Skip to main content

Skill Discovery & Registry Mirror

What you get

  • Discover tab under Settings → Skills: search prebuilt and community skills, install with one click.
  • Registry mirror panel: pick International (clawhub.ai), China (iFlytek SkillHub), or a custom URL. Settings are probed before save—unreachable registries are rejected with a clear toast.
  • Install → enabled: successful installs show Installed and enabled and add the skill to your catalog—no need to edit agent allowlists for the default case.

Steps

1

Open Discover

Go to Settings → Skills → Discover.
2

Choose your registry mirror (optional)

At the top of Discover, open Skill market mirror. Select international or China mirror, or enter a custom ClawHub-compatible base URL. Save only succeeds when the registry responds with valid JSON.
3

Search and install

Enter keywords in the search box, press Enter, then click Install on a skill card. Wait for the success toast.
4

Use in chat

Start or continue a conversation. Enabled skills are available through progressive skill loading—no extra toggle unless you use an explicit per-agent skill allowlist.
5

Enable built-in market tools (optional)

Under Settings → Agent → Capabilities → Built-in tools, skill_market and skill_manage are off by default. Turn them on when you need external marketplace search or skill management—saves Turn1 tokens. /learn automatically enables manage for that turn.
Explicit allowlist: If an agent uses a non-empty skill allowlist, Discover install automatically adds the new skill to that allowlist so it is available in chat on the next message. Set mount_to_agent: false on the install API to skip catalog enable and allowlist adoption.

Configure skill environment variables

Skills that call external services declare their secrets via primary_env / requires.env (e.g. GOOGLE_API_KEY). To fill them in:
  1. Open Settings → Skills, click a skill to open its detail sheet.
  2. Fill in the Environment variables section and save.
Your config is stored in a central skill configuration — not inside the SKILL.md file. On every agent build, Myrm automatically reconciles the saved config against the currently installed skills:
  • Installed skill → its env vars are injected at runtime.
  • Uninstalled / removed skill → its env vars are cleaned up automatically — no stale or orphaned secrets.
  • Renamed skill → the config follows the new runtime name automatically.
Secrets are injected as environment variables and never appear in chat context.

Local Skill Paths & Atomic Adoption

In addition to online marketplace discovery, Myrm allows developers to mount local directories for custom private skills:
  1. Adaptive Scan (Root & Multi-Directory): Whether given a single skill root directory (containing SKILL.md directly) or a parent folder housing multiple skill subdirectories, Myrm automatically parses and extracts skill metadata.
  2. Two-Phase Inspection & Atomic Adopt: Before saving a path, a dry-run preview inspects discovered skills, tags, required system tools, name conflicts, and security findings. Users can select desired skills to adopt and enable them atomically, or simply add the path.
  3. CWE-22 Path Traversal Defense: All input paths strictly prohibit relative traversal sequences (..), safeguarding host and sandbox filesystems against directory traversal attacks.
  4. Live Path Health Badges & One-Click Copy: Each configured path card in Settings displays live health status (e.g. discovered skills count, path not found) and provides a convenient one-click copy button for rapid terminal workflows.
  5. System Prerequisites Sniffing & One-Click Remediation: During skill preview and installation, Myrm evaluates host runtime prerequisites in milliseconds, detecting missing system CLI binaries (e.g. ffmpeg, pandoc, poppler) or Python packages. It provides visual status indicators and generates copy-paste remediation commands (brew install ffmpeg, winget install Gyan.FFmpeg, uv pip install ...) to eliminate runtime command not found errors.

Supply Chain Security Rescan & Auto-Quarantine

Third-party skill packages and their underlying dependencies (npm / PyPI) may expose newly discovered CVE vulnerabilities or fall victim to open-source supply chain poisoning over time. Myrm provides an automated Installed Skill Supply Chain Rescan Engine:
  1. Dual-Track Detection: Built-in known malicious package catalog (zero-latency offline matching, network-independent) + OSV.dev online CVE batch query with 24h local caching.
  2. Auto-Quarantine & Global Event Broadcast: When a critical vulnerability or poisoned package is detected, Myrm automatically quarantines & disables the compromised skill and broadcasts SKILL_POOL_UPDATED across the UI and runtime to prevent misuse.
  3. Audit Acknowledgment & Governance (AdvisoryAck): Security teams can audit and acknowledge (dismiss) specific findings with recorded rationale for isolated sandboxes, or reinstate warnings at any time.