article feature

Skills, extensions, and packages: customization surface

Skills are reusable workflows loaded from built-in, project, user, or package paths. Markdown skills disclose metadata progressively; Python-backed skills install editable packages and run importable modules. Extensions add tools, commands, and UI hooks. All execute with your user permissions and must be reviewed.

v v0.7.1reviewed 2026-08-09evidence code-derivedsources S015, S021, S002cutoff 2026-08-09
Features

Pinned repository file/line or test referenced in the audit.

Markdown skills

Skills are reusable workflows loaded from built-in, project, user, or package paths. Markdown skills disclose metadata progressively; Python-backed skills install editable packages and run importable modules. Extensions add tools, commands, and UI hooks. All execute with your user permissions and must be reviewed.

  • S015 supports the route's current claim set.
  • S021 supports the route's current claim set.
  • S002 supports the route's current claim set.

Python-backed skills

Skills are reusable workflows loaded from built-in, project, user, or package paths. Markdown skills disclose metadata progressively; Python-backed skills install editable packages and run importable modules. Extensions add tools, commands, and UI hooks. All execute with your user permissions and must be reviewed.

  • S015 supports the route's current claim set.
  • S021 supports the route's current claim set.
  • S002 supports the route's current claim set.

Built-in skills

Skills are reusable workflows loaded from built-in, project, user, or package paths. Markdown skills disclose metadata progressively; Python-backed skills install editable packages and run importable modules. Extensions add tools, commands, and UI hooks. All execute with your user permissions and must be reviewed.

  • S015 supports the route's current claim set.
  • S021 supports the route's current claim set.
  • S002 supports the route's current claim set.

Packages

Skills are reusable workflows loaded from built-in, project, user, or package paths. Markdown skills disclose metadata progressively; Python-backed skills install editable packages and run importable modules. Extensions add tools, commands, and UI hooks. All execute with your user permissions and must be reviewed.

  • S015 supports the route's current claim set.
  • S021 supports the route's current claim set.
  • S002 supports the route's current claim set.

Trust boundary

Everything here runs inside the local trust boundary. If a section mentions code execution, remember that process separation improves reliability and recovery more than it improves security.