All skills

Ranked content search over a text corpus you point it at, using BM25 (via xhluca/bm25s). Corpus-agnostic: cloned repos, project knowledge stores, uploaded files and archives, any local directory. In-memory BM25 index per invocation, with a session-local disk cache for repeat runs against the same corpus. Use for "rank these documents", "search this corpus", "which files are most about X", "find content about Y", or any multi-word concept query against a known body of text where grep would return everything or nothing. Needs a corpus on disk. Not for searching stored memories or prior-session decisions (remembering), not for a named symbol or a file's structure (tree-sitting), and not for a literal string you could grep.

Use this Skill: https://skilld.dev/gh/oaustegard/claude-skills/bm25

This session only. Nothing lands on disk.

README.md

≈345 tokens on demand. Your agent reads this file only when SKILL.md points to it.

bm25

Stateless BM25 content search over any text corpus. Wraps xhluca/bm25s in a small CLI.

See SKILL.md for the full reference.

Quick start

uv pip install --system --break-system-packages bm25s

BM25=/mnt/skills/user/bm25/scripts/bm25.py

python3 $BM25 ./repo 'csrf middleware'
python3 $BM25 'github.com/django/django' 'atomic transaction'
python3 $BM25 project 'RAG scaling laws'

Caching

The skill maintains a session-local cache at /home/claude/.bm25-cache/<key>/. The key hashes the inputs that determine the index (resolved corpus path, include/exclude globs, max file size), so any change naturally invalidates. First invocation against a corpus builds and saves; subsequent invocations load in ~50ms instead of rebuilding in seconds.

/home/claude/ is ephemeral, so the cache and the rest of the session state expire together — no cross-session invalidation problem. Use --no-cache to bypass if you've mutated the corpus mid-session.

Pairing with other skills

  • For code-specific search with regex routing and AST-expanded results, use searching-codebases instead.
  • For symbol lookup (find:, source:, refs:) over a parsed codebase, use tree-sitting directly.
  • bm25 fills the gap between those two and works on non-code corpora (project knowledge, transcripts, uploaded docs).

Source: SKILL.md on GitHub

3 warnings14d3 checks · Risk MEDIUM
  • Gen Agent Trust Hub14d

    The skill provides ranked content search with a session-local disk cache. It uses the inherently unsafe 'pickle' module to store and load cached indices, which could allow for arbitrary code execution if the cache directory is compromised or pre-seeded by an attacker. Additionally, it downloads and extracts tarballs from GitHub without verifying the safety of the extraction process, potentially allowing path traversal, and it processes untrusted text which creates a surface for indirect prompt injection.

  • Socket14d

    1 alert: gptSecurity

  • Snyk14d

    Risk: MEDIUM · 2 issues

Signed by skilld at 5e58100. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 3 weeks ago
metadata
{
  "version": "0.2.1"
}

README badge

README badge for oaustegard/claude-skills/bm25