@marswave/colaskill-cli
v0.0.1
Published
Agent-native CLI for discovering and securely installing skills from Cola Skill Hub
Readme
Cola Skill Hub CLI
Discover and securely install skills from Cola Skill Hub into Cola and other Agent Skills-compatible clients.
Install
Requires Node.js 22 or later.
npm install --global @marswave/colaskill-cliYou can also run the CLI without installing it globally:
npx -y @marswave/colaskill-cli --helpQuick start
Search and inspect skills:
colaskill search "image design"
colaskill view orange-line-illustration --locale zh-CNInstall a skill for Codex:
colaskill install orange-line-illustration \
--agent codex \
--scope userList skills installed by this CLI:
colaskill listStatus
This repository contains the first CLI MVP. It currently supports anonymous search, item inspection, secure installation of single-skill packages, and a local installation inventory. Collection installation, version selection, updates, removal, publishing, and ratings are planned for later releases.
CLI usage
Install to a project:
colaskill install orange-line-illustration \
--agent codex \
--scope projectInstall to Cola:
colaskill install orange-line-illustration \
--agent cola \
--scope userInstall to a custom directory:
colaskill install orange-line-illustration \
--dir ~/.my-agent/skillsMachine-readable output is available with --json.
API usage
import {SkillHubApiClient} from '@marswave/colaskill-cli';
const client = new SkillHubApiClient();
const result = await client.search({query: 'image design'});
console.log(result.items);Supported targets
| Agent | User scope | Project scope |
| ----------- | --------------------------- | -------------------- |
| Cola | ~/.cola/skills | — |
| Codex | ~/.codex/skills | ./.agents/skills |
| Claude Code | ~/.claude/skills | ./.claude/skills |
| Cursor | ~/.cursor/skills | ./.cursor/skills |
| Gemini CLI | ~/.gemini/skills | ./.gemini/skills |
| Hermes | ~/.hermes/skills | — |
| OpenCode | ~/.config/opencode/skills | ./.opencode/skills |
| Antigravity | ~/.gemini/config/skills | ./.agents/skills |
| OpenClaw | ~/.openclaw/skills | ./.openclaw/skills |
Use --dir for any other compatible Agent.
Installation safety
The CLI:
- requires a valid SHA-256 checksum from Cola Skill Hub;
- accepts only HTTPS package URLs;
- limits compressed size, extracted size, file size, and file count;
- rejects encrypted archives, path traversal, absolute paths, and symbolic links;
- requires exactly one
SKILL.mdroot; - extracts to a temporary directory and replaces an existing installation only with
--force; - rolls back the previous installation if replacement or inventory persistence fails;
- never executes package scripts during installation.
Installation metadata is written to <skill>/.colaskill/metadata.json. The CLI inventory
is stored in ~/.colaskill/inventory.json by default.
Development
npm install
node --run typecheck
npm test
node --run buildUse the staging API while developing:
node --run dev -- --api-base https://api.staging.colaos.ai search illustration