# Third-party skills

> Import skills from a public GitHub or GitLab repository into My skills, update them when the repository changes, and see which files were left out.

A **third-party skill** is a [skill](/docs/capabilities/skills/) imported from a public GitHub or GitLab repository. endue reads the `SKILL.md` files in the repository and adds each one to **My skills**, private to your account.

## When to use it

Use it when the procedure you want already exists as a `SKILL.md` in a public repository, or when your team keeps its skills in a repository and edits them there.

## Add a repository

<Steps>

1. **Open Resources › Skills** from the left sidebar and select the **Third-party** tab.

2. **Enter the repository URL**, for example `https://github.com/owner/repo`.

   To import one folder only, paste the folder's URL (`…/tree/main/skills`), or open **Advanced** and fill in:

   - **Branch or tag**: leave it empty to use the default branch.
   - **Path in repository**: only `SKILL.md` files under this folder are imported. Leave it empty for the whole repository.

3. **Select Import.** The result shows how many skills were imported, and lists the files that were not, each with its reason.

4. **Bind the skills to an agent** in that agent's [Agent Builder](/docs/build/agent-builder/), as with any other skill. Importing does not give a skill to any agent.

</Steps>

<Aside type="caution" title="Read what you import">
  A third-party skill is someone else's instructions, and your agent follows them.
  Read a skill before you bind it, and check it again after a Re-import changes it.
</Aside>

## What is imported

Each `SKILL.md` under the path becomes one skill. The file starts with frontmatter that has a `name` and a `description`, followed by the instructions:

```md
---
name: weekly-report
description: Writes the weekly status report from the issues closed this week.
---

1. List the issues closed since Monday.
2. Group them by project.
```

Only the text of `SKILL.md` is imported. Scripts, reference documents, and other files in the skill's folder are not. If the instructions tell the agent to run a script or read a file that sits next to `SKILL.md`, the agent cannot do it.

Imported skills appear in **My skills** with a **Third-party** badge and a **Source** link to the original `SKILL.md`. They are private to your account.

A file is left out, and listed under **Files not imported**, when:

| Reason | What to change |
| --- | --- |
| It is not a `SKILL.md` (scripts, reference documents) | Nothing. Only `SKILL.md` is imported. |
| It is a symbolic link | Put the file itself in the repository |
| It is larger than 256 KB | Shorten it |
| The repository has more than 50 skills | Import a folder with fewer skills, using the path |
| The frontmatter is missing or malformed, or has no `name` or `description` | Add both between `---` lines at the top |
| The body is empty | Add the instructions under the frontmatter |
| It is not UTF-8 text | Save it as UTF-8 |
| Its license does not allow redistribution | Nothing. It cannot be imported. |

## Updating from the repository

Select **Re-import** on the repository. endue checks the repository's latest commit against the one it imported last:

- **Nothing changed**: nothing happens, and it says so.
- **A `SKILL.md` changed**: that skill gets a new version. Skills whose file did not change stay as they are.
- **A `SKILL.md` was added**: it is imported as a new skill.
- **A `SKILL.md` was removed**: the skill is marked **Archived** and taken out of My skills. If the file comes back, the next Re-import restores it.

Updates happen only when you select Re-import. endue does not watch the repository.

## Deleting a repository

**Delete** removes the repository and every skill imported from it. It cannot be undone.

If any of those skills is bound to an agent, the delete is refused and the dialog lists which skills and which agents. Remove the skills from those agents in [Agent Builder](/docs/build/agent-builder/), then delete again.

## Limits

- Public repositories on github.com and gitlab.com only. Private repositories and other hosts are not supported. A URL with a username, password, token, or port number is rejected.
- Up to 10 repositories per account.
- Up to 50 skills per repository, and 256 KB per `SKILL.md`.
- The repository download is limited to 20 MB compressed. For a large repository, keep the skills in a smaller one.
- Only the text of `SKILL.md` is imported. Scripts and other files are not.
- A repository changes nothing until you select Re-import.
- If GitHub or GitLab is limiting requests, the import fails with that message. Try again a few minutes later.

## Related

<CardGrid>
  <LinkCard
    title="Skills"
    href="/docs/capabilities/skills/"
    description="What a skill is, and how binding works."
  />
  <LinkCard
    title="Agent Builder"
    href="/docs/build/agent-builder/"
    description="Where you bind a skill to an agent."
  />
  <LinkCard
    title="Security and permissions"
    href="/docs/account/security/"
    description="What an agent can and cannot reach."
  />
</CardGrid>
