
LoopSkill
io.github.wisechef-aiv0.9.65更新于 Oct 11, 2026
Search, install and compose AI agent skills, loops and bundles from the LoopSkill marketplace.
概览
让助手通过 MCP 从 LoopSkill 市场搜索、安装并组合 AI 智能体技能、循环与捆绑包。
- 功能
- LoopSkill 提供一个远程 MCP 端点,背后是技能、循环和捆绑包的注册表。助手可以混合全文与向量搜索技能、获取技能详情与版本、浏览公开捆绑包、列出循环及其安全契约,并运行循环的验证以获得客观的通过或失败结果。发布、运行和评分循环,以及安装付费层技能,都需要 API 密钥;大多数读取端点无需认证。
- 适用场景
- 当助手需要从目录中发现并拉取可复用的技能或捆绑包时,或当你希望运行循环内置的成功检查并获得通过/失败判定时,适合使用。若你打算自托管同一注册表并让 CLI 指向自己的实例,也同样适用。
- 运行要求
- 需要通过网络访问提供商托管的远程 MCP 端点。API 密钥通过 x-api-key 请求头传递,密钥以 rec_ 开头,发布、运行、评分和安装付费层技能时必须提供。免费层技能可匿名安装。免费密钥可通过智能体自助注册或在提供商网站创建获得。
安装
在 SourceWeft 中
- 打开 控制台中的 LoopSkill,将其添加到工作区。
- 为需要使用其工具的对话启用该服务。
Web executable,通过 Streamable HTTP。 远程服务在工作区中配置后即可从网页运行时运行。
其他 MCP 客户端
把它添加到你客户端的 mcpServers 配置中。
{
"mcpServers": {
"loopskill": {
"type": "http",
"url": "https://app.loopskill.io/api/mcp/http/"
}
}
}README
LoopSkill
A local CLI for skills you already have, plus a self-hostable registry to
pull more from. Start with the CLI — it needs no account and makes no
network call for import/diff.
[CI] [License: MPL-2.0] [Stars] [loopskill.io] [MCP native]
60 seconds: see skill drift, reproducibly
This is a literal, self-contained transcript. Paste every command below into a clean shell — it fabricates two fake "skill" installs, edits one and deletes the other to simulate drift, then diffs. You will get exactly this output; nothing here depends on skills you already have installed.
Exit code is 1 — drift found, script- and CI-friendly. Run loopskill diff again with nothing changed and exit code is 0. That's the whole
pitch: two snapshots, one command, drift visible in the time it took to
read this paragraph — on the skills you actually have, not a demo, once
you drop --home.
import and diff make zero network calls — this isn't a promise in
a docstring, it's a structural guarantee: the network-capable code lives
in exactly one module (loopskill.pull) that import/diff never
import, and
cli/tests/test_loopskill_cli.py::test_import_and_diff_make_zero_network_calls
proves it by breaking socket.socket for the duration of those commands.
Full CLI reference, lockfile format, and pull/apply (the two commands
that DO touch the network, opt-in): cli/README.md.
What this repo actually is
Two things, and the CLI is the one to start with:
cli/— a local, offline-by-construction tool for the skills you already have on disk. No account, no server, no LoopSkill dependency forimport/diff. Point it at any registry that serves the same well-known bundle-index shape forpull/apply, or never call those commands at all.app/— a self-hostable FastAPI registry (this repo) that the CLI'spull/applycan optionally talk to, and that also serves a browsable catalog at loopskill.io. The registry is not the reason to start here — the CLI working on your own machine, before you've made an account, is.
Loops: two limits stated up front
The registry also serves 10 vetted loops (scripts/seed_starter_catalog.py).
