skills directories beneath the selected workspace
installed pluginactive installations recorded in ~/.claude/plugins/installed_plugins.json
plugin cachecurrent, historical, and orphaned skill copies under ~/.claude/plugins/cache
marketplaceavailable plugin skills under registered local marketplace checkouts

Skillview scans only these documented roots and bounded project directories. It does not inspect Amp built-ins, remote personal/workspace repositories, Codex system skills, or arbitrary directories configured through amp.skills.path. Ephemeral runtime bundles under /private/tmp are also excluded from the standalone package.

options

--workspace <path> workspace to scan instead of the current directory
--port <number> localhost port, or 0 for an available port (default: 4173)
--no-open start the server without opening a browser
-h, --help show help

Examples:

bunx @pc_style/skillview --workspace ~/projects/my-app
bunx @pc_style/skillview --port 4317 --no-open

SKILL_VIEW_WORKSPACE_ROOT remains available as an environment override.

lifecycle labels

labelmeaning
enabled / disableddirect user/project skill state, or installed plugin state from Claude settings
installedplugin is registered but has no explicit enabled boolean
cachedmanaged plugin cache artifact
availablemarketplace source that may not be installed

what it does

  • previews skill descriptions, rendered Markdown, raw SKILL.md, metadata, and file trees
  • searches and filters by source and lifecycle
  • shows plugin, marketplace, version, linked-target, and canonical-path provenance
  • copies paths and skill content
  • reveals freshly validated skill folders in Finder on macOS
  • enables or disables direct user/project skills by renaming SKILL.md to SKILL.md.disabled and back, after confirmation
Files tab showing the skill's file tree
every skill's file tree, one click away

safety

Skillview binds only to 127.0.0.1. Skill content stays on your machine and is never sent to a cloud service.

The packaged server rejects non-loopback hosts and cross-origin browser requests, requires JSON for state-changing requests, and sends a restrictive Content Security Policy. All actions use server-issued skill IDs. Before reveal or toggle, the server freshly rediscovers the record, validates its source and canonical path, and checks its capabilities. Raw client-provided filesystem paths are not accepted.

Plugin cache, marketplace, installed-plugin, and linked records are inspection-only. Their files are managed by agent/plugin tooling and are never renamed by Skillview. Project and marketplace traversal is bounded; only explicit top-level skill symlinks in documented roots are followed, and those targets remain inspection-only.

Deletion and arbitrary file editing are deliberately unavailable.

Skill files are untrusted instructions and may include scripts. Skillview displays their text and file names but never executes their contents. Markdown previews cannot load remote images in the packaged app. See SECURITY.md to report a vulnerability privately.

status and compatibility

Stable. The local inspection and guarded enable/disable workflow is covered by automated tests. Discovery compatibility is intentionally explicit:

hostsupported local sourcesnot currently represented
Amp~/.config/agents/skills, ~/.agents/skills, ~/.config/amp/skills, project .agents/skills, Claude-compatible locationsbuilt-ins, remote personal/workspace skill repositories, directory-plugin registrations, amp.skills.path
Codex~/.agents/skills, project .agents/skills/etc/codex/skills, built-ins and plugin-distributed skills
Claude Codeuser/project skills, installed-plugin registry, cache and registered marketplace checkoutsremote marketplace state not present on disk

Node 20.19 or newer is required by the build/runtime dependency line. Compatibility describes filesystem layouts documented on 2026-08-16; agent hosts can change them independently.

roadmap

  • expose configured Amp skill paths without invoking or uploading skill content
  • represent Amp directory-plugin and remote-repository provenance when a stable local API exists
  • add content hashes and duplicate/version-drift comparisons without executing skill code
  • keep mutation support narrow: explicit user/project enable and disable only

Changes are recorded in CHANGELOG.md. The source-specific fixtures in src/server/skills.test.ts are the compatibility evidence; unsupported sources remain listed above rather than inferred.

local development

Requires Node.js 20.19 or newer.

bun install
bun run dev

Build and run the same standalone server shipped in the package:

bun run build
bun start -- --no-open

checks

bun run test
bun run build
npm pack --dry-run

The suite covers frontmatter parsing, Amp/Codex/Claude filesystem layouts, all six source kinds, linked-skill handling, plugin registry validation, provenance-preserving IDs, action authorization, cross-origin rejection, static asset isolation, and the production HTTP boundary.

publishing

Publishing remains a deliberate maintainer action:

npm pack --dry-run
npm publish --dry-run
npm publish

license

MIT

About

Local-only web GUI for inspecting agent skills (SKILL.md) across user, project, plugin, cache, and marketplace sources

Topics

Resources

Security policy

Stars

68 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Repository files navigation

skillview

A local-only web GUI for inspecting agent skills (SKILL.md format) across personal, project, plugin, cache, and marketplace sources.

npm versionlicense: MITstatus: stablenode >= 20.19local only

bunx @pc_style/skillview
skillview main interface — skill list with detail preview

Run it from the workspace you want to inspect. Skillview opens a browser and builds a provenance-aware inventory of the agent skills on your machine — the shared SKILL.md format used by Amp, Codex, Claude Code, and other coding agents. It reads native Amp/Codex directories, Claude directories and plugin registries, and explicitly exposed symlink targets.

