Best practices

How find-skills Works: In-Session Discovery, Frontmatter Triggers, and Safe Installation

When an autonomous coding agent encounters a specialized problem, its default behavior is to improvise. If you ask an agent to optimize SVGs, audit Core Web Vitals, or format a changelog, it attempts to write bespoke code from scratch. That improvisation costs reasoning tokens, risks edge-case errors, and forces you to re-explain domain conventions you have already solved elsewhere.

The alternative is progressive discovery: enabling the agent to search an open registry of vetted skills, identify a pre-authored procedure, and install it directly into your session. That is the exact mechanism provided by find-skills, an open-source instruction package published inside vercel-labs/skills on skills.sh.

AI Agent Skill Discovery architecture diagram showing skills.sh registry workflow, evaluation metrics, and approval gate
In-Session Skill Discovery: how an agent detects task needs, queries the open registry via npx skills, verifies quality thresholds, and installs procedures into local storage.

1. What find-skills Is (and What It Is Not)

It is easy to misunderstand what find-skills actually does. It is not an embedded search engine, a vector database, or a runtime server. It is a single instruction file (skills/find-skills/SKILL.md) that teaches Claude Code when to run the CLI installer, how to evaluate candidate packages, and how to request human confirmation before modifying your workspace.

Anthropic published the Agent Skills format in October 2025 as an open specification: a directory containing a SKILL.md file with YAML frontmatter (name and description), accompanied by optional scripts and references. In December 2025, Anthropic opened the specification so identical skill packages run across Claude Code, Cursor, Codex, and other agent harnesses.

Vercel built the discovery layer on top of that standard. Andrew Qu, Chief of Software at Vercel, launched skills.sh, a centralized index of public agent skills ranked by anonymous install metrics. The accompanying CLI tool, vercel-labs/skills (MIT licensed, v1.7.0, over 33k GitHub stars), provides the execution backbone executed via npx skills.

2. Frontmatter Calibration and Intent Triggers

In Claude Code, skills do not load their entire markdown content into memory at startup. Instead, the agent inspects only the YAML frontmatter description during task intake. A skill activates only when the user prompt semantically matches its trigger conditions.

The frontmatter inside find-skills is calibrated to awaken on specific conversational patterns:

  • Direct inquiries: "How do I do X?", "Find a skill for X", or "Is there a skill that can handle this?"
  • Implicit domain wishes: When a user wishes out loud that the agent possessed specialized domain knowledge (such as Tailwind refactoring, end-to-end testing, or PR reviews).
  • Repeated friction: When the agent recognizes a multi-step routine that benefits from an established community playbook.

By keeping trigger criteria explicit, find-skills stays dormant during ordinary coding tasks and activates only when external procedural knowledge is genuinely needed.

3. The Step-by-Step Discovery Protocol

Once triggered, find-skills does not guess or install packages blindly. It executes a disciplined six-stage evaluation loop:

  1. Stage 1: Isolate Domain and Objective. The agent extracts the core subject matter (such as SVG optimization, schema markup, or git branch hygiene).
  2. Stage 2: Query the Registry Leaderboard. The agent queries skills.sh to check whether an authoritative, widely installed skill already exists for the domain.
  3. Stage 3: Targeted Search Execution. If the leaderboard lacks an exact match, the agent runs "npx skills find [query]", optionally scoped with the --owner flag.
  4. Stage 4: Quality and Safety Filtering. The agent filters results against strict confidence thresholds. It favors skills with 1,000+ installs, verified maintainers (such as vercel-labs, anthropics, or microsoft), and active GitHub repositories with over 100 stars. Packages with fewer than 100 installs or unverified provenance are flagged as unvetted.
  5. Stage 5: Present the Verified Candidate. The agent presents the package name, description, install count, source repository, and the exact install command.
  6. Stage 6: The Graceful Miss. If no reputable skill matches the query, the agent explicitly reports the absence, proceeds with the task using its native capabilities, and suggests "npx skills init" so you can author a custom skill for your project.

4. Installation Surfaces: Project-Local vs Global

When you accept an installation recommendation, the CLI offers two distinct placement options:

Comment: # Option 1: Install inside the current project only (.claude/skills/)
You type: npx skills add https://github.com/vercel-labs/skills --skill find-skills
Comment: # Option 2: Install globally for all Claude Code sessions (~/.claude/skills/)
You type: npx skills add vercel-labs/skills --skill find-skills -a claude-code -g -y
Comment: # Verify installed skills in the active workspace
You type: npx skills list
Choose between project-local isolation and global workstation availability.

For individual repositories, local installation is preferred because it checks the SKILL.md into version control, ensuring every teammate and CI runner shares identical capabilities. Global installation is ideal for meta-tooling like find-skills itself, allowing any session to locate new skills on demand.

5. Context Window Economics and Skill Pruning

A common mistake among skill authors is hoarding dozens of installed skills. Remember a fundamental rule of agentic engineering: a loaded skill is not free.

Every skill registered in your workspace consumes token budget during the system prompt intake. If an agent loads 20 skills, their frontmatter descriptions crowd the context window, dilute model attention, and can induce hallucinations or trigger unwanted routines. Furthermore, a skill file contains executable instructions: an unaudited skill from an unknown author can run shell commands on your machine.

Audit your skills regularly. When a project sprint finishes or a one-off workflow concludes, remove unused skills using the CLI:

npx skills remove <skill-name>
Interactive Claude Code Session: In-Session Skill Discovery with find-skills
web-app/Search skills.sh for SVG Optimization
Is there a skill that can optimize our React SVG icon assets and strip useless XML attributes?
I found two established skills on the open registry: 1. **vercel-labs/skills@svg-optimizer** (12,400 installs, verified partner audit) Optimizes raw SVGs, strips XML boilerplate, and formats JSX icon components. Install: npx skills add vercel-labs/skills --skill svg-optimizer 2. **antfu/skills@svgo** (8,200 installs, GitHub 18k stars) Deep SVGO pipeline with custom precision thresholds. Would you like me to install vercel-labs/skills@svg-optimizer to this project?
Auto
OpusExtra high
Explore how Claude Code queries skills.sh, presents candidate metrics, and installs vetted skills with human approval.

Discovering and calibrating modular agent skills is a cornerstone of our curriculum for professional AI tool builders:

  1. Step 1: Skill Authoring and Progressive Disclosure. Author lightweight SKILL.md packages that reveal instructions only when triggered.
  2. Step 2: Intent Calibration and Frontmatter Design. Craft descriptions that trigger with precision on complex user queries without false positives.
  3. Step 3: Ecosystem Discovery and Tool Lifecycle. Integrate registry tooling like find-skills, conduct security audits, and prune unneeded skills to protect context memory.

Cross-Site Perspectives

For DevOps engineers and repository maintainers evaluating worktree isolation, automated CI/CD audits, and headless package verification, read our companion piece on Claude Skills Hub: [Automating Agent Skill Discovery with npx skills: CI Toolchains, Registry Vetting, and Worktree Scoping](https://claudeskillsgithub.com/blog/automating-agent-skill-discovery-npx-skills-github).

For enterprise systems architects and engineering leaders analyzing token decay, SOC2 governance boundaries, and public versus private registry architectures, explore the deep dive on ClaudeSkillsGuide: [find-skills and the Open Registry Architecture: Autonomous Discovery, Context Overhead, and Enterprise Governance](https://claudeskillsguide.com/blog/find-skills-open-registry-architecture-enterprise-governance).

Stay connected

Never miss a post

Updates on format changes, community features, and skill building.