Trying Out OpenCode's Skills

OpenCode allows the use of skills similar to those found in Claude.
I haven’t used AI agent skills much before, but I decided to try them out as they seem convenient for automation.

For details about OpenCode’s skills, please refer to the official website:
Agent Skills

Location to Save Skills

OpenCode searches for skill definitions under either the ‘Home Directory’ or ‘Project Directory’.

Project Directory

Project Settings: .opencode/skills/<name>/SKILL.md
Project Claude Compatibility: .claude/skills/<name>/SKILL.md
Project Agent Compatibility: .agents/skills/<name>/SKILL.md

Home Directory

Global Settings: ~/.config/opencode/skills/<name>/SKILL.md
Global Agent Compatibility: ~/.agents/skills/<name>/SKILL.md
Global Claude Compatibility: ~/.claude/skills/<name>/SKILL.md

It seems that project-specific skills are saved in the project directory, while universal, project-agnostic skills are saved in the home directory.

Since I also use Codex regularly, I decided to save my skills in .agents/skills/<name>/SKILL.md which Codex uses.

How to Write a Skill

While you can write skills yourself, it’s easier to let OpenCode handle it.
Note that although the skill description can be written in natural language, a YAML frontmatter is required at the beginning of the file.
The following items are mandatory in the YAML frontmatter:

  • name
  • description

Here is an example of the beginning of a ‘security-check’ skill defined for this blog’s Rails application, which audits for confidential information leaks before a git commit:

---
name: security-check
description: Audit the entire repository for confidential information leaks before a git commit. Check for hardcoded public IPs, domains, API keys, names, and fallback values of environment variables.
---

If instructed to audit confidential information leaks in the repository, or before executing `git commit`, use this skill.

## Verification Method

**Use grep or ripgrep for pattern matching only as a supplementary tool.** Final judgments should be made by directly opening each file. Automated searches may miss values in comments, embedded templates, or implicit default values, so it is standard practice to **open and verify all files directly**.
(This continues...)

By writing this and restarting OpenCode, the skill will be loaded.

## Language for Writing

Whether it's SKILL.md or AGENTS.md, I think it's acceptable to write in English or Japanese. However, I write in Japanese because it's easier for me to modify or add rules.

## Usage Method

Enter `/skills` to display a list of already created skills. Select one and then describe the details of what you want to execute. Alternatively, issue a natural language command, or let the AI autonomously use the skill when the appropriate timing arrives.
For example, if you have the following in AGENTS.md:

```md:AGENTS.md
## Pre-commit Security Check

- Always execute a repository-wide confidential information scan according to the procedures in `.agents/skills/security_check/SKILL.md` before executing `git commit`.
- If CRITICAL or HIGH severity issues are found, **halt the commit** and report the findings to the user for instructions.
- If only MEDIUM or lower severity issues are found, report them but the user may continue the commit.
- If no issues are found, proceed with the commit as usual.

Then the security check will be automatically performed when you issue a git commit command.
It’s convenient to use skills for frequently executed tasks or complex instructions that would be tedious to repeat each time. It also helps unify rules in multi-person projects.

© 2025 Hiroe Tech Notes. All rights reserved.

Comments

No comments yet.