tankpkg/skills: The Package Manager for Autonomous Competence
How a security-first manifest and a curated standard library are turning AI coding agents from chaotic generators into disciplined, sandboxed engineers.
- Tank replaces implicit trust with explicit, capability-based permissions to contain autonomous agents.
- The standard library delivers active testing loops rather than just passive prompts.
- Curated registries within skills actively filter out generic AI patterns to produce polished components.
The Zero-Trust Agent
Giving an AI agent unrestricted access to your terminal is a recipe for disaster. The rapid rise of the Anthropic SKILL specification has created a wild west of unverified, community-shared skills. These files expose systems to malicious code.
Agent skills are more dangerous than npm packages because they execute with the **agent's full authority** — reading files, making API calls, running shell commands. The attack surface is fundamentally larger.
The tank.json Firewall
Tank acts as a firewall rather than a simple downloader. The manifest file replaces implicit trust with explicit, granular permissions. It uses SHA-512 lockfiles and restricts outbound network access and subprocesses.
Downloading a Workflow
The tankpkg/skills repository provides a standard library of active workflows. Skills like the BDD issue fixer deliver formal computing loops. The agent receives a strict testing cycle to verify its own work, drastically reducing hallucination rates.
Filtering the Slop
The frontend-craft skill uses Python scripts to scrape high-quality component registries. Skip-lists preemptively block generic AI patterns, forcing better design outcomes and ensuring the resulting interfaces are distinct and polished.
The Post-NPM Era
The shift toward active agent skills requires a new paradigm for dependency management. Traditional package managers are insufficient for the security risks posed by autonomous code execution.
| Feature | Traditional Package Managers | Raw Agent Skills | Tank |
|---|---|---|---|
| Primary Consumer | Human Engineer | AI Agent | AI Agent |
| Execution Authority | Passive Dependency | Unrestricted | Sandboxed |
| State Verification | Hash matching | None | SHA-512 skills.lock |
| System Access | Unbounded | Unbounded | Explicit tank.json manifest |