Skip to content

Skill Resolvers

resolve_skill(uri) fetches a skill from a URI and returns a handle with the extracted local path. The AgentSkillStepConfig.skill field uses the same resolution.

from mmar_carl import resolve_skill
skill = resolve_skill("github://anthropics/skills/skills/pdf@main")
print(skill.local_root) # ~/.cache/mmar_carl/skills/github/<key>/skills/pdf
SchemeResolves from
github://owner/repo/path@refA GitHub tarball (no git needed).
local:// / plain pathA local directory.
https://A remote archive.
module://pkg.pathA Python package.

SkillResolverRegistry dispatches by scheme; register custom resolvers to extend it. GithubResolver downloads tarballs from codeload.github.com and caches them under ~/.cache/mmar_carl/skills/github/<key>/.

Pin a skill to a known SKILL.md digest so a compromised upstream is caught:

skill = resolve_skill(
"github://anthropics/skills/skills/pdf@main",
sha256="<hex-of-SKILL.md>",
trust_policy="sha_pinned",
)

With trust_policy="sha_pinned", CARL verifies the SHA256 of the local SKILL.md after extraction and raises SkillIntegrityError on a mismatch. Force a fresh download with GithubResolver().resolve(uri, force_refresh=True).

from mmar_carl import SkillLoader
skills = SkillLoader().catalog_all() # SKILL.md dirs + the agent-skills library

SkillManifest parses the SKILL.md frontmatter, including get_allowed_tools() / get_allowed_tool_names() for the allowed-tools list.