Skip to main content
Glama

Why Skills Board

Useful skills tend to disappear into chats, bookmarks, and personal agent setups. Skills Board gives a team one searchable place to collect them and lets every teammate choose how to use them.

  • One team library. Save useful skills once, organize them with team-specific tags, and make them easy to find again.

  • Different agents welcome. Share the same entry across Claude, Codex, Cursor, and other agent setups.

  • A choice of handoff. Open the original source, copy a compatible install command, or download the latest skill files as a ZIP.

  • Organization-scoped access. Create a team, invite members, and keep each library available to its members.

  • Optional MCP access. Connect compatible agents to authenticated, scope-controlled tools for finding and organizing team skills and collections.

IMPORTANT

A saved skill is a team's own choice, not a security review, compatibility certification, or pinned release. Skills Board reads the latest available source; inspect that source before using it in an agent.

Related MCP server: agentskill-mcp

How it works

  1. Create a team library and add a skill from its GitHub repository.

  2. Skills Board keeps the original source visible and records the entry for the team.

  3. Teammates search by task, description, repository, or tag.

  4. Each teammate opens the source, copies a compatible command, or downloads the latest files as a ZIP.

The public catalog can help with discovery when the deployment has Vercel OIDC available. The team library and direct GitHub flow remain the core product.

Run locally

Prerequisites

  • Node.js 20.9 or newer

  • pnpm 10

  • PostgreSQL 15 or newer

1. Install the app

git clone https://github.com/TommyBez/skillsboard.git
cd skillsboard
corepack enable
pnpm install
cp .env.example .env.local

Generate a Better Auth secret with openssl rand -base64 32, then add it and your PostgreSQL connection string to .env.local.

2. Prepare the database

Apply the committed Drizzle migrations to a new database. This creates both the Better Auth tables and the application-specific tables from the versioned SQL in drizzle/.

pnpm db:migrate

3. Start developing

pnpm dev

Open http://localhost:3000. Restart the server after changing DATABASE_URL, because the PostgreSQL pool is created when the module loads.

Environment variables

Variable

Required

Purpose

DATABASE_URL

Yes

PostgreSQL connection string used by the application; Neon may use the pooled URL here.

DATABASE_URL_UNPOOLED

For migrations on Neon

Direct PostgreSQL connection used by Drizzle migrations. It can match DATABASE_URL for local, non-pooled Postgres.

BETTER_AUTH_SECRET

Yes

Secret used to sign and encrypt authentication data.

BETTER_AUTH_URL

Recommended

Public application origin; use http://localhost:3000 locally.

CRON_SECRET

Yes for hosted release cleanup

Dedicated random secret used to authenticate the daily expired collection-release cleanup configured in vercel.json.

RESEND_API_KEY

Yes outside development

Sends sign-in OTP and team invitation emails through Resend.

EMAIL_FROM

Yes outside development

Verified Resend sender for OTP and invitation emails (e.g. Skills Board <login@your-verified-domain.com>).

RESEND_WEBHOOK_SECRET

Yes for hosted email delivery

Verifies Resend bounce, complaint, suppression, and unsubscribe webhooks.

EMAIL_PRIVACY_SECRET

Yes in Vercel Production

At least 32 random bytes encoded as base64 or hex; the dedicated root for email hashes and encrypted unsubscribe links. Local/self-hosted environments can fall back to a domain-separated key derived from BETTER_AUTH_SECRET.

EMAIL_PRIVACY_SECRET_PREVIOUS

Only during key rotation

JSON array of retained base64/hex roots used for dual-hash suppression lookup and unsubscribe-token decryption. A prior root cannot be removed while retained records still depend on it.

KV_REST_API_URL

Yes outside development

REST endpoint of the Upstash Redis database that counts email capture submissions per client address. On Vercel, the Marketplace integration writes it into the project by itself.

KV_REST_API_TOKEN

Yes outside development

REST token for that database, written by the same integration. The read-only token it also writes is not used.

UPSTASH_REDIS_REST_URL

Self-hosted alternative

Same endpoint under the canonical Upstash name, for a database created by hand. The Upstash client reads it before KV_REST_API_URL, so a Vercel project leaves it unset.

UPSTASH_REDIS_REST_TOKEN

Self-hosted alternative

Same token under the canonical Upstash name, read before KV_REST_API_TOKEN. With neither pair complete, the capture form keeps working and is not rate limited.

GITHUB_TOKEN

No

Raises GitHub API rate limits for metadata and ZIP downloads.

VERCEL_OIDC_TOKEN

No

Supplied automatically by Vercel for the optional skills.sh catalog.

Sign-in and sign-up use email one-time codes (no passwords). Outside development, configure both RESEND_API_KEY and a domain-verified EMAIL_FROM; the fallback Resend test sender only works for Resend’s own test recipients. In development, OTP emails are skipped and any 6-digit code works. Without Vercel OIDC, the Discover catalog degrades gracefully while team libraries continue to work.

Hosted deployments run the collection-release retention cleanup once per day. Set CRON_SECRET in the Vercel Production environment before deploying; the endpoint fails closed when the secret is absent. Self-hosted deployments can invoke /api/cron/collection-release-retention from their scheduler with Authorization: Bearer <CRON_SECRET>.

