One endpoint.
Every agent skill.
Connect any MCP client to SkillsRegistry and your agent can search 125,247 skills and MCP servers by what they do — and get back the endpoint or repository it needs to actually use one. Trust score and scan coverage on every result. No key, no signup.
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
Any MCP client — Claude Code, Cursor, Continue, Windsurf. Streamable HTTP at
https://api.skillsregistry.net/mcp.
Setup for other clients →
Where listings come from
Listings are indexed from public registries, including the official MCP Registry, and from GitHub. Every skill page links to its source listing and its code repository.
The problem
Your agents are only as safe as the tools they call
Enterprise AI agents autonomously reach for third-party skills — MCP servers, tools, scripts — at runtime. Most are unsigned, unscanned, and unowned. One skill that reads credentials it never declared, or writes to files it shouldn't, is a production incident, a data-exfil path, or a compliance finding waiting to happen.
Unvetted supply chain
Skills pulled from public marketplaces carry prompt-injection, credential-harvest, and command-injection risk. No one scored them before your agent ran them.
No control plane
Which tools can your agents use? At what trust level? From which sources? Without a registry, the answer is "whatever they find."
No provenance or audit
When something goes wrong, you need to know what ran, which version, from where, and whether it was signed. Marketplaces don't keep receipts.
SkillsRegistry is the control plane in between: one governed catalog with scan coverage stated per listing and first-party skills signed — and where you set the rules your agents follow.
Built to trust every tool your agents use
Every skill is semantically indexed. Skills we have analysed are security-scanned, and each listing states its scan coverage.
Semantic Search
Agents describe the job in natural language; the right tool surfaces ranked by confidence — not keyword luck. One query across every source.
Multi-dimensional Trust
Analysed skills scored 0-100 on security, supply chain, quality, reliability, compliance, and provenance — one verdict tier your policies can gate on. Human and agent signals kept separate.
Version control you own
The most reliable version surfaces first (trust-weighted), or pin the exact one you've certified. No surprise upgrades reaching production agents.
Provenance & lineage
Complex jobs decompose into multi-skill workflows, with lineage preserved back to every upstream source — a complete audit trail of what ran and from where.
For enterprise
Run your own private registry
A tenant-scoped catalog for your organization — your internal skills alongside the curated public ones, under policies you control. Hosted overlay, self-hosted, or fully air-gapped.
Enforce a trust floor
Set the minimum verdict tier ("A-tier only") and agents simply can't resolve anything below it. Allow / block lists per source, publisher, or skill.
Your private skills
Publish internal skills scoped to your tenant through the same signed handler. They never leave your catalog, and rank on their own trust.
Pin the versions you trust
Freeze exact versions and control upgrades, or let the most reliable version auto-surface. No surprise changes reaching production agents.
One search, public + private
Query your private catalog, the public catalog, or both in a single call. Same MCP + REST surface your agents already use.
Signed & auditable
First-party skills are Ed25519-signed; crawled listings carry source provenance and lineage. A complete audit trail of what ran, which version, and from where.
Deploy your way
A private overlay on the hosted service, or docker run the whole registry on-prem / air-gapped. Same code, same endpoints, nothing leaves your network.
This is what your agent sees
Real MCP calls, real responses — no mocking. Captured on this page build. Streams on load so you can watch it land.
- ▪ search_skills
- ▪ get_skill
- ▪ list_leaderboard
- ▪ get_trust_breakdown
- ▪ resolve_composition
- ▪ search
- ▪ fetch
- ▪ algonacci-unlock-pdf 99% verified
- ▪ wowuz-mcppdf 100% verified
- ▪ risha-max-0xpdf-mcp 70% verified
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp The score is not a vibe
Every deeply-scanned skill decomposes into six measurable dimensions from 27 analyzer passes. A skill can score 96 overall and still get blocked — because one axis dips where it matters.
Every skill carries a trust score, but they are not all the same claim: an unscanned skill is scored from source provenance alone, while these 27 are taken to full six-axis depth. Scan coverage is stated on every listing so you can tell them apart, and the deep-scan backfill widens the analysed set continuously. Full breakdown via API →
92,428 published skills, placed by trust
Every point is a published skill. Most land at the baseline every source starts from — the trustworthy few earn their place on the right, where scans come back clean and signatures check out.
What the catalog is made of · by category
Category & domain derived from each skill's name and description. Filter the full catalog by them on browse.
Find skills by task
Click a category to explore top-ranked skills for that task.
Static analysis, formatting, and lint enforcement.
Use this tool when you need to streamline code review workflows and enforce coding standards across teams. It analyzes pull requests, checks code patterns, and ensures consistency with team standards, providing automated code analysis, security checks, and suggestions for improvements. The tool accepts GitHub repository data as input and outputs detailed code review information, including files, diffs, and compliance validation results.
Use this tool when you need to perform thorough code reviews and receive senior-level feedback on code quality, security, and performance. It integrates with Codex and Gemini CLIs to analyze code snippets, files, or directories, providing automated feedback on best practices. Ideal for developers seeking to improve code quality and security, it supports various review tools and provides detailed output for refinement.
