Feature | Skills | Slash Commands |
Trigger Method | The AI model automatically identifies and invokes. | The user manually enters a command. |
Application Scenario | Professional domain task processing | Quick operations and workflows |
Permission Control | Supports tool allowlist restrictions. | No special permission control |
Working Directory | Supports custom base directory. | Use the current working directory. |
Visibility | Transparent to users, with automatic AI decision-making. | User-initiated |
SKILL.md file in a specific directory:.codebuddy/skills/ (under the project root directory)~/.codebuddy/skills/ (under the user home directory)SKILL.md file:.codebuddy/skills/├── pdf/│ └── SKILL.md├── data-analysis/│ └── SKILL.md└── code-review/└── SKILL.md
---name: pdfdescription: PDF document processing expertallowed-tools: Read, Write, Bash, WebFetch---You are a PDF document processing expert, skilled in:- Parse and extract PDF content- Convert PDF to other formats- Generate a PDF reportUse the following workflow when users need to handle PDF-related tasks:1. First, check whether the PDF file exists.2. Use an appropriate tool to extract content.3. Process it as needed.4. Generate a result report.Available tools:- pdftotext: Extract text content.- pdfinfo: Obtain PDF information.
Field | Required | Description | Example |
name | No | Skill name. If not specified, the directory name is used. | pdf |
description | No | Skill description that helps AI understand when to use it. | PDF document processing expert (project) |
allowed-tools | No | Allowlist of tools that can be used, separated by commas | Read, Write, Bash |
disable-model-invocation | No | When set to true, the Skill does not appear in the Skill tool and can only be triggered manually through /skill-name. | true |
user-invocable | No | When set to false, the Skill is hidden from the / menu and is only available for internal AI invocation or reference by other Skills. The default value is true. | false |
context | No | When set to fork, the Skill runs in an independent subagent context. | fork |
agent | No | Specifies the subagent type. This is valid only when context: fork is set. | Explore |
model | No | Model used when the Skill runs. This takes effect only when context: fork is set. If not configured, the default model of the agent is used. | claude-sonnet-4 |
hooks | No | Declares Skill-specific Hooks in SKILL.md. This takes effect only when context: fork is set. For details, see Configuring Hooks in a Skill. | See below |
Placeholder | Replace With | Applicable Source |
${CODEBUDDY_PLUGIN_ROOT} | Plugin installation root directory | Skills from plugin sources only |
${CODEBUDDY_SKILL_DIR} | Absolute path of the directory containing the current SKILL.md | All sources |
${CODEBUDDY_SESSION_ID} | Current session ID (injected at runtime) | All sources |
Uppercase environment variables such as ${MY_ENV_VAR} | Value of process.env.MY_ENV_VAR | All sources |
${MY_ENV_VAR:-default value} | Environment variable. The default value is used when it is missing. | All sources |
${CLAUDE_PLUGIN_ROOT}, ${CLAUDE_SKILL_DIR}, and ${CLAUDE_SESSION_ID} are also recognized as equivalent aliases.${CODEBUDDY_PLUGIN_ROOT} is retained literally because this variable applies only to plugin sources.---description: A sample skill with placeholders---Read the script @${CODEBUDDY_SKILL_DIR}/scripts/analyze.py and execute it with the key ${MY_API_TOKEN:-dev-fallback}.Current session ID: ${CODEBUDDY_SESSION_ID}
!command`` syntax. When a Skill is triggered, whether automatically by the AI or manually by the user through /skill-name, these commands are executed and their output is substituted into the Skill content for subsequent analysis by the AI.---description: Project status analysis---### Current working directory!`echo "CWD=$(pwd)"`### Git status!`git status --short`### Recent Commits!`git log --oneline -5`Based on the information above, analyze the current status of the project.
$ARGUMENTS Parameter substitution: Before a Shell command is executed, $ARGUMENTS is replaced with the parameters passed by the user.@file File reference: After a Shell command is executed, @file references are processed based on size and token limits. Small files are injected directly, longer content is truncated with a prompt to continue reading, and oversized files retain the original reference.$ARGUMENTS substitution → !command`` execution → @file reference processing, consistent with the processing order of slash commands.context: fork runs the Skill in an isolated subagent context without access to the conversation history.---name: deep-researchdescription: Conduct in-depth research on a topiccontext: forkagent: Explore---Research $ARGUMENTS:1. Use Glob and Grep to find relevant files2. Read and analyze the code.3. Summarize the findings and attach specific file references.
