skill-base-web-deploy — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited skill-base-web-deploy (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
This skill guides you through setting up and operating the Skill Base platform server. Requires Node.js >= 18.
npx skill-base or Docker).-h, -p), data directory (-d), or how to back up the database.skb command to search, install, or publish specific skills (refer to skill-base-cli instead).# Recommended: fix the data directory for easy backup and migration
npx skill-base -d ./skill-data -p 8000Default port is 8000; if -d is not specified, data will be stored in npm cache-related paths. In production, always use `-d` to point to a specific directory.
npx skill-base)| Option | Description |
|---|---|
-p, --port | Listening port, default 8000 |
-h, --host | Listening address, default 0.0.0.0 (listens on all local network cards/IPv4 addresses, accessible from both internal and external networks; set to 127.0.0.1 for local-only access) |
-d, --data-dir | Data root directory; sets DATA_DIR and DATABASE_PATH=<dir>/skills.db |
--base-path | Deployment base path prefix, default / (e.g., /skills/ for subpath deployment) |
--no-cappy | Disable Cappy the capybara mascot |
-v, --verbose | Enable debug logging |
--help | Show help information |
--version | Show version number |
Intranet or local hardening example: npx skill-base --host 127.0.0.1 -p 8000 -d ./data
Subpath deployment example: npx skill-base --base-path /skills/ -p 8000
Debug mode example: npx skill-base -v -d ./data
When no administrator exists, opening the site in a browser will launch the initialization wizard: create a system administrator account and password. Afterward, team members need to be added by the administrator, and users log in via Web and CLI.
After the server is running, the Web UI and CLI share the same backend:
| Capability | Web UI | CLI |
|---|---|---|
| Browse / search skills | Yes | skb search |
| Version history & changelogs | Yes | skb update |
| Tags & favorites | Yes (admin tag library; owner assigns tags) | — |
| Collections (admin-curated packs, max 10 skills) | Browse on home | skb install --collection <id_or_slug> |
| GitHub import (public repos only) | Publish page | skb import-github |
| Desktop client | docs/desktop.md | Same install/update logic as CLI |
Collections are flat recommendation packs maintained by admins — they link to skills via collection_skills, not a folder hierarchy. Clients install the whole pack in one zip download.
pnpm install
pnpm start
# Or for development: `pnpm dev`Build in the repository root directory containing the Dockerfile:
docker build -t skill-base .Image conventions: DATA_DIR=/data, DATABASE_PATH=/data/skills.db, PORT=8000. For host persistence, mount to `/data` inside the container:
docker run -d -p 8000:8000 -v "$(pwd)/data:/data" --name skill-base-server skill-baseIf you need to change the port, map both host and container ports and set PORT, e.g., -p 3000:3000 -e PORT=3000.
After specifying -d or mounting /data, typical contents:
data/
├── skills.db
├── skills.db-wal
└── skills/
└── <skill-id>/
└── vYYYYMMDD.HHmmss.zipBackup: Simply copy the entire data directory during low write activity or off-peak hours.
PORT; cloud hosts need to allow corresponding inbound traffic.skb init --server <root URL> (without /api); verify the site is accessible from that machine.-d path must be readable/writable by the process; for Docker volumes, check host directory permissions.skill-base-cliAfter deploying the Web server, users on the client side use `skb` pointing to the same site root URL; see the skill-base-cli skill within the project.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.