Stop re-explaining your runbooks to Claude every single session. Package them once as a Skill, and every future chat, Cowork run, and Claude Code session just knows how your team operates.
See the workflow in action, tap through the tabs below:
$ scaffold a new skill locally
mkdir -p ~/.claude/skills/soc2-evidence cd ~/.claude/skills/soc2-evidence cat > SKILL.md << 'EOF' --- name: soc2-evidence description: Collect and format SOC 2 access-review evidence from IAM exports and screenshots. Use when preparing audit evidence or asked for access review documentation. --- Pull the quarterly IAM export, flag any grant older than 90 days, and format the findings into the evidence template in evidence-template.md. EOF
$ example prompt once the skill is installed
Pull this quarter's IAM evidence for the SOC 2 audit and flag anything that needs owner sign-off before Friday.
$ example prompt for the log-triage skill
Grep last night's nginx and journald logs for the patterns in log-triage/SKILL.md and summarize anything that matches a known incident signature.
Only install Skills you wrote or that come from a source you trust. A SKILL.md can tell Claude to run scripts and call tools, so a malicious one is a malicious dependency, not a harmless text file. Review every bundled script before you enable it, especially anything that fetches data from a URL.
Custom Skills also do not sync between claude.ai, Claude Code, and Cowork automatically. If you built one in Cowork, you still need to add it separately wherever else your team wants to use it.
Every DevOps and security team has the same problem. The runbook lives in someone's head, or in a wiki page nobody opens until an incident is already on fire. You explain the SOC 2 evidence process to a new hire, then explain it again three months later because they forgot half of it. Claude Skills fix a version of this problem for AI: instead of re-explaining your process in every chat, you write it down once, and Claude reads it back whenever the job matches.
What Claude Skills Actually Are
A Skill is a folder with a SKILL.md file at the root, plus whatever scripts or reference docs you want to bundle alongside it. The file needs YAML frontmatter with a name (lowercase, hyphens, no reserved words like "claude" or "anthropic") and a description that states both what the Skill does and when Claude should use it. That description is the whole trigger mechanism: Claude scans it against your request and decides whether to pull the rest of the Skill into context.
That "pull in when needed" behavior is called progressive disclosure, and it's the reason Skills don't bloat every conversation. There are three levels. The metadata (name and description) loads at startup for every Skill you have enabled, at roughly 100 tokens each. The SKILL.md body, usually under 5,000 tokens, only loads once a request actually matches. Bundled scripts and reference files cost nothing until Claude opens them. You can pack a 40-page reference doc into a Skill and it will not touch your context window unless Claude specifically needs page 12.
Quick Setup: Your First Skill in Under 10 Minutes
There are two ways to make one. If you're on a paid Cowork plan, you can record yourself doing the task once, up to about ten minutes, and Claude proposes a Skill from what it watched (it keeps the resulting screenshots and generated file, not the video or audio). For anything scriptable, writing the SKILL.md by hand is faster and gives you tighter control.
In Claude Code, Skills live under ~/.claude/skills/ as plain folders, so you can create, edit, and version them like any other file. On claude.ai, you enable and manage Skills under Customize, then Skills, and test them with a handful of real prompts while watching Claude's thinking to confirm it actually triggered the right one. One thing to plan around: a custom Skill uploaded to one surface does not automatically show up on the others. If you built it in Cowork, add it separately to Claude Code or the API if your team needs it there too.
The Mindset Shift: Treat Skills Like Runbooks-as-Code
The teams getting the most out of this feature are not writing clever prompts. They're taking the runbook, playbook, or checklist that already exists (usually half-finished, in a wiki, written by someone who left) and turning it into a Skill with the same discipline they'd apply to a Terraform module. Version it. Review it before merging. Keep the description narrow enough that it triggers on the right requests and not on everything.
The other habit worth building: Skills compose. A "log format reference" Skill and a "Jira ticket template" Skill can both fire in the same conversation, and Claude uses each where it's relevant without you having to orchestrate the handoff. That's a genuinely different way of working than one giant prompt trying to cover every case.
