[18.10.0] - 2026-09-30 - "SME Operations, 15 Official Beatra Skills, and Four New Advisories Closed"
Adds 124 reviewed skills - a complete SME operations catalog and fifteen official Beatra media skills - hardens the protected maintainer gates, closes ten Dependabot advisories, and ships 2,602 skills.
A catalog release for Claude Code, Cursor, Codex CLI, Gemini CLI, and related AI coding assistants. It includes the complete protected maintainer batch merged after 18.9.0, with existing installation interfaces preserved.
Start here
- Install:
npx agentic-awesome-skills@18.10.0 - Choose your tool
- Best skills by tool
- Bundles
- Workflows
Added
- SME operations catalog (#1688, #1689, #1690-#1698) — 106 small-business operations skills covering people, finance, compliance, projects, knowledge, and reporting: onboarding and offboarding, payroll and expense accounting, credit-cycle analysis, contracts and policy libraries, capacity and workload planning, KPI and OKR tracking, recruitment and career development, and month-end close. Each is a self-contained Markdown workflow with explicit limitations and no bundled executables; the batch keeps every entry inside the repository's 500-line budget with detail in
references/. - Fifteen official Beatra media skills (#1473-#1487) —
beatra,talking-avatar-video,suno-lyrics-to-song,ai-logo-maker,music-generation-studio,product-photo-studio,poster-design-studio,ecommerce-listing-image-set,ai-image-generation-studio,ai-podcast-voiceover,voiceover-narration-studio,ai-multilingual-dubbing,voice-cloning-studio,ai-photo-restyler, andviral-video-teardown-remake. Each entry is a reviewed pointer, not the executable package: it pins the archive URL and SHA-256, requires digest verification and a manual inspection before activation, and disables the client's silent self-update before any other command.risk: critical, paid hosted work. - mirrord (#1706) —
mirrordruns a local process inside a live Kubernetes pod's network, environment, and traffic so a change can be verified against real services without deploying. Asks before traffic-stealing or cluster-modifying steps.risk: safe. - Busabase workspace (#1682) —
busabasecovers authorized workspace record and knowledge operations, permission-aware ChangeRequests, and canonical-versus-pending readback through the hosted MCP server.risk: critical. - Changelog entry (#1699) —
changelog-entryturns a commit range or pull request into a Keep a Changelog block, grouping conventional-commit types into Added, Changed, Deprecated, Removed, Fixed, and Security.risk: safe.
Changed
- SkillSpector advisory scans (#1703) — add a PR-only, non-blocking SkillSpector workflow that waits for the exact-head
pr-evidenceresult, then scans full changed skill directories from immutable Git refs with a pinned NVIDIA SkillSpector v2.12.0, a frozen dependency lock, no scanner credentials, and a Linux network namespace. Reports bind the base and head SHA and remain advisory; they satisfy no required check and change no merge authority. - Dependency advisories (#1712) — close ten open Dependabot alerts by resolving
brace-expansion1.1.21 and 5.0.12,fast-uri3.1.8, andip-address10.7.2 in the root, catalog web app, and thetelegramandwhatsapp-cloud-apiexample lockfiles, using the override pattern already present in those manifests. The mirrored plugin copies are regenerated by the protected canonical-sync lane.npm auditreports zero vulnerabilities in all four manifests. - Vercel production headers (#1685) — tighten the hosted catalog's production response headers and document the intended policy.
- Contributor rendering (#1683) — keep enough contrib.rocks headroom that the README shows every contributor instead of truncating the list.
- Maintainer documentation (#1707) — align the canonical maintainer skill with the current CI workflow and the SkillSpector report interpretation.
Fixed
- Fork copy classification (#1709) — a new
SKILL.mdthat Git paired as a copy of an existing file was accepted or rejected depending on whether the similarity heuristic chose a canonical skill or a generated plugin mirror as the copy origin. The fork classifier now treats a copy origin as read-only, matching the documented source-only rule, while the destination still carries every path, mode, object, and size check and editing, renaming, or deleting that origin still fails closed. - Fork run allowlist (#1714) — the PR-only SkillSpector workflow was missing from the fork-run approval allowlist, so every fork pull request stalled on
action_requiredwith no required check able to run. The read-only, secretless, SHA-pinned workflow is now approvable, and a regression test binds the allowlist entry to that contract.
Documentation and community
- Added the
busabase/skillsandmetalbear-co/skillssource credits plus fifteen official Beatra source credits to the README. - Thanks to @WHOISABHISHEKADHIKARI for the eleven SME operations batches and for repairing the dangling catalog links and oversized entries, @beatra-ai for the fifteen official Beatra media skills, @ranglang for
busabase, @hank-metalbear formirrord, and @Prajeeth-12 forchangelog-entry.
Validation scope
Exact-head maintainer review for changed skill content, protected source PRs, repository validation and tests, reference validation, docs security, protected CI and CodeQL, dependency review, canonical synchronization, release preflight, npm publication, and release provenance verification.