How find-skills Works: In-Session Discovery, Frontmatter Triggers, and Safe Installation
When an autonomous coding agent encounters a specialized problem, its default behavior is to improvise. If you ask an agent to optimize SVGs, audit Core Web Vitals, or format a changelog, it attempts to write bespoke code from scratch. That improvisation costs reasoning tokens, risks edge-case errors, and forces you to re-explain domain conventions you have already solved elsewhere.
The alternative is progressive discovery: enabling the agent to search an open registry of vetted skills, identify a pre-authored procedure, and install it directly into your session. That is the exact mechanism provided by find-skills, an open-source instruction package published inside vercel-labs/skills on skills.sh.

1. What find-skills Is (and What It Is Not)
It is easy to misunderstand what find-skills actually does. It is not an embedded search engine, a vector database, or a runtime server. It is a single instruction file (skills/find-skills/SKILL.md) that teaches Claude Code when to run the CLI installer, how to evaluate candidate packages, and how to request human confirmation before modifying your workspace.
Anthropic published the Agent Skills format in October 2025 as an open specification: a directory containing a SKILL.md file with YAML frontmatter (name and description), accompanied by optional scripts and references. In December 2025, Anthropic opened the specification so identical skill packages run across Claude Code, Cursor, Codex, and other agent harnesses.
Vercel built the discovery layer on top of that standard. Andrew Qu, Chief of Software at Vercel, launched skills.sh, a centralized index of public agent skills ranked by anonymous install metrics. The accompanying CLI tool, vercel-labs/skills (MIT licensed, v1.7.0, over 33k GitHub stars), provides the execution backbone executed via npx skills.
2. Frontmatter Calibration and Intent Triggers
In Claude Code, skills do not load their entire markdown content into memory at startup. Instead, the agent inspects only the YAML frontmatter description during task intake. A skill activates only when the user prompt semantically matches its trigger conditions.
The frontmatter inside find-skills is calibrated to awaken on specific conversational patterns:
- Direct inquiries: "How do I do X?", "Find a skill for X", or "Is there a skill that can handle this?"
- Implicit domain wishes: When a user wishes out loud that the agent possessed specialized domain knowledge (such as Tailwind refactoring, end-to-end testing, or PR reviews).
- Repeated friction: When the agent recognizes a multi-step routine that benefits from an established community playbook.
By keeping trigger criteria explicit, find-skills stays dormant during ordinary coding tasks and activates only when external procedural knowledge is genuinely needed.
3. The Step-by-Step Discovery Protocol
Once triggered, find-skills does not guess or install packages blindly. It executes a disciplined six-stage evaluation loop:
- Stage 1: Isolate Domain and Objective. The agent extracts the core subject matter (such as SVG optimization, schema markup, or git branch hygiene).
- Stage 2: Query the Registry Leaderboard. The agent queries skills.sh to check whether an authoritative, widely installed skill already exists for the domain.
- Stage 3: Targeted Search Execution. If the leaderboard lacks an exact match, the agent runs "npx skills find [query]", optionally scoped with the --owner flag.
- Stage 4: Quality and Safety Filtering. The agent filters results against strict confidence thresholds. It favors skills with 1,000+ installs, verified maintainers (such as vercel-labs, anthropics, or microsoft), and active GitHub repositories with over 100 stars. Packages with fewer than 100 installs or unverified provenance are flagged as unvetted.
- Stage 5: Present the Verified Candidate. The agent presents the package name, description, install count, source repository, and the exact install command.
- Stage 6: The Graceful Miss. If no reputable skill matches the query, the agent explicitly reports the absence, proceeds with the task using its native capabilities, and suggests "npx skills init" so you can author a custom skill for your project.
4. Installation Surfaces: Project-Local vs Global
When you accept an installation recommendation, the CLI offers two distinct placement options:
For individual repositories, local installation is preferred because it checks the SKILL.md into version control, ensuring every teammate and CI runner shares identical capabilities. Global installation is ideal for meta-tooling like find-skills itself, allowing any session to locate new skills on demand.
5. Context Window Economics and Skill Pruning
A common mistake among skill authors is hoarding dozens of installed skills. Remember a fundamental rule of agentic engineering: a loaded skill is not free.
Every skill registered in your workspace consumes token budget during the system prompt intake. If an agent loads 20 skills, their frontmatter descriptions crowd the context window, dilute model attention, and can induce hallucinations or trigger unwanted routines. Furthermore, a skill file contains executable instructions: an unaudited skill from an unknown author can run shell commands on your machine.
Audit your skills regularly. When a project sprint finishes or a one-off workflow concludes, remove unused skills using the CLI:
npx skills remove <skill-name>Featured Knowledge Path: The Prompt and Context Engineering Path
Discovering and calibrating modular agent skills is a cornerstone of our curriculum for professional AI tool builders:
- Step 1: Skill Authoring and Progressive Disclosure. Author lightweight SKILL.md packages that reveal instructions only when triggered.
- Step 2: Intent Calibration and Frontmatter Design. Craft descriptions that trigger with precision on complex user queries without false positives.
- Step 3: Ecosystem Discovery and Tool Lifecycle. Integrate registry tooling like find-skills, conduct security audits, and prune unneeded skills to protect context memory.
Cross-Site Perspectives
For DevOps engineers and repository maintainers evaluating worktree isolation, automated CI/CD audits, and headless package verification, read our companion piece on Claude Skills Hub: [Automating Agent Skill Discovery with npx skills: CI Toolchains, Registry Vetting, and Worktree Scoping](https://claudeskillsgithub.com/blog/automating-agent-skill-discovery-npx-skills-github).
For enterprise systems architects and engineering leaders analyzing token decay, SOC2 governance boundaries, and public versus private registry architectures, explore the deep dive on ClaudeSkillsGuide: [find-skills and the Open Registry Architecture: Autonomous Discovery, Context Overhead, and Enterprise Governance](https://claudeskillsguide.com/blog/find-skills-open-registry-architecture-enterprise-governance).
Never miss a post
Updates on format changes, community features, and skill building.