POST /api/loops/{slug}/run is synchronous and works anywhere. Putting a loop on
a fleet member so it fires on a schedule is a second path with two constraints
worth knowing before you build on it:
- A loop reports nothing unless its own prompt says to. Telemetry exists
only because the loop's prompt calls
scripts/loopskill-emit-run.sh. Nothing else observes a fire — not the scheduler, not the server. Omit that line and the loop runs forever while every dashboard shows zero. This is the reasonloop_runssat at 1 for a year. - Cron materialization is Hermes-only.
app/loop_apply.pywrites the Hermes scheduler's~/.hermes/cron/jobs.json, and nothing else speaks that format yet. On Codex, Claude or OpenCode hostsscripts/install-loop-apply.shrefuses rather than installing a cron that can never converge. The skill path is cross-vendor; the scheduled-loop path is not.
Both are covered end to end in docs/SELF_HOST.md.
Self-host the registry (optional, for pull/apply against your own instance)
Zero-config: SQLite, auto-generated dev secrets, a seeded starter catalog. Your dev API key is printed on first boot. Full guide, including the Postgres/production path: docs/SELF_HOST.md.
Then run a loop — the runner is live (no LLM needed for verify-mode):
A fresh registry that doesn't just list a loop — it executes the loop's success check under enforced bounds and hands you a verdict.
What's actually in this codebase (and the honest answer to "why so big")
333 app Python files, 81,817 lines of app code, 118 Alembic migrations,
482 test files (clean-checkout counts; the local tree carries one untracked
junk test that CI never sees), 2 GitHub stars, 0 forks (measured 2026-08-21 via gh repo view wisechef-ai/loopskill-api --json stargazerCount,forkCount).
That ratio is real and it isn't a good one. Issue
#68 asked about
it; the honest answer — including why the codebase grew from a working
recipe-search product's battle-tested auth/Stripe/sandbox stack rather
than from a blank registry, and the concrete cuts committed as a result —
is in
docs/decisions/2026-08-11-bundles0811-p4-issue-68-codebase-size.md.
Every number above is checked against a live filesystem measurement by
tests/test_readme_claims.py on every run — it fails the build if this
paragraph drifts from reality the way #68's original numbers did.
Core API surface (self-hosted registry)
MCP-native: agents (Claude Code, Cursor, anything speaking MCP) discover and install over the protocol. There's also a signed-URL tarball path for direct fetch.
Architecture
FastAPI + SQLAlchemy. The same alembic migration chain runs on SQLite
(self-host) and Postgres (hosted) — no create_all drift; the SQLite boot
replays the real migrations, so what you self-host is what production
runs. Full module layout: AGENTS.md.
Auth flow
API keys are rec_-prefixed and passed in the x-api-key header. Most
read endpoints (search, detail, discover) are unauthenticated. Free-tier
skills install anonymously with no key (200 + tarball); installing a
paid-tier skill, publishing, running, and rating all require a key.
Develop
Sandbox (Linux only): the kernel sandbox (
app/sandbox/) needs firejail or bubblewrap. Where neither is functional (macOS, hardened containers), the loop runner falls back to bounded mode — POSIX rlimits + scrubbed env + isolated workspace — so loops still run; the response declares whichconfinementlevel it achieved. Multi-tenant fleet owners setWR_LOOP_RUN_REQUIRE_SANDBOX=trueto refuse bounded-mode execution and require a real kernel sandbox.
Contributor guide for AI agents: AGENTS.md.
Why open-core
The whole registry is the OSS product (MPL-2.0). Self-host it anywhere —
docker compose up is the complete experience, not a teaser, and nothing
phones home. The hosted plan is "don't run it yourself," never a feature
gate. Same posture as n8n / PostHog / Supabase.
License
MPL-2.0 — see LICENSE. The whole registry is open source; we only charge for hosting it.
Links
- CLI (start here): cli/README.md
- Home: loopskill.io
- Self-host guide: docs/SELF_HOST.md
- Issue #68 answer: docs/decisions/2026-08-11-bundles0811-p4-issue-68-codebase-size.md
- Contributing (AI agents): AGENTS.md
来源:README.md,提交 2e141d1
工具
0版本历史
1- v0.9.65最新Oct 11, 2026