Type | Description |
general-purpose | General (default) |
Explore | Read-only tool for optimizing codebase exploration |
Plan | Planning and analysis |
Custom | agent defined in .codebuddy/agents/ |
user-invocable: false hides the Skill from the / menu. This is applicable when:---name: project-guidelinesdescription: Project coding standards and best practices.user-invocable: false---# Project Coding StandardsThis project adheres to the following coding standards:- Use TypeScript strict mode.- Use camelCase for function names.- Use PascalCase for component names....
/ menu.agent field determines the execution environment.context: fork is only applicable to Skills that contain explicit tasks. When there are only guidelines without specific tasks, no meaningful output is produced.hooks field requires a version of CodeBuddy Code that supports Frontmatter Hooks (Beta).~/.codebuddy/settings.json, a Skill can also declare the hooks field directly in the frontmatter of SKILL.md, packaging the Hook together with the Skill itself. This is especially useful for fork-type Skills—you can add guards, logging, and callbacks inside the fork subagent without polluting the main session.context: fork takes effect: Skills on the injection path (default inline mode) do not have clear lifecycle boundaries, so frontmatter hooks are parsed but not registered with the runtime.Stop is automatically converted to SubagentStop: Writing a Stop event in the frontmatter is automatically rewritten to SubagentStop, aligning with the actual event when the subagent completes.hooks field is exactly the same as the hooks in settings.json—grouped by event name, with each configuration optionally containing a matcher and a hooks[] array:---name: secure-reviewerdescription: Code review Skill that checks the file allowlist before execution.context: forkagent: Explorehooks:PreToolUse:- matcher: "Read|Glob|Grep"hooks:- type: commandcommand: ${CODEBUDDY_SKILL_DIR}/scripts/check-paths.shtimeout: 10PostToolUse:- matcher: "Bash"hooks:- type: promptprompt: "Check whether the Bash output contains sensitive information. If found, explain it in the reason field."Stop: # Automatically rewritten to SubagentStop- hooks:- type: commandcommand: echo "review skill finished" >> ${CODEBUDDY_PROJECT_DIR}/.cbc-review.log---Please review the files mentioned in $ARGUMENTS...
types:command: Executes a shell command (with optional fields such as shell: bash | powershell, timeout, if, once, and async).prompt: Passed to a small model (Haiku-tier by default) for semantic determination.agent: Spawns a subagent for more complex determinations, with optional agentType / model parameters.http: Sends the event payload to a specified URL via POST/PUT/PATCH..codebuddy/skills/, local projects, or the plugin marketplace are considered untrusted sources because they can silently trigger Shell commands, so explicit user consent is required.~/.codebuddy/settings.json.{"allowUntrustedFrontmatterHooks": true}
[AgentTask] Frontmatter hooks from skill 'secure-reviewer' skipped(source not admin-trusted; enable `allowUntrustedFrontmatterHooks` in settings to allow)
hooks/hooks.json take a different path and are not controlled by this gate.settings.json are merged additively—all matching hooks from both sides under the same event are triggered in parallel, with no overriding. The differences are as follows:Source | Scope | Constrained by admin-trusted Gate or Not |
settings.json (global/project/local) | Entire session | No |
Plugin hooks/hooks.json | Entire session (when the plugin is enabled) | No |
Agent .md frontmatter | Lifecycle of the subagent | Yes |
Skill SKILL.md frontmatter (fork only) | Lifecycle of the fork subagent | Yes |
CODEBUDDY_DEBUG=1 at startup to see registration lines such as [ScopedHookRegistry] registered N hook config(s) for scope ... in the logs.[parseFrontmatterHooks] skill 'xxx': event 'YYY' invalid: .... Check the logs carefully to locate the issue..codebuddy/skills/pdf/SKILL.md---name: pdfdescription: PDF document processing and conversion expertallowed-tools: Read, Write, Bash, WebFetch---# PDF Processing ExpertYou are a professional PDF document processing expert.## Core Capabilities- Extract text content from PDF.- Convert PDF to Markdown, HTML, and other formats.- Merge and split PDF files.- Extract PDF metadata and bookmarks.## Workflow1. Check whether the PDF file exists and is accessible.2. Use pdftotext or pdfinfo to obtain basic information.3. Select an appropriate processing tool based on the task type.4. Verify the integrity of the output results.## Available Tools- pdftotext: Extract plain text.- pdfinfo: Obtain document information.- pdftk: Merge and split operations.
