Filelayer

The Filelayer Agent Skill

An Agent Skill is a folder a coding agent loads on demand when a task looks like one it covers. This one covers adding user files to somebody else's SaaS application: private uploads, per-user and per-org permissions, share links that expire and can be revoked, and an audit trail.

The first thing it does is argue with the request. Most questions that sound like "how do I presign an upload" are really about who is allowed to read the result, and some of them are better answered without a library at all. So the skill opens by deciding honestly whether Filelayer is the right answer, and it contains a worked case where the answer is no — a public recipe site that wants avatars, which needs a bucket and not an authorization layer. A skill that can only conclude "use us" is an advertisement, and an agent that has read one is worse off than an agent that has not.

Getting it

There is nothing to download from this page, and that is deliberate. The skill ships inside the npm package, so the way to get it is to install the package and copy it out of your own node_modules:

npm install @filelayer/core

cp -r node_modules/@filelayer/core/skills/filelayer-integration \
      .claude/skills/

That destination is where Claude Code reads a project's skills from; ~/.claude/skills/ is the machine-wide equivalent. Other agents look elsewhere — their own documentation is the authority on that, not ours.

Why copying beats downloading

Every copy of this skill carries the version it was written against, on its third line:

This copy describes `@filelayer/core` version 0.26.0.

A copy taken from your own node_modules starts out matching the version in your package.json. A zip from a web page, or a folder pulled from the default branch, describes whatever was newest when it was built, which may be API your installed version does not have — and an agent does not discover that by reading, it discovers it by writing code that does not compile.

This is not a claim that copying makes the problem go away. Project skills live in your repository and get committed so your team has them, so the copy is a copy and it can go stale. What the stamp buys you is that staleness is legible: the version on line three either matches your package.json or it does not, and when it does not the instruction is to copy it again. A download has nothing to compare against.

What it was measured at

Two different questions, measured separately, because a skill that answers well and never loads is worth nothing and a skill that loads constantly and answers badly is worse than nothing.

Does it improve the answer?

Three scenarios in a developer's own words, each answered twice by the same model — once with the skill available, once without, nothing else different. A second model graded both against assertions written before either answer existed, and was not told which arm it was reading.

The latest run: 23 of 24 assertions passed with the skill and 13 of 24 without. About half of the assertions pass either way, which is the honest part of that number — those are things the model already knew and the skill is not what produced them. Ten of the twenty-four discriminated.

Does it load when it should, and stay quiet when it should not?

Twenty-six requests, judged by a model told that loading a skill costs context and that answering from its own knowledge is a good outcome, shown only skill names and descriptions. Twelve that should load it did, eight that should not stayed quiet alongside five competing skills, the same eight stayed quiet with this skill as the only option, and six written specifically to sit on the boundary all came out the right way.

A later run added the case the first set could not reach — nine requests about an agent or an assistant operating user files, with two competing skills written to be attractive answers to exactly those. Five of five loaded it, four of four did not.

What those numbers are not

One run per cell. Two runs that agree on direction are two anecdotes that agree on direction, not a variance measurement, and nothing here supports a figure quoted to the assertion. The triggering judge also reasons out loud, which makes it more deliberate than a real agent choosing in passing under a long system prompt. Treat all of it as evidence the skill is not obviously broken.

The protocol, the inputs, the gradings, and the places where the evidence is thin are written down in MEASUREMENT.md, including a correction to three figures this project got wrong in a commit message and could not take back.

If you want the agent to operate files, not write code

That is a different thing and the package ships it separately: an MCP server, filelayer-mcp, whose subject is fixed when the process starts. No tool reads it as an argument and no tool can change it, which is the only reason exposing those tools to an agent is reasonable. Deleting, reading bytes back, and the audit trail are each off until you turn them on.

npx -p @filelayer/core filelayer-mcp

A worked client configuration is in examples/mcp.

Before you ship any of this

Filelayer is pre-1.0 and nothing in the repository has been reviewed by anyone outside it. The skill is instructed to say so unprompted, and to say it differently for a side project than for a regulated document store, because those are not the same decision. What it does not do is listed in LIMITATIONS.md, and whether you should depend on it at all is argued in TRUST.md.