Use this tool when you need to enforce consistent coding standards and styles in your projects, particularly for Flutter and Dart development. It reviews code and provides suggestions for improvement, helping to solve problems related to code readability and maintainability. The tool takes in code files as input and outputs style improvement suggestions, making it a valuable asset for development teams seeking to streamline their coding processes.
Use this tool when you need to analyze Python code quality and enforce coding standards, solving problems such as detecting syntax errors, type inconsistencies, and complex code structures. It takes in Python code as input and outputs detailed reports on linting and type checking results, using tools like flake8 and mypy. Utilize it in development contexts where maintaining high-quality, readable, and reliable code is crucial.
Use this tool when you need to analyze and refine code quality through automated scoring, linting, formatting, and transpilation. It solves problems related to code consistency, readability, and compatibility, providing outputs such as scored code quality and formatted code. Ideal for use in development environments where code review and optimization are crucial.
Crawl pages and extract structured data from the web.
Use this tool when you need to build and manage web scrapers with advanced features like async crawling and structured data extraction. It solves problems of extracting specific data from websites, handling complex HTML structures, and scaling crawling tasks. The Silkworm server takes in website URLs and CSS/XPath selectors as input and outputs extracted, structured data.
scrapling — zendenho7-scrapling. Use this tool when you need to extract data from websites that employ anti-bot measures, as it provides an adaptive web scraping framework with anti-bot bypass and spider crawling capabilities, accepting website URLs as input and outputting extracted data in a usable format, ideal for data mining and web data integration tasks. It solves problems related to accessing restricted web content and handles various website structures and anti-scraping protections. Use scrapling to automate data extraction from complex websites with ease.
playwright-scraper-skill-1-2-0 — itsjustfred-playwright-scraper-skill-1-2-0. Use this tool when you need to extract data from websites with anti-bot protection, as it provides a Playwright-based web scraping solution to bypass these barriers. It solves problems related to data extraction from websites that block traditional scraping methods, offering a reliable way to fetch data. With input parameters for target URLs and outputting scraped data, it's ideal for use cases requiring automated data collection from protected websites.
Use this tool when you need to leverage web scraping and crawling capabilities for AI agents, enabling efficient data extraction from single or multi-page websites with adaptive stopping. It solves problems related to data collection, information extraction, and web content analysis by providing a lightweight server that exposes these capabilities as tools. The server takes in website URLs and scraping parameters as inputs and outputs extracted data in a usable format.
Use this tool when you need to retrieve and process web scraping requests efficiently, solving problems of data extraction and handling anti-scraping measures. It takes in web scraping requests as input and outputs the extracted data, providing a seamless interface for Large Language Models (LLMs). Ideal for use cases requiring automated data collection from websites, leveraging ScraperAPI's capabilities.
Query, migrate, and inspect SQL and NoSQL stores.
Use this tool when you need to connect to multiple databases and perform SQL operations, such as executing queries, managing tables, and performing CRUD operations. It solves problems related to database integration, querying, and management, supporting various databases including MySQL, PostgreSQL, and Oracle. It takes database connections and SQL queries as inputs and provides query results and database schema information as outputs.
Use this tool when you need to interact with various databases, such as SQLite, SQL Server, PostgreSQL, and MySQL, to execute queries, manage tables, and export data. It provides a direct interface for database operations through the Model Context Protocol, allowing for seamless data management and analysis. Ideal for use cases requiring database querying, data extraction, and table administration.
Use this tool when you need to interact with relational databases, such as PostgreSQL, MySQL, or SQLite, to execute SQL queries, inspect database schemas, or run migrations. It provides a comprehensive interface for database management, accepting SQL queries and schema definitions as inputs and producing query results and migration reports as outputs. Ideal for use cases requiring database setup, data analysis, or schema updates, this tool streamlines database operations and simplifies data management tasks.
db-legacy-migration-agent — felipeassis10-db-legacy-migration-agent. Use this tool when you need to migrate legacy relational databases to PostgreSQL, as it parses schemas from Oracle, DB2, MySQL, and MSSQL, and generates Prisma schemas and TypeScript query helpers. It solves database compatibility issues and simplifies migration processes. Ideal for use cases involving database modernization, consolidation, or cloud migration, where a seamless transition from legacy systems to PostgreSQL is required.
Use this tool when you need to integrate AI models with various database management systems, as it provides a unified interface for querying, schema inspection, and connection management across MySQL, MSSQL, Oracle, and Sybase databases. It solves the problem of requiring separate server configurations for each database type, streamlining data access and manipulation. This tool is ideal for use cases involving multi-database interactions, data migration, or federated queries.
Read, transform, and extract content from PDFs and docs.
Use this tool when you need to extract content from PDF files with precise layout and LaTeX recognition, solving problems of inaccessible or unstructured data in large documents. It takes PDF files as input and outputs extracted content, utilizing a Python-based engine with a Node.js fallback for robust processing. Ideal for use cases requiring efficient and accurate text extraction from complex PDFs.
