Skip to main content
Skills package task instructions, reference material, and optional scripts in reusable directories. Agents can discover skills before loading their full instructions. Code execution is involved only when a skill uses scripts and an executor is configured The SkillToolset examples use the Google ADK 2.2 API. Complete installation and model configuration first

Local skills

Create skills/incident-summary/SKILL.md in your project:
skills/incident-summary/SKILL.md
Create and run main.py from the project root:
main.py
The response should contain impact, timeline, and follow-up sections, marking missing information as unknown. This skill only processes supplied text and needs no code executor Default tools are list_skills, load_skill, load_skill_resource, and run_skill_script. Configuring a registry also adds search_skills

SkillToolset parameters

Run skill scripts

UnsafeLocalCodeExecutor runs skill code in the current process environment without sandbox isolation. Enable it only for reviewed, trusted skills: code can access the process’s files, network, and credentials. Use a restricted container or remote sandbox when isolation is required
When a shell script times out or is cancelled, the entire process group (including child processes spawned by the script) is terminated with up to 5 seconds for cleanup, preventing orphaned processes
For a skill with executable scripts/, replace the toolset and agent configuration after loading skill above:
Creating SkillToolset directly does not install script dependencies. Relevant loaders in Harness, CLI-generated code, and AgentKit session capability services configure a local executor. Review skill sources before using those entry points as well

Cloud skill spaces

Prepare a readable source ID and account credentials permitted to list skills and download their files. SKILL_SOURCE_ID is an environment variable defined by this example. Each VeSkillRegistry accepts exactly one source ID, not a comma-separated list If the complete AK/SK pair is absent, the loader tries the environment’s IAM Role credentials. Set AGENTKIT_TOOL_REGION to select an AgentKit skill-space region. Credentials, resources, region, and platform must match. SkillHub and AgentKit skill-space availability depend on the services enabled for the account
cloud_skills.py
Run python cloud_skills.py to inspect discoverable skills Creating a registry does not download every skill. search_skills fetches all source metadata and currently does not filter by the query. get_skill refreshes metadata and downloads the named skill on demand. Cached versions are reused; changed versions are downloaded again. The cache directory must be writable Nonstandard cloud frontmatter fields such as allowed-tools, triggers, and requires are retained in metadata. Retention does not automatically enforce their permission or dependency declarations

Skill space policy

Set the SKILL_SPACE_POLICY environment variable to filter which skills are loaded from a cloud skill space by skill ID. The variable is a JSON object with the following fields: When mode is allow, only skills whose IDs are in the list are loaded. When mode is deny, skills whose IDs are in the list are excluded. When the variable is not set, all skills are loaded
The policy value must not exceed 8192 bytes. A malformed policy disables all cloud skill loading to avoid accidentally exposing an unrestricted set of skills
When SKILL_SPACE_POLICY is set, VeADK automatically forwards it to remote sandbox sessions so that skill loading inside the sandbox follows the same filter. No manual pass-through is needed when using execute_skills, invoke_skill, poll_skill, or run_sandbox_agent; see Code sandboxes

Harness skills center

Create a project and configure deployment credentials using Harness deployment. Replace the example names and IDs with accessible skills. Plain names or slugs identify Skill Hub skills; the space: prefix identifies an AgentKit skill space
The generated harness.yaml stores sources as a list:
Harness loads configured skills on startup; a space: source loads every skill in that space. An invocation can add skills for that request:
If any skill cannot be downloaded, lacks a valid SKILL.md, or has an invalid format, loading fails instead of continuing with an incomplete set. Skills-center access requires permission to read the space and its object-storage contents

Skill directory layout

Each skill has its own directory containing at least SKILL.md. Its name should match the directory name, and its description should explain its purpose
Use references/ for material read on demand, assets/ for templates or media, and scripts/ for executable scripts. Create these optional directories only as needed and explain when to use their files in the skill instructions

Legacy local entry (deprecated)

Agent(skills=..., skills_mode="local") remains compatible but is deprecated. Migrate local skills to SkillToolset Sandbox modes remain available. Before running this example, configure SKILL_SOURCE_ID, the model, and the credentials and Tool ID required by code sandbox. Confirm that the sandbox has the required skills and network permissions:
sandbox_skills.py

Dynamic skill loading

enable_dynamic_load_skills=True applies to the legacy Agent.skills entry. It rereads sources before each turn and updates skill lists, instructions, and tools. The toolset is initialized even if skills starts empty. Applications sharing a mutable agent across concurrent calls must manage refresh and invocation concurrency The flag does not hot-reload local objects passed directly to SkillToolset(skills=[...]). Registry-based loading does not require this flag. See runtime compatibility for external-runtime restrictions on legacy skill modes
Last modified on September 22, 2026