Live index · 8 sources

One endpoint.
Every agent skill.

Connect any MCP client to SkillsRegistry and your agent can search 125,247 skills and MCP servers by what they do — and get back the endpoint or repository it needs to actually use one. Trust score and scan coverage on every result. No key, no signup.

claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp

Any MCP client — Claude Code, Cursor, Continue, Windsurf. Streamable HTTP at https://api.skillsregistry.net/mcp. Setup for other clients →

125,247 skills indexed
84,389 security-scanned
A–F trust tiers

Where listings come from

Listings are indexed from public registries, including the official MCP Registry, and from GitHub. Every skill page links to its source listing and its code repository.

The problem

Your agents are only as safe as the tools they call

Enterprise AI agents autonomously reach for third-party skills — MCP servers, tools, scripts — at runtime. Most are unsigned, unscanned, and unowned. One skill that reads credentials it never declared, or writes to files it shouldn't, is a production incident, a data-exfil path, or a compliance finding waiting to happen.

Unvetted supply chain

Skills pulled from public marketplaces carry prompt-injection, credential-harvest, and command-injection risk. No one scored them before your agent ran them.

No control plane

Which tools can your agents use? At what trust level? From which sources? Without a registry, the answer is "whatever they find."

No provenance or audit

When something goes wrong, you need to know what ran, which version, from where, and whether it was signed. Marketplaces don't keep receipts.

SkillsRegistry is the control plane in between: one governed catalog with scan coverage stated per listing and first-party skills signed — and where you set the rules your agents follow.

Built to trust every tool your agents use

Every skill is semantically indexed. Skills we have analysed are security-scanned, and each listing states its scan coverage.

Semantic Search

Agents describe the job in natural language; the right tool surfaces ranked by confidence — not keyword luck. One query across every source.

Multi-dimensional Trust

Analysed skills scored 0-100 on security, supply chain, quality, reliability, compliance, and provenance — one verdict tier your policies can gate on. Human and agent signals kept separate.

Version control you own

The most reliable version surfaces first (trust-weighted), or pin the exact one you've certified. No surprise upgrades reaching production agents.

Provenance & lineage

Complex jobs decompose into multi-skill workflows, with lineage preserved back to every upstream source — a complete audit trail of what ran and from where.

For enterprise

Run your own private registry

A tenant-scoped catalog for your organization — your internal skills alongside the curated public ones, under policies you control. Hosted overlay, self-hosted, or fully air-gapped.

Enforce a trust floor

Set the minimum verdict tier ("A-tier only") and agents simply can't resolve anything below it. Allow / block lists per source, publisher, or skill.

Your private skills

Publish internal skills scoped to your tenant through the same signed handler. They never leave your catalog, and rank on their own trust.

Pin the versions you trust

Freeze exact versions and control upgrades, or let the most reliable version auto-surface. No surprise changes reaching production agents.

One search, public + private

Query your private catalog, the public catalog, or both in a single call. Same MCP + REST surface your agents already use.

Signed & auditable

First-party skills are Ed25519-signed; crawled listings carry source provenance and lineage. A complete audit trail of what ran, which version, and from where.

Deploy your way

A private overlay on the hosted service, or docker run the whole registry on-prem / air-gapped. Same code, same endpoints, nothing leaves your network.

This is what your agent sees

Real MCP calls, real responses — no mocking. Captured on this page build. Streams on load so you can watch it land.

agent — mcp session — api.skillsregistry.net/mcp live · ⌘K for your own query
▸ POST /mcp {"method":"tools/list"}
→ 7 tools · 218ms
  • ▪ search_skills
  • ▪ get_skill
  • ▪ list_leaderboard
  • ▪ get_trust_breakdown
  • ▪ resolve_composition
  • ▪ search
  • ▪ fetch
▸ POST /mcp {"tool":"search_skills", "query":"pdf parsing", "limit":3}
→ 3 results · confidence high · 254ms
  • ▪ algonacci-unlock-pdf 99% verified
  • ▪ wowuz-mcppdf 100% verified
  • ▪ risha-max-0xpdf-mcp 70% verified
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
Works with Claude Code, Cursor, Continue, Windsurf, or any MCP client. Full setup guide → REST docs →

The score is not a vibe

Every deeply-scanned skill decomposes into six measurable dimensions from 27 analyzer passes. A skill can score 96 overall and still get blocked — because one axis dips where it matters.