Use this tool when you need to extract content from PDF files, whether protected or unprotected, to analyze documents, index content, or extract data. It provides functionality to read and parse PDFs, handle password-protected documents, and format extracted content. Ideal for workflows requiring PDF parsing and text extraction, such as document analysis or data extraction from PDF sources.
Use this tool when you need to extract insights from PDF files, such as text, tables, and diagrams, and require a server-based solution for large-scale document processing. The pdf-mcp tool solves problems related to PDF parsing, indexing, and rendering, accepting PDF files as input and outputting extracted text, tables, and images. It is particularly useful in contexts where large language models (LLMs) need to analyze and understand complex PDF documents.
Use this tool when you need to extract text from PDF documents, solving problems such as data mining, document analysis, and text processing. It takes PDF files as input and outputs extracted text, providing a compatible interface with any Model Context Protocol (MCP) client. Ideal for use cases requiring accurate text extraction from PDFs, such as information retrieval and document indexing.
Use this tool when you need to extract structured data from technical PDFs, such as tables, formulas, and references, to automate document processing and knowledge retrieval. It takes PDF files as input and outputs extracted data in a machine-readable format, leveraging PyMuPDF4LLM and Ollama for high-performance processing. Ideal for use cases involving scientific literature analysis, research automation, and document indexing.
GitHub workflow tools — PR review, branch and commit operations.
Use this tool when you need to streamline code review workflows and enforce coding standards across teams. It analyzes pull requests, checks code patterns, and ensures consistency with team standards, providing automated code analysis, security checks, and suggestions for improvements. The tool accepts GitHub repository data as input and outputs detailed code review information, including files, diffs, and compliance validation results.
GitHub PR Analyzer MCP Server — punyprogrammer-pr-analyzer-mcp-server. Use this tool when you need to streamline GitHub pull request review processes and centralize feedback. It fetches GitHub pull request details and saves reviews to Notion, solving problems related to code review management and team collaboration. Ideal for development teams seeking to automate and organize their GitHub PR workflows, this tool takes GitHub pull request data as input and outputs saved reviews in Notion.
Use this tool when you need to analyze GitHub Pull Requests in a structured and maintainable way. It solves problems related to code review and integration by providing a robust framework for evaluating PRs. The server takes GitHub PR data as input and outputs analyzed results, making it ideal for use cases involving automated code review and testing.
Use this tool when you need to automate code review processes on GitHub, enabling large language models (LLMs) to analyze and implement suggestions on pull requests. It solves problems of manual code review and resolution by providing automated workflows for processing and resolving review comments. The tool accepts GitHub pull requests as input and outputs programmatically implemented code review suggestions, streamlining developer workflows and improving code quality.
Vuln scanning, secret detection, and policy checks.
Use this tool when you need to identify exposed secrets in your codebase, such as API keys, tokens, and passwords, to prevent security breaches. The secrets-scan tool scans a specified directory or file, using regex and entropy heuristics to detect hardcoded credentials. It accepts inputs like target path, minimum entropy threshold, and exclude patterns, and outputs a list of potential secrets found, making it ideal for pre-production security checks.
expanso-secrets-scan — aronchick-expanso-secrets-scan. Use this tool when you need to detect and identify hardcoded secrets such as API keys, tokens, and passwords in text or code, helping to prevent security breaches and data exposure. It solves problems related to insecure coding practices and sensitive data leakage by scanning for potential vulnerabilities. The tool takes in text or code as input and outputs a list of detected secrets, making it ideal for use in secure coding and compliance contexts.
Use this tool when you need to identify hardcoded secrets in a repository, solving security risks and compliance issues by detecting sensitive information. It scans a checked-out repo using gitleaks and returns structured findings, providing a clear interface for inputting repository data and outputting potential security threats. Ideal for use cases requiring secret detection and security auditing in development environments.
nirwan-secret-scanner — nirwandogra-nirwan-secret-scanner. Use this tool when you need to detect and prevent sensitive information leaks in your codebase, such as API keys, tokens, and passwords. It scans files, repositories, and directories to identify exposed secrets, helping to mitigate security risks and data breaches. Ideal for use in development, testing, and deployment pipelines to ensure secure coding practices.
ggshield-scanner — amascia-gg-ggshield-scanner. Use this tool when you need to detect and protect sensitive information in your codebase, such as hardcoded secrets and credentials. The ggshield-scanner identifies over 500 types of secrets, solving problems related to security and data breaches. It takes in code files as input and outputs a list of detected secrets, making it an essential tool for securing your projects and preventing unauthorized access.
Ranked by semantic similarity, then by Cognium trust.
Get started
Start free in minutes, or set up a governed private registry for your organization.
Use the free public API
Point your agents at api.skillsregistry.net — MCP + REST, no auth, no signup. Search 100,000+ trust-scored skills today.
Self-host it
Run the whole registry on-prem or air-gapped — same code, same endpoints. Nothing leaves your network.
Get a private registry
A tenant-scoped catalog with trust policies, allow/block lists, version pinning, private skills, and SSO — hosted, self-hosted, or air-gapped. We'll help you roll it out.
Book a demoFrequently asked questions
What SkillsRegistry is, how it works, and how to use it.