skillmeld 0.2.0 — discovery now works out of the box
The hosted catalog is live: a signed, hash-pinned index of community skills rebuilt weekly, so discover and fetch work with zero setup. Plus hardened Skills-API emit and a security bump.
skillmeld 0.2.0 ships the hosted data layer. Catalog sync now pulls a signed manifest — Ed25519-signed, hash-pinned content, anti-rollback — from data.ifylab.dev, rebuilt weekly from community skill repositories, with a verdict index scanned at build time. Hosted verdicts are advisory only: the local security scan always runs, and a hosted PASS never overrides it. Emitting to the Claude Skills API now pins the current beta headers and states the workspace-wide sharing scope in the provenance record. Also in this release: per-skill license detection for repositories that license each skill in its own folder, and a dependency security bump.
Read the source