Also works with npx @pc_style/skillview if you don't use Bun.

highlights

  • provenance-aware — the same skill can appear as an installed plugin copy, a cached version, and a marketplace source; each record keeps its source, plugin, marketplace, and version context
  • fast filtering — search by name, description, or path; filter by source and lifecycle
  • deep inspection — rendered Markdown, raw SKILL.md, file trees, and metadata for every skill
  • safe by design — read-mostly, localhost-only, no cloud sync
Instant search filtering skills by keywordMetadata tab showing plugin, marketplace, and version provenance
instant search across 100+ skillsfull provenance: plugin, marketplace, version

sources

Skillview discovers:

sourcewhere
Amp user~/.config/agents/skills, ~/.agents/skills, and ~/.config/amp/skills
Codex usershared skills in ~/.agents/skills
Claude userdirect skills in ~/.claude/skills
linkedvalid skill-directory symlinks explicitly exposed in a discovered user or project root
Amp / Codex project.agents/skills directories beneath the selected workspace
Claude project.claude/skills directories beneath the selected workspace
installed pluginactive installations recorded in ~/.claude/plugins/installed_plugins.json
plugin cachecurrent, historical, and orphaned skill copies under ~/.claude/plugins/cache
marketplaceavailable plugin skills under registered local marketplace checkouts

Skillview scans only these documented roots and bounded project directories. It does not inspect Amp built-ins, remote personal/workspace repositories, Codex system skills, or arbitrary directories configured through amp.skills.path. Ephemeral runtime bundles under /private/tmp are also excluded from the standalone package.

options

--workspace <path> workspace to scan instead of the current directory
--port <number> localhost port, or 0 for an available port (default: 4173)
--no-open start the server without opening a browser
-h, --help show help

Examples:

bunx @pc_style/skillview --workspace ~/projects/my-app
bunx @pc_style/skillview --port 4317 --no-open

SKILL_VIEW_WORKSPACE_ROOT remains available as an environment override.

lifecycle labels

labelmeaning
enabled / disableddirect user/project skill state, or installed plugin state from Claude settings
installedplugin is registered but has no explicit enabled boolean
cachedmanaged plugin cache artifact
availablemarketplace source that may not be installed

what it does

  • previews skill descriptions, rendered Markdown, raw SKILL.md, metadata, and file trees
  • searches and filters by source and lifecycle
  • shows plugin, marketplace, version, linked-target, and canonical-path provenance
  • copies paths and skill content
  • reveals freshly validated skill folders in Finder on macOS
  • enables or disables direct user/project skills by renaming SKILL.md to SKILL.md.disabled and back, after confirmation
Files tab showing the skill's file tree
every skill's file tree, one click away

safety

Skillview binds only to 127.0.0.1. Skill content stays on your machine and is never sent to a cloud service.

The packaged server rejects non-loopback hosts and cross-origin browser requests, requires JSON for state-changing requests, and sends a restrictive Content Security Policy. All actions use server-issued skill IDs. Before reveal or toggle, the server freshly rediscovers the record, validates its source and canonical path, and checks its capabilities. Raw client-provided filesystem paths are not accepted.

Plugin cache, marketplace, installed-plugin, and linked records are inspection-only. Their files are managed by agent/plugin tooling and are never renamed by Skillview. Project and marketplace traversal is bounded; only explicit top-level skill symlinks in documented roots are followed, and those targets remain inspection-only.

Deletion and arbitrary file editing are deliberately unavailable.

Skill files are untrusted instructions and may include scripts. Skillview displays their text and file names but never executes their contents. Markdown previews cannot load remote images in the packaged app. See SECURITY.md to report a vulnerability privately.

status and compatibility

Stable. The local inspection and guarded enable/disable workflow is covered by automated tests. Discovery compatibility is intentionally explicit:

hostsupported local sourcesnot currently represented
Amp~/.config/agents/skills, ~/.agents/skills, ~/.config/amp/skills, project .agents/skills, Claude-compatible locationsbuilt-ins, remote personal/workspace skill repositories, directory-plugin registrations, amp.skills.path
Codex~/.agents/skills, project .agents/skills/etc/codex/skills, built-ins and plugin-distributed skills
Claude Codeuser/project skills, installed-plugin registry, cache and registered marketplace checkoutsremote marketplace state not present on disk

Node 20.19 or newer is required by the build/runtime dependency line. Compatibility describes filesystem layouts documented on 2026-08-16; agent hosts can change them independently.

roadmap

  • expose configured Amp skill paths without invoking or uploading skill content
  • represent Amp directory-plugin and remote-repository provenance when a stable local API exists
  • add content hashes and duplicate/version-drift comparisons without executing skill code
  • keep mutation support narrow: explicit user/project enable and disable only

Changes are recorded in CHANGELOG.md. The source-specific fixtures in src/server/skills.test.ts are the compatibility evidence; unsupported sources remain listed above rather than inferred.

local development

Requires Node.js 20.19 or newer.

bun install
bun run dev

Build and run the same standalone server shipped in the package:

bun run build
bun start -- --no-open

checks

bun run test
bun run build
npm pack --dry-run

The suite covers frontmatter parsing, Amp/Codex/Claude filesystem layouts, all six source kinds, linked-skill handling, plugin registry validation, provenance-preserving IDs, action authorization, cross-origin rejection, static asset isolation, and the production HTTP boundary.

publishing

Publishing remains a deliberate maintainer action:

npm pack --dry-run
npm publish --dry-run
npm publish

license

MIT

About

Local-only web GUI for inspecting agent skills (SKILL.md) across user, project, plugin, cache, and marketplace sources

Topics

Resources

Security policy

Stars

68 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

skillview

A local-only web GUI for inspecting agent skills (SKILL.md format) across personal, project, plugin, cache, and marketplace sources.

npm versionlicense: MITstatus: stablenode >= 20.19local only

bunx @pc_style/skillview
skillview main interface — skill list with detail preview

Run it from the workspace you want to inspect. Skillview opens a browser and builds a provenance-aware inventory of the agent skills on your machine — the shared SKILL.md format used by Amp, Codex, Claude Code, and other coding agents. It reads native Amp/Codex directories, Claude directories and plugin registries, and explicitly exposed symlink targets.