Security Supply chain Code quality Reliability Compliance Provenance

Every skill carries a trust score, but they are not all the same claim: an unscanned skill is scored from source provenance alone, while these 27 are taken to full six-axis depth. Scan coverage is stated on every listing so you can tell them apart, and the deep-scan backfill widens the analysed set continuously. Full breakdown via API →

92,428 published skills, placed by trust

Every point is a published skill. Most land at the baseline every source starts from — the trustworthy few earn their place on the right, where scans come back clean and signatures check out.

← lower trust verified · higher trust →

What the catalog is made of · by category

ai-ml
17,127
search
9,466
database
8,218
finance
6,858
media
6,503
file-system
4,595
api-integration
4,255
cloud-infra
4,216
browser-automation
3,956
communication
3,941

Category & domain derived from each skill's name and description. Filter the full catalog by them on browse.

Find skills by task

Click a category to explore top-ranked skills for that task.

Static analysis, formatting, and lint enforcement.

100%
GitHub Code Review Assistant

Use this tool when you need to streamline code review workflows and enforce coding standards across teams. It analyzes pull requests, checks code patterns, and ensures consistency with team standards, providing automated code analysis, security checks, and suggestions for improvements. The tool accepts GitHub repository data as input and outputs detailed code review information, including files, diffs, and compliance validation results.

sanjanaspanda-github-code-review
95%
Review MCP Server

Use this tool when you need to perform thorough code reviews and receive senior-level feedback on code quality, security, and performance. It integrates with Codex and Gemini CLIs to analyze code snippets, files, or directories, providing automated feedback on best practices. Ideal for developers seeking to improve code quality and security, it supports various review tools and provides detailed output for refinement.

je4550-review-mcp
100%
FastMCP Style Enforcer

Use this tool when you need to enforce consistent coding standards and styles in your projects, particularly for Flutter and Dart development. It reviews code and provides suggestions for improvement, helping to solve problems related to code readability and maintainability. The tool takes in code files as input and outputs style improvement suggestions, making it a valuable asset for development teams seeking to streamline their coding processes.

chinggu88-flutter-mcp
69%
code-quality-mcp

Use this tool when you need to analyze Python code quality and enforce coding standards, solving problems such as detecting syntax errors, type inconsistencies, and complex code structures. It takes in Python code as input and outputs detailed reports on linting and type checking results, using tools like flake8 and mypy. Utilize it in development contexts where maintaining high-quality, readable, and reliable code is crucial.

javier-morenosa-code-quality-mcp
70%
io.github.noahgift/ruchy-mcp

Use this tool when you need to analyze and refine code quality through automated scoring, linting, formatting, and transpilation. It solves problems related to code consistency, readability, and compatibility, providing outputs such as scored code quality and formatted code. Ideal for use in development environments where code review and optimization are crucial.

io-github-noahgift-ruchy-mcp

Crawl pages and extract structured data from the web.

93%
Silkworm

Use this tool when you need to build and manage web scrapers with advanced features like async crawling and structured data extraction. It solves problems of extracting specific data from websites, handling complex HTML structures, and scaling crawling tasks. The Silkworm server takes in website URLs and CSS/XPath selectors as input and outputs extracted, structured data.

bitingsnakes-silkworm
100%
scrapling

scrapling — zendenho7-scrapling. Use this tool when you need to extract data from websites that employ anti-bot measures, as it provides an adaptive web scraping framework with anti-bot bypass and spider crawling capabilities, accepting website URLs as input and outputting extracted data in a usable format, ideal for data mining and web data integration tasks. It solves problems related to accessing restricted web content and handles various website structures and anti-scraping protections. Use scrapling to automate data extraction from complex websites with ease.

