---
title: "Import Agent Skills (SKILL.md): Read Them First"
url: https://www.insulin.dev/blog/import-agent-skills/
canonical: https://www.insulin.dev/blog/import-agent-skills/
type: Blog
description: "How to import agent skills from a SKILL.md, a .zip, GitHub or SkillsMP: which paths stop at a review form, which import directly, and what to read first."
---

# Import Agent Skills (SKILL.md): Read Them First

> Canonical HTML version: https://www.insulin.dev/blog/import-agent-skills/

1.  [Home](/)
2.  /
3.  [Blog](/blog/)
4.  /
5.  Import Agent Skills (SKILL.md): Read Them First

# Import Agent Skills (SKILL.md): Read Them First

Only a single markdown file or a raw SKILL.md URL gets a review form before it saves. A .zip or a GitHub folder imports directly, so the reading is yours.

![Qiuyang Luo](/authors/qiuyang-luo.jpg)

Qiuyang Luo

Sep 24, 2026

 ![Import Agent Skills (SKILL.md): Read Them First](/images/blog/import-agent-skills/hero.png)

Explore AI Summary

 [![](/logos/company/openai.svg)](https://chat.openai.com/?q=Read%20and%20summarize%20https%3A%2F%2Fwww.insulin.dev%2Fblog%2Fimport-agent-skills%2F%2C%20then%20cite%20the%20source.%20Focus%20on%20what%20it%20says%20about%20Agent%20Marketplace. "Summarize with ChatGPT")[![](/logos/company/anthropic.svg) ](https://claude.ai/new?q=Read%20and%20summarize%20https%3A%2F%2Fwww.insulin.dev%2Fblog%2Fimport-agent-skills%2F%2C%20then%20cite%20the%20source.%20Focus%20on%20what%20it%20says%20about%20Agent%20Marketplace. "Summarize with Claude")[![](/logos/company/gemini.svg)](https://www.google.com/search?udm=50&aep=11&q=Read%20and%20summarize%20https%3A%2F%2Fwww.insulin.dev%2Fblog%2Fimport-agent-skills%2F%2C%20then%20cite%20the%20source.%20Focus%20on%20what%20it%20says%20about%20Agent%20Marketplace. "Summarize with Gemini")[](https://www.perplexity.ai/search/new?q=Read%20and%20summarize%20https%3A%2F%2Fwww.insulin.dev%2Fblog%2Fimport-agent-skills%2F%2C%20then%20cite%20the%20source.%20Focus%20on%20what%20it%20says%20about%20Agent%20Marketplace. "Summarize with Perplexity")

Table of Contents

-   [What happens when you import an agent skill?](#what-happens-when-you-import-an-agent-skill)
-   [Which import paths offer a review step?](#which-import-paths-offer-a-review-step)
-   [Does Insulin scan or vet an imported skill?](#does-insulin-scan-or-vet-an-imported-skill)
-   [What should you check before an imported skill goes to work?](#what-should-you-check-before-an-imported-skill-goes-to-work)
-   [Who can import a skill for the whole organization?](#who-can-import-a-skill-for-the-whole-organization)
-   [Frequently asked questions](#frequently-asked-questions)
-   [Takeaways](#takeaways)

_Importing an agent skill brings a markdown instruction file (a SKILL.md, on its own or in a package) into your Insulin workspace, where agents load it without being asked. Only two import paths stop at a review form, and Insulin’s documentation describes no security scan and no Fours vetting of what comes in._

* * *

A colleague has found a skill on GitHub that does what your renewal desk does by hand, and wants the team to use it. Two questions follow: can Insulin import it, and how do you know it’s fit for your agents to follow?

The first has a quick answer. The **Add** menu on the Skills page imports a skill from a file, a GitHub URL or SkillsMP. The second is mostly yours to answer. Insulin shows a review form on two of those paths, and **its documentation describes no security scan of an imported skill’s contents and no Fours vetting of skills from GitHub or SkillsMP**. Below, each path is mapped to the review it offers and the checks it leaves to you.

## What happens when you import an agent skill?

**Importing a skill is** adding one to your workspace from outside Insulin (a file, a GitHub URL or a SkillsMP entry) through the Skills page’s **Add** menu, rather than installing one of the Fours-curated templates on the **Skill Store** tab. Once it is saved, agents can use it without anyone asking them to.

That second sentence is the reason to read first. A skill is “a markdown-based instruction package containing procedures or domain knowledge,” and when an agent needs what one covers, “it loads the skill’s content into its context and follows the instructions within.” Agents “discover and load enabled skills automatically based on relevance to the current conversation,” steered by the skill’s **Trigger**. For where a skill ends and an agent begins, see [the difference between an agent and a skill](/blog/agents-and-skills/).

Where the skill lands depends on the store you import from:

-   **Personal**: open to every member, and creates a private copy in your own workspace.
-   **Organization**: org admins only, and creates an org-shared copy visible to your whole organization.

