# Add to your Claude Code skills
git clone https://github.com/udecode/dotaiLast scanned: 4/30/2026
{
"issues": [],
"status": "PASSED",
"scannedAt": "2026-04-30T06:29:47.958Z",
"semgrepRan": false,
"npmAuditRan": true,
"pipAuditRan": true
}See how dotai compares with popular alternatives.
dotai is an open-source ai agents skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by udecode. Skills for agents. It has 1,158 GitHub stars.
Yes. dotai passed SkillsLLM's automated security scan — a dependency vulnerability audit plus prompt-injection heuristics — with no high-severity issues. You can read the full report in the Security Report section on this page.
Clone the repository with "git clone https://github.com/udecode/dotai" and add it to your Claude Code skills directory (see the Installation section above).
dotai is primarily written in JavaScript. It is open-source under udecode on GitHub, so you can review or fork the full source.
Yes. SkillsLLM lists many other AI Agents skills you can browse and compare side by side. Open the AI Agents category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh dotai against similar tools.
No comments yet. Be the first to share your thoughts!
⚠️ Third-Party Software Notice
This skill is third-party open-source software developed and hosted independently on GitHub. SkillsLLM is an informational directory and does not control or maintain the underlying repository.
Any security checks, ratings, or warnings displayed by SkillsLLM are automated and limited in scope. They do not constitute a security certification or guarantee that the software is safe, error-free, or free from malicious code, vulnerabilities, compromised dependencies, or prompt-injection risks.
Review the source code, permissions, dependencies, and configuration before installing or running any third-party skill. Use is at your own risk. To the maximum extent permitted by applicable law, SkillsLLM is not liable for losses arising from third-party software.
Shared skills that the pstack plugin does not cover: test audits (test-audit, adapted from openclaw's), screenshot walkthroughs and video transcripts, and pstack setup, sync and skill-drift audits (sync-pstack). Review runs on pstack's panels with Codex seats, on the work each project's reviews list names.
The engineering method comes from the pstack plugin, pstack@pstack-claude from michael-denyer/pstack-claude, pinned per project: poteto-mode, its playbooks, the principle skills, how, why, architect, arena, interrogate, swarm, reflect, show-me-your-work, tdd, deslop and the rest. dotai does not vendor them.
Read SKILLS.md for the generated inventory, capability limits and pinned install commands for the unchanged upstream skills listed in upstream-skills.json. Their source is not copied here.
skills/ owns reusable methods. Keep product names, private paths, credentials, release environments and infrastructure assumptions out of shared instructions.sync-pstack sets pstack up in a project through an interview and keeps every pstack project on one plugin tag and one shared overrides block. Its assets/block.md is the shared override source; project-only rules stay in each project.Install a skill with the Skills CLI, naming the skill and each agent, for example npx skills add udecode/dotai --skill test-audit --agent codex claude-code. Project scope is the default; use --global only for a user-wide install.
scripts/validate-skills
node scripts/build-workflow.mjs
node scripts/build-workflow.mjs --check
build-workflow.mjs regenerates SKILLS.md and workflow-manifest.json, rejects duplicate ownership, resolves dependencies and local Markdown references, and records file checksums and modes. --forbid '<pattern>' optionally scans shipped content for project or private vocabulary.