What Is the Skills Catalog and How to Install or Uninstall Skills

The Skills catalog is a curated, remote collection of reusable skill packages that users can browse, install into a local directory, or uninstall through validated path removal.

The munder-difflin application manages Claude skills through two distinct channels: locally defined packages and a remote Skills catalog. Understanding how these systems interact—and how the application handles installation and uninstallation—is essential for extending Claude's capabilities safely. The core logic resides primarily in src/main/skills.ts, with IPC handlers registered in src/main/index.ts and exposed APIs defined in src/preload/index.ts.

Understanding Local vs. Catalog Skills

The application distinguishes between skills stored locally on the filesystem and those fetched from a centralized repository.

Local Skills

Local skills reside in user-controlled directories such as ~/.claude/skills, project-level .claude/skills folders, or the bundled read-only resources/skills directory. The runtime discovers these by traversing the directories and identifying folders containing a SKILL.md file. This scan loop is implemented in src/main/skills.ts at lines 85-96.

Catalog Skills

The Skills catalog represents a remote, curated collection fetched as a markdown table from validated sources. The application downloads, parses, and caches this catalog, specifically requiring URLs that resolve to officialskills.sh pages for security (see lines 322-330 in src/main/skills.ts). The fetch logic spans lines 224-250 in the same file.

How Skills Are Discovered

Local discovery relies on a filesystem walker that checks candidate directories for the presence of SKILL.md. For catalog skills, the renderer process calls skillsCatalog() through the preload bridge (exposed at lines 762-766 of src/preload/index.ts), which triggers the main process to return the cached remote list.

Installing Skills from the Catalog

Installation follows a strict four-step pipeline orchestrated between the renderer and main processes.

  1. Browse the catalog: The UI retrieves available skills via the skillsCatalog() IPC call.
  2. Trigger installation: The frontend invokes skillsInstall(url, name), which forwards to the installSkill handler in the main process.
  3. Download and verify: The handler clones the skill repository or fetches individual files into ~/.claude/skills. Before completing the operation, the system enforces safety checks in src/main/skills.ts (lines 337-354) to prevent exceeding file-count or size limits and ensures the target path cannot escape the skills root directory.
  4. Completion: Upon validation, the skill becomes available for immediate use.
// Preload API (used by the renderer)
await window.api.skillsCatalog();               // → fetches the remote catalog (cached)
await window.api.skillsInstall('https://github.com/example/awesome-skill', 'awesome-skill');
// → downloads the skill into ~/.claude/skills/awesome-skill

Uninstalling Skills Safely

Removing a skill requires strict path validation to prevent accidental deletion of system files. The process maps UI actions to main process handlers through the skillsUninstall(path) IPC method.

First, the uninstallSkill handler validates that the supplied path resides inside a known skills root—either ~/.claude/skills, a project folder, or the bundled resources folder—and confirms the path is not the root directory itself (see validation logic in src/main/skills.ts, lines 422-449). Once verified, the application recursively deletes the directory, leaving a clean state.

await window.api.skillsUninstall('~/.claude/skills/awesome-skill');
// → safely removes the installed skill after root validation

Summary

  • The Skills catalog provides a curated, remote marketplace of skills fetched from officialskills.sh pages, while local skills are discovered via filesystem scanning for SKILL.md files.
  • Installation downloads catalog entries into ~/.claude/skills with enforced safety checks for file size, count, and path traversal implemented in src/main/skills.ts.
  • Uninstallation validates target paths against known skill roots before deletion, preventing removal of system directories.
  • All core functionality is implemented in src/main/skills.ts and exposed to the frontend via src/preload/index.ts.

Frequently Asked Questions

What is the difference between local skills and catalog skills?

Local skills are static packages stored in user directories like ~/.claude/skills or project folders, discovered by scanning for SKILL.md files. Catalog skills are dynamic, remotely hosted packages fetched from curated markdown tables on officialskills.sh pages, offering a centralized distribution method.

Where are installed skills stored on the filesystem?

Installed catalog skills are cloned into the user's Claude skills directory at ~/.claude/skills. The installer may also target project-level .claude/skills directories, but never writes outside these validated roots due to path traversal checks in src/main/skills.ts lines 337-354.

How does the application prevent unauthorized skill installations?

The system validates that catalog URLs point to officialskills.sh domains before fetching (lines 322-330). During installation, it enforces file-count limits, size restrictions, and confirms the extracted files remain within the designated skills root, aborting if any check fails.

Can I uninstall bundled or project-level skills using the same method?

Yes, the skillsUninstall handler accepts paths from any known skills root, including bundled resources/skills or project directories. However, the validation logic at lines 422-449 strictly prevents uninstallation if the path equals the root directory itself or resides outside registered skill locations.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →