mrkeyoor.com_
Mon 05 Oct 06:26 UTC
Self-Hostedevaluationupdated 05 Oct 2026

skillbox review

Skillbox is a self-hosted library for storing, revising, granting, and delivering instruction packages to AI agents. It serves skills over MCP and a CLI, keeps immutable revisions, and can recommend relevant entries through a provider you configure.

Verdict

Our Skillbox run installed 332 packages and built successfully, but 2 of 44 tests failed, so its thoughtful security boundaries do not yet add up to a clean release check. Use it when immutable revisions, scoped client keys, and MCP delivery solve a real coordination problem across your agents. Skip it for a public multi-user service, private-repository imports, or a simple personal folder that Git already handles well.

We ran it

Lab card: what happened when we ran skillboxScreenshot of skillbox (github.com/kitze/skillbox)
Install✓ · 16s332 packages · 234 MB
Build✓ · 10s
Tests✗ · 7s42 passed · 2 failed of 44 (bun test)
Repo105 files~13,508 lines of source · 1 MB · 0 CI workflows · Dockerfile · tests dir

Answers from our run

Does skillbox build from source?

Dependencies installed in 16 seconds (332 packages), and the build succeeded in 10 seconds. We cloned commit cda64ad into a clean Debian container with 3 CPUs and no project-specific setup.

Do skillbox's tests pass?

Not all of them: 42 of 44 passed and 2 failed when we ran the project's own test command (bun test). Some failures need services or credentials a bare container does not have.

Who should not use skillbox?

Organizations looking for a public multi-tenant skill service: the README defines Skillbox as single-owner and self-hosted.

What are the alternatives to skillbox?

Skills, OpenSkills, Skills Manager. Our Skillbox run installed 332 packages and built successfully, but 2 of 44 tests failed, so its thoughtful security boundaries do not yet add up to a clean release check.

Setup3/516-second install, but Docker, PostgreSQL, and HTTPS need ownership
Docs5/5Exact setup, permission, provider, backup, and limit details
Community2/5261 stars and September issue work, with no published release
Maturity3/5Broad controls and Docker support, but our suite had 2 failures

Who it’s for

Individuals running several AI clients who want one private source of versioned skills.
Teams that need separate read, update, archive, and proposal permissions for agent instructions.
MCP users who want authorized clients to discover and fetch pinned skill revisions.
Self-hosters prepared to operate Docker Compose, PostgreSQL, backups, HTTPS, and credential rotation.

Who it’s NOT for

Organizations looking for a public multi-tenant skill service: the README defines Skillbox as single-owner and self-hosted.
Users who want private GitHub imports: the importer accepts public repositories only and rejects private repositories, redirects, symlinks, submodules, and Git LFS.
Catalogs needing semantic ranking above 200 leaf skills: the recommendation contract falls back to PostgreSQL search instead of ranking a hidden subset.
Windows users who need repeatable package materialization today: open issue 7 reports an EPERM failure when a revision directory already exists.
Release pipelines that require a green fresh-container suite: our Bun run had 2 unnamed failures out of 44 tests.
People who want hosted accounts or a ready-made catalog: a new instance is empty, and the hosted roadmap remains future work.

Setup reality

Our fresh sandbox installed commit cda64ad in 16 seconds, adding 332 packages and using 234 MB. The build passed in 10 seconds. bun test exited 1 after 7 seconds: 42 passed and 2 unnamed tests failed out of 44.

The intended setup needs Docker Engine or Desktop, Compose v2, and Bash on Linux, macOS, or WSL. It creates local credentials, starts PostgreSQL and the app, and binds to 127.0.0.1:4791. Remote use needs your own HTTPS origin and reverse proxy.

Jev recommendations are optional but require your own Vercel AI Gateway, TypeSafe AI, or OpenRouter key. Direct development needs Bun and PostgreSQL 16 or newer. Backups must retain the matching admin token because changing it can make saved integration credentials unreadable.

Skillbox treats instructions as versioned packages

Skillbox stores agent skills with immutable revisions, file editing, conflict checks, and restoration. A profile grants selected skills or bundles to a client, with separate permissions for creation, updates, archiving, and proposals. Clients can search, load, report use, or fetch a pinned revision through HTTP MCP and a Node or Bun bridge. That is useful when copying folders between Codex, Claude, and Cursor has stopped being manageable.

The server does not execute uploaded skill code. Fetching checks each path, file hash, size, executable bit, and package checksum before an atomic write. Revoking a client key blocks later access, though it cannot retract files already downloaded. Keys appear once and only their hashes remain in the database. The owner token is more powerful and should not be handed to clients.

MCP delivery keeps scope and revision attached

Skillbox implements base tools for search, recommendation, loading, file reading, and usage reports. Write and proposal tools appear only when the client's grants allow them. It also serves the native io.modelcontextprotocol/skills interface from the MCP 2026-07-28 specification, including skill discovery, manifests, and verified resources. Catalog responses contain active, authorized, compatible skills rather than every record in the database.

