# Agent skills for a team: one version for everyone, private skills and publishing

By markdownregistry. Published October 2, 2026. Updated October 2, 2026.

A team stays on the same skills the way it stays on the same dependencies: one committed record of exactly what is installed, and a deliberate step to change it. Below: a lockfile everyone installs from, installing one exact version, how Claude Code shares skills, what a private registry adds, and how to publish a skill of your own. The commands were run on October 2, 2026; the figures are from [State of agent markdown, September 2026](https://markdownregistry.com/reports/state-of-agent-markdown-2026-09).

| Skill | Copies of the current version | Copies of an older version | Share on an older version |
| --- | --- | --- | --- |
| skill-creator | 14 | 8 | 36.4% |
| frontend-design | 3 | 12 | 80.0% |
| docx | 3 | 10 | 76.9% |
| pptx | 3 | 8 | 72.7% |
| xlsx | 5 | 9 | 64.3% |

Copies of five Anthropic skills, chosen because they change often, found in other repositories: how many match the current upstream version and how many an older one (byte-exact matches only). Registry crawl, data frozen September 27, 2026; method and downloads in [the report](https://markdownregistry.com/reports/state-of-agent-markdown-2026-09).

Every claim about another tool was checked against that tool's own documentation on October 2, 2026. Figures are from [State of agent markdown, September 2026](https://markdownregistry.com/reports/state-of-agent-markdown-2026-09), data frozen September 27, 2026.

## How do I keep everyone on my team on the same version of our agent skills?

Commit a lockfile and have everyone install from it. With mdr, each skill you add is recorded in mdr.lock with its version label and the SHA-256 of its main file. Commit that file, and every teammate and build server runs mdr install to get exactly those versions, with the files checked against their hashes before they are written. Nobody gets a newer version by accident: to move, one person runs mdr outdated, reads mdr diff, runs mdr update and commits the changed lockfile. In a build, mdr verify fails if a pinned version no longer resolves or its audit grade falls below the minimum you set.

```
$ mdr install
installed anthropics/skills/skill-creator@git:20260206.1ed29a0  7 files (7 hash-verified)  audit A  to skills/skill-creator
$ mdr verify --min-grade A
✓ anthropics/skills/skill-creator  git:20260206.1ed29a0  audit A (>= A)  sha256:d57b6e3a4453

all 1 pinned entry verified at grade A or better
```

That is a directory that held only `mdr.lock`: `mdr install` put back the version the lockfile names, not the latest one. Skills do move under a team that does not pin: in the registry's crawl, at least 19.4% (8,272 of the 42,581 first indexed at least 14 days before the data was frozen) got an upstream commit dated within 14 days after first indexing, a lower bound.

## How to install a specific version of a skill from a GitHub repo

Name the version when you install. With mdr, run mdr info owner/repo/skill to list the versions the registry has recorded, then mdr add owner/repo/skill@ followed by the version label; the lockfile holds that version until you choose to move. GitHub's gh skill does the same for any GitHub repository: install with --pin and a tag or a commit SHA, and a pinned skill is skipped during updates. Copying the folder from GitHub at a commit also works, but nothing records which commit you took.

```
$ mdr info anthropics/skills/skill-creator
versions:
  git:20260306.b0cbd3d     2026-03-06  b0cbd3d  audit A  sha256:dcd4803e61e9
  git:20260225.3d59511     2026-02-25  3d59511  audit A  sha256:ba8bebb2c085
  git:20260206.1ed29a0     2026-02-06  1ed29a0  audit A  sha256:d57b6e3a4453
$ mdr add anthropics/skills/skill-creator@git:20260206.1ed29a0 --dir skills/skill-creator
installed anthropics/skills/skill-creator@git:20260206.1ed29a0  7 files (7 hash-verified)  audit A  to skills/skill-creator
$ mdr outdated
anthropics/skills/skill-creator  git:20260206.1ed29a0 to git:20260306.b0cbd3d  audit A  (2026-03-06)  mdr diff anthropics/skills/skill-creator
```

The label `git:20260206.1ed29a0` is the commit date and the short commit of that version. `mdr outdated` then names the newer version and the command that shows the change. GitHub's pinning is described in [the gh skill changelog](https://github.blog/changelog/2026-04-16-manage-agent-skills-with-github-cli/).

## How do I share Claude Code skills across my team and keep them in sync?

Claude Code's docs give three ways: commit a skill to the repository to share it with everyone who works there, distribute it through a plugin, or deliver it through managed settings to reach a whole team. A project's skills live in .claude/skills/, so for skills your team wrote, committing them keeps everyone in sync through version control. For skills you took from somewhere else, a committed copy stays whatever version you copied, so pin it and check for updates on purpose.

Copies do fall behind. For five skills from anthropics/skills, chosen because they change often, 75 files in other repositories are byte-for-byte copies of a recorded upstream version, and 47 of them (62.7%) match an older version rather than the current one. Where Claude Code looks for skills: [Claude Code docs, skills](https://code.claude.com/docs/en/skills). Pinning step by step: [how to pin an agent skill to an exact version](https://markdownregistry.com/guides/pin-agent-skills).

## What is the best private agent skills registry for a company?

There is no single best one; it depends on where your skills need to go. If your team only uses Claude Code, a private git repository is enough: commit the skills under .claude/skills/, or distribute them as a plugin or through managed settings. If you want versions, a lockfile and an audit on private skills across projects and agents, markdownregistry has a private registry: mdr publish sends a skill folder to your team's namespace, mdr add @team/name installs it at an exact version, access tokens are read or write and can be switched off per machine, and you can set a minimum audit grade below which a version cannot be published. It costs $4 per month in early access, rising to $12 per month.

```
mdr login --token <token>
mdr publish ./skills/release-notes --ns acme --label 1.0.0
mdr add @acme/release-notes@1.0.0
```

Those three lines show the commands' form, with a made-up team and skill. What the private registry includes is on [the pricing page](https://markdownregistry.com/pricing).

## How do I publish my own agent skill so other people can install it?

Put the skill in a public GitHub repository: a folder with a SKILL.md whose frontmatter has a name and a description, as the Agent Skills specification requires. Anyone can then install it from the repository, with npx skills add owner/repo, with gh skill install owner/repo, or by copying the folder into their agent's skills directory. GitHub's gh skill publish also offers to turn on immutable releases, so a published release cannot be altered afterwards. markdownregistry indexes public repositories it finds through GitHub topic and README searches; once it has yours, mdr add owner/repo/skill installs it pinned.

Giving the repository a topic such as `agent-skills` helps it be found; the registry does not index every repository. Before you publish, check the frontmatter against [the SKILL.md format](https://markdownregistry.com/guides/skill-md-frontmatter) and read [what the automatic audit looks for](https://markdownregistry.com/guides/agent-skill-security), because every version the registry records gets a grade.

## Sources

- [Claude Code docs: skills](https://code.claude.com/docs/en/skills)
- [GitHub changelog: gh skill](https://github.blog/changelog/2026-04-16-manage-agent-skills-with-github-cli/)
- [Agent Skills specification](https://agentskills.io/specification)
- [vercel-labs/skills](https://github.com/vercel-labs/skills)

Last checked October 2, 2026. The page: https://markdownregistry.com/guides/agent-skills-for-teams
