18 skill descriptions exceed the 1024-character Agent Skills spec limit (longest 1522)

#30 · open · 0 comments

View on GitHub ↗

KS-OTO

## Summary 18 of the 78 skill descriptions exceed the [Agent Skills specification](https://agentskills.io/specification) limit for the `description` frontmatter field. Reporting only — no fix proposed here; whether and how to address this is your call. ## The constraint From the Agent Skills specification (frontmatter fields table): > **description** — Yes (required) — **Max 1024 characters.** Non-empty. Describes what the skill does and when to use it. And in the field detail: > The required `description` field: > - **Must be 1-1024 characters** > - Should describe both what the skill does and when to use it > - Should include specific keywords that help agents identify relevant tasks Anthropic's authoring guide states the same: *"`description`: Must be non-empty, Maximum 1,024 characters."* ## Affected skills | # | Skill | Chars | Over limit | File | |---:|---|---:|---:|---| | 1 | `offensive-windows-privesc` | 1522 | +498 | `Skills/privesc/offensive-windows-privesc/SKILL.md` | | 2 | `offensive-tls-attacks` | 1506 | +482 | `Skills/crypto/offensive-tls-attacks/SKILL.md` | | 3 | `offensive-dependency-confusion` | 1420 | +396 | `Skills/supply-chain/offensive-dependency-confusion/SKILL.md` | | 4 | `offensive-supply-chain` | 1407 | +383 | `Skills/supply-chain/offensive-supply-chain/SKILL.md` | | 5 | `offensive-social-engineering` | 1341 | +317 | `Skills/social-engineering/offensive-social-engineering/SKILL.md` | | 6 | `offensive-linux-privesc` | 1313 | +289 | `Skills/privesc/offensive-linux-privesc/SKILL.md` | | 7 | `offensive-crypto-attacks` | 1303 | +279 | `Skills/crypto/offensive-crypto-attacks/SKILL.md` | | 8 | `offensive-phishing` | 1290 | +266 | `Skills/social-engineering/offensive-phishing/SKILL.md` | | 9 | `offensive-cicd-pipeline` | 1177 | +153 | `Skills/cicd/offensive-cicd-pipeline/SKILL.md` | | 10 | `offensive-k8s-attacks` | 1152 | +128 | `Skills/container/offensive-k8s-attacks/SKILL.md` | | 11 | `offensive-anti-forensics` | 1149 | +125 | `Skills/forensics/offensive-anti-forensics/SKILL.md` | | 12 | `offensive-persistence` | 1132 | +108 | `Skills/post-exploitation/offensive-persistence/SKILL.md` | | 13 | `offensive-api-abuse` | 1111 | +87 | `Skills/api/offensive-api-abuse/SKILL.md` | | 14 | `offensive-graphql` | 1108 | +84 | `Skills/web/offensive-graphql/SKILL.md` | | 15 | `offensive-c2-frameworks` | 1088 | +64 | `Skills/forensics/offensive-c2-frameworks/SKILL.md` | | 16 | `offensive-cicd-secrets` | 1058 | +34 | `Skills/cicd/offensive-cicd-secrets/SKILL.md` | | 17 | `offensive-cloud` | 1050 | +26 | `Skills/cloud/offensive-cloud/SKILL.md` | | 18 | `offensive-data-exfiltration` | 1025 | +1 | `Skills/post-exploitation/offensive-data-exfiltration/SKILL.md` | Median over-limit description: 1177 chars. Largest overage: +498. ## Observations - **No current breakage observed.** All 18 were discovered and installed successfully by `[email protected]`, so whatever consumes them today is tolerant of the limit. - **Description text is pre-loaded.** Per Anthropic's authoring guidance, *"At startup, only the metadata (name and description) from all Skills is pre-loaded"* — descriptions are the always-on portion of the library's context cost, before any skill is activated. - **Concentration.** Total description text across all 78 skills is 49,876 chars; the 18 over-limit ones account for ~44% of it. Longest are concentrated in `privesc/`, `crypto/`, `supply-chain/`, and `social-engineering/`. - **Style.** These read as feature inventories rather than selection triggers. The spec frames `description` as the text an agent uses to decide *whether* to load a skill; the depth they carry duplicates what the document body already contains. ## Verification Counts were produced by parsing each `SKILL.md`'s frontmatter with a strict YAML parser (`yaml.safe_load`), so the numbers are the parsed string lengths, not raw line lengths. Not verified: whether any downstream consumer (Claude's skill loader, `skills.sh`, editor integrations) truncates, rejects, or silently caps descriptions at the limit. I only confirmed that the `skills` CLI does not. ## Scope note Unrelated to #28 / PR #29. All 18 of these files already had valid frontmatter, so they were installable before and after that change — the fix there does not touch them. No action requested. Flagging so the maintainers can decide whether the limit matters for this library and, if so, how to bring the 18 descriptions into conformance.

Comments