github sickn33/agentic-awesome-skills v18.10.0
v18.10.0 "SME Operations, 15 Official Beatra Skills, and Four New Advisories Closed"

4 hours ago

[18.10.0] - 2026-09-30 - "SME Operations, 15 Official Beatra Skills, and Four New Advisories Closed"

Adds 124 reviewed skills - a complete SME operations catalog and fifteen official Beatra media skills - hardens the protected maintainer gates, closes ten Dependabot advisories, and ships 2,602 skills.

A catalog release for Claude Code, Cursor, Codex CLI, Gemini CLI, and related AI coding assistants. It includes the complete protected maintainer batch merged after 18.9.0, with existing installation interfaces preserved.

Start here

  • Install: npx agentic-awesome-skills@18.10.0
  • Choose your tool
  • Best skills by tool
  • Bundles
  • Workflows

Added

  • SME operations catalog (#1688, #1689, #1690-#1698) — 106 small-business operations skills covering people, finance, compliance, projects, knowledge, and reporting: onboarding and offboarding, payroll and expense accounting, credit-cycle analysis, contracts and policy libraries, capacity and workload planning, KPI and OKR tracking, recruitment and career development, and month-end close. Each is a self-contained Markdown workflow with explicit limitations and no bundled executables; the batch keeps every entry inside the repository's 500-line budget with detail in references/.
  • Fifteen official Beatra media skills (#1473-#1487) — beatra, talking-avatar-video, suno-lyrics-to-song, ai-logo-maker, music-generation-studio, product-photo-studio, poster-design-studio, ecommerce-listing-image-set, ai-image-generation-studio, ai-podcast-voiceover, voiceover-narration-studio, ai-multilingual-dubbing, voice-cloning-studio, ai-photo-restyler, and viral-video-teardown-remake. Each entry is a reviewed pointer, not the executable package: it pins the archive URL and SHA-256, requires digest verification and a manual inspection before activation, and disables the client's silent self-update before any other command. risk: critical, paid hosted work.
  • mirrord (#1706) — mirrord runs a local process inside a live Kubernetes pod's network, environment, and traffic so a change can be verified against real services without deploying. Asks before traffic-stealing or cluster-modifying steps. risk: safe.
  • Busabase workspace (#1682) — busabase covers authorized workspace record and knowledge operations, permission-aware ChangeRequests, and canonical-versus-pending readback through the hosted MCP server. risk: critical.
  • Changelog entry (#1699) — changelog-entry turns a commit range or pull request into a Keep a Changelog block, grouping conventional-commit types into Added, Changed, Deprecated, Removed, Fixed, and Security. risk: safe.

Changed

  • SkillSpector advisory scans (#1703) — add a PR-only, non-blocking SkillSpector workflow that waits for the exact-head pr-evidence result, then scans full changed skill directories from immutable Git refs with a pinned NVIDIA SkillSpector v2.12.0, a frozen dependency lock, no scanner credentials, and a Linux network namespace. Reports bind the base and head SHA and remain advisory; they satisfy no required check and change no merge authority.
  • Dependency advisories (#1712) — close ten open Dependabot alerts by resolving brace-expansion 1.1.21 and 5.0.12, fast-uri 3.1.8, and ip-address 10.7.2 in the root, catalog web app, and the telegram and whatsapp-cloud-api example lockfiles, using the override pattern already present in those manifests. The mirrored plugin copies are regenerated by the protected canonical-sync lane. npm audit reports zero vulnerabilities in all four manifests.
  • Vercel production headers (#1685) — tighten the hosted catalog's production response headers and document the intended policy.
  • Contributor rendering (#1683) — keep enough contrib.rocks headroom that the README shows every contributor instead of truncating the list.
  • Maintainer documentation (#1707) — align the canonical maintainer skill with the current CI workflow and the SkillSpector report interpretation.

Fixed

  • Fork copy classification (#1709) — a new SKILL.md that Git paired as a copy of an existing file was accepted or rejected depending on whether the similarity heuristic chose a canonical skill or a generated plugin mirror as the copy origin. The fork classifier now treats a copy origin as read-only, matching the documented source-only rule, while the destination still carries every path, mode, object, and size check and editing, renaming, or deleting that origin still fails closed.
  • Fork run allowlist (#1714) — the PR-only SkillSpector workflow was missing from the fork-run approval allowlist, so every fork pull request stalled on action_required with no required check able to run. The read-only, secretless, SHA-pinned workflow is now approvable, and a regression test binds the allowlist entry to that contract.

Documentation and community

  • Added the busabase/skills and metalbear-co/skills source credits plus fifteen official Beatra source credits to the README.
  • Thanks to @WHOISABHISHEKADHIKARI for the eleven SME operations batches and for repairing the dangling catalog links and oversized entries, @beatra-ai for the fifteen official Beatra media skills, @ranglang for busabase, @hank-metalbear for mirrord, and @Prajeeth-12 for changelog-entry.

Validation scope

Exact-head maintainer review for changed skill content, protected source PRs, repository validation and tests, reference validation, docs security, protected CI and CodeQL, dependency review, canonical synchronization, release preflight, npm publication, and release provenance verification.

Don't miss a new agentic-awesome-skills release

NewReleases is sending notifications on new releases.