Problem
cmd skills add does not record where a skill came from. Once installed, there is no manifest mapping skill name to source repo -- nothing in ~/.commandcode/ or the skill directory preserves the owner/repo[/path][@ref] spec used at install time.
Consequence: there is no way to update an installed skill from within the CLI. cmd skills only has add / remove / list (unchanged since v0.18.2). The only update path is:
- Rediscover the source repo yourself (out of band -- the CLI can't tell you)
- Re-run
cmd skills add <owner/repo/path> -f
For skills installed from multi-skill repos or subpaths (e.g. cmd skills add acme/repo/path/to/skill), rediscovering the exact spec is genuinely error-prone.
Prior art
- Mods already solve this in Command Code itself:
cmd mods update reinstalls and reconciles every configured mod package, because mod sources are tracked in settings.json. Skills are the odd one out.
- GitHub CLI shipped
gh skill (v2.90.0, April 2026), which records provenance metadata at install time and supports gh skill update [name|--all] across agent hosts.
Proposal
- At
cmd skills add time, write the resolved source spec (owner/repo[/path][@ref] plus installed commit SHA) to a manifest -- either a skills.json alongside the skills directory or a per-skill metadata file.
- Add
cmd skills update [skill-name] and cmd skills update --all: re-fetch from the recorded source and overwrite in place (same semantics as add -f).
cmd skills list could then also show source + whether upstream has moved.
Part 1 is the load-bearing piece -- without provenance, no update verb is possible. Backfill for already-installed skills can be manual (prompt on first update, or accept a spec argument to re-pin).
Tested on v1.5.0 (macOS); docs at commandcode.ai/docs/skills confirm only add/list/remove exist.
Problem
cmd skills adddoes not record where a skill came from. Once installed, there is no manifest mapping skill name to source repo -- nothing in~/.commandcode/or the skill directory preserves theowner/repo[/path][@ref]spec used at install time.Consequence: there is no way to update an installed skill from within the CLI.
cmd skillsonly hasadd/remove/list(unchanged since v0.18.2). The only update path is:cmd skills add <owner/repo/path> -fFor skills installed from multi-skill repos or subpaths (e.g.
cmd skills add acme/repo/path/to/skill), rediscovering the exact spec is genuinely error-prone.Prior art
cmd mods updatereinstalls and reconciles every configured mod package, because mod sources are tracked insettings.json. Skills are the odd one out.gh skill(v2.90.0, April 2026), which records provenance metadata at install time and supportsgh skill update [name|--all]across agent hosts.Proposal
cmd skills addtime, write the resolved source spec (owner/repo[/path][@ref]plus installed commit SHA) to a manifest -- either askills.jsonalongside the skills directory or a per-skill metadata file.cmd skills update [skill-name]andcmd skills update --all: re-fetch from the recorded source and overwrite in place (same semantics asadd -f).cmd skills listcould then also show source + whether upstream has moved.Part 1 is the load-bearing piece -- without provenance, no update verb is possible. Backfill for already-installed skills can be manual (prompt on first
update, or accept a spec argument to re-pin).Tested on v1.5.0 (macOS); docs at commandcode.ai/docs/skills confirm only add/list/remove exist.