## Which import paths offer a review step?

**Two: uploading a single markdown file, and importing a raw `SKILL.md` URL from GitHub.** Both stop at a form of prefilled fields (name, description, prompt, Trigger, category and tags) that you edit before **Save**. The other paths have no review step in the docs: a `.zip` upload and a GitHub repo, folder or blob URL import directly, and a SkillsMP install brings in the skill’s GitHub package.

Import path

In-product review?

What comes in

Manual checks required

**Build with Agents**, via `/skill-creator` in Chat (Personal store only)

You draft it with the agent as you go

What you author

Read the saved Prompt and Trigger before relying on it

**Upload a skill**: one `.md` or `.markdown` file, up to 50 KB

**Yes.** **Generate** makes a draft; you edit it, then **Save**

One file, normalized into a draft

Compare the draft’s Prompt with your file; rewrite the Trigger

**Upload a skill**: a `.zip` up to 10 MB that includes a `SKILL.md`

**No.** **Import** imports it directly

`SKILL.md` and its referenced files: references, scripts, assets

Unzip it and read every file before you import

**Import from GitHub**: a raw `SKILL.md` URL

**Yes.** The same review-and-save flow

The `SKILL.md`, as a draft

As for an uploaded markdown file

**Import from GitHub**: a repo, folder or blob URL

**No.** The full package imports directly

The package, referenced files preserved

Read the whole folder on GitHub before you import

**Install from SkillsMP**

**None described**

The public skill’s underlying GitHub package

Find that package on GitHub and read it before you install

Three things the table compresses:

-   **A blob URL is not a single-file import.** It points at one file on github.com, yet repo, folder and blob URLs all “import the full package directly, preserving referenced files.” Only the `raw.githubusercontent.com` form of a `SKILL.md` URL takes the review path.
-   **The draft is not your file.** For a markdown upload, **Generate** “normalizes it into a draft,” and **Save** stores the draft. Read its Prompt against your original before you save. Name, description and prompt are required.
-   **Saved means available.** After an upload, “the skill is now available to agents in your workspace.” Whatever reading you do has to happen before that click.

## Does Insulin scan or vet an imported skill?

**Not according to its documentation.** The Marketplace docs set size limits and require a `SKILL.md` inside a `.zip`. They describe no security scan of what an imported skill contains, and no Fours review of skills that come from GitHub or SkillsMP.

The only skills the docs describe as Fours-curated are the templates on the **Skill Store** tab, which you install rather than import. SkillsMP is a directory outside Insulin: **Install from SkillsMP** searches skillsmp.com and imports “a public skill from its underlying GitHub package.” Finding a skill there, or anywhere on GitHub, tells you where it came from, not whether your agents should follow it.

So the review is yours, and its timing depends on the path. On the two paths with a form, do it in the form. On every other path (a `.zip`, a GitHub package, SkillsMP), do it before you click **Import** or **Install**. If you have to import first, switch the skill off straight away: a disabled skill stays in your library but is excluded from agent use, and its detail view shows the Trigger and Prompt for you to read before you switch it back on. Read a package’s other files at the source. At the Organization store, the gap between importing and switching off reaches everyone, which is one more reason to prove a skill in your Personal store first.

## What should you check before an imported skill goes to work?

**Six things, in this order: the prompt, the Trigger, any bundled files, the provenance badge, a personal trial, and your way back out.**

1.  **Read the whole prompt as instructions.** It is what an agent follows when it loads the skill, so read it the way you’d read a procedure a new colleague handed you. Does every step serve the skill’s stated purpose? Does anything tell the agent to contact someone, send something, or set aside your other rules? Any links or addresses you don’t recognize? Cut what surprises you; **Edit** covers the prompt.
2.  **Rewrite the Trigger.** The Trigger is “a short description of when the skill applies,” and agents use it to decide whether a skill is relevant. For a markdown skill it defaults to the skill’s description, and a description says what a skill is, not when to use it. Name the situation instead: “When drafting a renewal quote for an existing customer” beats “Renewal pricing helper.” Edit it in the review form or, later, in the detail view.
3.  **Open every bundled file.** A `.zip` or GitHub package can carry more than `SKILL.md`. The docs say its referenced files (references, scripts, assets) “are preserved for runtime loading,” and say nothing more about scripts. A file you haven’t opened is a file you haven’t reviewed.
4.  **Check the provenance badge.** Skill cards show one of From template, Uploaded, From GitHub, From SkillsMP, Built with Agents or Custom, “so you can tell where each skill came from.” Read it on the card, because the detail view shows a SkillsMP import as **Custom**. The badge names the route, not the repository, so keep a note of the URL you imported from.
5.  **Try it in your Personal store first.** Use it on real work there. In Chat, typing `/` lists the skills you have enabled, each slugified from its name, so you can pick it deliberately instead of waiting for its Trigger. When it has earned a wider audience, an org admin imports the same reviewed source at the Organization store, the eval-first order behind [installing an AI agent for the whole organization](/blog/roll-out-an-agent-org-wide/). If the source has changed since your trial, read it again.
6.  **Plan your way out: disable, don’t delete.** A disabled skill “stays in your library but is excluded from agent use,” so you can fix it with **Edit** and switch it back on. **Delete** can’t be undone, and deleting an org skill “permanently removes it for everyone in your organization.”

