{"_id":"@best-ai-skills/cli","_rev":"3-34a45ec122e470d1c48e56ace6b7c6f5","name":"@best-ai-skills/cli","dist-tags":{"latest":"0.1.0"},"versions":{"0.1.0":{"name":"@best-ai-skills/cli","version":"0.1.0","keywords":["agent","ai","cli","skills"],"license":"MIT","_id":"@best-ai-skills/cli@0.1.0","maintainers":[{"name":"litanghui","email":"leetanghui424@gmail.com"}],"homepage":"https://best-ai-skills.com","bugs":{"url":"https://github.com/17old-org/best-ai-skills/issues"},"bin":{"bas":"dist/index.js","best-ai-skills":"dist/index.js"},"dist":{"shasum":"6a0d1dd084c9ef5095f9f813c6580474f4362b72","tarball":"https://registry.npmjs.org/@best-ai-skills/cli/-/cli-0.1.0.tgz","fileCount":33,"integrity":"sha512-6PE9OOOICT+vfIRdbz9W2wbiGqMdPeUO0A4pmsR4fAT0Spwu3f17tDPFbss8V8q1IiZmhmy5zgcUJGBlN/uagQ==","signatures":[{"sig":"MEUCIQDFuXlbczYEX5K/8rb8M0WwW72suCLteBbz+oFgeV82gQIgPiz/N+A+vSc3hXOxHJdzwahR5h6qrF53ZOoiKhDzKgc=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":95384},"type":"module","engines":{"node":">=22"},"gitHead":"948da033f3cd054c4270e4325ee7f172baa88404","scripts":{"test":"node --import tsx --test test/*.test.ts","build":"tsc -p tsconfig.json","check":"biome check src test","prepack":"npm run build","prebuild":"node clean-dist.mjs","typecheck":"tsc --noEmit -p tsconfig.json && tsc --noEmit -p tsconfig.test.json"},"_npmUser":{"name":"litanghui","email":"leetanghui424@gmail.com"},"deprecated":"Renamed to skillry-cli. Install with: npm i -g skillry-cli","repository":{"url":"git+https://github.com/17old-org/best-ai-skills.git","type":"git","directory":"apps/cli"},"_npmVersion":"11.9.0","description":"Install Best AI Skills securely from an agent or terminal.","directories":{},"_nodeVersion":"24.14.0","dependencies":{"fflate":"^0.8.3","@napi-rs/keyring":"1.3.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"catalog:","typescript":"catalog:","@types/node":"catalog:"},"_npmOperationalInternal":{"tmp":"tmp/cli_0.1.0_1786207386868_0.22258334921807998","host":"s3://npm-registry-packages-npm-production"}}},"time":{"created":"2026-08-08T16:43:06.693Z","modified":"2026-08-26T08:21:33.164Z","0.1.0":"2026-08-08T16:43:07.022Z"},"bugs":{"url":"https://github.com/17old-org/best-ai-skills/issues"},"license":"MIT","homepage":"https://best-ai-skills.com","keywords":["agent","ai","cli","skills"],"repository":{"url":"git+https://github.com/17old-org/best-ai-skills.git","type":"git","directory":"apps/cli"},"description":"Install Best AI Skills securely from an agent or terminal.","maintainers":[{"name":"litanghui","email":"leetanghui424@gmail.com"}],"readme":"# Best AI Skills CLI\n\nThe official macOS and Windows CLI for browser login and verified Skill\ninstallation.\n\n```bash\nnpx @best-ai-skills/cli@latest login\nnpx @best-ai-skills/cli@latest install taste-driven-frontend\nnpx @best-ai-skills/cli@latest install taste-driven-frontend --agent claude-code\n```\n\nThe default service is `https://best-ai-skills.com`. Local development can use\neither `--base-url http://localhost:3001` or `BEST_AI_SKILLS_URL`.\n\n## Commands\n\n```text\nbest-ai-skills login\nbest-ai-skills status\nbest-ai-skills logout\nbest-ai-skills install <slug> [--agent <agent> | --target <directory>] [--force]\n```\n\nThe default `shared` target installs to `~/.agents/skills/<slug>`. `--agent`\nselects a known Agent Skills directory:\n\n| Agent target | Skills parent directory |\n| --- | --- |\n| `shared`, `codex`, `cursor`, `gemini-cli`, `kimi-code`, `opencode` | `~/.agents/skills` |\n| `claude-code` | `~/.claude/skills` |\n| `antigravity` | `~/.gemini/config/skills` |\n\n`--target` overrides the default with an explicit parent directory. It cannot\nbe combined with `--agent`. The installed directory is always\n`<skills-parent>/<slug>`.\n\nBrowser login starts with the Better Auth Device Flow. The exchange returns an\nopaque, seven-day token that is accepted only by `/api/cli/**`; it is not a\nbrowser session. Only its SHA-256 digest is stored by the server. The plaintext\nCLI token is stored through the native OS keyring: macOS Keychain or Windows\nCredential Manager. The CLI has no plaintext fallback and never writes the\ntoken to JSON, `.env`, command-line arguments, or logs.\n\nEvery downloaded ZIP must include valid `Content-Length` and\n`X-Archive-Sha256` headers. Before writing anything, the CLI rejects absolute\npaths, traversal, Windows device names, case-insensitive duplicates,\nfile/directory collisions, excessive file counts, and oversized compressed or\nuncompressed content. It accepts a flat archive or a single `<slug>/` root.\n\nInstallation uses `.best-ai-skills/staging` under the selected Skills parent,\nthen moves the verified directory into place atomically on the same volume.\n`--force` preserves the old Skill under `.best-ai-skills/backups`, outside the\nroot-level directories Agents inspect as Skills. Archive lifecycle scripts are\nnever run.\n\nAfter the atomic rename succeeds, the CLI posts an idempotent installation\nreceipt. A reporting outage never rolls back a verified local installation.\n\n## Development\n\nNode.js 22 or newer is required.\n\n```bash\npnpm --filter @best-ai-skills/cli typecheck\npnpm --filter @best-ai-skills/cli build\npnpm --filter @best-ai-skills/cli test\npnpm --filter @best-ai-skills/cli check\n```\n\nTests use a mocked keyring and never read or modify a real credential store.\n\n## Publishing note\n\nThe package is configured for public npm access, but provenance is intentionally\ndisabled while the CLI source lives in a private monorepo. Re-enable provenance\nonly after moving the CLI source to a matching public repository and configuring\nnpm Trusted Publishing from a supported CI provider.\n","readmeFilename":"README.md"}