// the find
midudev/autoskills
One command. Your entire AI skill stack. Installed.
autoskills is a CLI (`npx autoskills`) that scans a project's manifest files (package.json, Gradle, etc.), figures out the tech stack, and drops matching AI-agent skill files (SKILL.md plus reference docs) into your repo for tools like Claude, Codex, and opencode. It's aimed at developers who want stack-specific agent context without hand-assembling skill files for every framework they touch.
Skills aren't fetched live from arbitrary upstream repos at install time - they're synced into a repo-local registry, hashed with SHA-256, and pinned in a manifest, with a skills-lock.json recording exactly what was installed and from where; that's a real supply-chain mitigation for a tool whose whole job is writing files based on your dependency list. Detection is based on parsing actual config files rather than guessing from extensions, so matches should be deterministic. Registry breadth is genuinely wide - frontend, backend, mobile, cloud infra (Durable Objects, Terraform), testing - each entry structured as SKILL.md plus references/scenarios, not just a README dump. Project hygiene (CI, compat workflow, dependabot, pre-commit hook, issue templates) suggests this is maintained, not a weekend script.
License is CC BY-NC 4.0 - noncommercial - so you can't bundle or ship it as part of anything commercial without separate permission, which rules it out for a lot of teams outright. The 'curated' registry is entirely maintainer-controlled via an internal sync-skills.mjs script pulling from unspecified upstream sources; the README gives the audit process one sentence, so you're trusting the maintainers' judgment on every file that gets written into your repo and fed to an agent with tool access. Detection only works off known manifest files (package.json, Gradle), so polyglot repos, Cargo/Go-only projects, or nonstandard monorepo layouts likely get nothing or a wrong match. No described update story for skills you've already installed - skills-lock.json records what was installed, but not how you detect or apply upstream changes to a SKILL.md you already have on disk.