Also works with npx @pc_style/skillview if you don't use Bun.

highlights

  • provenance-aware — the same skill can appear as an installed plugin copy, a cached version, and a marketplace source; each record keeps its source, plugin, marketplace, and version context
  • fast filtering — search by name, description, or path; filter by source and lifecycle
  • deep inspection — rendered Markdown, raw SKILL.md, file trees, and metadata for every skill
  • safe by design — read-mostly, localhost-only, no cloud sync
Instant search filtering skills by keywordMetadata tab showing plugin, marketplace, and version provenance
instant search across 100+ skillsfull provenance: plugin, marketplace, version

sources

Skillview discovers:

sourcewhere
Amp user~/.config/agents/skills, ~/.agents/skills, and ~/.config/amp/skills
Codex usershared skills in ~/.agents/skills
Claude userdirect skills in ~/.claude/skills
linkedvalid skill-directory symlinks explicitly exposed in a discovered user or project root
Amp / Codex project.agents/skills directories beneath the selected workspace
Claude project.claude/skills directories beneath the selected workspace
installed pluginactive installations recorded in ~/.claude/plugins/installed_plugins.json
plugin cachecurrent, historical, and orphaned skill copies under ~/.claude/plugins/cache
marketplaceavailable plugin skills under registered local marketplace checkouts

Skillview scans only these documented roots and bounded project directories. It does not inspect Amp built-ins, remote personal/workspace repositories, Codex system skills, or arbitrary directories configured through amp.skills.path. Ephemeral runtime bundles under /private/tmp are also excluded from the standalone package.

options

--workspace <path> workspace to scan instead of the current directory
--port <number> localhost port, or 0 for an available port (default: 4173)
--no-open start the server without opening a browser
-h, --help show help

Examples:

bunx @pc_style/skillview --workspace ~/projects/my-app
bunx @pc_style/skillview --port 4317 --no-open

SKILL_VIEW_WORKSPACE_ROOT remains available as an environment override.

lifecycle labels

labelmeaning
enabled / disableddirect user/project skill state, or installed plugin state from Claude settings
installedplugin is registered but has no explicit enabled boolean
cachedmanaged plugin cache artifact
availablemarketplace source that may not be installed

what it does

  • previews skill descriptions, rendered Markdown, raw SKILL.md, metadata, and file trees
  • searches and filters by source and lifecycle
  • shows plugin, marketplace, version, linked-target, and canonical-path provenance
  • copies paths and skill content
  • reveals freshly validated skill folders in Finder on macOS
  • enables or disables direct user/project skills by renaming SKILL.md to SKILL.md.disabled and back, after confirmation
Files tab showing the skill's file tree
every skill's file tree, one click away

safety

Skillview binds only to 127.0.0.1. Skill content stays on your machine and is never sent to a cloud service.

The packaged server rejects non-loopback hosts and cross-origin browser requests, requires JSON for state-changing requests, and sends a restrictive Content Security Policy. All actions use server-issued skill IDs. Before reveal or toggle, the server freshly rediscovers the record, validates its source and canonical path, and checks its capabilities. Raw client-provided filesystem paths are not accepted.

Plugin cache, marketplace, installed-plugin, and linked records are inspection-only. Their files are managed by agent/plugin tooling and are never renamed by Skillview. Project and marketplace traversal is bounded; only explicit top-level skill symlinks in documented roots are followed, and those targets remain inspection-only.

Deletion and arbitrary file editing are deliberately unavailable.

Skill files are untrusted instructions and may include scripts. Skillview displays their text and file names but never executes their contents. Markdown previews cannot load remote images in the packaged app. See SECURITY.md to report a vulnerability privately.

status and compatibility

Stable. The local inspection and guarded enable/disable workflow is covered by automated tests. Discovery compatibility is intentionally explicit:

hostsupported local sourcesnot currently represented
Amp~/.config/agents/skills, ~/.agents/skills, ~/.config/amp/skills, project .agents/skills, Claude-compatible locationsbuilt-ins, remote personal/workspace skill repositories, directory-plugin registrations, amp.skills.path
Codex~/.agents/skills, project .agents/skills/etc/codex/skills, built-ins and plugin-distributed skills
Claude Codeuser/project skills, installed-plugin registry, cache and registered marketplace checkoutsremote marketplace state not present on disk

Node 20.19 or newer is required by the build/runtime dependency line. Compatibility describes filesystem layouts documented on 2026-08-16; agent hosts can change them independently.

roadmap

  • expose configured Amp skill paths without invoking or uploading skill content
  • represent Amp directory-plugin and remote-repository provenance when a stable local API exists
  • add content hashes and duplicate/version-drift comparisons without executing skill code
  • keep mutation support narrow: explicit user/project enable and disable only

Changes are recorded in CHANGELOG.md. The source-specific fixtures in src/server/skills.test.ts are the compatibility evidence; unsupported sources remain listed above rather than inferred.

local development

Requires Node.js 20.19 or newer.

bun install
bun run dev

Build and run the same standalone server shipped in the package:

bun run build
bun start -- --no-open

checks

bun run test
bun run build
npm pack --dry-run

The suite covers frontmatter parsing, Amp/Codex/Claude filesystem layouts, all six source kinds, linked-skill handling, plugin registry validation, provenance-preserving IDs, action authorization, cross-origin rejection, static asset isolation, and the production HTTP boundary.

publishing

Publishing remains a deliberate maintainer action:

npm pack --dry-run
npm publish --dry-run
npm publish

license

MIT

About

Local-only web GUI for inspecting agent skills (SKILL.md) across user, project, plugin, cache, and marketplace sources

Topics

Resources

Security policy

Stars

68 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

skillview

A local-only web GUI for inspecting agent skills (SKILL.md format) across personal, project, plugin, cache, and marketplace sources.

npm versionlicense: MITstatus: stablenode >= 20.19local only

bunx @pc_style/skillview
skillview main interface — skill list with detail preview

Run it from the workspace you want to inspect. Skillview opens a browser and builds a provenance-aware inventory of the agent skills on your machine — the shared SKILL.md format used by Amp, Codex, Claude Code, and other coding agents. It reads native Amp/Codex directories, Claude directories and plugin registries, and explicitly exposed symlink targets.