The CLI can fetch a named revision, publish with an expected current revision, or audit package compatibility. Its bootstrap tells agents to search the catalog at task start and load the chosen revision before acting. This is a better contract than silently copying the newest folder. It gives the agent a concrete package identity and lets the server reject a stale update instead of overwriting newer work.

What happened when we ran it

Our sandbox installed commit cda64ad in 16 seconds. Bun added 332 packages and used 234 MB on disk. The build completed in 10 seconds inside an unprivileged lab-node:22 container with 3 CPUs, 8 GB of RAM, and no secrets. The repository itself had 105 files, about 13,508 source lines, and a 1 MB checkout.

The test command exited 1 after 7 seconds. Bun reported 42 passed and 2 failed out of 44 tests across 12 files, with 354 expectation calls. Both failures were shown as (unnamed) in the supplied log, at 12.81 ms and 4.49 ms. The tail gives no test names or assertion messages, so it does not support a claim about the cause. It only establishes that commit cda64ad did not produce a green suite in our fresh container.

The repository has a Dockerfile, a Compose file, and a tests directory, but no CI workflow file. That absence matters because the documented isolated suite builds the frontend and creates its own PostgreSQL service. Without a visible repository workflow, adopters should decide where those 44 tests and the type check run before deployment.

Recommendations fall back instead of hiding part of the catalog

Optional Jev recommendations can use Vercel AI Gateway, TypeSafe AI, or OpenRouter with the owner's own key. Skillbox sends task text and descriptions of authorized active skills to the selected provider. Results use an uncalibrated 0 to 4 relevance rubric, returning scores of 3 or higher. The README correctly avoids calling those scores probabilities.

A request considers at most 200 leaf skills or 120,000 serialized characters. Larger catalogs fall back to PostgreSQL search rather than ranking an undisclosed subset. Provider errors, missing keys, malformed responses, rate limits, and an 8-second deadline take the same explicit fallback path. Cache entries live for 5 minutes, with 2 concurrent evaluations and 10 uncached requests per scope each minute.

This is one of the more careful parts of the design. A failed semantic request does not return a partial ranking dressed up as complete. The response says it used search and includes a fallback reason. Paid calls are optional, and the separate live benchmark requires an explicit flag and your credential. None of that proves recommendation quality, but it makes the failure mode legible.

Self-hosting means owning PostgreSQL, TLS, and the admin token

The quick start requires Docker Engine or Desktop, Compose v2, and Bash. It generates credentials without overwriting an existing .env, then binds the app to 127.0.0.1:4791. Remote deployment needs an HTTPS origin and a reverse proxy you operate. The docs advise keeping PostgreSQL unexposed, and the Compose setup gives the app a read-only filesystem with dropped capabilities.

Stored provider credentials use AES-256-GCM with material derived from SKILLBOX_ADMIN_TOKEN. Changing that token can make those credentials unreadable. Backups therefore need both the database and matching protected environment data. Skill exports may contain private instructions as well. Skillbox supplies backup and restore commands, but it installs no schedule or retention policy for you.

The service is single-owner, not a public multi-tenant product. Its own deployment guide recommends a trusted network or authenticated ingress and warns that client grants do not change that boundary. Public GitHub imports also exclude private repositories, redirects, symlinks, submodules, and Git LFS. Open issue 7 adds a Windows-specific concern: repeated package materialization can fail with EPERM when the revision directory exists.

September activity has not produced a release yet

The repository was pushed September 19, 2026. Issue and pull-request activity continued through September 23, when GitHub showed 261 stars, 24 forks, and 9 open issues and pull requests. There is no GitHub release, and package.json reports version 0.1.0. Open issue 8 also reports that malformed UTF-8 can be silently replaced during text-only MCP reads, while binary resource reads preserve bytes.

Skillbox has unusually explicit boundaries for a young project: it does not run skills, does not seed credentials, and does not pretend a large catalog was fully ranked when it was not. Those choices make it worth a trial for a private shared library. The deciding cost is operational. If one person has a dozen local skills, Git may be enough. If several clients need scoped access to exact revisions, the 234 MB install and PostgreSQL service start to earn their keep.

Alternatives

ProjectWhat it isPick it when
Skills gh↗An open command-line tool for finding and installing agent skills.pick this instead when local installation is enough and you do not need a private server with grants and revisions.
OpenSkillsA universal skills loader for AI coding agents distributed through npm.pick this instead when you want a small cross-client loader rather than PostgreSQL and MCP hosting.
Skills Manager gh↗A desktop app for organizing and syncing skills across many coding clients.pick this instead when a local graphical manager fits better than a shared self-hosted service.
Anthropic Skills gh↗A public collection of Agent Skills that can be copied into supported clients.pick this instead when you need ready-made examples rather than private skill governance.

What people are saying

  1. [velocity-scout] kitze/skillbox

Sources

  1. Skillbox README
  2. Skillbox deployment guide
  3. Issue 7: Windows package materialization
  4. Issue 8: malformed UTF-8 reads

More self-hosted reviews

hysteria · vm2api · FounderOS-DEMO · UFI-TOOLS · awesome-cloudflare-selfhosted · life · the whole board →