skills add --skill <name> bypasses the metadata.internal gate (--all honors it)
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Newbie friendliness
- 68/100
- Issue type
- Bug
- Clarity
- Mostly clear
- Activity status
- Active
- Tech stack
- node.js, typescript
- Domain
- cli, documentation, tooling
Research direction
Start by tracing the npx skills add explicit --skill path and compare its metadata handling with the --all path described in the reproduction. Verify the behavior with the listed commands and ensure an internal skill is refused unless INSTALL_INTERNAL_SKILLS=1 is set. Also update CLAUDE.md:12 so its installation guidance matches the documented behavior in .claude/skills/README.md and the other catalog surfaces.
Written by the indexing model from the issue text.
Description
Summary
#3856 marked the six repo-native skills metadata.internal: true so they stay out of public installs. The gate works on --all. It does not work when a skill is named explicitly with --skill, so all six are still publicly installable today with no flag and no env var.
Reproduction
Run each in an empty directory. Observed today on main at 14b9e2039, installer npx skills add.
| Command | INSTALL_INTERNAL_SKILLS |
Internal six | Total installed |
|---|---|---|---|
npx skills add heygen-com/hyperframes --all |
unset | excluded ✅ | 20 |
npx skills add heygen-com/hyperframes --all |
=1 |
pulled ✅ | 26 |
npx skills add heygen-com/hyperframes --skill changelog-video |
unset | pulled ❌ | 1 |
$ mkdir /tmp/t && cd /tmp/t
$ npx skills add heygen-com/hyperframes --skill changelog-video
● Selected 1 skill: changelog-video
◇ Installed 1 skill
✓ ./.agents/skills/changelog-video
universal: Antigravity, Codex, Cursor, Droid, Gemini CLI +15 more
symlinked: Claude Code
The installed SKILL.md is byte-identical to .claude/skills/changelog-video/SKILL.md on current main, marker included:
metadata:
internal: true
So the registry is serving current content and the flag is present in the payload. The explicit-install path just never checks it.
Expected
.claude/skills/README.md, added in #3856, states the contract:
Each repo-native skill declares
metadata.internal: true, sonpx skills addskips it during normal installs (including--all). This does not change local agent discovery. To explicitly install these skills elsewhere, setINSTALL_INTERNAL_SKILLS=1when running the installer.
An explicit --skill <internal-name> without INSTALL_INTERNAL_SKILLS=1 should refuse, the way --all does. Right now the env var is the documented escape hatch for a door that has no lock.
Why it matters
The explicit path ships the full skill directory, 712K, not just the prompt:
assets/fonts/TT_Norms_Pro_{Medium,Bold,Normal}.woff2
assets/fonts/tt_norms_pro_mono_regular-webfont.woff2
assets/fonts/ABCSolarDisplay-Bold.woff2
assets/bgm.mp3
assets/bg-pattern.mp4
references/{build-spec,script-voice,visualization-registry}.md
references/lexicon.json
examples/master-skeleton.html
scripts/align-captions.mjs
Those are commercial foundry webfonts and house brand assets going out through a public install command. That is the exposure #3856 was closing, and it is still open on this path. Worth a licensing check independent of the fix.
Second, smaller finding
CLAUDE.md:12 still documents the pre-#3856 behavior:
npx skills add heygen-com/hyperframes # interactive picker (terminal only; --all also pulls the 6 repo-internal skills under .claude/skills)
The --all run above disproves that, 20 skills and none of the six. #3856 updated AGENTS.md, README.md, and docs/guides/skills.mdx but not CLAUDE.md. The repo's own "Skill catalog maintenance" section requires these surfaces move in lockstep.
Environment
macOS 15.6, Node via npx, repo at 14b9e2039.
- Dominant language
- TypeScript
- Stars
- 54.1k
- Forks
- 4.9k
- Avg merge
- 10h 29m
- Merged PRs (30d)
- 756
Getting set up
This project ships no dev container, Dockerfile or contributing guide, so setting up is up to you: start from its README, and see our first-contribution guide for the general steps.
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from heygen-com/hyperframes
-
Difficulty 2/5 1-3 hours Newbie friendliness 87/100
heygen-com/hyperframes#5002 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
heygen-com/hyperframes#4702 · 1 comment · 1 reaction ·
Maintainers usually reply within 1 day
-
Studio catalog prompt editor has no accessible namePossibly taken @lorenzozanee claimed this 10 days ago. Openbug difficulty/easy triage/ready
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
heygen-com/hyperframes#4384 ·
Maintainers usually reply within 1 day
-
lint: validate composition variables declared on supported root elementsMay be free again A pull request for this issue was closed without being merged. Openbug difficulty/easy triage/ready
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
heygen-com/hyperframes#4383 ·
Maintainers usually reply within 1 day
-
lint: report AVIF/M4A media-kind mismatches consistently with JPEG/MP3May be free again A pull request for this issue was closed without being merged. Openbug difficulty/easy triage/ready
Difficulty 2/5 1-3 hours Newbie friendliness 91/100
heygen-com/hyperframes#4382 · 1 comment ·
Maintainers usually reply within 1 day
All issues in heygen-com/hyperframes
Similar issues
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
Effect-TS/effect#8728 · 1 comment ·
Maintainers usually reply within 1 day
-
check:passed streams:add
Difficulty 2/5 1-3 hours Newbie friendliness 66/100
Maintainers usually reply within 1 day
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 90/100
linagora/twake-drive-mobile#436 ·
Maintainers usually reply within 1 day
-
[Bug] The shared instance selector's placeholder and no-match text ignore the display languagePossibly taken A pull request linked to this issue is open or already merged. Open
Difficulty 2/5 1-3 hours Newbie friendliness 90/100
apache/rocketmq-dashboard#5561 ·
Maintainers usually reply within 3 days
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
CopilotKit/OpenDots#69 ·
Maintainers usually reply within 1 day