Also works with npx @pc_style/skillview if you don't use Bun.

highlights

  • provenance-aware — the same skill can appear as an installed plugin copy, a cached version, and a marketplace source; each record keeps its source, plugin, marketplace, and version context
  • fast filtering — search by name, description, or path; filter by source and lifecycle
  • deep inspection — rendered Markdown, raw SKILL.md, file trees, and metadata for every skill
  • safe by design — read-mostly, localhost-only, no cloud sync
Instant search filtering skills by keywordMetadata tab showing plugin, marketplace, and version provenance
instant search across 100+ skillsfull provenance: plugin, marketplace, version

sources

Skillview discovers:

sourcewhere
Amp user~/.config/agents/skills, ~/.agents/skills, and ~/.config/amp/skills
Codex usershared skills in ~/.agents/skills
Claude userdirect skills in ~/.claude/skills
linkedvalid skill-directory symlinks explicitly exposed in a discovered user or project root
Amp / Codex project.agents/skills directories beneath the selected workspace
Claude project.claude/skills directories beneath the selected workspace
installed pluginactive installations recorded in ~/.claude/plugins/installed_plugins.json
plugin cachecurrent, historical, and orphaned skill copies under ~/.claude/plugins/cache
marketplaceavailable plugin skills under registered local marketplace checkouts

Skillview scans only these documented roots and bounded project directories. It does not inspect Amp built-ins, remote personal/workspace repositories, Codex system skills, or arbitrary directories configured through amp.skills.path. Ephemeral runtime bundles under /private/tmp are also excluded from the standalone package.

options

--workspace <path> workspace to scan instead of the current directory
--port <number> localhost port, or 0 for an available port (default: 4173)
--no-open start the server without opening a browser
-h, --help show help

Examples:

bunx @pc_style/skillview --workspace ~/projects/my-app
bunx @pc_style/skillview --port 4317 --no-open

SKILL_VIEW_WORKSPACE_ROOT remains available as an environment override.

lifecycle labels

labelmeaning
enabled / disableddirect user/project skill state, or installed plugin state from Claude settings
installedplugin is registered but has no explicit enabled boolean
cachedmanaged plugin cache artifact
availablemarketplace source that may not be installed

what it does

  • previews skill descriptions, rendered Markdown, raw SKILL.md, metadata, and file trees
  • searches and filters by source and lifecycle
  • shows plugin, marketplace, version, linked-target, and canonical-path provenance
  • copies paths and skill content
  • reveals freshly validated skill folders in Finder on macOS
  • enables or disables direct user/project skills by renaming SKILL.md to SKILL.md.disabled and back, after confirmation
Files tab showing the skill's file tree
every skill's file tree, one click away

safety

Skillview binds only to 127.0.0.1. Skill content stays on your machine and is never sent to a cloud service.

The packaged server rejects non-loopback hosts and cross-origin browser requests, requires JSON for state-changing requests, and sends a restrictive Content Security Policy. All actions use server-issued skill IDs. Before reveal or toggle, the server freshly rediscovers the record, validates its source and canonical path, and checks its capabilities. Raw client-provided filesystem paths are not accepted.

Plugin cache, marketplace, installed-plugin, and linked records are inspection-only. Their files are managed by agent/plugin tooling and are never renamed by Skillview. Project and marketplace traversal is bounded; only explicit top-level skill symlinks in documented roots are followed, and those targets remain inspection-only.

Deletion and arbitrary file editing are deliberately unavailable.

Skill files are untrusted instructions and may include scripts. Skillview displays their text and file names but never executes their contents. Markdown previews cannot load remote images in the packaged app. See SECURITY.md to report a vulnerability privately.

status and compatibility

Stable. The local inspection and guarded enable/disable workflow is covered by automated tests. Discovery compatibility is intentionally explicit:

hostsupported local sourcesnot currently represented
Amp~/.config/agents/skills, ~/.agents/skills, ~/.config/amp/skills, project .agents/skills, Claude-compatible locationsbuilt-ins, remote personal/workspace skill repositories, directory-plugin registrations, amp.skills.path
Codex~/.agents/skills, project .agents/skills/etc/codex/skills, built-ins and plugin-distributed skills
Claude Codeuser/project skills, installed-plugin registry, cache and registered marketplace checkoutsremote marketplace state not present on disk

Node 20.19 or newer is required by the build/runtime dependency line. Compatibility describes filesystem layouts documented on 2026-08-16; agent hosts can change them independently.

roadmap

  • expose configured Amp skill paths without invoking or uploading skill content
  • represent Amp directory-plugin and remote-repository provenance when a stable local API exists
  • add content hashes and duplicate/version-drift comparisons without executing skill code
  • keep mutation support narrow: explicit user/project enable and disable only

Changes are recorded in CHANGELOG.md. The source-specific fixtures in src/server/skills.test.ts are the compatibility evidence; unsupported sources remain listed above rather than inferred.

local development

Requires Node.js 20.19 or newer.

bun install
bun run dev

Build and run the same standalone server shipped in the package:

bun run build
bun start -- --no-open

checks

bun run test
bun run build
npm pack --dry-run

The suite covers frontmatter parsing, Amp/Codex/Claude filesystem layouts, all six source kinds, linked-skill handling, plugin registry validation, provenance-preserving IDs, action authorization, cross-origin rejection, static asset isolation, and the production HTTP boundary.

publishing

Publishing remains a deliberate maintainer action:

npm pack --dry-run
npm publish --dry-run
npm publish

license

MIT

About

Local-only web GUI for inspecting agent skills (SKILL.md) across user, project, plugin, cache, and marketplace sources

Topics

Resources

Security policy

Stars

68 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Repository files navigation

skillview

A local-only web GUI for inspecting agent skills (SKILL.md format) across personal, project, plugin, cache, and marketplace sources.

npm versionlicense: MITstatus: stablenode >= 20.19local only

bunx @pc_style/skillview
skillview main interface — skill list with detail preview

Run it from the workspace you want to inspect. Skillview opens a browser and builds a provenance-aware inventory of the agent skills on your machine — the shared SKILL.md format used by Amp, Codex, Claude Code, and other coding agents. It reads native Amp/Codex directories, Claude directories and plugin registries, and explicitly exposed symlink targets.

