Import a skill via ZIP
When you already have a ready-made skill — with a manifest, prompt, and scripts — you can bring the whole thing into your organization via Import from ZIP in Skill Studio. This page describes the exact layout the ZIP needs, the limits the validator enforces, and how to import through the interface.
Required layout
The ZIP must contain, at the root, two required files:
my-skill.zip
├── manifest.yaml # required — Platform schema (schema_version 1)
├── prompt.md # required — the instructions for the agent
├── requirements.txt # optional — Python dependencies
└── scripts/ # optional — executable code
├── render.py
└── helpers.py
manifest.yaml(ormanifest.yml) — the manifest in the Platform schema. It must haveschema_version: 1, a validskill_key, and aname.prompt.md— the prompt content (what the agent reads). It's required, even if short.- Any other file (scripts,
requirements.txt, assets) is preserved.
A ZIP without manifest.yaml or without prompt.md is rejected. The names are fixed — don't use SKILL.yaml/SKILL.md in the import package.
Limits and validation
Before accepting the package, the validator applies strict rules. Knowing them avoids rejections:
| Rule | Limit / behavior |
|---|---|
| ZIP size | ≤ 10 MB. Anything above is rejected. |
| Number of files | ≤ 50 files. |
| Path traversal | Paths with .. or absolute paths are rejected. |
| Symlinks | Not allowed. |
| Binaries | Extensions .exe, .dll, .so, .dylib, .com, .msi are rejected. |
schema_version | Must be exactly 1. |
skill_key | Must match ^[a-z0-9][a-z0-9-]{1,98}[a-z0-9]$. |
name | Required. |
execution_mode | local_plain (default) or local_protected. remote_server is rejected. |
| Script scanner | Script files (.py, .sh, .js, .ts, .rb…) go through a content analysis. |
The security scanner
The script files in the package go through a content scan that looks for dangerous patterns — destructive commands, secret-exfiltration attempts, direct calls to model providers, and so on. The result can be:
- Blocked — the import fails and the message points to the file and the reason. Fix the script and try again.
- Warning — the import proceeds, but Studio surfaces flags for you to review.
Binaries are already barred by the extension rule. The scanner runs over the source code of the allowed scripts. Keep the scripts simple and follow the outputs/ discipline.
Env-secrets consistency
If the manifest declares secrets in both forms — required_env and env.secrets[] — they must agree. A mismatch is rejected on import. See Env-secrets (author) for the contract.
manifest.yaml example
A minimal, valid manifest to import, with one declared secret:
schema_version: 1
skill_key: lead-proposal
name: lead_proposal
display_name: "Proposal Generator"
version: "1.0.0"
description: Generates a .docx commercial proposal from a CSV of leads.
entrypoint: scripts/build_proposal.py
permissions:
network: outbound
filesystem: outputs_only
docs:
summary: prompt.md
inputs:
- name: leads_csv
type: string
description: Path to the leads CSV.
required: true
outputs:
- name: proposal.docx
type: file
description: The generated proposal.
env:
secrets:
- name: CRM_API_TOKEN
secret_ref: crm-api-token
required: true
execution_mode: local_plain
Step-by-step in the interface
- In the web console, open Skills and click Import from ZIP.
- Select the
.zipfile assembled per the layout above. - Choose the destination skill group (required).
- Submit. The validator runs the limits and the scanner.
- If something fails, the message indicates what (size, missing file, invalid manifest, blocked script). Fix it and resubmit.
- On success, the skill enters as a draft in the editor. Review the Prompt Editor and the Files.
- When it's ready, publish — see Publish and version.
Importing the same skill with the same version and the same content is idempotent (a no-op). Changed the content? Bump the version in manifest.yaml, otherwise publishing returns a conflict. See Publish and version.
See also
Was this page helpful?
Report a problem on this pageDo not send passwords, keys, tokens, or customer data.