zendenho7-scrapling
100%
playwright-scraper-skill-1-2-0

playwright-scraper-skill-1-2-0 — itsjustfred-playwright-scraper-skill-1-2-0. Use this tool when you need to extract data from websites with anti-bot protection, as it provides a Playwright-based web scraping solution to bypass these barriers. It solves problems related to data extraction from websites that block traditional scraping methods, offering a reliable way to fetch data. With input parameters for target URLs and outputting scraped data, it's ideal for use cases requiring automated data collection from protected websites.

itsjustfred-playwright-scraper-skill-1-2-0
87%
crawl4ai-mcp-server

Use this tool when you need to leverage web scraping and crawling capabilities for AI agents, enabling efficient data extraction from single or multi-page websites with adaptive stopping. It solves problems related to data collection, information extraction, and web content analysis by providing a lightweight server that exposes these capabilities as tools. The server takes in website URLs and scraping parameters as inputs and outputs extracted data in a usable format.

sadiuysal-crawl4ai-mcp-server
86%
scraperapi-mcp

Use this tool when you need to retrieve and process web scraping requests efficiently, solving problems of data extraction and handling anti-scraping measures. It takes in web scraping requests as input and outputs the extracted data, providing a seamless interface for Large Language Models (LLMs). Ideal for use cases requiring automated data collection from websites, leveraging ScraperAPI's capabilities.

scraperapi-scraperapi-mcp

Query, migrate, and inspect SQL and NoSQL stores.

99%
Database JDBC

Use this tool when you need to connect to multiple databases and perform SQL operations, such as executing queries, managing tables, and performing CRUD operations. It solves problems related to database integration, querying, and management, supporting various databases including MySQL, PostgreSQL, and Oracle. It takes database connections and SQL queries as inputs and provides query results and database schema information as outputs.

kjstart-database-jdbc
85%
MCP Database Server

Use this tool when you need to interact with various databases, such as SQLite, SQL Server, PostgreSQL, and MySQL, to execute queries, manage tables, and export data. It provides a direct interface for database operations through the Model Context Protocol, allowing for seamless data management and analysis. Ideal for use cases requiring database querying, data extraction, and table administration.

shailesh5050-mcp-database-server
60%
mcp-server-database

Use this tool when you need to interact with relational databases, such as PostgreSQL, MySQL, or SQLite, to execute SQL queries, inspect database schemas, or run migrations. It provides a comprehensive interface for database management, accepting SQL queries and schema definitions as inputs and producing query results and migration reports as outputs. Ideal for use cases requiring database setup, data analysis, or schema updates, this tool streamlines database operations and simplifies data management tasks.

citadel-cloud-management-mcp-server-database
70%
db-legacy-migration-agent

db-legacy-migration-agent — felipeassis10-db-legacy-migration-agent. Use this tool when you need to migrate legacy relational databases to PostgreSQL, as it parses schemas from Oracle, DB2, MySQL, and MSSQL, and generates Prisma schemas and TypeScript query helpers. It solves database compatibility issues and simplifies migration processes. Ideal for use cases involving database modernization, consolidation, or cloud migration, where a seamless transition from legacy systems to PostgreSQL is required.

felipeassis10-db-legacy-migration-agent
89%
SQL MCP Server

Use this tool when you need to integrate AI models with various database management systems, as it provides a unified interface for querying, schema inspection, and connection management across MySQL, MSSQL, Oracle, and Sybase databases. It solves the problem of requiring separate server configurations for each database type, streamlining data access and manipulation. This tool is ideal for use cases involving multi-database interactions, data migration, or federated queries.

bryr0-sql-mcp

Read, transform, and extract content from PDFs and docs.

100%
PDF MCP Server

Use this tool when you need to extract content from PDF files with precise layout and LaTeX recognition, solving problems of inaccessible or unstructured data in large documents. It takes PDF files as input and outputs extracted content, utilizing a Python-based engine with a Node.js fallback for robust processing. Ideal for use cases requiring efficient and accurate text extraction from complex PDFs.

wowuz-mcppdf
99%
PDF Reader

Use this tool when you need to extract content from PDF files, whether protected or unprotected, to analyze documents, index content, or extract data. It provides functionality to read and parse PDFs, handle password-protected documents, and format extracted content. Ideal for workflows requiring PDF parsing and text extraction, such as document analysis or data extraction from PDF sources.

