How to use skills
- 1 · Email
Registration by email
- 2 · One file
The skill comes by email as one file with the extension .skill
- 3 · Chat
You upload the file to a chat with ChatGPT or Claude and write one word: Run
In Gemini the file is uploaded once in Settings > Skills, and Gemini runs the skills that contain instructions without scripts
How a skill works
A skill is a file with the extension .skill that contains a technical package of AI instructions and deterministic scripts, optimised for precise work with files and with the abilities of the AI, and this gives a more solid, stable and predictable professional result
The format works by progressive disclosure: the assistant keeps only a short description of each skill in its context, and when a request matches it, loads the full instructions and runs the bundled scripts in its own code environment. The steps that need an exact result are executed as code, and the language model handles the steps that need judgement
duo-ready.skill
SKILL.mdinstructions for the assistantscripts/code for the steps that need an exact resultreferences/knowledge that the assistant loads when it is needed
Featured
All skills
Supported assistants
ChatGPT
ChatGPT accepts a .skill file in a chat and starts it after the word Run, and it also reads skills inside plugins, in the web app and in the desktop app
Claude
Claude reads .skill files directly, in the web app, the desktop app, the mobile app and Claude Code
Gemini
Gemini accepts a .skill file in Settings > Skills, in the web app, the Mac app and the mobile app, and replaces its Gems with skills in November 2026
Why it is safe
Every skill is plain text, so the instructions and the code of every script can be read before use, and a skill has no access of its own because it works only inside the permissions of the assistant. Every skill also passes the checks below before it is published, and the report is public
VirusTotalEvery .skill file is scanned by the antivirus engines of VirusTotal, a service of Google
OWASP Top 10 for LLM ApplicationsThe instructions are reviewed by hand against the ten main risks of AI applications, and prompt injection is the first of them
Semgrep · GitHub CodeQLThe code of every script goes through static analysis
Sigstore · SHA-256Every file is signed and has a public checksum, so a changed file can be detected
MITRE ATLASThe threat model of every skill is mapped to the known attack techniques against AI systems
NIST AI Risk Management FrameworkThe risk review follows the four functions of the framework: govern, map, measure and manage
European CommissionThe author is listed in the expert database of the European Commission
GDPR · BerlinSkills hub receives one thing from a user, the email address, and files, chats and results stay in the assistant