~/.codebuddy/skills/data-analysis/SKILL.md---name: data-analysisdescription: Data analysis and visualization expertallowed-tools: Read, Write, Bash, WebFetch, NotebookEdit---# Data Analysis ExpertYou are a professional data analyst, skilled in using Python and related tools for data analysis.## Core Capabilities- Data cleaning and preprocessing- Statistical analysis and modeling- Data visualization- Generate an analysis report## Analysis Workflow1. Understand the data structure and quality2. Clean and preprocess data3. Perform statistical analysis4. Create visualizations5. Generate analysis conclusions## Tool Library- pandas: data processing- numpy: numerical computing- matplotlib/seaborn: visualization- scikit-learn: machine learning## Best Practices- Always explore data quality first- Use Jupyter Notebook for interactive analysis- Save intermediate results to avoid repeated computation
.codebuddy/skills/code-review/SKILL.md---name: code-reviewdescription: Code review and quality inspection expertallowed-tools: Read, Grep, Bash, Edit---# Code Review ExpertYou are an experienced code reviewer who follows industry best practices.## Review Focus1. **Code Quality**- Naming Conventions- Code Complexity- Duplicate Code2. **Security**- SQL Injection Risks- XSS Vulnerabilities- Authentication and Authorization Issues3. **Performance**- Algorithm Efficiency- Resource Usage- Caching Policy4. **Maintainability**- Code Comments- Modular Design- Test Coverage## Review Process1. Understand the purpose of the code changes.2. Check code style and standards.3. Analyze potential bugs and performance issues.4. Verify security.5. Provide constructive suggestions for improvement.## Output Format- Strengths: List what was done well.- Issues: Point out areas that need improvement.- Suggestions: Provide specific improvement plans.
skillOverrides setting allows you to control the visibility of individual Skills from settings without modifying SKILL.md, which is useful for Skills that are inconvenient to modify, such as project Skills committed to a shared repository.skillOverrides in settings, indexed by Skill name, with each value being one of four states:Value | Visible to Model | In / Menu | Description |
on | Name + Description | Yes | Does not override and falls back to the current SKILL.md frontmatter state. |
name-only | Name only | Yes | Collapse the description to save context budget. |
user-invocable-only | Hidden | Yes | Hidden from the model (not included in the list), but calls by name from users and the model are still allowed. |
off | Hidden | Hidden | Hidden from both the model and the menu, and calling by name returns a disabled prompt. |
/skills menu labels the user-invocable-only state as user-only. This is only a short label for display, and the canonical value written to the configuration file remains user-invocable-only.on. Example:{"skillOverrides": {"legacy-context": "name-only","deploy": "off"}}
off, both /skill-name and model invocations by name will be intercepted with a prompt:Skill "<name>" is disabled via skillOverrides. Re-enable it in /skills or remove the override from your settings to run it.
skillOverrides. Instead, they are managed through /plugin and appear as locked (locked by plugin) in /skills, where they cannot be edited./skills menu visual editing: Use ↑/↓ to select, enter / space / ←/→ to cycle through states. When you press Esc, all changes are written to .codebuddy/settings.local.json and the number of changes is reported (Updated N skill override / No changes). If you leave without pressing Esc, changes are not saved.PROJECT_LOCAL (.codebuddy/settings.local.json) > PROJECT (.codebuddy/settings.json) > USER (~/.codebuddy/settings.json). Higher-priority settings override lower-priority ones by Skill name. When the workspace root is the home directory, PROJECT and USER refer to the same file.on.allowed-tools field to limit the tools available to a Skill:allowed-tools: Read, Write, Bash(git:*), Grep
Bash(git:*) - Only git-related commands are allowed.Edit(src/**/*.ts) - Only editing files in specific paths is allowed.baseDirectory (the directory containing SKILL.md), which can be referenced in Skill instructions:When processing files, search for related resources in the {baseDirectory} directory first.
# ✖ Not recommendeddescription: Process files# ✔ Recommendeddescription: PDF document parsing and conversion expert, supporting text extraction and format conversion (project)
# ✖ Excessive permissionsallowed-tools: Bash# ✔ Precise controlallowed-tools: Read, Write, Bash(git:status,git:diff), Grep
.codebuddy/skills/├── document/│ ├── pdf/SKILL.md│ └── markdown/SKILL.md├── data/│ ├── analysis/SKILL.md│ └── visualization/SKILL.md└── code/├── review/SKILL.md└── refactor/SKILL.md
/skills command to view all currently loaded Skills:/skills
~/.codebuddy/skills/).codebuddy/skills/)When performing data analysis, refer to the data patterns and business rules stored in Memory.
<!-- .codebuddy/commands/analyze-data.md -->Use the data-analysis skill to analyze the file: $1
Was this page helpful?
You can also Contact sales or Submit a Ticket for help.
Help us improve! Rate your documentation experience in 5 mins.
Feedback