The public email capture form is rate limited to five submissions an hour per client address, counted in Upstash Redis under hashed addresses. On Vercel, add an Upstash Redis database from the Marketplace in a region close to the deployment and connect it to the project: the integration writes KV_REST_API_URL and KV_REST_API_TOKEN into Production and Preview, and nothing else has to be set. Self-hosted deployments point at a database created in console.upstash.com and set UPSTASH_REDIS_REST_URL and UPSTASH_REDIS_REST_TOKEN instead. The Upstash client reads the canonical pair first and falls back to the KV_REST_API_ one, so where both are present the canonical pair is what counts. Either way the form fails open: with no credentials, or with Redis unreachable, submissions are accepted uncounted and the gap is logged.

Product communications are separate from transactional OTP and invitation email. Signup consent is optional and off by default, can be changed under Settings → Email, and is enforced with local consent history, suppression records, signed unsubscribe links, and verified Resend delivery webhooks. See docs/email-compliance.md before configuring a product broadcast.

MCP access

Skills Board exposes an OAuth-protected MCP endpoint at /api/mcp. After signing in, open Settings → MCP to connect it. The tools can search team skills and collections, retrieve install commands, and discover public or repository skills. With skills:write, they can save new skills and organize collections. They cannot edit or delete saved team skills, install them in an agent, or execute them.

The full contract lives at skillsboard.sh/developers (Markdown at /developers.md): the public endpoints, the OAuth flow, every tool and the scope it needs, and the versioning, error, and rate-limit conventions the HTTP surface follows. The machine-readable index of all of it is /llms.txt.

Official plugin

This repository is also the marketplace for the official Skills Board plugin. The plugin ships the MCP server configuration above and one skill that explains how to use a team library from an agent. It is not tied to one client: the directory in plugin/ carries an Agent Plugins 1.0.0 manifest, and a Claude Code manifest alongside it. Installing it is an alternative to the manual MCP setup above rather than a step after it.

In Claude Code:

/plugin marketplace add TommyBez/skillsboard
/plugin install skills-board@skills-board

In any client the plugins CLI supports:

npx plugins add TommyBez/skillsboard

Installing the plugin configures the MCP server. Connecting it still requires signing in to Skills Board and approving the requested scopes in the client.

Tech stack

Layer

Technology

Application

Next.js 16 App Router, React 19, TypeScript

UI

Tailwind CSS 4, shadcn/ui, Base UI

Authentication

Better Auth (email OTP) with organizations and OAuth provider support

Data

PostgreSQL, Drizzle ORM

Email

Resend and React Email

Agent access

Model Context Protocol via mcp-handler

Hosting

Vercel and Neon in the hosted deployment; self-hosting is supported

Project commands

Command

What it does

pnpm dev

Start the Turbopack development server.

pnpm typecheck

Run the TypeScript compiler without emitting files.

pnpm check

Run the repository's required local checks.

pnpm db:generate --name <description>

Generate a versioned migration after changing the schema.

pnpm db:check

Check that the schema and committed migration snapshots match.

pnpm db:migrate

Apply pending migrations to the configured database.

pnpm db:push

Push the schema only to a throwaway database used for prototyping.

pnpm build

Create a production build.

pnpm start

Start the production server.

pnpm email

Preview React Email templates on port 3001.

Contributing

Issues and pull requests are welcome. Read CONTRIBUTING.md before making a substantial change, follow the Code of Conduct, and report vulnerabilities through the process in SECURITY.md.

See the people who have helped build Skills Board on the contributors page.

License

Skills Board is available under the MIT License.

A
license - permissive license
Not graded
quality - not tested
B
maintenance

Maintenance

Maintainers
Response time
Release cycle
Releases (12mo)
Commit activity

Related MCP Servers

  • A
    license
    Not graded
    quality
    C
    maintenance
    A management toolkit for AI agent skills that provides an MCP server for search-first skill discovery and on-demand loading. It enables users to validate, organize, and serve standardized skills to MCP-compatible clients like Cursor and GitHub Copilot.
    409
    MIT
  • A
    license
    A
    quality
    F
    maintenance
    MCP server for discovering and installing AI agent skills from agentskill.sh. Search skills across platforms, browse trending skills, and install them with built-in security scanning.
    4
    20
    3
    MIT
  • A
    license
    A
    quality
    F
    maintenance
    Agent-first skill marketplace MCP server. AI agents discover, install, and share skills across 7 platforms via MCP protocol. 15 tools including skill search, download, upload, and agent discovery.
    18
    3
    MIT

View all related MCP servers

Related MCP Connectors

  • A registry of 5,900+ peer-authored skills any MCP agent can search and load on demand.

  • Agent-first skill marketplace with USK open standard for Claude, Cursor, Gemini, Codex CLI.

  • Git-backed platform for skills, tools, and context for AI agents

View all MCP Connectors

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/TommyBez/skillsboard'

If you have feedback or need assistance with the MCP directory API, please join our Discord server