Skip to main content
Skills give an agent instructions for a procedure or knowledge about your systems. A skill can explain how your application authenticates requests, how to investigate a particular weakness, or which conventions to follow when preparing a fix. Pass skills as strings in the agent’s skills array. You can write the instructions directly in your code or load them from another source, such as a Markdown file.

Add skills to an agent

To add a skill to an existing agent, preserve its configured skills with object composition:
Focus each skill on a specific topic. “Check authentication for vulnerabilities” adds little context; the token format, endpoints, and expected behavior give the agent something concrete to investigate.

Load instructions from a file

You can keep skills in Markdown files alongside your code. Read each file and pass its contents to the SDK:
The SDK treats each string as instructions. It does not interpret file paths or read files for you. In this example, the Markdown file must be available where your code calls readFile().

Replace configured skills

Supply a new array to replace the skills exposed in the agent’s configuration:
This replaces the configurable skills while retaining the underlying pre-built agent’s behavior. See Agents for how configuration inherits from a base agent.

Use skills for different kinds of work

Skills can guide offensive testing, triage, or remediation. For example: Use skills to explain how work should be done. Use guardrails to specify constraints, such as avoiding particular endpoints or stopping when a critical vulnerability is found.

Save and update skills

Registering an agent saves its skill strings with the rest of its configuration:
When your team retrieves the agent, its skills array contains those instructions. It does not depend on files from the environment that registered it. To change the saved skills, pass the updated strings to antigen.agents.update(). The skills array you send becomes the agent’s saved array.

Append a skill

Retrieve the agent and spread its existing skills into the new array before adding your instructions. This keeps the saved skills and adds authentication:

Replace the skills

Pass only the instructions you want to keep. This replaces all previously saved configurable skills with authentication:
update() does not merge arrays. Include the existing entries to append to them, or leave them out to replace them. If you keep instructions in a file, read the file again and submit its updated contents. Editing a local file alone does not change a registered agent.