Skill Discovery & Registry Mirror
What you get
- Discover tab under Settings → Skills: search prebuilt and community skills, install with one click.
- Registry mirror panel: pick International (clawhub.ai), China (iFlytek SkillHub), or a custom URL. Settings are probed before save—unreachable registries are rejected with a clear toast.
- Install → enabled: successful installs show Installed and enabled and add the skill to your catalog—no need to edit agent allowlists for the default case.
Steps
1
Open Discover
Go to Settings → Skills → Discover.
2
Choose your registry mirror (optional)
At the top of Discover, open Skill market mirror. Select international or China mirror, or enter a custom ClawHub-compatible base URL. Save only succeeds when the registry responds with valid JSON.
3
Search and install
Enter keywords in the search box, press Enter, then click Install on a skill card. Wait for the success toast.
4
Use in chat
Start or continue a conversation. Enabled skills are available through progressive skill loading—no extra toggle unless you use an explicit per-agent skill allowlist.
5
Enable built-in market tools (optional)
Under Settings → Agent → Capabilities → Built-in tools,
skill_market and skill_manage are off by default. Turn them on when you need external marketplace search or skill management—saves Turn1 tokens. /learn automatically enables manage for that turn.Explicit allowlist: If an agent uses a non-empty skill allowlist, Discover install automatically adds the new skill to that allowlist so it is available in chat on the next message. Set
mount_to_agent: false on the install API to skip catalog enable and allowlist adoption.Configure skill environment variables
Skills that call external services declare their secrets viaprimary_env / requires.env (e.g. GOOGLE_API_KEY). To fill them in:
- Open Settings → Skills, click a skill to open its detail sheet.
- Fill in the Environment variables section and save.
- Installed skill → its env vars are injected at runtime.
- Uninstalled / removed skill → its env vars are cleaned up automatically — no stale or orphaned secrets.
- Renamed skill → the config follows the new runtime name automatically.
Local Skill Paths & Atomic Adoption
In addition to online marketplace discovery, Myrm allows developers to mount local directories for custom private skills:- Adaptive Scan (Root & Multi-Directory): Whether given a single skill root directory (containing
SKILL.mddirectly) or a parent folder housing multiple skill subdirectories, Myrm automatically parses and extracts skill metadata. - Two-Phase Inspection & Atomic Adopt: Before saving a path, a dry-run preview inspects discovered skills, tags, required system tools, name conflicts, and security findings. Users can select desired skills to adopt and enable them atomically, or simply add the path.
- CWE-22 Path Traversal Defense: All input paths strictly prohibit relative traversal sequences (
..), safeguarding host and sandbox filesystems against directory traversal attacks. - Live Path Health Badges & One-Click Copy: Each configured path card in Settings displays live health status (e.g. discovered skills count, path not found) and provides a convenient one-click copy button for rapid terminal workflows.
- System Prerequisites Sniffing & One-Click Remediation: During skill preview and installation, Myrm evaluates host runtime prerequisites in milliseconds, detecting missing system CLI binaries (e.g.
ffmpeg,pandoc,poppler) or Python packages. It provides visual status indicators and generates copy-paste remediation commands (brew install ffmpeg,winget install Gyan.FFmpeg,uv pip install ...) to eliminate runtimecommand not founderrors.
Supply Chain Security Rescan & Auto-Quarantine
Third-party skill packages and their underlying dependencies (npm / PyPI) may expose newly discovered CVE vulnerabilities or fall victim to open-source supply chain poisoning over time. Myrm provides an automated Installed Skill Supply Chain Rescan Engine:- Dual-Track Detection: Built-in known malicious package catalog (zero-latency offline matching, network-independent) + OSV.dev online CVE batch query with 24h local caching.
- Auto-Quarantine & Global Event Broadcast: When a critical vulnerability or poisoned package is detected, Myrm automatically quarantines & disables the compromised skill and broadcasts
SKILL_POOL_UPDATEDacross the UI and runtime to prevent misuse. - Audit Acknowledgment & Governance (AdvisoryAck): Security teams can audit and acknowledge (dismiss) specific findings with recorded rationale for isolated sandboxes, or reinstate warnings at any time.
Related
- Skill Creation — turn a conversation into a reusable skill
- Skill Evolution — auto-improve skills after installation