Current SkillBox dashboard showing Calls, History references, update states, and runtime targets

macOS desktop app · open source · local-first

SkillBox

Local skill manager for AI agents.

Keep Agents, Codex, Claude Code, Cursor, and project-local SKILL.md roots organized from one managed store. Review one GitHub repository snapshot, resolved SHA, and selected child skills before SkillBox writes or deploys anything.

~/.skillbox source of truth
5 profiles runtime-aware workspaces
Calls + references local evidence stays transparent

v0.9.0 · 30-second overview

See the workflow before installing.

The demo follows one managed library through runtime-aware workspaces, reviewed GitHub installs, one-SHA child selection, compatibility checks, evidence-aware Calls, and transparent local coverage.

This v0.9.0 promo keeps runtime folders intentional while ~/.skillbox remains the local source of truth. The current collection-header workflow appears below.

Library

One library for local and remote skills

User skills and GitHub-backed remote skills live under a managed store, so agent folders are deployment targets instead of hidden state.

SkillBox dashboard with local and remote skill cards, Calls, and History references

GitHub collections

Choose one type. Import only eligible children.

SkillBox fetches one bounded repository ref, shows the resolved SHA, child status, and runtime compatibility before it writes. The current project UI applies one explicit User/Remote choice to actionable children, then selects or clears the eligible set from the collection header. Mixed or unresolved type state stays blocked, every child remains independently managed, nothing deploys automatically, and collection-level update and rollback remain Phase D work.

Phase C first shipped in v0.9.0; the shared header controls shown here build on that reviewed per-child boundary. Validated copied skills may also group by normalized GitHub source as display-only provenance, without inventing branch, HEAD, or update authority.

SkillBox collection import review showing one shared Remote type choice, selected eligible children, and a blocked conflict

Runtime profiles

Know exactly where each skill can run

Workspaces identify Agents, Codex, Claude Code, Cursor, and exact custom roots. Deployment stays explicit and ~/.skillbox remains the source of truth.

SkillBox Workspaces showing runtime profile, scope, root path, Calls, and History references

Local evidence

Rank Calls. Keep references separate.

Calls combine locally confirmed and defensible inferred invocations. Lower-signal History references stay separate, with provider coverage available on demand.

SkillBox Rankings with Top skills, full ranking, and expanded confirmed, inferred, and reference coverage

Audit trail

Calls, references, and operations stay inspectable

Sync local Codex, Claude Code, and Cursor histories without copying chat bodies. The History view preserves evidence class and management operations without claiming account analytics.

SkillBox History with separate Calls, References, and Operations filters

Trust boundaries

Built for local-first skill management.

Runtime folders, GitHub URLs, downloaded archives, and existing skills are treated as untrusted input.

Local source of truth `~/.skillbox` holds managed copies, versions, metadata, and backups.
Signed macOS releases GitHub Releases publish signed and notarized DMGs with updater artifacts.
Version history GitHub sources stay linked to immutable skill versions for preview and rollback.
No silent overwrite Existing runtime content is reviewed instead of being replaced behind your back.
One reviewed SHA GitHub collection children share the reviewed snapshot; collection update and rollback are not automatic.

FAQ

Questions people search before installing.

Short answers for developers evaluating SkillBox as their local-first skill manager.

What is SkillBox?

SkillBox is a local-first macOS app and CLI for organizing AI agent skills from one managed library. It focuses on Codex skills, Claude skills, and other SKILL.md-based workflows that need safer import, update, and deployment controls.

Where does SkillBox store skills?

SkillBox stores managed user skills and GitHub-backed remote skills under ~/.skillbox. Runtime folders are treated as deployment targets instead of the only source of truth.

Which agent runtimes does SkillBox target?

SkillBox targets local SKILL.md runtime folders such as .codex/skills, .agents/skills, .claude/skills, and project-local skill roots. The product is built around explicit workspace targets so a single skill library can deploy to the runtimes you use.

How are GitHub-backed skill updates reviewed?

GitHub-backed remote skills stay linked to their source and version history. SkillBox previews remote diffs before applying changes, so imports and updates can be reviewed before they touch runtime folders.

How does a GitHub skill collection work?

A repository or tree ref is fetched once and reviewed as one snapshot. In the current project UI, one collection-header User/Remote decision resolves actionable children and Select all changes only the eligible set; unresolved, invalid, imported, system, or conflicted children stay unchanged. Each selected child remains an independent managed skill, and collection-level update and rollback are not included yet.

Is SkillBox available beyond macOS?

macOS is the current release target. SkillBox is open source, but the packaged desktop app and signed releases are currently focused on macOS.

Install

Get the current macOS release.

SkillBox currently targets macOS. Download the latest signed DMG or install the cask from the project tap.

GitHub Releases Download for macOS Latest signed and notarized DMG
brew tap santosli/tap
brew install --cask skillbox