## Who can import a skill for the whole organization?

**Only an org admin.** The Organization store’s **Add** menu offers three methods (Upload a skill, Import from GitHub and Install from SkillsMP), because a skill you author with Build with Agents is always personal. Importing there creates a copy visible to your whole organization, and creating, importing, editing and deleting skills at that store all require org admin access.

Personal imports sit outside the role tiers. Skills are self-owned, so any member of the organization may create and manage their own, “including a VIEWER”: the test, in the docs’ words, “is ownership, not org role.” Which sources your team accepts is best settled as a written standard, and the checklist above is a reasonable place to start.

## Frequently asked questions

### How do I import an agent skill from a SKILL.md file?

Open Marketplace, choose Skills, then Add and Upload a skill. A single .md or .markdown file up to 50 KB goes through Generate and a review form before Save. A .zip up to 10 MB must include a SKILL.md and imports directly, without that review.

### Does Insulin scan or vet imported skills?

Its documentation describes no security scan of an imported skill’s contents and no Fours vetting of skills from GitHub or SkillsMP. Only single markdown files and raw SKILL.md URLs stop at a review form, so on the other paths the review is yours.

### Which GitHub URL gives me a review step?

A raw.githubusercontent.com SKILL.md URL goes through the same review-and-save flow as an uploaded markdown file. Repo, folder and blob URLs import the full package directly, with its referenced files, and skip the form.

### Are skills from SkillsMP vetted by Fours?

No vetting is documented. SkillsMP is a directory outside Insulin, and Install from SkillsMP imports the public skill from its underlying GitHub package. Read that package before you install. On its card the skill shows From SkillsMP; its detail view shows Custom.

### Who can import a skill for the whole organization?

Only an org admin, from the Organization store, where an import creates a copy visible to your whole organization. Any member, including a viewer, can import into their own Personal store, because skills are self-owned.

### Should I delete a skill I no longer trust?

Disable it first. A disabled skill stays in your library but is excluded from agent use, so you can fix it and switch it back on. Deleting cannot be undone, and deleting an org skill removes it for everyone in your organization.

## Takeaways

-   Two paths show a review form: a single markdown upload and a raw `SKILL.md` URL. A `.zip` and a GitHub repo, folder or blob URL import directly, and no review step is described for SkillsMP.
-   Insulin’s documentation describes no security scan and no Fours vetting of imported skills. The review is yours.
-   On a direct path, read everything (the prompt and every bundled file) before you click **Import** or **Install**.
-   Rewrite the Trigger to say _when_ the skill applies; agents use it to decide relevance.
-   Personal store first, Organization store once it has earned it. Disable rather than delete.

Importing is one way skills reach your team; the [Insulin Agent Marketplace](/agent-marketplace/) is where you install ready-made agents and skills for one user or the whole organization. For every limit, badge and store rule on this page, the [Marketplace documentation](https://doc.fours.com/insulin/marketplace/) is the full reference.

## Sources

Primary sources for the platform rules cited above. Last verified September 24, 2026. Cloud providers change fees, eligibility, and program terms without notice — check the source before relying on a figure.

-   [Insulin Marketplace — Fours Doc](https://doc.fours.com/insulin/marketplace/) — The Add methods by store; the 50 KB markdown and 10 MB .zip limits and the required SKILL.md; Generate and the review form versus direct .zip import; raw SKILL.md URLs versus repo, folder and blob URLs; SkillsMP importing from the underlying GitHub package; how agents load skills and the Trigger's default; Fours-curated Skill Store templates; provenance badges, with SkillsMP shown as Custom in the detail view; Enable/Disable, Edit and Delete; the org-admin rules
-   [Insulin Getting Started — Fours Doc](https://doc.fours.com/insulin/getting-started/#your-own-things-are-not-role-gated) — Skills are self-owned: any member, including a VIEWER, may create and manage their own; creating or editing a skill in the Organization store still requires org admin
-   [Insulin Agents — Fours Doc: Slash Commands](https://doc.fours.com/insulin/agents/#slash-commands) — Typing / lists the agent's built-in skills, such as /skill-creator, plus the skills you have enabled, each slugified from its name

## Keep reading

-   [Knowledge BasesAgent Skill vs Knowledge Base: Where Runbooks GoOct 7, 2026](/blog/skill-or-knowledge-base/)
-   [Agent MarketplaceAI Agent Lifecycle: Ownership to RetirementAug 24, 2026](/blog/ai-agent-lifecycle-management/)
-   [Agent MarketplaceInstall an AI Agent for the Whole OrganizationAug 18, 2026](/blog/roll-out-an-agent-org-wide/)
-   [AgentsAgents and Skills: What the Difference IsAug 16, 2026](/blog/agents-and-skills/)

[Browse every post on the Insulin Blog](/blog/)

### Stay Updated

New posts, product updates and marketplace strategy are shared on LinkedIn as they publish.

[Follow Fours on LinkedIn](https://www.linkedin.com/company/suger-inc)
