PROJECTSKILLSCONNECTING…

SYS.50 / CLI

The terminal

Your Skills and Constitution are files. The CLI puts them where the agent in your editor already looks.

Surfaces5 SECTIONS

Install and sign in

One package, two binaries, and a browser approving a terminal.

INSTALL
npm install -g projectskills

pskl is the short name; projectskills does the same thing. Node 22 or newer.

pskl login prints an eight-character code and opens the browser. No password is ever typed into a shell. Check the code on screen matches the one in your terminal before approving — that comparison is what stops somebody talking you into approving their login.

The full command reference

Every command, its flags, and what your plan will refuse.

The complete reference lives at /cli/guide — install, sign in, create, pull, share, webhooks, SBOM, explain, MCP, models, Skills, impact queries, KEEL and findings, each with its flags and the entitlement your plan makes the server check.

It is generated from the same list the in-app dialog renders, so the two cannot drift. What follows here is the part a command list cannot tell you.

What lands on disk

Four paths, and which of them to commit.

PathWhat it isCommit it?
.claude/skills/<name>/SKILL.mdThe artefacts your agent loadsyes
.projectskills/project.jsonWhich project this directory isyes — a project id is not a secret
.projectskills/artifacts.jsonWhat was written and its hash — how pull knows not to overwrite a file you editedyes
The credential file in your user configYour token, written private to younever

A project id is safe to commit because the API answers "not found" to anybody who is not a member of the project. There is no id-guessing surface to protect.

Exit codes are distinct on purpose

A tool that answers 1 for everything cannot be branched on.

"Not on your plan" and "not built yet" need opposite responses from a script, so they do not share a code. Gates are opt-in throughout: pskl findings and `pskl skills audit` exit zero whatever they find unless you ask for a threshold with --fail-on.

In CI

A token, an environment variable, and two commands worth wiring up.

Machines that cannot open a browser authenticate with a token from your account, supplied in the environment rather than on the command line. pskl whoami is the cheapest way to prove the wiring works, and the HTTP API describes what the CLI is talking to.

`pskl findings diff` --markdown produces a pull-request comment body for CI to post, and --fail-on turns a new finding at or above a severity into a non-zero exit. pskl skills freshness is worth running on a schedule rather than per commit.

DOCS23 CHAPTERS