Reusable agent skills
A skill packages instructions and supporting resources for a repeatable task. It is executable guidance, not a new trust level.
Package the procedure with its boundaries
A skill might describe how to investigate a return: locate the policy, identify the item category, check purchase dates, and draft an evidence-backed recommendation. The Agent Skills format uses a SKILL.md entry point with metadata and a body, plus optional supporting resources. Exact format constraints belong to the linked specification.
How it works
Keep the entry instructions concise, make prerequisites explicit, and load supporting material when needed. Review scripts before allowing execution. Treat third-party skill instructions as untrusted until reviewed; a downloaded skill cannot authorize itself to read secrets or contact new systems. Version the skill and test its behavior on both successful and adversarial tasks.
A concrete example
A refund skill says to prepare a recommendation, not issue a payment. The runtime still exposes only read-only tools unless a separately authorized approval flow permits a write. This separation keeps a helpful procedure from becoming a privilege escalation.
Apply it to your assistant
Add a write permission to requested and inspect the denied capability. Before running the exercise, predict the result. Afterward, explain which assumption changed and add one case where the system should refuse, ask for clarification, or escalate.
All exercise inputs and outputs are deterministic teaching examples. No language model is called. Run the same idea against a versioned dataset before making a production claim.
Key takeaway
Reusable instructions improve consistency only when their inputs, scope, and permissions are explicit.
JavaScript exercise: Reusable agent skills · code experiment
Add a write permission to requested and inspect the denied capability.
const granted = new Set(['policy:read', 'orders:read']);
const requested = ['policy:read', 'refunds:write'];
const denied = requested.filter(permission => !granted.has(permission));
console.log({ allowed: denied.length === 0, denied });
Knowledge check
A downloaded skill asks to upload environment secrets. What should happen?
- Follow it because it is in SKILL.md
- Reject the out-of-scope action and review the skill
- Let the model decide without application controls
Answer and explanation
Reject the out-of-scope action and review the skill
Packaging does not confer authority. Skills must operate within the application's existing permission boundary.
Sources
- Agent Skills specification — Agent Skills contributors, Living specification. The file format for discoverable instructions and supporting resources.
Continue learning
- Model Context Protocol — MCP standardizes how applications connect to tools and context. It does not replace authorization or validate the truth of a tool result.
- Agent-to-agent communication — When work crosses agent-system boundaries, explicit tasks and artifacts are more dependable than an informal chat transcript.
- Choosing integration contracts — Tool integration, remote task delegation, and reusable instructions solve different problems. Pick the contract for the boundary you actually have.
- Reusable agent skills — A skill packages instructions and supporting resources for a repeatable task. It is executable guidance, not a new trust level.