Skills can load from a mounted repo's .claude/skills, in cloud sandboxes only.
What's wrong with this entry?
A new docs section describes loading skills from a mounted repository's root .claude/skills directory. Skills are discovered once per session from the code as it stood when the session started, and this works in cloud sandboxes only, not self-hosted.
- Carries an explicit warning that repository skills are agent instructions running inside your trust boundary, so anyone who can commit to the repo can change agent behaviour.
Skills from a GitHub repository
Strings lifted out of the shipped bundle, so the claim above can be checked against them.