Prototype of the skill-set layering discussed with agentskills.io:
- AI Catalog (/.well-known/ai-catalog.json) entries typed
application/agent-skills+json point at an agentskills PR #254
discovery index and represent an installable skill set.
- The optional io.hermes.skill-set extension carries set-level usage
intent: a suggested load-alias command and a shared instruction
preamble. Clients that ignore the extension still install the
correct set.
- tools/skill_set_catalog.py implements the client: $schema gating,
required sha256 digest verification, skill-md + archive (.tar.gz/.zip)
artifacts, and #254 archive-safety rules (traversal/absolute-path/
link rejection, decompression caps).
- hermes skills install-set <url> installs every member through the
existing quarantine -> scan -> install pipeline, then creates the
/<name> skill bundle so the whole set loads in one turn.
- scripts/publish_skill_set.py is the publisher-side counterpart:
builds the static .well-known tree (catalog + index + artifacts)
from local skill directories with byte-stable archives.