Also works with npx @pc_style/skillview if you don't use Bun.

highlights

  • provenance-aware — the same skill can appear as an installed plugin copy, a cached version, and a marketplace source; each record keeps its source, plugin, marketplace, and version context
  • fast filtering — search by name, description, or path; filter by source and lifecycle
  • deep inspection — rendered Markdown, raw SKILL.md, file trees, and metadata for every skill
  • safe by design — read-mostly, localhost-only, no cloud sync
Instant search filtering skills by keywordMetadata tab showing plugin, marketplace, and version provenance
instant search across 100+ skillsfull provenance: plugin, marketplace, version

sources

Skillview discovers:

sourcewhere
Amp user~/.config/agents/skills, ~/.agents/skills, and ~/.config/amp/skills
Codex usershared skills in ~/.agents/skills
Claude userdirect skills in ~/.claude/skills
linkedvalid skill-directory symlinks explicitly exposed in a discovered user or project root
Amp / Codex project.agents/skills directories beneath the selected workspace
Claude project.claude/skills directories beneath the selected workspace
installed pluginactive installations recorded in ~/.claude/plugins/installed_plugins.json
plugin cachecurrent, historical, and orphaned skill copies under ~/.claude/plugins/cache
marketplaceavailable plugin skills under registered local marketplace checkouts

Skillview scans only these documented roots and bounded project directories. It does not inspect Amp built-ins, remote personal/workspace repositories, Codex system skills, or arbitrary directories configured through amp.skills.path. Ephemeral runtime bundles under /private/tmp are also excluded from the standalone package.

options

--workspace <path> workspace to scan instead of the current directory
--port <number> localhost port, or 0 for an available port (default: 4173)
--no-open start the server without opening a browser
-h, --help show help

Examples:

bunx @pc_style/skillview --workspace ~/projects/my-app
bunx @pc_style/skillview --port 4317 --no-open

SKILL_VIEW_WORKSPACE_ROOT remains available as an environment override.

lifecycle labels

labelmeaning
enabled / disableddirect user/project skill state, or installed plugin state from Claude settings
installedplugin is registered but has no explicit enabled boolean
cachedmanaged plugin cache artifact
availablemarketplace source that may not be installed

what it does

  • previews skill descriptions, rendered Markdown, raw SKILL.md, metadata, and file trees
  • searches and filters by source and lifecycle
  • shows plugin, marketplace, version, linked-target, and canonical-path provenance
  • copies paths and skill content
  • reveals freshly validated skill folders in Finder on macOS
  • enables or disables direct user/project skills by renaming SKILL.md to SKILL.md.disabled and back, after confirmation
Files tab showing the skill's file tree
every skill's file tree, one click away

safety

Skillview binds only to 127.0.0.1. Skill content stays on your machine and is never sent to a cloud service.

The packaged server rejects non-loopback hosts and cross-origin browser requests, requires JSON for state-changing requests, and sends a restrictive Content Security Policy. All actions use server-issued skill IDs. Before reveal or toggle, the server freshly rediscovers the record, validates its source and canonical path, and checks its capabilities. Raw client-provided filesystem paths are not accepted.

Plugin cache, marketplace, installed-plugin, and linked records are inspection-only. Their files are managed by agent/plugin tooling and are never renamed by Skillview. Project and marketplace traversal is bounded; only explicit top-level skill symlinks in documented roots are followed, and those targets remain inspection-only.

Deletion and arbitrary file editing are deliberately unavailable.

Skill files are untrusted instructions and may include scripts. Skillview displays their text and file names but never executes their contents. Markdown previews cannot load remote images in the packaged app. See SECURITY.md to report a vulnerability privately.

status and compatibility

Stable. The local inspection and guarded enable/disable workflow is covered by automated tests. Discovery compatibility is intentionally explicit:

hostsupported local sourcesnot currently represented
Amp~/.config/agents/skills, ~/.agents/skills, ~/.config/amp/skills, project .agents/skills, Claude-compatible locationsbuilt-ins, remote personal/workspace skill repositories, directory-plugin registrations, amp.skills.path
Codex~/.agents/skills, project .agents/skills/etc/codex/skills, built-ins and plugin-distributed skills
Claude Codeuser/project skills, installed-plugin registry, cache and registered marketplace checkoutsremote marketplace state not present on disk

Node 20.19 or newer is required by the build/runtime dependency line. Compatibility describes filesystem layouts documented on 2026-08-16; agent hosts can change them independently.

roadmap

  • expose configured Amp skill paths without invoking or uploading skill content
  • represent Amp directory-plugin and remote-repository provenance when a stable local API exists
  • add content hashes and duplicate/version-drift comparisons without executing skill code
  • keep mutation support narrow: explicit user/project enable and disable only

Changes are recorded in CHANGELOG.md. The source-specific fixtures in src/server/skills.test.ts are the compatibility evidence; unsupported sources remain listed above rather than inferred.

local development

Requires Node.js 20.19 or newer.

bun install
bun run dev

Build and run the same standalone server shipped in the package:

bun run build
bun start -- --no-open

checks

bun run test
bun run build
npm pack --dry-run

The suite covers frontmatter parsing, Amp/Codex/Claude filesystem layouts, all six source kinds, linked-skill handling, plugin registry validation, provenance-preserving IDs, action authorization, cross-origin rejection, static asset isolation, and the production HTTP boundary.

publishing

Publishing remains a deliberate maintainer action:

npm pack --dry-run
npm publish --dry-run
npm publish

license

MIT

About

Local-only web GUI for inspecting agent skills (SKILL.md) across user, project, plugin, cache, and marketplace sources

Topics

Resources

Security policy

Stars

68 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

skillview

A local-only web GUI for inspecting agent skills (SKILL.md format) across personal, project, plugin, cache, and marketplace sources.

npm versionlicense: MITstatus: stablenode >= 20.19local only

bunx @pc_style/skillview
skillview main interface — skill list with detail preview

Run it from the workspace you want to inspect. Skillview opens a browser and builds a provenance-aware inventory of the agent skills on your machine — the shared SKILL.md format used by Amp, Codex, Claude Code, and other coding agents. It reads native Amp/Codex directories, Claude directories and plugin registries, and explicitly exposed symlink targets.

