agentx skill add adds the source itself when you install from a URL you have not added yet.
Add a source
Add
#<ref> to pin the source to a branch, a tag or a commit, for example owner/repo#v2 or git@github.com:owner/repo.git#release. Without a pin the source follows the repository’s default branch. A tree URL pins the branch it names.
A path after the repository, such as owner/repo/skills, scopes the listing to that directory. On a server other than GitHub, end the repository name with .git so agentx knows where the repository ends and the path begins. The path must name a directory by its plain names: ., .. and .git are refused, however they are written.
Adding a source you already have fetches it again and sets the pin to what you typed this time. The confirmation then tells you what moved:
Credentials
The fetch runs with your own git, so the credential helper, SSH key and URL rewrites you use in a terminal apply here too. A private repository you can already clone just works. Never put a token in the URL. agentx drops it before the URL is used anywhere, and never repeats it back to you, not even in an error. For an SSH URL thegit@ part is the address rather than a credential, so it is kept and only a password is dropped. If the fetch then fails, store the credential in a git credential helper instead:
What is fetched
agentx fetches only the commits and directory trees of one branch, no tags and no file contents, then theSKILL.md file of every skill in the repository in one round trip. Those come down whatever path you added, so listing any part of the source afterwards needs no network. A source the size of a monorepo costs a few megabytes, not a clone. A git server that cannot serve such a partial fetch gets a full one instead; nothing changes for you.
A fetch lands whole or not at all. agentx fills its copy in two round trips and moves the source to the new commit only once everything has arrived, so a fetch that fails, whether from a dropped connection, a Ctrl-C or a machine that goes down, leaves the source exactly as it was. Listing and searching keep working at the last version that arrived complete. Fetch again to pick it up.
A failed add leaves nothing behind
An add undoes itself when it cannot finish. agentx registers the repository with its own git store before it fetches, and takes that registration back if the fetch fails or if the source cannot be recorded. A source is on this machine whole or not at all, sosource list never hides one.
Taking it back needs the same lock every agentx command takes, so an add that fails while another command is running waits a few seconds for that command. If the other command outlasts the wait, the add names what it left:
Fetch a source again
agentx skill check fetches the sources your managed skills came from on its own, and while the desktop app is open, its background process fetches every source you added when it starts and every thirty minutes, including the ones you have not installed anything from yet.
Name several sources to fetch them together, by URL or by id, or fetch every source on this machine:
3 when they failed for different reasons.
A fetch keeps the pin the source has. To change it, add the source again with the ref you want:
List your sources
List the skills of a source
SKILL.md is a skill. Hidden directories and node_modules are skipped. Names and descriptions come from the repository, so agentx prints them with control characters replaced by spaces, keeping one skill to a row; --json gives you the value as it was written. Give a path to see one part of the repository, for example anthropics/skills/skills/pdf, or the source id instead of the URL. The command reads what the last source add fetched and never touches the network, whichever part of the source you ask for.
Remove a source
agentx skill list shows each of those skills as source removed, and the snapshot the desktop app reads says the same:
agentx adopt, adds it again too.
A command that names the removed source by its id cannot fetch it, since an id is not a URL. While a skill still records the source, the command tells you what to run instead:
agentx skill remove <name> or its --from universal form, nothing on this machine records the source’s URL any more, and the id is refused like any other. Add the source again by its URL.
Script it
Add--json to get a source event per source, and from source skills a source_skill event per skill:
source fetch emits one progress event per source as that source finishes, then one source event per source that fetched, in the order you named them. A source event carries previous_commit when the fetch moved the source, so a script can tell a real change from a no-op:
Exit codes
1: the URL is not one of the accepted forms, the pin and the tree URL name different refs, orsource fetchwas given neither a source nor--all.3: the source cannot be reached, is not a git repository, or needs credentials git does not have. The hint names the fix. Fromsource fetchover several sources, it also means they failed for different reasons; read the warnings.5: the pinned ref or the path does not exist in the source, the source is not on this machine, or what this machine holds of it is incomplete. For an id of a source you removed, the hint names theagentx source addcommand that brings it back.7: another agentx command is running. Retry when it finishes. An add that could not take its own half-done work back says what it left and how to clear it.8: the account repo in agentx home cannot be read or written. Runagentx doctor.
source command: fetching one source answers exactly as adding or listing it would.