Skip to main content
Skills are open SKILL.md files, and the registry’s read surface is public. You never need the Python SDK — or an account — to find a skill, judge its evidence, and get it onto disk where your runtime (Claude Code, Cursor, Copilot, Cline, …) auto-discovers it. Four routes, one destination: Whatever the route, do the two trust checks first: the verified lift (with-vs-without benchmark, with model + case count + date) and the safety band (Passed / Caution / Blocked / Not yet reviewed). Both are on every skill’s public page — see How skills are vetted. None of the routes below decides for you. decimalai skills pull writes whatever the registry serves — including a Caution or even a Blocked skill, with no prompt and no warning — and copy-paste obviously can’t stop you. The one gate that exists is on the raw rail: /s/<slug>/SKILL.md 404s for a Blocked skill. Blocked skills are still listed, deliberately, so you can see that a skill exists and why it’s unsafe — the band on the page is the check, not the tooling.

Web copy-paste

Open any skill at app.decimal.ai/skills/<slug> — for example playwright-cli — view the full SKILL.md body, and copy it into your project:
The Copy SKILL.md button on the skill page copies the body with frontmatter already stamped — name plus the source stamp below — so just add a description: line (runtimes route on name + description). If you copy the raw body by hand instead, add a minimal block yourself:

Provenance: the source stamp

The raw-serve routes stamp two extra frontmatter keys into the body they hand you — both curl https://app.decimal.ai/s/<slug>/SKILL.md and the Copy SKILL.md button. decimalai skills pull does not: it reconstructs name + description only, so add these by hand if you pulled with the CLI:
That’s the whole scheme — where the file came from, and a fingerprint of the exact body you took. Six months from now it answers “which version is this, and have we edited it?” The source value is a permalink to that exact version: it keeps serving version <version> for as long as that version exists, so it never tells you a newer one has shipped. To answer “am I behind?”, fetch the always-current https://app.decimal.ai/s/<slug>/SKILL.md and compare your stamped source_sha256 against the first 12 hex of the response ETag — and its -v<n> suffix against your stamped <version>. No stamp, no answer.

CLI pull (decimalai skills pull)

The DecimalAI CLI ships with the Python package, but skills pull is anonymous — no API key, no signup:
Writes <out>/<slug>/SKILL.md with reconstructed frontmatter, plus the skill’s eval.yaml test suite when the author published one — so you can re-run the with-vs-without benchmark yourself with the open runner. Other forms:
Read-only by design: no fork is created and nothing is tracked. If you later want a fork in your org (upstream-update detection, effectiveness measurement on your own traffic), that’s decimalai skills install — the one skills command that needs an API key.

Raw URLs (scripts, CI, and LLM agents)

Every published skill is fetchable as plain text — no HTML scraping, no auth:
The ETag doubles as an integrity check: its hash half is the full sha256 that the source stamp truncates to 12 hex, so a stamped file is verified against the live registry in one request — compare your source_sha256 to the first 12 hex of the ETag, no local hashing required. The hash is taken over the body before the stamp is injected, so hashing the served bytes will not match. Note the @<version> form is a version archive, not a currency check — it serves whichever historical version you ask for. The ETag’s -v<n> suffix on the unpinned URL is what carries the current version number.

MCP server

decimalai-mcp gives any MCP client — Claude Code, Claude Desktop, Cursor — three read-only registry tools: search_skills, get_skill (full record: trust bands, verified lift, SKILL.md body), and get_leaderboard. No API key required:
uvx fetches and runs it without installing anything permanently (uv required). Then ask your agent things like:
“find me a measured skill for enterprise customer onboarding, and show its verified lift, case count, and safety band”
Today that returns gtm-enterprise-onboarding first — +78.3 points over 23 cases, safety Passed — with the evidence inline, so you can judge it without opening a browser. This is the discovery route — it answers “which skill should I use, and what’s the evidence?” without leaving your editor. It is deliberately read-only: it searches and inspects, it never writes files. Pair it with decimalai skills pull (above) to actually install what it finds.
Optional: set DECIMAL_API_KEY to also see which skills your org has already installed.

When you do want the SDK

Everything above is consume-only: the file lands on disk and your runtime takes it from there. The SDK adds the feedback loop — forking skills into your org, routing them per-turn, and measuring which ones actually help your agent on your traffic. When you’re ready for that: Quickstart and the registry guide.