Skip to content

Project skills reference ​

See Catalog acquisition, idempotent content and progressive disclosure for the shared visual model.

Project skills are exposed through the web UI, REST API, and MCP tools. The web UI uses the same REST surface as MCP.

REST routes ​

Catalog and assignment routes use /api/projects/{id}/skills; defaults use /api/projects/{id}/skill-defaults, project marketplaces use /api/projects/{id}/skill-marketplaces, and curated discovery uses /api/skill-marketplaces.

MethodRoutePurpose
GET/api/projects/{id}/skillsList catalog skills with status, provenance, source, content hash, resources count, and assigned agents.
GET/api/projects/{id}/skills/{skillId}Get one skill, including instructions and bundled text resources.
POST/api/projects/{id}/skillsCreate or update a manual skill from name, optional displayName, description, and required instructions.
DELETE/api/projects/{id}/skills/{skillId}Delete a skill and its assignments.
POST/api/projects/{id}/skills/generateGenerate an unsaved skill draft server-side from description or prompt.
POST/api/projects/{id}/skills/syncDiscover and sync skills from the connected repository.
POST/api/projects/{id}/skills/import/previewPreview candidate skills from owner/repo, a https://github.com repo/tree/blob URL, or a raw https://raw.githubusercontent.com SKILL.md URL.
POST/api/projects/{id}/skills/importImport selected candidates from owner/repo, a https://github.com repo/tree/blob URL, or a raw https://raw.githubusercontent.com SKILL.md URL.
POST/api/projects/{id}/skills/uploadUpload files, folders, or a .zip archive as skill content.
GET/api/skill-marketplacesList enabled administrator-curated marketplaces.
POST/api/projects/{id}/skill-marketplaces/{marketplace}/browseBrowse or search a curated marketplace without changing the catalog.
POST/api/projects/{id}/skill-marketplaces/{marketplace}/importImport selected marketplace candidates through the normal repository-import pipeline.
GET/api/projects/{id}/skills/assignmentsList all skill-to-agent assignments in the project.
PUT/api/projects/{id}/skills/{skillId}/assignments/{agentName}Assign a skill to an agent.
DELETE/api/projects/{id}/skills/{skillId}/assignments/{agentName}Unassign a skill from an agent.

Import source restrictions ​

import and import/preview parse the supplied source through an allow-list before any clone or fetch. Only two hosts are accepted: github.com (HTTPS only, default port, no userinfo) and raw.githubusercontent.com (which must point directly at a SKILL.md). The owner/repo shorthand maps to the canonical https://github.com/{owner}/{repo}.git clone URL. Any other scheme (http, git, ssh, file), a non-default port, embedded credentials, or a different host is rejected with a 400 and a message such as "Unsupported skill source host … Only github.com and raw.githubusercontent.com are allowed." This is an SSRF guard, not a convenience limit.

DTOs ​

Skill ​

FieldMeaning
idProject-local skill id.
nameSKILL.md frontmatter name. Unique per project.
descriptionShort description shown in the catalog and prompt metadata.
provenancebuilt-in, connected-repo-sync, repo-import, file-upload, manual, or marketplace.
source_repositoryConnected repo identifier or imported repo URL when applicable.
source_locationSkill folder path in the source when applicable.
marketplace_nameCurated marketplace identity when provenance is marketplace.
statusactive, missing, or malformed.
content_hashStable hash used for idempotent sync/import/upload.
resource_countNumber of bundled text resources.
assigned_agentsAgent names currently assigned to the skill.
created_at, updated_atCatalog timestamps.

GET /skills/{skillId} also returns instructions and resources[] with relative_path and content.

Acquisition result ​

Create, sync, import, and upload return:

FieldMeaning
results[]Per-candidate outcome with location, name, kind, skill_id, and validation errors.
marked_missing[]Connected-repo skills marked missing because their source location disappeared.

MCP tools ​

The MCP skill tools mirror the REST surface except multipart upload, which is web-only:

ToolPurpose
skill_listList catalog skills with assignments and status.
skill_getFetch a full skill including SKILL.md instructions and resources.
skill_deleteDelete a catalog skill and assignments.
skill_createCreate or update a manual skill.
skill_generateGenerate an unsaved skill draft server-side.
skill_syncSync recognized skill directories from the connected repository.
skill_import_previewPreview candidate skills from owner/repo, HTTPS GitHub repository/tree/blob URLs, or HTTPS raw.githubusercontent.com URLs pointing directly to SKILL.md.
skill_importImport one or more previewed locations from owner/repo, HTTPS GitHub repository/tree/blob URLs, or HTTPS raw.githubusercontent.com URLs pointing directly to SKILL.md.
skill_assignments_listList all project assignments.
skill_assignAssign a skill to an agent.
skill_unassignRemove an assignment.

