# What Is the Skills Catalog and How to Install or Uninstall Skills

> Discover the Skills catalog a remote collection of reusable skill packages. Learn to easily install or uninstall skills into your local directory.

- Repository: [Chaitanya Giri/munder-difflin](https://github.com/chaitanyagiri/munder-difflin)
- Tags: how-to-guide
- Published: 2026-08-20

---

**The Skills catalog is a curated, remote collection of reusable skill packages that users can browse, install into a local directory, or uninstall through validated path removal.**

The **munder-difflin** application manages Claude skills through two distinct channels: locally defined packages and a remote **Skills catalog**. Understanding how these systems interact—and how the application handles installation and uninstallation—is essential for extending Claude's capabilities safely. The core logic resides primarily in [`src/main/skills.ts`](https://github.com/chaitanyagiri/munder-difflin/blob/main/src/main/skills.ts), with IPC handlers registered in [`src/main/index.ts`](https://github.com/chaitanyagiri/munder-difflin/blob/main/src/main/index.ts) and exposed APIs defined in [`src/preload/index.ts`](https://github.com/chaitanyagiri/munder-difflin/blob/main/src/preload/index.ts).

## Understanding Local vs. Catalog Skills

The application distinguishes between skills stored locally on the filesystem and those fetched from a centralized repository.

### Local Skills

Local skills reside in user-controlled directories such as `~/.claude/skills`, project-level `.claude/skills` folders, or the bundled read-only `resources/skills` directory. The runtime discovers these by traversing the directories and identifying folders containing a [`SKILL.md`](https://github.com/chaitanyagiri/munder-difflin/blob/main/SKILL.md) file. This scan loop is implemented in [`src/main/skills.ts`](https://github.com/chaitanyagiri/munder-difflin/blob/main/src/main/skills.ts) at lines 85-96.

### Catalog Skills

The **Skills catalog** represents a remote, curated collection fetched as a markdown table from validated sources. The application downloads, parses, and caches this catalog, specifically requiring URLs that resolve to [`officialskills.sh`](https://github.com/chaitanyagiri/munder-difflin/blob/main/officialskills.sh) pages for security (see lines 322-330 in [`src/main/skills.ts`](https://github.com/chaitanyagiri/munder-difflin/blob/main/src/main/skills.ts)). The fetch logic spans lines 224-250 in the same file.

## How Skills Are Discovered

Local discovery relies on a filesystem walker that checks candidate directories for the presence of [`SKILL.md`](https://github.com/chaitanyagiri/munder-difflin/blob/main/SKILL.md). For catalog skills, the renderer process calls `skillsCatalog()` through the preload bridge (exposed at lines 762-766 of [`src/preload/index.ts`](https://github.com/chaitanyagiri/munder-difflin/blob/main/src/preload/index.ts)), which triggers the main process to return the cached remote list.

## Installing Skills from the Catalog

Installation follows a strict four-step pipeline orchestrated between the renderer and main processes.

1. **Browse the catalog**: The UI retrieves available skills via the `skillsCatalog()` IPC call.
2. **Trigger installation**: The frontend invokes `skillsInstall(url, name)`, which forwards to the `installSkill` handler in the main process.
3. **Download and verify**: The handler clones the skill repository or fetches individual files into `~/.claude/skills`. Before completing the operation, the system enforces safety checks in [`src/main/skills.ts`](https://github.com/chaitanyagiri/munder-difflin/blob/main/src/main/skills.ts) (lines 337-354) to prevent exceeding file-count or size limits and ensures the target path cannot escape the skills root directory.
4. **Completion**: Upon validation, the skill becomes available for immediate use.

```typescript
// Preload API (used by the renderer)
await window.api.skillsCatalog();               // → fetches the remote catalog (cached)
await window.api.skillsInstall('https://github.com/example/awesome-skill', 'awesome-skill');
// → downloads the skill into ~/.claude/skills/awesome-skill

```

## Uninstalling Skills Safely

Removing a skill requires strict path validation to prevent accidental deletion of system files. The process maps UI actions to main process handlers through the `skillsUninstall(path)` IPC method.

First, the `uninstallSkill` handler validates that the supplied path resides inside a known skills root—either `~/.claude/skills`, a project folder, or the bundled resources folder—and confirms the path is not the root directory itself (see validation logic in [`src/main/skills.ts`](https://github.com/chaitanyagiri/munder-difflin/blob/main/src/main/skills.ts), lines 422-449). Once verified, the application recursively deletes the directory, leaving a clean state.

```typescript
await window.api.skillsUninstall('~/.claude/skills/awesome-skill');
// → safely removes the installed skill after root validation

```

## Summary

- The **Skills catalog** provides a curated, remote marketplace of skills fetched from [`officialskills.sh`](https://github.com/chaitanyagiri/munder-difflin/blob/main/officialskills.sh) pages, while local skills are discovered via filesystem scanning for [`SKILL.md`](https://github.com/chaitanyagiri/munder-difflin/blob/main/SKILL.md) files.
- Installation downloads catalog entries into `~/.claude/skills` with enforced safety checks for file size, count, and path traversal implemented in [`src/main/skills.ts`](https://github.com/chaitanyagiri/munder-difflin/blob/main/src/main/skills.ts).
- Uninstallation validates target paths against known skill roots before deletion, preventing removal of system directories.
- All core functionality is implemented in [`src/main/skills.ts`](https://github.com/chaitanyagiri/munder-difflin/blob/main/src/main/skills.ts) and exposed to the frontend via [`src/preload/index.ts`](https://github.com/chaitanyagiri/munder-difflin/blob/main/src/preload/index.ts).

## Frequently Asked Questions

### What is the difference between local skills and catalog skills?

Local skills are static packages stored in user directories like `~/.claude/skills` or project folders, discovered by scanning for [`SKILL.md`](https://github.com/chaitanyagiri/munder-difflin/blob/main/SKILL.md) files. Catalog skills are dynamic, remotely hosted packages fetched from curated markdown tables on [`officialskills.sh`](https://github.com/chaitanyagiri/munder-difflin/blob/main/officialskills.sh) pages, offering a centralized distribution method.

### Where are installed skills stored on the filesystem?

Installed catalog skills are cloned into the user's Claude skills directory at `~/.claude/skills`. The installer may also target project-level `.claude/skills` directories, but never writes outside these validated roots due to path traversal checks in [`src/main/skills.ts`](https://github.com/chaitanyagiri/munder-difflin/blob/main/src/main/skills.ts) lines 337-354.

### How does the application prevent unauthorized skill installations?

The system validates that catalog URLs point to [`officialskills.sh`](https://github.com/chaitanyagiri/munder-difflin/blob/main/officialskills.sh) domains before fetching (lines 322-330). During installation, it enforces file-count limits, size restrictions, and confirms the extracted files remain within the designated skills root, aborting if any check fails.

### Can I uninstall bundled or project-level skills using the same method?

Yes, the `skillsUninstall` handler accepts paths from any known skills root, including bundled `resources/skills` or project directories. However, the validation logic at lines 422-449 strictly prevents uninstallation if the path equals the root directory itself or resides outside registered skill locations.