Repository navigation
Releases: NetAnlatAkademi/skillforge
Release list
SkillForge 26.250.1
What's Changed
- feat(graph,discovery): discovery drift, the asset graph, and the whole tool list by @cagrisolakoglu in #8
Full Changelog: v26.249.1...v26.250.1
SkillForge 26.249.1
What's Changed
- feat(provenance): where an asset came from, and what its next version adds by @cagrisolakoglu in #7
Full Changelog: v26.222.1...v26.249.1
SkillForge 26.222.1
Full Changelog: v26.215.1...v26.222.1
SkillForge 26.215.1
Full Changelog: v26.210.1...v26.215.1
SkillForge 26.210.1
What's Changed
- feat(mcp): inspect MCP servers from their declaration, and ask only the HTTP ones by @cagrisolakoglu in #5
- feat(mcp): authorization, tool conformance, and the 2025-11-25 adapter by @cagrisolakoglu in #6
Full Changelog: v26.209.3...v26.210.1
SkillForge 26.209.3
What's Changed
- feat(eval): a model runner, so activation is tested rather than approximated by @cagrisolakoglu in #4
Full Changelog: v26.209.2...v26.209.3
SkillForge 26.209.2
What's Changed
- docs(package): the nuget.org page carries usage, not the repository README by @cagrisolakoglu in #3
Full Changelog: v26.209.1...v26.209.2
SkillForge 26.209.1
What's Changed
- feat(providers): SF7xxx, a skill is checked against the providers it … by @cagrisolakoglu in #1
- feat(migrate): skillforge migrate inspect, an inventory of the tooling that is here by @cagrisolakoglu in #2
New Contributors
- @cagrisolakoglu made their first contribution in #1
Full Changelog: v26.208.2...v26.209.1
SkillForge 26.208.2
Full Changelog: v26.208.1...v26.208.2
SkillForge 26.208.1
The first release. SkillForge lints, inspects, packages and diffs agent skills — SKILL.md files — from the command line.
dotnet tool install --global SkillForge.Cli --version 26.208.1
skillforge validate ./skillsOr in a workflow:
- uses: NetAnlatAkademi/skillforge@v26.208.1
with:
path: ./skills
suppress: SF1009,SF1010Five commands
validate— 17 rules, one diagnostic code each. Point it at one skill or at a directory of them; a directory is validated as a batch and becomes one SARIF run.inspect— file inventory, external URLs, inferred capabilities, declared tools.pack— deterministic.skill.zipwith a.sha256insha256sum -cformat. Same input, same bytes.diff— what a skill can do now that it could not do before: permissions, hosts, scripts, files, compatibility.init— scaffolds a skill that validates clean.
Output as console text, JSON, or SARIF 2.1.0.
It reports signals, never a verdict
SkillForge will not label a skill safe or unsafe (ADR-006). It says what it found and why that might matter; the judgement is the reader's. A shield or a tick would promise something a text scanner cannot deliver, which is also why the logo is an anvil.
Every rule was measured before it shipped
Running the rules on 229 real skills changed several of them:
- SF0008 called a reference to a sibling skill an error. All 21 such "errors" were legitimate cross-references inside one collection, so it became SF1011, a warning.
- SF3002 read the skill body as well as the description, and produced 16 findings of which roughly one was genuine — the rest ordinary English, including one security skill's own detection pattern written as a string literal. Body scanning was dropped; the same 229 skills now give 5 findings.
- SF1009 and SF1010 fire on almost every real skill. They were kept, because they are right — but
--strictis documented as unusable by default, and--suppressplus avalidationsection inskillforge.yamlexist so a repository can decide otherwise.
docs/validation-rules.md records the measurements, the thresholds and the known false positives rather than hiding them.
Versions
YY.DayOfYear.Build — 26.208.1 is the first build on 27 July 2026. Valid SemVer, but the shape promises nothing about compatibility; breaking changes are called out in the notes instead.
Full notes in CHANGELOG.md.