skillshare v0.25.0 Release Notes
TL;DR
skillshare mcp serveserves your skills over MCP to Agents that cannot reach the synced folders, with tools for clients that do not support the Skills extension yet.skillshare linkandunlinkuse a skills folder where it already lives, such as your own checkout or an external drive, also from the dashboard.- Oh My Pi gets MCP, code hooks, plugins and extension selection.
- Two new targets, DeepSeek Harness and GitLab Duo, and Unicode skill names under
target_naming: standard.
Serve skills over MCP
skillshare mcp serve is a read-only MCP server for Agents that cannot reach the synced skills folders, such as one in a throwaway VM or behind an MCP gateway.
skillshare mcp serve # stdio, every enabled skill
skillshare mcp serve --target claude # only what the claude target selects
skillshare mcp serve --check # list skipped skills and exit
SKILLSHARE_MCP_TOKEN=change-me skillshare mcp serve --http 0.0.0.0:8765 \
--tls-cert cert.pem --tls-key key.pem # HTTPS for other machines- It implements the Skills extension (SEP-2640). Each skill is one entry with its full frontmatter and a manifest of its files with their
sha256digest and size. - Most Agents do not support the extension yet, so the server also offers
list_skillsandread_skill. Any Agent that uses MCP tools can read skills through them; a client that declares the extension gets the skills natively and does not see the tools. - Changes in the source show up within 5 seconds without a restart. Global by default;
-pserves the project in the current directory. - A skill that breaks the Agent Skills format (for example a
namethat differs from its directory), has more than 512 files or 16 MiB, or contains a nested skill that is not served is skipped with a warning on stderr. --httpon a non-loopback address requiresSKILLSHARE_MCP_TOKENand HTTPS through--tls-certand--tls-key, or a loopback address behind a TLS proxy. Cross-origin browser requests are refused.
In the dashboard, Add server has a Skillshare tab that adds skillshare mcp serve as an MCP server, with the target and scope to serve. Do not connect local Agents that already sync skills: they would see each skill twice.
Thanks to @salmonumbrella for proposing this in #428 with a thorough spec that shaped most of the design.
Followed source links
Link a folder directly under the skills source and skillshare lists and syncs the skills inside it, without installing a copy.
skillshare link ~/code/dev-skills --enable # links it as _dev-skills
skillshare sync
skillshare unlink _dev-skills # removes only the link--enablealso turns onfollow_source_links, globally or per project. With it on,list,sync,status,auditand the dashboard find the skills inside first-level links.- On Windows,
linkcreates a junction, which needs no Developer Mode. - A link that would loop back into the source, overlaps a sync target, or is missing is skipped with a warning.
- While a linked external drive is unmounted, that run deletes nothing: target links, copies and install metadata stay until it is back.
update --allskips linked checkouts, because they are your own working copies; update one by name.
On the Skills page, Link folder does the same with a path, an optional name and the follow_source_links switch. A linked folder is listed as its own group, and its row unlinks it after a confirmation; the link can be restored from Trash.
Oh My Pi
The omp target already received skills and instructions. It now also gets:
- MCP servers in its own
mcpServersformat. - Code hooks as native extensions.
- Plugins from reviewed local or Git sources, or imported from its marketplace.
- A guarded Extensions tab for choosing which extensions load.
An account declared with agent: omp gets skills, instructions, MCP and code hooks.
skillshare mcp add docs --url https://example.com/mcp --target omp -g --sync
skillshare plugin add ./my-omp-plugin --target omp -gThanks to @salmonumbrella for requesting this in #409.
Targets
- DeepSeek Harness and GitLab Duo are new built-in targets:
deepseek-harnessandgitlab-duo. - Unicode skill names. Under
target_naming: standard, names in lowercase letters of any script, such ascaféor日本語-tool, now sync like ASCII names instead of being skipped. Underscores are still rejected.
Other fixes
updateand linked repositories. A link inside the skills source to a checkout elsewhere was treated as a tracked repo, soskillshare updateand the dashboard rangit pullthere, and with--forcereset it. A linked checkout is now only updated when you name it. Git worktrees and submodules, which have a.gitfile, get the same guards.- Option values that look like a scope flag. In commands such as
link --name -g, the value was read as the-gflag. A value after an option that takes one now stays its value, and--ends the options. - Windows junctions across drives. When the skills source and the trash were on different drives,
unlinkandtrash restorerecreated a junction as a symlink, which needs Developer Mode. It now stays a junction. - Plugin commits without a new version. A repository that pushes commits without changing its version showed the same version with an Update button. The version tag now adds the old → new commit.
- Pi OAuth client registration.
oauth.clientRegistrationacceptsdcrorcimd. Withcimd, aclientIdorclientName, or acallbackUrlother than HTTP onlocalhostor127.0.0.1with path/callback, is reported before sync instead of being written to Pi. - Skills search with no match. Linked folders no longer appear as empty groups while a search or filter excludes every skill, so Clear filters is shown.