7 Workflows Worth Packaging as Skills
1. SOC 2 evidence collector
Bundle the exact steps for pulling access-review evidence: which IAM export to run, how to flag grants older than 90 days, and the evidence template to fill in. Auditors get consistent formatting every quarter, and nobody has to remember the process from scratch.
2. Blameless postmortem drafter
Package your postmortem template plus a short script that pulls the incident timeline from PagerDuty or your Slack export. Claude drafts the first pass while the details are still fresh, instead of an engineer reconstructing it from memory a week later.
3. Terraform module scaffolder
Bundle your org's naming conventions, required tags, and pinned provider versions. Every new module starts from a compliant baseline instead of drifting toward whatever the last person happened to copy and paste.
4. Log triage cheatsheet
Bundle the actual regex patterns and query snippets your team uses against your specific log formats, nginx, journald, CloudTrail, whatever you run. Claude greps for the right signatures instead of guessing at generic patterns.
5. Quarterly access review
Turn the least-privilege review into a Skill: which IAM policies to pull, how to flag stale grants, who needs to sign off. This is a great candidate for the Cowork screen-recording path since it's mostly clicking through the same console screens every quarter.
6. On-call handoff notes
Capture your team's handoff format: open incidents, watch items, any deploy freezes in effect. Claude drafts a consistent note at the end of every shift instead of a rushed, inconsistent one typed while someone's already logging off.
7. Vulnerability triage and ticket filer
Bundle your CVSS scoring rubric and Jira ticket template so a raw scan result becomes a properly labeled, correctly prioritized ticket without an engineer re-typing the same fields every time a scanner finishes a run.
Safety and Gotchas
Only install Skills you wrote yourself or that come from a source you actually trust. A SKILL.md can instruct Claude to run bash commands and call tools, so treat a new Skill the way you'd treat a new dependency pulled into production, not a harmless text file. Read every bundled script before enabling it, and be extra cautious with anything that fetches data from a URL. If you're on an Enterprise plan, turn on Skill content scanning in the admin settings, though it only covers Skills uploaded through claude.ai and Cowork, not ones pushed through the API.
Naming has real constraints too: the name field is capped at 64 characters, lowercase letters, numbers, and hyphens only, and it can't contain the words "claude" or "anthropic" or any XML tags. The description field is capped much higher, but Claude only matches against what you actually write there, so vague descriptions mean vague triggering. Say what the Skill does and when to use it, in the same sentence.
Usage and Cost Tips
Skills don't carry a separate line-item charge. They run on whatever Claude plan or API usage you already have; the "cost" that matters is token budget, not dollars beyond your plan. Since metadata for every enabled Skill loads at startup, don't enable forty Skills you never use just because you can. Keep the active set to what your team actually reaches for, and archive the rest. For anything with a big reference doc, split it into a short SKILL.md plus separate reference files Claude only opens on demand. That's the whole point of the three-tier loading model: it rewards you for organizing information instead of dumping it all into one file.
FAQ
Do Skills work the same way across claude.ai, Claude Code, and Cowork?
The format is identical everywhere, one SKILL.md with YAML frontmatter, but custom Skills don't sync automatically between surfaces. Upload or place the same Skill separately wherever your team needs it.
Can a coworker's Skill mess up my Claude Code setup?
Only if you install it. Skills are filesystem-based and opt-in, so nothing runs until you enable it, but once enabled it can direct Claude to run scripts, so review it first, same as reviewing a pull request.
What's the difference between a Skill and an MCP connector?
An MCP connector gives Claude a live tool to call, like an API. A Skill packages instructions and reference material for how to use tools well. They're complementary: a Skill can tell Claude exactly how to use a connector you already have.
Skills are one of the lowest-effort ways to make Claude actually match how your team works, instead of re-teaching it every session. Start with the runbook your team complains about most, the one everyone half-remembers, and turn that into your first Skill this week. For more on getting Claude to run your actual workflows instead of generic ones, see our breakdowns of Claude Code automation and Claude MCP connectors, or check out our courses if you want a structured path through all of it.