Also works with npx @pc_style/skillview if you don't use Bun.

highlights

  • provenance-aware — the same skill can appear as an installed plugin copy, a cached version, and a marketplace source; each record keeps its source, plugin, marketplace, and version context
  • fast filtering — search by name, description, or path; filter by source and lifecycle
  • deep inspection — rendered Markdown, raw SKILL.md, file trees, and metadata for every skill
  • safe by design — read-mostly, localhost-only, no cloud sync
Instant search filtering skills by keywordMetadata tab showing plugin, marketplace, and version provenance
instant search across 100+ skillsfull provenance: plugin, marketplace, version

sources

Skillview discovers:

sourcewhere
Amp user~/.config/agents/skills, ~/.agents/skills, and ~/.config/amp/skills
Codex usershared skills in ~/.agents/skills
Claude userdirect skills in ~/.claude/skills
linkedvalid skill-directory symlinks explicitly exposed in a discovered user or project root
Amp / Codex project.agents/skills directories beneath the selected workspace
Claude project.claude/skills directories beneath the selected workspace
installed pluginactive installations recorded in ~/.claude/plugins/installed_plugins.json
plugin cachecurrent, historical, and orphaned skill copies under ~/.claude/plugins/cache
marketplaceavailable plugin skills under registered local marketplace checkouts

Skillview scans only these documented roots and bounded project directories. It does not inspect Amp built-ins, remote personal/workspace repositories, Codex system skills, or arbitrary directories configured through amp.skills.path. Ephemeral runtime bundles under /private/tmp are also excluded from the standalone package.

options

--workspace <path> workspace to scan instead of the current directory
--port <number> localhost port, or 0 for an available port (default: 4173)
--no-open start the server without opening a browser
-h, --help show help

Examples:

bunx @pc_style/skillview --workspace ~/projects/my-app
bunx @pc_style/skillview --port 4317 --no-open

SKILL_VIEW_WORKSPACE_ROOT remains available as an environment override.

lifecycle labels

labelmeaning
enabled / disableddirect user/project skill state, or installed plugin state from Claude settings
installedplugin is registered but has no explicit enabled boolean
cachedmanaged plugin cache artifact
availablemarketplace source that may not be installed

what it does

  • previews skill descriptions, rendered Markdown, raw SKILL.md, metadata, and file trees
  • searches and filters by source and lifecycle
  • shows plugin, marketplace, version, linked-target, and canonical-path provenance
  • copies paths and skill content
  • reveals freshly validated skill folders in Finder on macOS
  • enables or disables direct user/project skills by renaming SKILL.md to SKILL.md.disabled and back, after confirmation
Files tab showing the skill's file tree
every skill's file tree, one click away

safety

Skillview binds only to 127.0.0.1. Skill content stays on your machine and is never sent to a cloud service.

The packaged server rejects non-loopback hosts and cross-origin browser requests, requires JSON for state-changing requests, and sends a restrictive Content Security Policy. All actions use server-issued skill IDs. Before reveal or toggle, the server freshly rediscovers the record, validates its source and canonical path, and checks its capabilities. Raw client-provided filesystem paths are not accepted.

Plugin cache, marketplace, installed-plugin, and linked records are inspection-only. Their files are managed by agent/plugin tooling and are never renamed by Skillview. Project and marketplace traversal is bounded; only explicit top-level skill symlinks in documented roots are followed, and those targets remain inspection-only.

Deletion and arbitrary file editing are deliberately unavailable.

Skill files are untrusted instructions and may include scripts. Skillview displays their text and file names but never executes their contents. Markdown previews cannot load remote images in the packaged app. See SECURITY.md to report a vulnerability privately.

status and compatibility

Stable. The local inspection and guarded enable/disable workflow is covered by automated tests. Discovery compatibility is intentionally explicit:

hostsupported local sourcesnot currently represented
Amp~/.config/agents/skills, ~/.agents/skills, ~/.config/amp/skills, project .agents/skills, Claude-compatible locationsbuilt-ins, remote personal/workspace skill repositories, directory-plugin registrations, amp.skills.path
Codex~/.agents/skills, project .agents/skills/etc/codex/skills, built-ins and plugin-distributed skills
Claude Codeuser/project skills, installed-plugin registry, cache and registered marketplace checkoutsremote marketplace state not present on disk

Node 20.19 or newer is required by the build/runtime dependency line. Compatibility describes filesystem layouts documented on 2026-08-16; agent hosts can change them independently.

roadmap

  • expose configured Amp skill paths without invoking or uploading skill content
  • represent Amp directory-plugin and remote-repository provenance when a stable local API exists
  • add content hashes and duplicate/version-drift comparisons without executing skill code
  • keep mutation support narrow: explicit user/project enable and disable only

Changes are recorded in CHANGELOG.md. The source-specific fixtures in src/server/skills.test.ts are the compatibility evidence; unsupported sources remain listed above rather than inferred.

local development

Requires Node.js 20.19 or newer.

bun install
bun run dev

Build and run the same standalone server shipped in the package:

bun run build
bun start -- --no-open

checks

bun run test
bun run build
npm pack --dry-run

The suite covers frontmatter parsing, Amp/Codex/Claude filesystem layouts, all six source kinds, linked-skill handling, plugin registry validation, provenance-preserving IDs, action authorization, cross-origin rejection, static asset isolation, and the production HTTP boundary.

publishing

Publishing remains a deliberate maintainer action:

npm pack --dry-run
npm publish --dry-run
npm publish

license

MIT

About

Local-only web GUI for inspecting agent skills (SKILL.md) across user, project, plugin, cache, and marketplace sources

Topics

Resources

Security policy

Stars

68 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

skillview

A local-only web GUI for inspecting agent skills (SKILL.md format) across personal, project, plugin, cache, and marketplace sources.

npm versionlicense: MITstatus: stablenode >= 20.19local only

bunx @pc_style/skillview
skillview main interface — skill list with detail preview

Run it from the workspace you want to inspect. Skillview opens a browser and builds a provenance-aware inventory of the agent skills on your machine — the shared SKILL.md format used by Amp, Codex, Claude Code, and other coding agents. It reads native Amp/Codex directories, Claude directories and plugin registries, and explicitly exposed symlink targets.

