SkillOptimizer

For skill authors

Show readers what your skill was measured to do, check every change to it before it merges, and call the same check from your own tools.

Add the badge to your README

Every skill with a page on this site has a badge. It states only what was measured: how much lighter, or how much cheaper on a smaller model. A skill we haven't tested says so, with no number.

Example badge for Work Execution Command

The snippets below are for the example skill. For yours, replace ce-work with the last part of its page address, /skills/<name>. A skill without a page doesn't have a badge yet: check it first.

Markdown
[![SkillOptimizer result](/badge/ce-work.svg)](/skills/ce-work)

HTML
<a href="/skills/ce-work"><img src="/badge/ce-work.svg" alt="SkillOptimizer result" /></a>

Check every change in CI

The GitHub Action checks every changed SKILL.md in a pull request and comments the answer with AIR's security review beside it. It keeps one comment per pull request and updates it on every push.

It runs the free check, the same one anyone can start here without signing in. It never calls a skill lighter, because only a measured test earns that and the action doesn't start one. It tells you whether there is anything worth measuring, and whether the skill is safe to install.

.github/workflows/skilloptimizer.yml
name: SkillOptimizer check on: pull_request: paths: - "**/SKILL.md" permissions: contents: read pull-requests: write jobs: check: runs-on: ubuntu-latest steps: - uses: skilloptimizer/action@v1 with: api-url: https://api.skilloptimizer.dev

The action name and API address in this snippet are placeholders until the action is published.

api-url
Required. The address of the SkillOptimizer API.
site-url
When set, each result in the comment links to its own page here.
paths
Which changed files to check. Defaults to every SKILL.md.
api-key
Optional. Gives the action its own rate limit; it does not change what the check can do.

The job needs pull-requests: write to post its comment and contents: read to read the changed files.

Call the API

Everything this site does with a skill goes through a public API. POST /v1/checks takes a pasted SKILL.md, an upload or a link, and streams the reading stages, then the result with the security review. The full reference is the API's own /docs page.

Check a skill from your terminal
curl -N /v1/checks -H 'content-type: application/json' -d '{"kind":"url","value":"https://github.com/<owner>/<repo>/blob/main/<skill>/SKILL.md"}'