| .github/workflows | ||
| deploy | ||
| docs | ||
| scripts | ||
| server | ||
| web | ||
| .env.release.example | ||
| .gitignore | ||
| compose.release.yml | ||
| docker-compose.yml | ||
| LICENSE | ||
| Makefile | ||
| README.md | ||
SkillHub
An enterprise-grade agent skill registry — publish, discover, and manage reusable skill packages across your organization.
SkillHub is a self-hosted platform that gives teams a private, governed place to share agent skills. Publish a skill package, push it to a namespace, and let others find it through search or install it via CLI. Built for on-premise deployment behind your firewall, with the same polish you'd expect from a public registry.
Highlights
- Self-Hosted & Private — Deploy on your own infrastructure.
Keep proprietary skills behind your firewall with full data
sovereignty. One
make dev-allcommand to get running locally. - Publish & Version — Upload agent skill packages with semantic
versioning, custom tags (
beta,stable), and automaticlatesttracking. - Discover — Full-text search with filters by namespace, downloads, ratings, and recency. Visibility rules ensure users only see what they're authorized to.
- Team Namespaces — Organize skills under team or global scopes. Each namespace has its own members, roles (Owner / Admin / Member), and publishing policies.
- Review & Governance — Team admins review within their namespace; platform admins gate promotions to the global scope. Every action is audit-logged for compliance.
- CLI-First — Native REST API plus a compatibility layer for existing ClawHub CLI tools — no client changes needed.
- Pluggable Storage — Local filesystem for development, S3 / MinIO for production. Swap via config.
Quick Start
Prerequisites
- Docker & Docker Compose
One-Command Runtime
Published runtime images are built by GitHub Actions and pushed to GHCR.
This is the recommended path for anyone who wants a ready-to-use local
environment without building the backend or frontend on their machine.
Published images target both linux/amd64 and linux/arm64.
Start the latest runtime from main:
curl -fsSL https://raw.githubusercontent.com/iflytek/skillhub/main/scripts/runtime.sh | sh -s -- up
Start the first beta release explicitly:
curl -fsSL https://raw.githubusercontent.com/iflytek/skillhub/main/scripts/runtime.sh | \
sh -s -- up --version v0.1.0-beta.1
Then open:
- Web UI:
http://localhost - Backend API:
http://localhost:8080
The script downloads the runtime files into ${TMPDIR:-/tmp}/skillhub-runtime
by default and starts Docker Compose from there, so it does not pollute
your current working directory.
If you want a persistent location instead of the temp directory:
curl -fsSL https://raw.githubusercontent.com/iflytek/skillhub/main/scripts/runtime.sh | \
SKILLHUB_HOME=$HOME/.skillhub-runtime sh -s -- up --version v0.1.0-beta.1
Other useful commands:
curl -fsSL https://raw.githubusercontent.com/iflytek/skillhub/main/scripts/runtime.sh | sh -s -- downcurl -fsSL https://raw.githubusercontent.com/iflytek/skillhub/main/scripts/runtime.sh | sh -s -- cleancurl -fsSL https://raw.githubusercontent.com/iflytek/skillhub/main/scripts/runtime.sh | sh -s -- pscurl -fsSL https://raw.githubusercontent.com/iflytek/skillhub/main/scripts/runtime.sh | sh -s -- logs
The runtime stack uses its own Compose project name, so it does not
collide with containers from make dev-all.
Use clean if you also want to remove the downloaded runtime files from
${TMPDIR:-/tmp}/skillhub-runtime.
The runtime uses the existing local,docker profile combination so it
is immediately usable with the same mock-auth flow as local development.
Available seeded users:
local-userlocal-admin
Pass X-Mock-User-Id to the backend when you need an authenticated
session without configuring GitHub OAuth. If the GHCR package remains
private, run docker login ghcr.io before docker compose up -d.
Local Development
make dev-all
Then open:
- Web UI:
http://localhost:3000 - Backend API:
http://localhost:8080
Local profile seeds two mock-auth users automatically:
local-userfor normal publishing and namespace operationslocal-adminwithSUPER_ADMINfor review and admin flows
Use them with the X-Mock-User-Id header in local development.
Stop everything with:
make dev-all-down
Reset local dependencies and start from a clean slate with:
make dev-all-reset
Run make help to see all available commands.
Architecture
┌─────────────┐ ┌─────────────┐ ┌──────────────┐
│ Web UI │ │ CLI Tools │ │ REST API │
└──────┬──────┘ └──────┬──────┘ └──────┬───────┘
│ │ │
└───────────────────┼───────────────────┘
│
┌──────▼──────┐
│ Nginx │
└──────┬──────┘
│
┌──────▼──────┐
│ Spring Boot │ Auth · RBAC · Core Services
└──────┬──────┘
│
┌────────────┼────────────┐
│ │ │
┌──────▼───┐ ┌─────▼────┐ ┌────▼────┐
│PostgreSQL│ │ Redis │ │ Storage │
└──────────┘ └──────────┘ └─────────┘
Contributing
Contributions are welcome. Please open an issue first to discuss what you'd like to change.
License
MIT