tankpkg/skills: The Package Manager for Autonomous Competence

How a security-first manifest and a curated standard library are turning AI coding agents from chaotic generators into disciplined, sandboxed engineers.

8 min read • View on GitHub • More from tankpkg

A mechanical golem passing a crate through a secure scanning checkpoint.
Tank acts as a strict customs checkpoint for agent capabilities, ensuring malicious code cannot execute on the host machine.
Key Takeaways

The Zero-Trust Agent

Giving an AI agent unrestricted access to your terminal is a recipe for disaster. The rapid rise of the Anthropic SKILL specification has created a wild west of unverified, community-shared skills. These files expose systems to malicious code.

Agent skills are more dangerous than npm packages because they execute with the **agent's full authority** — reading files, making API calls, running shell commands. The attack surface is fundamentally larger.

Tank Repository, Project Documentation · tankpkg/tank

The tank.json Firewall

Tank acts as a firewall rather than a simple downloader. The manifest file replaces implicit trust with explicit, granular permissions. It uses SHA-512 lockfiles and restricts outbound network access and subprocesses.

The capability sandbox intercepts autonomous AI actions before they execute on the host machine.

Downloading a Workflow

The tankpkg/skills repository provides a standard library of active workflows. Skills like the BDD issue fixer deliver formal computing loops. The agent receives a strict testing cycle to verify its own work, drastically reducing hallucination rates.

Filtering the Slop

The frontend-craft skill uses Python scripts to scrape high-quality component registries. Skip-lists preemptively block generic AI patterns, forcing better design outcomes and ensuring the resulting interfaces are distinct and polished.

A close-up of a heavy industrial sieve catching amorphous sludge while letting perfect geometric shapes fall through.
The frontend-craft skill acts as a sieve, filtering out generic AI slop to produce polished, high-quality components.

The Post-NPM Era

The shift toward active agent skills requires a new paradigm for dependency management. Traditional package managers are insufficient for the security risks posed by autonomous code execution.

FeatureTraditional Package ManagersRaw Agent SkillsTank
Primary ConsumerHuman EngineerAI AgentAI Agent
Execution AuthorityPassive DependencyUnrestrictedSandboxed
State VerificationHash matchingNoneSHA-512 skills.lock
System AccessUnboundedUnboundedExplicit tank.json manifest