Also works with npx @pc_style/skillview if you don't use Bun.

highlights

  • provenance-aware — the same skill can appear as an installed plugin copy, a cached version, and a marketplace source; each record keeps its source, plugin, marketplace, and version context
  • fast filtering — search by name, description, or path; filter by source and lifecycle
  • deep inspection — rendered Markdown, raw SKILL.md, file trees, and metadata for every skill
  • safe by design — read-mostly, localhost-only, no cloud sync
Instant search filtering skills by keywordMetadata tab showing plugin, marketplace, and version provenance
instant search across 100+ skillsfull provenance: plugin, marketplace, version

sources

Skillview discovers:

sourcewhere
Amp user~/.config/agents/skills, ~/.agents/skills, and ~/.config/amp/skills
Codex usershared skills in ~/.agents/skills
Claude userdirect skills in ~/.claude/skills
linkedvalid skill-directory symlinks explicitly exposed in a discovered user or project root
Amp / Codex project.agents/skills directories beneath the selected workspace
Claude project.claude/skills directories beneath the selected workspace
installed pluginactive installations recorded in ~/.claude/plugins/installed_plugins.json
plugin cachecurrent, historical, and orphaned skill copies under ~/.claude/plugins/cache
marketplaceavailable plugin skills under registered local marketplace checkouts

Skillview scans only these documented roots and bounded project directories. It does not inspect Amp built-ins, remote personal/workspace repositories, Codex system skills, or arbitrary directories configured through amp.skills.path. Ephemeral runtime bundles under /private/tmp are also excluded from the standalone package.

options

--workspace <path> workspace to scan instead of the current directory
--port <number> localhost port, or 0 for an available port (default: 4173)
--no-open start the server without opening a browser
-h, --help show help

Examples:

bunx @pc_style/skillview --workspace ~/projects/my-app
bunx @pc_style/skillview --port 4317 --no-open

SKILL_VIEW_WORKSPACE_ROOT remains available as an environment override.

lifecycle labels

labelmeaning
enabled / disableddirect user/project skill state, or installed plugin state from Claude settings
installedplugin is registered but has no explicit enabled boolean
cachedmanaged plugin cache artifact
availablemarketplace source that may not be installed

what it does

  • previews skill descriptions, rendered Markdown, raw SKILL.md, metadata, and file trees
  • searches and filters by source and lifecycle
  • shows plugin, marketplace, version, linked-target, and canonical-path provenance
  • copies paths and skill content
  • reveals freshly validated skill folders in Finder on macOS
  • enables or disables direct user/project skills by renaming SKILL.md to SKILL.md.disabled and back, after confirmation
Files tab showing the skill's file tree
every skill's file tree, one click away

safety

Skillview binds only to 127.0.0.1. Skill content stays on your machine and is never sent to a cloud service.

The packaged server rejects non-loopback hosts and cross-origin browser requests, requires JSON for state-changing requests, and sends a restrictive Content Security Policy. All actions use server-issued skill IDs. Before reveal or toggle, the server freshly rediscovers the record, validates its source and canonical path, and checks its capabilities. Raw client-provided filesystem paths are not accepted.

Plugin cache, marketplace, installed-plugin, and linked records are inspection-only. Their files are managed by agent/plugin tooling and are never renamed by Skillview. Project and marketplace traversal is bounded; only explicit top-level skill symlinks in documented roots are followed, and those targets remain inspection-only.

Deletion and arbitrary file editing are deliberately unavailable.

Skill files are untrusted instructions and may include scripts. Skillview displays their text and file names but never executes their contents. Markdown previews cannot load remote images in the packaged app. See SECURITY.md to report a vulnerability privately.

status and compatibility

Stable. The local inspection and guarded enable/disable workflow is covered by automated tests. Discovery compatibility is intentionally explicit:

hostsupported local sourcesnot currently represented
Amp~/.config/agents/skills, ~/.agents/skills, ~/.config/amp/skills, project .agents/skills, Claude-compatible locationsbuilt-ins, remote personal/workspace skill repositories, directory-plugin registrations, amp.skills.path
Codex~/.agents/skills, project .agents/skills/etc/codex/skills, built-ins and plugin-distributed skills
Claude Codeuser/project skills, installed-plugin registry, cache and registered marketplace checkoutsremote marketplace state not present on disk

Node 20.19 or newer is required by the build/runtime dependency line. Compatibility describes filesystem layouts documented on 2026-08-16; agent hosts can change them independently.

roadmap

  • expose configured Amp skill paths without invoking or uploading skill content
  • represent Amp directory-plugin and remote-repository provenance when a stable local API exists
  • add content hashes and duplicate/version-drift comparisons without executing skill code
  • keep mutation support narrow: explicit user/project enable and disable only

Changes are recorded in CHANGELOG.md. The source-specific fixtures in src/server/skills.test.ts are the compatibility evidence; unsupported sources remain listed above rather than inferred.

local development

Requires Node.js 20.19 or newer.

bun install
bun run dev

Build and run the same standalone server shipped in the package:

bun run build
bun start -- --no-open

checks

bun run test
bun run build
npm pack --dry-run

The suite covers frontmatter parsing, Amp/Codex/Claude filesystem layouts, all six source kinds, linked-skill handling, plugin registry validation, provenance-preserving IDs, action authorization, cross-origin rejection, static asset isolation, and the production HTTP boundary.

publishing

Publishing remains a deliberate maintainer action:

npm pack --dry-run
npm publish --dry-run
npm publish

license

MIT

About

Local-only web GUI for inspecting agent skills (SKILL.md) across user, project, plugin, cache, and marketplace sources

Topics

Resources

Security policy

Stars

68 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Repository files navigation

skillview

A local-only web GUI for inspecting agent skills (SKILL.md format) across personal, project, plugin, cache, and marketplace sources.

npm versionlicense: MITstatus: stablenode >= 20.19local only

bunx @pc_style/skillview
skillview main interface — skill list with detail preview

Run it from the workspace you want to inspect. Skillview opens a browser and builds a provenance-aware inventory of the agent skills on your machine — the shared SKILL.md format used by Amp, Codex, Claude Code, and other coding agents. It reads native Amp/Codex directories, Claude directories and plugin registries, and explicitly exposed symlink targets.