See the generated MCP tool index for the full authoritative tool list.

Source ​

ConcernSource
REST route map and status codesapps/Agentweaver.Api/Endpoints/SkillEndpoints.cs:15
Web client route wrappers and multipart uploadapps/web/src/api/client.ts:373
TypeScript DTOsapps/web/src/api/types.ts:1306
MCP skill toolsapps/Agentweaver.Mcp/Tools/SkillTools.cs:40

Curated marketplaces ​

Administrators configure trusted marketplace definitions in the API SkillMarketplaces:Definitions configuration section. Each definition has a name, GitHub repository, optional subpath/layout note, branch, and enabled flag. Disabled or removed definitions disappear from browse results but never delete skills already imported from them. The built-in configuration includes GitHub Awesome Copilot (github/awesome-copilot at skills) and Azure Skills (microsoft/skills at .github/plugins/azure-skills/skills). Browse failures return an unavailable-source response and do not modify the project catalog.

Defaults and project marketplace sources ​

REST actionContractMCP tool
POST /api/projects/{id}/skill-defaults/previewPreview bundled role defaults for a confirmed team/predefined blueprint; return a state-bound digest without writes.skill_defaults_preview
POST /api/projects/{id}/skill-defaults/applyAtomically apply the matching preview; stale digest returns 409.skill_defaults_apply
GET /api/projects/{id}/skill-marketplacesCurated and project-added sources.skill_marketplace_sources_list
POST /api/projects/{id}/skill-marketplaces/sourcesAdd a project source.skill_marketplace_source_add
DELETE /api/projects/{id}/skill-marketplaces/sources/{name}Remove a project-added source, not a curated definition.skill_marketplace_source_remove

skill_marketplaces_list, skill_marketplace_browse, and skill_marketplace_import discover, preview, and import marketplace candidates. Adding a source does not import or assign skills. Curated names win collisions; project sources cannot shadow them. The import parser's strict HTTPS host rules are distinct from marketplace-source parsing.

Diagram details and constraints
ElementContract
titleSkills: catalog to safe delivery
takeawayOnly successful shared-filesystem writes produce pointers; all other delivery is inline.
group-title-0ACQUIRE · VALIDATE · ASSIGN
group-title-1DELIVERY BRANCHES · EXECUTION
Skill sourcesSkill sources
Skill sourcesCheckout · repo · marketplace
Skill sourcesUpload and manual entry are also inputs
Skill sourcesSkillCatalogService.cs:335-372
Active assignmentsActive assignments
Active assignmentsLook up skills for this agent
Active assignmentsNo active assignments → no skill block
Active assignmentsSkillPromptComposer.cs:45-81
Project skill catalogProject skill catalog
Project skill catalogParse / validate / content-hash upsert
Project skill catalogMissing / malformed sources are tracked
Project skill catalogSkillCatalogService:1045-1156
Shared worktree availableShared worktree available
Shared worktree availableBest-effort stale-folder cleanup
Shared worktree availableAttempt each assigned skill materialization
Shared worktree availableSkillPromptComposer.cs:63-106
Explicit agent assignmentExplicit agent assignment
Explicit agent assignmentCatalog skills bind to agents
Explicit agent assignmentDelivery selects active assigned entries
Explicit agent assignmentSkillPromptComposer.cs:49-54
Successful write onlySuccessful write only
Successful write onlyPrompt metadata + SKILL.md path
Successful write onlyAgent reads relevant skill instructions
Successful write onlySkillPromptComposer.cs:91-98,145
Defaults preview / applyDefaults preview / apply
Defaults preview / applyConfirmed team + preview digest
Defaults preview / applyApply recomputes; stale digest rejects
Defaults preview / applySkillDefaultsService.cs:231-250
Inline full instructionsInline full instructions
Inline full instructionsPod-local / unavailable filesystem
Inline full instructionsAlso used for each failed materialization
Inline full instructionsSkillPromptComposer.cs:99-160
Skill sourcesvalidate
Project skill catalogassign
Explicit agent assignmentlookup
Active assignmentsshared FS
Shared worktree availablewrite succeeds
Active assignmentsno FS
Shared worktree availablewrite fail
scopeDefaults preview has no side effects; explicit apply is digest-checked. Cleanup is best-effort.
groupsACQUIRE · VALIDATE · ASSIGN; DELIVERY BRANCHES · EXECUTION