Open source · self-hosted · scanned before it ships

skills-server

A self-hosted marketplace for three kinds of package: skills, which are text your agent reads; connectors, which declare the requests it may make with a credential and the hosts it may address; and Agent Plugins, which bundle skills and may declare an MCP server. Browse them, submit your own, and track their review status. Signing in with Google is also how you submit for the first time -- there's no separate sign-up.

Sign in with Google Browse the public directory

Scanned before it ships

Every package passes a static/LLM security shield plus a VirusTotal multi-engine sweep before it's trusted. A connector is also checked against its own declaration: a read class on a writing method, or a base URL outside the hosts it named, is refused rather than published.

Nothing hidden

See the exact SKILL.md, file listing, owner and known risks for every version -- and for a connector, every operation with its capability class, the hosts a token could reach, and the scopes it would carry. Before you install it.

Yours to run

Self-hosted, open source, no vendor lock-in -- just a portable SKILL.md format you can take anywhere.