Token导航 LogoToken导航TokenDH.com
研究检索external-servicegithub未标认证来源可访问许可证需确认审计通过

skill-extractor技能提取器

Agent Skill

skill-extractor 用于查找、检索和筛选相关信息,适合在 Codex、Claude、Cursor、Gemini CLI 中需要根据关键词、任务场景或来源线索快速定位候选结果时使用。可结合来源仓库、安装命令和原始 README 继续核验具体用法。安装前建议确认权限范围、维护状态,以及是否会触发联网、命令执行或文件读写。

总安装

954

周安装

41

GitHub Stars

377

下载量

335
CodexClaudeCursorGemini CLI

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

unknown

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:skill-extractor(技能提取器)
来源仓库:https://github.com/trailofbits/skills-curated
仓库路径:skills/skill-extractor
安装命令:
npx skills add https://github.com/trailofbits/skills-curated --skill skill-extractor
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 npx skills 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

skills.shnpx skills
npx skills add https://github.com/trailofbits/skills-curated --skill skill-extractor

简介

用于从代码库或文档中提取可复用技能片段,辅助 Agent 能力扩展。

  • 可识别函数、类或注释中的模式,生成标准化 skill 定义文件。
  • 支持多种编程语言与格式输入,输出符合规范的结构化元数据。
  • 提取过程可能涉及大量文件扫描,建议在沙箱环境中运行以防误操作。
  • 当前无详细用例,建议查看源码中是否包含排除规则或白名单机制。

SKILL.md

Skill Extractor

Extracts reusable knowledge from work sessions and saves it as a Claude Code skill.

When to Use

  • Just solved a non-obvious problem through investigation
  • Discovered a workaround that required trial-and-error
  • Found a debugging technique that would help in similar situations
  • Learned a project-specific pattern worth preserving
  • Fixed an error where the root cause wasn't immediately apparent

When NOT to Use

  • Simple documentation lookups (just bookmark the docs)
  • Trivial fixes (typos, obvious errors)
  • One-off project-specific configurations
  • Knowledge that's already well-documented elsewhere
  • Unverified solutions (wait until it actually works)

Finding Extraction Candidates

Use these prompts to identify knowledge worth extracting:

  • "What did I just learn that wasn't obvious before starting?"
  • "If I faced this exact problem again, what would I wish I knew?"
  • "What error message or symptom led me here, and what was the actual cause?"
  • "Is this pattern specific to this project, or would it help in similar projects?"
  • "What would I tell a colleague who hits this same issue?"

If you can't answer at least two of these with something non-trivial, it's probably not worth extracting.

Command

/skill-extractor [--project] [context hint]
  • Default: saves to ~/.claude/skills/[name]/SKILL.md
  • --project: saves to .claude/skills/[name]/SKILL.md
  • Context hint helps focus extraction (e.g., /skill-extractor the cyclic data DoS fix)

Extraction Process

Step 0: Check for Existing Skills

Before creating a new skill, search for existing ones that might cover the same ground:

# Check user skills
ls ~/.claude/skills/

# Check project skills
ls .claude/skills/

# Search by keyword
grep -r "keyword" ~/.claude/skills/ .claude/skills/ 2>/dev/null

If a related skill exists, consider updating it instead of creating a new one. See skill-lifecycle.md for guidance on when to update vs create.

Step 1: Identify the Learning

If $ARGUMENTS contains a context hint (e.g., "the cyclic data DoS fix"), use it to focus the extraction on that specific topic.

Analyze the conversation to identify:

  • What problem was solved?
  • What made the solution non-obvious?
  • What would someone need to know to solve this faster next time?
  • What are the exact trigger conditions (error messages, symptoms)?

Present a brief summary to the user:

I identified this potential skill:

**Problem:** [Brief description]
**Key insight:** [What made it non-obvious]
**Triggers:** [Error messages or symptoms]

Step 2: Quality Assessment

Evaluate the candidate skill against these criteria:

CriterionPass?Evidence
Reusable - Helps future tasks, not just this instance[Why]
Non-trivial - Required discovery, not docs lookup[Why]
Verified - Solution actually worked[Evidence]
Specific triggers - Exact error messages or scenarios[What they are]
Explains WHY - Trade-offs and judgment, not just steps[How]
Value-add - Teaches judgment, not just facts Claude could look up[How]

Present assessment to user and ask: "Proceed with extraction? [yes/no]"

The user decides whether to proceed regardless of how many criteria pass. Respect their judgment - if they say yes, extract; if no, skip.

