How it works
Five ideas — skills, pins, keys, the client and the manifest — are all you need to understand SkilVault.
Skills
A skill is a set of instructions (a SKILL.md file, sometimes with supporting files) that teaches Claude how to do one kind of task well — reviewing a pull request, writing a commit message, planning a refactor. Every skill in SkilVault is reviewed before it is published. See Skill format.
The catalog and your library
The catalog is every published skill; anyone can browse it at /catalog without an account. Your library is the skills you have pinned — always listed in your CLIs. On paid plans your key can also read any other published skill on demand; on the free plan only pinned skills are readable, though you can still search and browse the whole catalog.
Pinned skills and plans
A pinned skill is always listed in your CLIs. The free plan gives you 5 pins; paid plans give more, and on Pro and Unlimited you are not limited to your pins for reading — skilvault find and an automatic prompt router surface the right skill for the task, and skilvault read <name> works for any published skill, not only a pinned one (see Plans & billing). Unpinning a skill frees its pin immediately, so you can swap what is pinned whenever the work changes.
API keys
An API key (it starts with svk_live_) is what connects a machine to your account. Whoever holds the key gets your library, so treat it like a password. Each plan allows a number of keys — one per machine or CI runner is typical. You can revoke a key at any time and it stops working instantly. See API keys.
The skilvault client
The client is one program, ~/.local/bin/skilvault, plus a small skill stub in each CLI's own skills folder. It gives that CLI a handful of commands — list, search, read, install, remove,update — to work with your library. You can also run them yourself. See The skilvault client.
Because the client is a skill, Claude knows to use it: when you mention a skill by name it reads it, and at the start of non-trivial work it searches your library for a match.
Fetch-and-read versus install
Each skill you select appears in your CLI as an ordinary skill, so the CLI picks it when it fits. What sits in the CLI's skills folder is a small lazy skill that loads the real one with skilvault read at the moment it is used: downloaded once per version, signature-checked, and always the latest. Read more in Skills in your CLI.
Versions and checksums
Every published version of a skill is immutable, has a SHA-256 checksum, and is signed offline by the operator. Before the client reads or installs anything it checks that signature against the keys it was installed with, then downloads the pack and checks it against the signed checksum. If either check fails, or the version is older than one it already used, it refuses. Downloads are cached by checksum, so a version is only fetched once per machine.
The whole flow
You pin skills in the dashboard → your library (limited by your pin cap)
Your machine has a key → the key identifies your library
skilvault list / search / read → asks SkilVault for your manifest
Manifest: name, version, sha256, url, → one entry per pinned skill
signature
Client checks signature, then sha → prints SKILL.md into the session
Claude follows the skill → entirely on your machineSkilVault only sees which skills you fetch and use — never your code, prompts or sessions. Skills run on your machine. Details in Security & privacy.