sume skills export: review the Sume agent skill before you install it
Run sume skills export to read the packaged Sume skill's source before sume skills install writes it into .agents/skills or .claude/skills. Commands and gates.

Run sume skills export sume to read the packaged Sume skill's source files, then sume skills install once you are happy with them. Install writes into .agents/skills or .claude/skills; export is how you review before a custom install.
A skill is instructions your agent will follow, so reading it first is ordinary hygiene. These commands come from Agent skills and the CLI command reference.
Which skills commands exist?
Update deserves the same care as install. sume skills update refreshes an installed skill, which means its instructions can change under you. If your team pins agent behavior, run export after an update and diff it against what you reviewed, the same way you would review a dependency bump. The CLI docs do not describe a version pin for skills, so a diff is the check you have.
| Command | What it does |
|---|---|
| sume skills list | Shows the bundled skills |
| sume skills install | Installs or refreshes the packaged Sume skill into local agent skill directories |
| sume skills update | Refreshes an installed skill |
| sume skills export sume | Exports the skill's source files for review |
| sume skills remove sume | Removes the installed skill |
What is a sensible review flow?
Export first, read, then install. In a shell:
Two practical notes. Install targets .agents/skills or .claude/skills, so check which of those your agent actually reads before assuming the skill is active. And export writes source files for you to read; it does not install anything, which is why it is safe to run first on any machine.
sume skills list
sume skills export sume
# read the exported files, then:
sume skills install
sume skills updateWhat gates should the skill keep?
The CLI's own agent guidance is the checklist to look for. Agents should prefer read-only commands while planning, redact sensitive output with --agent --json, and not create resources or submit paid work without explicit operator confirmation.
The CLI has two flags for that: --confirm-submit for non-paid writes such as job cancellation or asset registration, and --confirm-paid for generation that can reserve or spend credits. Image, Video and Music generation are not CLI submit commands yet, so agents call the Developer API for those.
Does a skill replace MCP?
No. A skill is know-how the agent reads; MCP is a live connection to tools. Sume's docs recommend the hosted MCP server for Cursor and Claude remote connectors. The comparison is in Agent skills vs MCP.
Sume does not claim a skill makes an agent safe. The guardrails that actually stop spend are on the API side: required idempotency keys on paid writes, and per-run spend caps.
The same discipline applies to anything an agent can run unattended. For scheduled and API-triggered runs, the controls are on the run itself: an Idempotency-Key, a spend cap per run, on_active_run, and a webhook that tells you when it finished. See Safe automation for AI agents that call paid APIs for how those fit together.
Sources
Related posts
More in Agents
- Verify a Sume run webhook in Python: replay window and empty secret
A Python verifier for the sume-v1 signature on a Sume run webhook: raw body, five-minute replay window, constant-time compare, and no empty secrets.
- A weekly scheduled agent run for podcast clips: cron, cap and trigger
Set a Sume Scheduled Action to run every week, with a cron schedule, an IANA time zone and a spend cap that a manual or API run can lower but never raise.
- Run the Sume video agent from your backend with Agent Completions
POST /v1/agent/completions runs the same agent as the Sume Agents chat, with tools and media generation, and returns an async run receipt you poll or webhook.
- Scheduled AI video agent runs: cron, API triggers, and receipts
A Sume schedule is a saved Agents automation that runs on a cron cadence and returns a run receipt. Author it in the dashboard; start and monitor runs by API.
Written by Sume