Step 3: Gather Details

Ask the user:

  1. Skill name - Suggest a kebab-case name based on context, let them override
  2. Scope - User-level (default) or project-level (--project)

Step 4: Optional Research

If the topic involves a specific library or framework:

  • Use web search to find current best practices
  • Use Context7 MCP (if available) for official documentation
  • Include relevant sources in the References section

Skip research for:

  • Project-specific internal patterns
  • Generic programming concepts
  • Time-sensitive extractions

Step 5: Generate the Skill

Use the template from skill-template.md.

Quality standards: Follow quality-guide.md to ensure the skill provides lasting value. Key points:

  • Behavioral guidance over reference dumps
  • Explain WHY, not just WHAT
  • Specific triggers that compete well against other skills

Step 6: Validate Before Saving

Run through the validation checklist in skill-template.md. If validation fails, fix the issues before saving.

Step 7: Save the Skill

Create the directory and save:

  • User-level: ~/.claude/skills/[name]/SKILL.md
  • Project-level: .claude/skills/[name]/SKILL.md

Report success:

Skill saved to: [path]

The skill will be available in future sessions when the context matches:
"[first line of description]"

Memory Consolidation

When extracting, consider how the new knowledge relates to existing skills:

Combine or separate?

  • Combine if the new knowledge is a variation or edge case of an existing skill
  • Separate if it has distinct trigger conditions or solves a fundamentally different problem
  • When in doubt, start separate - you can always merge later

Update vs create:

  • Update an existing skill when you've discovered additional edge cases, better solutions, or corrections
  • Create a new skill when the knowledge has different trigger conditions, even if the domain is related

Cross-referencing:

  • If skills are related but separate, add a "See also" section linking them
  • Example: A skill for "debugging connection pool exhaustion" might link to "serverless cold start optimization"

Skill Lifecycle

Skills aren't permanent. See skill-lifecycle.md for guidance on:

  • Updating skills with new discoveries
  • Deprecating skills when tools or patterns change
  • Archiving skills that are no longer relevant

Rationalizations to Reject

If you catch yourself thinking any of these, do NOT extract:

  • "This might be useful someday" - Only extract verified, reusable knowledge
  • "Let me just save everything" - Quality over quantity
  • "The user didn't confirm but it seems valuable" - Always get explicit confirmation
  • "I'll skip the 'When NOT to Use' section" - It's mandatory for good skills
  • "The description can be vague" - Specific triggers are essential for discovery

Example Extraction

Scenario: User discovered that an AST visitor crashes with RecursionError when analyzing serialized files containing cyclic references (e.g., a list that contains itself).

Identified learning:

  • Cyclic data structures create cyclic ASTs
  • Visitor pattern without cycle tracking causes infinite recursion
  • Need to track visited nodes or enforce depth limits

Generated skill name: cyclic-ast-visitor-hardening

Key sections:

  • When to Use: "RecursionError in AST visitor", "analyzing untrusted serialized input"
  • When NOT to Use: "Recursion from deeply nested (but acyclic) structures"
  • Problem: Visitor doesn't track visited nodes, enters infinite loop on cycles
  • Solution: Add visited: set parameter, check before recursing
  • Verification: Cyclic test case completes without RecursionError

适合场景

01

用户想查找某类 Agent Skill 时

02

需要根据任务场景推荐可安装能力包时

03

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

Codex

39.63%
按下载量换算133

Claude

27.48%
按下载量换算92

Cursor

17.56%
按下载量换算59

Gemini CLI

9.42%
按下载量换算32

安全审计

Gen Agent Trust Hub

通过

Socket

通过

Snyk

通过

权限和风险

external-service

该 Skill 可能调用第三方服务、云服务或外部模型 API,使用前需要确认账号、额度、数据发送范围和服务条款。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills