Skillbox treats instructions as versioned packages
Skillbox stores agent skills with immutable revisions, file editing, conflict checks, and restoration. A profile grants selected skills or bundles to a client, with separate permissions for creation, updates, archiving, and proposals. Clients can search, load, report use, or fetch a pinned revision through HTTP MCP and a Node or Bun bridge. That is useful when copying folders between Codex, Claude, and Cursor has stopped being manageable.
The server does not execute uploaded skill code. Fetching checks each path, file hash, size, executable bit, and package checksum before an atomic write. Revoking a client key blocks later access, though it cannot retract files already downloaded. Keys appear once and only their hashes remain in the database. The owner token is more powerful and should not be handed to clients.
MCP delivery keeps scope and revision attached
Skillbox implements base tools for search, recommendation, loading, file reading, and usage reports. Write and proposal tools appear only when the client's grants allow them. It also serves the native io.modelcontextprotocol/skills interface from the MCP 2026-07-28 specification, including skill discovery, manifests, and verified resources. Catalog responses contain active, authorized, compatible skills rather than every record in the database.
The CLI can fetch a named revision, publish with an expected current revision, or audit package compatibility. Its bootstrap tells agents to search the catalog at task start and load the chosen revision before acting. This is a better contract than silently copying the newest folder. It gives the agent a concrete package identity and lets the server reject a stale update instead of overwriting newer work.
What happened when we ran it
Our sandbox installed commit cda64ad in 16 seconds. Bun added 332 packages and used 234 MB on disk. The build completed in 10 seconds inside an unprivileged lab-node:22 container with 3 CPUs, 8 GB of RAM, and no secrets. The repository itself had 105 files, about 13,508 source lines, and a 1 MB checkout.
The test command exited 1 after 7 seconds. Bun reported 42 passed and 2 failed out of 44 tests across 12 files, with 354 expectation calls. Both failures were shown as (unnamed) in the supplied log, at 12.81 ms and 4.49 ms. The tail gives no test names or assertion messages, so it does not support a claim about the cause. It only establishes that commit cda64ad did not produce a green suite in our fresh container.
The repository has a Dockerfile, a Compose file, and a tests directory, but no CI workflow file. That absence matters because the documented isolated suite builds the frontend and creates its own PostgreSQL service. Without a visible repository workflow, adopters should decide where those 44 tests and the type check run before deployment.
Recommendations fall back instead of hiding part of the catalog
Optional Jev recommendations can use Vercel AI Gateway, TypeSafe AI, or OpenRouter with the owner's own key. Skillbox sends task text and descriptions of authorized active skills to the selected provider. Results use an uncalibrated 0 to 4 relevance rubric, returning scores of 3 or higher. The README correctly avoids calling those scores probabilities.
A request considers at most 200 leaf skills or 120,000 serialized characters. Larger catalogs fall back to PostgreSQL search rather than ranking an undisclosed subset. Provider errors, missing keys, malformed responses, rate limits, and an 8-second deadline take the same explicit fallback path. Cache entries live for 5 minutes, with 2 concurrent evaluations and 10 uncached requests per scope each minute.
This is one of the more careful parts of the design. A failed semantic request does not return a partial ranking dressed up as complete. The response says it used search and includes a fallback reason. Paid calls are optional, and the separate live benchmark requires an explicit flag and your credential. None of that proves recommendation quality, but it makes the failure mode legible.
Self-hosting means owning PostgreSQL, TLS, and the admin token
The quick start requires Docker Engine or Desktop, Compose v2, and Bash. It generates credentials without overwriting an existing .env, then binds the app to 127.0.0.1:4791. Remote deployment needs an HTTPS origin and a reverse proxy you operate. The docs advise keeping PostgreSQL unexposed, and the Compose setup gives the app a read-only filesystem with dropped capabilities.
Stored provider credentials use AES-256-GCM with material derived from SKILLBOX_ADMIN_TOKEN. Changing that token can make those credentials unreadable. Backups therefore need both the database and matching protected environment data. Skill exports may contain private instructions as well. Skillbox supplies backup and restore commands, but it installs no schedule or retention policy for you.
The service is single-owner, not a public multi-tenant product. Its own deployment guide recommends a trusted network or authenticated ingress and warns that client grants do not change that boundary. Public GitHub imports also exclude private repositories, redirects, symlinks, submodules, and Git LFS. Open issue 7 adds a Windows-specific concern: repeated package materialization can fail with EPERM when the revision directory exists.
September activity has not produced a release yet
The repository was pushed September 19, 2026. Issue and pull-request activity continued through September 23, when GitHub showed 261 stars, 24 forks, and 9 open issues and pull requests. There is no GitHub release, and package.json reports version 0.1.0. Open issue 8 also reports that malformed UTF-8 can be silently replaced during text-only MCP reads, while binary resource reads preserve bytes.
Skillbox has unusually explicit boundaries for a young project: it does not run skills, does not seed credentials, and does not pretend a large catalog was fully ranked when it was not. Those choices make it worth a trial for a private shared library. The deciding cost is operational. If one person has a dozen local skills, Git may be enough. If several clients need scoped access to exact revisions, the 234 MB install and PostgreSQL service start to earn their keep.