Also works with npx @pc_style/skillview if you don't use Bun.

highlights

  • provenance-aware — the same skill can appear as an installed plugin copy, a cached version, and a marketplace source; each record keeps its source, plugin, marketplace, and version context
  • fast filtering — search by name, description, or path; filter by source and lifecycle
  • deep inspection — rendered Markdown, raw SKILL.md, file trees, and metadata for every skill
  • safe by design — read-mostly, localhost-only, no cloud sync
Instant search filtering skills by keywordMetadata tab showing plugin, marketplace, and version provenance
instant search across 100+ skillsfull provenance: plugin, marketplace, version

sources

Skillview discovers:

sourcewhere
Amp user~/.config/agents/skills, ~/.agents/skills, and ~/.config/amp/skills
Codex usershared skills in ~/.agents/skills
Claude userdirect skills in ~/.claude/skills
linkedvalid skill-directory symlinks explicitly exposed in a discovered user or project root
Amp / Codex project.agents/skills directories beneath the selected workspace
Claude project.claude/skills directories beneath the selected workspace
installed pluginactive installations recorded in ~/.claude/plugins/installed_plugins.json
plugin cachecurrent, historical, and orphaned skill copies under ~/.claude/plugins/cache
marketplaceavailable plugin skills under registered local marketplace checkouts

Skillview scans only these documented roots and bounded project directories. It does not inspect Amp built-ins, remote personal/workspace repositories, Codex system skills, or arbitrary directories configured through amp.skills.path. Ephemeral runtime bundles under /private/tmp are also excluded from the standalone package.

options

--workspace <path> workspace to scan instead of the current directory
--port <number> localhost port, or 0 for an available port (default: 4173)
--no-open start the server without opening a browser
-h, --help show help

Examples:

bunx @pc_style/skillview --workspace ~/projects/my-app
bunx @pc_style/skillview --port 4317 --no-open

SKILL_VIEW_WORKSPACE_ROOT remains available as an environment override.

lifecycle labels

labelmeaning
enabled / disableddirect user/project skill state, or installed plugin state from Claude settings
installedplugin is registered but has no explicit enabled boolean
cachedmanaged plugin cache artifact
availablemarketplace source that may not be installed

what it does

  • previews skill descriptions, rendered Markdown, raw SKILL.md, metadata, and file trees
  • searches and filters by source and lifecycle
  • shows plugin, marketplace, version, linked-target, and canonical-path provenance
  • copies paths and skill content
  • reveals freshly validated skill folders in Finder on macOS
  • enables or disables direct user/project skills by renaming SKILL.md to SKILL.md.disabled and back, after confirmation
Files tab showing the skill's file tree
every skill's file tree, one click away

safety

Skillview binds only to 127.0.0.1. Skill content stays on your machine and is never sent to a cloud service.

The packaged server rejects non-loopback hosts and cross-origin browser requests, requires JSON for state-changing requests, and sends a restrictive Content Security Policy. All actions use server-issued skill IDs. Before reveal or toggle, the server freshly rediscovers the record, validates its source and canonical path, and checks its capabilities. Raw client-provided filesystem paths are not accepted.

Plugin cache, marketplace, installed-plugin, and linked records are inspection-only. Their files are managed by agent/plugin tooling and are never renamed by Skillview. Project and marketplace traversal is bounded; only explicit top-level skill symlinks in documented roots are followed, and those targets remain inspection-only.

Deletion and arbitrary file editing are deliberately unavailable.

Skill files are untrusted instructions and may include scripts. Skillview displays their text and file names but never executes their contents. Markdown previews cannot load remote images in the packaged app. See SECURITY.md to report a vulnerability privately.

status and compatibility

Stable. The local inspection and guarded enable/disable workflow is covered by automated tests. Discovery compatibility is intentionally explicit:

hostsupported local sourcesnot currently represented
Amp~/.config/agents/skills, ~/.agents/skills, ~/.config/amp/skills, project .agents/skills, Claude-compatible locationsbuilt-ins, remote personal/workspace skill repositories, directory-plugin registrations, amp.skills.path
Codex~/.agents/skills, project .agents/skills/etc/codex/skills, built-ins and plugin-distributed skills
Claude Codeuser/project skills, installed-plugin registry, cache and registered marketplace checkoutsremote marketplace state not present on disk

Node 20.19 or newer is required by the build/runtime dependency line. Compatibility describes filesystem layouts documented on 2026-08-16; agent hosts can change them independently.

roadmap

  • expose configured Amp skill paths without invoking or uploading skill content
  • represent Amp directory-plugin and remote-repository provenance when a stable local API exists
  • add content hashes and duplicate/version-drift comparisons without executing skill code
  • keep mutation support narrow: explicit user/project enable and disable only

Changes are recorded in CHANGELOG.md. The source-specific fixtures in src/server/skills.test.ts are the compatibility evidence; unsupported sources remain listed above rather than inferred.

local development

Requires Node.js 20.19 or newer.

bun install
bun run dev

Build and run the same standalone server shipped in the package:

bun run build
bun start -- --no-open

checks

bun run test
bun run build
npm pack --dry-run

The suite covers frontmatter parsing, Amp/Codex/Claude filesystem layouts, all six source kinds, linked-skill handling, plugin registry validation, provenance-preserving IDs, action authorization, cross-origin rejection, static asset isolation, and the production HTTP boundary.

publishing

Publishing remains a deliberate maintainer action:

npm pack --dry-run
npm publish --dry-run
npm publish

license

MIT

About

Local-only web GUI for inspecting agent skills (SKILL.md) across user, project, plugin, cache, and marketplace sources

Topics

Resources

Security policy

Stars

68 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages