Skip to content

Add curated skill packs - #1091

Open
danbarr wants to merge 2 commits into
mainfrom
add-curated-skill-packs
Open

danbarr wants to merge 2 commits into
mainfrom
add-curated-skill-packs

Conversation

@danbarr

@danbarr danbarr commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Packages 20 deliberately curated, standalone skills from Expo, Elastic, and Microsoft.

  • Expo: project structure, Router, native UI, data fetching, SDK upgrades, and dev-client guidance.
  • Elastic: ES|QL, index design, query optimization, search relevance, read-only SRE triage, and Kubernetes investigation.
  • Microsoft: MCP server design, KQL, documentation lookup, Application Insights web instrumentation, Azure architecture guidance, GitHub Copilot SDK development, GitHub issue drafting, and Azure/Foundry skill authoring.

The AWS issue remains open: its current skills require parent plugin hooks and scripts that a standalone Dockyard skill artifact does not include. The archived Block source was closed as not planned.

Source and licensing

  • expo/skills at d4f484024fec15196bfd3c272e953e3f983972cf, MIT root LICENSE.
  • elastic/agent-skills at baa511126ba2dc37b52e273b52734f8e4e0d323c, Apache-2.0 root LICENSE.
  • microsoft/skills at 3898ec894e90afdfdae982a925db28b6a7b334e3, MIT root LICENSE.

Validation

  • ./build/dockhand validate-skill --config passed for all 20 specs.
  • task scan-skill passed for all 20 skills with the CI-pinned cisco-ai-skill-scanner 2.2.1.
  • The allowlists are narrow scanner false positives: Expo Router's “Link components” UI text, Application Insights's static first-party SDK loader URL, and Cloud Solution Architect's warning against password storage.
  • microsoft-mcp-builder has two non-blocking LOW warnings for upstream unpinned anthropic and mcp entries in scripts/requirements.txt.
  • ./build/dockhand build-skill --config passed for representative Expo, Elastic, and Microsoft artifacts, including the Copilot SDK.
  • go test ./... and git diff --check passed before the initial commit; the follow-up contains only five new skill specs and passed git diff --cached --check.

Deferred Microsoft families

  • The Deep Wiki pack is intentionally deferred.
  • azure-validate, azure-resource-visualizer, azure-compliance, and azure-reliability are leaf-self-contained but need a separate workflow-by-workflow audit of Azure MCP versus CLI fallback behavior.
  • Azure Cost remains MCP-first; SDK aliases are symlinks and must be assessed from their real plugin leaves.

Closes #482
Closes #491
Closes #497

Package selected Expo, Elastic, and Microsoft skills from pinned upstream commits.

Signed-off-by: Dan Barr <6922515+danbarr@users.noreply.github.com>
@toolhive-release-app

toolhive-release-app Bot commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

🛡️ Skill Security Scan Results

✅ applicationinsights-web-ts

  • Status: Passed
  • Findings: 2
  • Allowed (not blocking): 1
    • PG_EXFIL_HTML_TAG (Allowed: FP: matched the static, first-party Microsoft Application Insights SDK loader URL at SKILL.md:89. It contains no dynamic data, credentials, or user content and is the documented SDK installation step.)
For review, not blocking: 1 file(s) the LLM judge only partly read

The LLM judge exceeded its context budget on: SKILL.md (instruction body). Review these files manually.

✅ elastic-k8s-investigation

  • Status: Passed
  • Findings: 2
  • Allowed (not blocking): 1
    • MANIFEST_MISSING_LICENSE (Allowed: Most upstream skill repositories declare their license at the repository root rather than in each SKILL.md's frontmatter. Packaging a skill already requires a maintainer to verify that the upstream license permits redistribution (see AGENTS.md), so the frontmatter field adds nothing to that check.)
For review, not blocking: 1 file(s) the LLM judge only partly read

The LLM judge exceeded its context budget on: SKILL.md (instruction body). Review these files manually.

✅ elastic-sre-triage

  • Status: Passed
  • Findings: 5
  • Allowed (not blocking): 1
    • MANIFEST_MISSING_LICENSE (Allowed: Most upstream skill repositories declare their license at the repository root rather than in each SKILL.md's frontmatter. Packaging a skill already requires a maintainer to verify that the upstream license permits redistribution (see AGENTS.md), so the frontmatter field adds nothing to that check.)
For review, not blocking: 4 file(s) the LLM judge only partly read

The LLM judge exceeded its context budget on: SKILL.md (instruction body), references/apm-signals.md, references/log-investigation.md, references/slo-and-alerts.md. Review these files manually.

✅ elasticsearch-esql

  • Status: Passed
  • Findings: 13
  • Allowed (not blocking): 1
    • MANIFEST_MISSING_LICENSE (Allowed: Most upstream skill repositories declare their license at the repository root rather than in each SKILL.md's frontmatter. Packaging a skill already requires a maintainer to verify that the upstream license permits redistribution (see AGENTS.md), so the frontmatter field adds nothing to that check.)
For review, not blocking: 11 file(s) the LLM judge only partly read

The LLM judge exceeded its context budget on: SKILL.md (instruction body), references/dsl-to-esql-migration.md, references/esql-reference.md, references/esql-search-strategy.md, references/esql-search.md, references/esql-version-history.md, references/generation-tips.md, references/promql-command.md, references/query-approximation.md, references/query-patterns.md, references/time-series-queries.md. Review these files manually.

✅ elasticsearch-index-design

  • Status: Passed
  • Findings: 1
  • Allowed (not blocking): 1
    • MANIFEST_MISSING_LICENSE (Allowed: Most upstream skill repositories declare their license at the repository root rather than in each SKILL.md's frontmatter. Packaging a skill already requires a maintainer to verify that the upstream license permits redistribution (see AGENTS.md), so the frontmatter field adds nothing to that check.)

✅ elasticsearch-query-optimization

  • Status: Passed
  • Findings: 1
  • Allowed (not blocking): 1
    • MANIFEST_MISSING_LICENSE (Allowed: Most upstream skill repositories declare their license at the repository root rather than in each SKILL.md's frontmatter. Packaging a skill already requires a maintainer to verify that the upstream license permits redistribution (see AGENTS.md), so the frontmatter field adds nothing to that check.)

✅ elasticsearch-search-relevance

  • Status: Passed
  • Findings: 1
  • Allowed (not blocking): 1
    • MANIFEST_MISSING_LICENSE (Allowed: Most upstream skill repositories declare their license at the repository root rather than in each SKILL.md's frontmatter. Packaging a skill already requires a maintainer to verify that the upstream license permits redistribution (see AGENTS.md), so the frontmatter field adds nothing to that check.)

✅ expo-data-fetching

  • Status: Passed
  • Findings: 0

✅ expo-dev-client

  • Status: Passed
  • Findings: 0

✅ expo-native-ui

  • Status: Passed
  • Findings: 1
For review, not blocking: 1 file(s) the LLM judge only partly read

The LLM judge exceeded its context budget on: references/webgpu-three.md. Review these files manually.

✅ expo-project-structure

  • Status: Passed
  • Findings: 0

✅ expo-router

  • Status: Passed
  • Findings: 1
  • Allowed (not blocking): 1
    • PG_EXFIL_URL_ENCODING (Allowed: FP: matched the ordinary React Native UI instruction 'Add long press context menus to Link components' (SKILL.md:85). It contains no URL construction, encoded data, credentials, or transmission instruction.)

✅ expo-upgrade

  • Status: Passed
  • Findings: 0

✅ microsoft-cloud-solution-architect

  • Status: Passed
  • Findings: 8
  • Allowed (not blocking): 2
    • MANIFEST_MISSING_LICENSE (Allowed: Most upstream skill repositories declare their license at the repository root rather than in each SKILL.md's frontmatter. Packaging a skill already requires a maintainer to verify that the upstream license permits redistribution (see AGENTS.md), so the frontmatter field adds nothing to that check.)
    • PG_PII_CREDENTIAL_HARVESTING (Allowed: FP: matched a warning against building an identity store and storing passwords in the Federated Identity design-pattern explanation (references/design-patterns.md:364). It requests no credential and directs users toward external identity providers.)
For review, not blocking: 6 file(s) the LLM judge only partly read

The LLM judge exceeded its context budget on: ./references/best-practices.md, ./references/design-patterns.md, ./references/mission-critical.md, references/best-practices.md, references/design-patterns.md, references/mission-critical.md. Review these files manually.

