Skip to main content

Agent Skills

A skill is a folder: a SKILL.md that tells the agent how to do one kind of task, and the scripts, references and templates that go with it. Put skills in .agents/skills/, switch them on, and the agent reads a skill’s instructions when a request matches it and runs its scripts with a tool call. Skills follow the agentskills.io format, so a skill written for another agent works here too.

Your first skill

1

Write the skill

A skill is a folder named after the skill, holding a SKILL.md:
SKILL.md starts with YAML frontmatter. name and description are required, and name must equal the folder’s name. The rest of the file is the instructions the agent reads:
The script is an ordinary program. It gets its input as command-line arguments and answers on standard output:
2

Switch skills on

Run this from the folder that holds .agents/:
The model read the skill’s instructions, then ran its script with the arguments it chose. Its wording, and how it splits the sources into arguments, will differ on your run.

How it works

  1. Found once, when the agent is built. Every folder under the skills directory with a valid SKILL.md becomes a skill. A skill added later is seen by the next agent you build.
  2. Listed in the system prompt. Each skill appears by name and description, with the tool call that reads it. The catalog shows tool calls, never host paths, so the model does not try to run a skill’s script with a shell command:
  3. Read and run through two tools.

The skill folder

Only SKILL.md is required. Frontmatter fields:

Scripts in any language

The interpreter is chosen by the file’s extension: The interpreter must be installed where the script runs. A file with any other extension is run directly, so it needs a shebang line and its executable bit.

Where a script runs, and what it can see

  • With a sandbox (governance on, with a sandbox that runs commands): the skill’s files are copied into the sandbox under /workspace/.skills/<name>/ and the script runs there, unable to see the host. A skill copied in may be at most 20 MB. See Execution.
  • Without one: the script runs on the host, in the skill’s folder, as your process’s user.
On the host a script does not inherit the agent’s environment. It gets PATH, HOME, the locale (LANG, LC_*), TMPDIR and TERM, and nothing else, so it cannot read LLM_API_KEY or any other secret your process holds. Pass a variable a skill needs by name with skill_script_env:
skill_script_env applies to scripts that run on the host only. A script run in a sandbox gets the sandbox’s environment, never your process’s: give it a value with governance_config["sandbox_manifest"]["environment"]["plain"] (Execution), and put nothing secret there. A skill script that checks what it can see, run on the host from a process that has both variables set:
Without skill_script_env, it printed:
With "skill_script_env": ["MY_SERVICE_URL"]:
Under governance, reading a skill’s files is the capability skill.files.read and running a script is skill.script.run (high risk, on the host or sandbox surface), so a policy can allow, ask about, or deny each. The built-in development profiles allow both.
Governance is on by default, and with no sandbox that runs commands a skill script runs on the host: governed by policy, but not contained. Every such run, the default among them, carries the warning host_scripts_not_contained in its header (trajectory["harness"]["security_warnings"]), and the agent logs it once at start-up. Give the agent a sandbox to contain the scripts (Execution).With governance off, a skill script runs on the host with no policy and no sandbox. The agent records the warning ungoverned_host_scripts in every run’s header (trajectory["harness"]["security_warnings"]) and logs it once at start-up. Only switch on skills you trust, or turn on governance with a sandbox (security model).

Options

Every setting is in the agent settings reference.

Writing a good skill

  • Make the description a trigger. The model sees only the name and description until it reads the skill. “Formats a list of sources as numbered citations” is chosen for a citation request; “Utilities” is not.
  • Keep SKILL.md short, and link out. Put long material in references/ and say in SKILL.md when to read it; the agent reads it with read_skill_file only when needed.
  • Say how to run each script: its name, its arguments, and what to do with the output.
  • Take input as arguments and answer on standard output. Avoid hard-coded paths: a script may run on the host or in a sandbox. Exit non-zero on failure; the model sees stderr and the exit code.

When things go wrong

The agent logs to the omnicoreagent logger and prints nothing on its own. To see the warnings below, turn logging on:
Check that the skill was found. Discovery skips a folder, with a warning, when its SKILL.md has no frontmatter, lacks name or description, or names a different skill than its folder:
Also check that the skills directory is where you think: the default .agents/skills is relative to the working directory the agent was built in. Set skills_dir to an absolute path to be sure. If the skill is found but not chosen, make its description say when to use it.
Logged once when the agent starts, and recorded in each run’s header as ungoverned_host_scripts. It is a warning, not an error: scripts still run. Turn on governance, with a sandbox, to contain them.
The tool returns an error to the model, which usually corrects itself. What the model sees:
script_name is relative to scripts/: "format_sources.py", not "scripts/format_sources.py".
On the host a script gets only a minimal environment. Name the variables it needs in skill_script_env.
The model chose the default timeout. Say in SKILL.md how long the script takes and which timeout to pass. On the host, a timed-out script is killed together with every process it started.

Next

AGENTS.md

A project’s own instructions for the agent, in every run.

Execution

Where code runs: sandboxes, skill scripts and code mode.

Security model

Policies that allow, ask about or deny running a script.

Workspace files

Where the agent keeps the files it makes.