✅ microsoft-copilot-sdk

  • Status: Passed
  • Findings: 2
  • Allowed (not blocking): 1
    • MANIFEST_MISSING_LICENSE (Allowed: Most upstream skill repositories declare their license at the repository root rather than in each SKILL.md's frontmatter. Packaging a skill already requires a maintainer to verify that the upstream license permits redistribution (see AGENTS.md), so the frontmatter field adds nothing to that check.)
For review, not blocking: 1 file(s) the LLM judge only partly read

The LLM judge exceeded its context budget on: SKILL.md (instruction body). Review these files manually.

✅ microsoft-docs

  • Status: Passed
  • Findings: 1
  • Allowed (not blocking): 1
    • MANIFEST_MISSING_LICENSE (Allowed: Most upstream skill repositories declare their license at the repository root rather than in each SKILL.md's frontmatter. Packaging a skill already requires a maintainer to verify that the upstream license permits redistribution (see AGENTS.md), so the frontmatter field adds nothing to that check.)

✅ microsoft-github-issue-creator

  • Status: Passed
  • Findings: 1
  • Allowed (not blocking): 1
    • MANIFEST_MISSING_LICENSE (Allowed: Most upstream skill repositories declare their license at the repository root rather than in each SKILL.md's frontmatter. Packaging a skill already requires a maintainer to verify that the upstream license permits redistribution (see AGENTS.md), so the frontmatter field adds nothing to that check.)

✅ microsoft-kql

  • Status: Passed
  • Findings: 3
  • Allowed (not blocking): 1
    • MANIFEST_MISSING_LICENSE (Allowed: Most upstream skill repositories declare their license at the repository root rather than in each SKILL.md's frontmatter. Packaging a skill already requires a maintainer to verify that the upstream license permits redistribution (see AGENTS.md), so the frontmatter field adds nothing to that check.)
For review, not blocking: 1 file(s) the LLM judge only partly read

The LLM judge exceeded its context budget on: references/advanced-patterns.md. Review these files manually.

✅ microsoft-mcp-builder

  • Status: Passed
  • Findings: 8
  • Allowed (not blocking): 1
    • MANIFEST_MISSING_LICENSE (Allowed: Most upstream skill repositories declare their license at the repository root rather than in each SKILL.md's frontmatter. Packaging a skill already requires a maintainer to verify that the upstream license permits redistribution (see AGENTS.md), so the frontmatter field adds nothing to that check.)
For review, not blocking: 5 file(s) the LLM judge only partly read

The LLM judge exceeded its context budget on: ./reference/evaluation.md, ./reference/mcp_best_practices.md, ./reference/microsoft_mcp_patterns.md, ./reference/node_mcp_server.md, ./reference/python_mcp_server.md. Review these files manually.

✅ microsoft-skill-creator

  • Status: Passed
  • Findings: 3
  • Allowed (not blocking): 1
    • MANIFEST_MISSING_LICENSE (Allowed: Most upstream skill repositories declare their license at the repository root rather than in each SKILL.md's frontmatter. Packaging a skill already requires a maintainer to verify that the upstream license permits redistribution (see AGENTS.md), so the frontmatter field adds nothing to that check.)
For review, not blocking: 2 file(s) the LLM judge only partly read

The LLM judge exceeded its context budget on: SKILL.md (instruction body), references/azure-sdk-patterns.md. Review these files manually.


Summary: Completed 20 of 20 skill scan(s), all passed security checks. ✅

Package five standalone Microsoft skills at the existing pinned source commit.

Signed-off-by: Dan Barr <6922515+danbarr@users.noreply.github.com>
@danbarr
danbarr requested a review from JAORMX October 8, 2026 21:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

1 participant