algonacci-unlock-pdf
100%
pdf-mcp

Use this tool when you need to extract insights from PDF files, such as text, tables, and diagrams, and require a server-based solution for large-scale document processing. The pdf-mcp tool solves problems related to PDF parsing, indexing, and rendering, accepting PDF files as input and outputting extracted text, tables, and images. It is particularly useful in contexts where large language models (LLMs) need to analyze and understand complex PDF documents.

i-can-hack-pdf-mcp
97%
PDFtotext MCP Server

Use this tool when you need to extract text from PDF documents, solving problems such as data mining, document analysis, and text processing. It takes PDF files as input and outputs extracted text, providing a compatible interface with any Model Context Protocol (MCP) client. Ideal for use cases requiring accurate text extraction from PDFs, such as information retrieval and document indexing.

jpwebb-pdftotext-mcp
95%
mcp-scientific-rag

Use this tool when you need to extract structured data from technical PDFs, such as tables, formulas, and references, to automate document processing and knowledge retrieval. It takes PDF files as input and outputs extracted data in a machine-readable format, leveraging PyMuPDF4LLM and Ollama for high-performance processing. Ideal for use cases involving scientific literature analysis, research automation, and document indexing.

davinson-pezo-mcp-scientific-rag

GitHub workflow tools — PR review, branch and commit operations.

100%
GitHub Code Review Assistant

Use this tool when you need to streamline code review workflows and enforce coding standards across teams. It analyzes pull requests, checks code patterns, and ensures consistency with team standards, providing automated code analysis, security checks, and suggestions for improvements. The tool accepts GitHub repository data as input and outputs detailed code review information, including files, diffs, and compliance validation results.

sanjanaspanda-github-code-review
70%
GitHub PR Analyzer MCP Server

GitHub PR Analyzer MCP Server — punyprogrammer-pr-analyzer-mcp-server. Use this tool when you need to streamline GitHub pull request review processes and centralize feedback. It fetches GitHub pull request details and saves reviews to Notion, solving problems related to code review management and team collaboration. Ideal for development teams seeking to automate and organize their GitHub PR workflows, this tool takes GitHub pull request data as input and outputs saved reviews in Notion.

punyprogrammer-pr-analyzer-mcp-server
100%
GitHub PR MCP Server

Use this tool when you need to analyze GitHub Pull Requests in a structured and maintainable way. It solves problems related to code review and integration by providing a robust framework for evaluating PRs. The server takes GitHub PR data as input and outputs analyzed results, making it ideal for use cases involving automated code review and testing.

gourav221b-github-pr-mcp-server
99%
CodeRabbit MCP Server

Use this tool when you need to automate code review processes on GitHub, enabling large language models (LLMs) to analyze and implement suggestions on pull requests. It solves problems of manual code review and resolution by providing automated workflows for processing and resolving review comments. The tool accepts GitHub pull requests as input and outputs programmatically implemented code review suggestions, streamlining developer workflows and improving code quality.

bradthebeeble-coderabbitai-mcp

Vuln scanning, secret detection, and policy checks.

92%
secrets-scan

Use this tool when you need to identify exposed secrets in your codebase, such as API keys, tokens, and passwords, to prevent security breaches. The secrets-scan tool scans a specified directory or file, using regex and entropy heuristics to detect hardcoded credentials. It accepts inputs like target path, minimum entropy threshold, and exclude patterns, and outputs a list of potential secrets found, making it ideal for pre-production security checks.

secrets-scan
100%
expanso-secrets-scan

expanso-secrets-scan — aronchick-expanso-secrets-scan. Use this tool when you need to detect and identify hardcoded secrets such as API keys, tokens, and passwords in text or code, helping to prevent security breaches and data exposure. It solves problems related to insecure coding practices and sensitive data leakage by scanning for potential vulnerabilities. The tool takes in text or code as input and outputs a list of detected secrets, making it ideal for use in secure coding and compliance contexts.

aronchick-expanso-secrets-scan
@cognium
100%
@cognium/secrets-scan

Use this tool when you need to identify hardcoded secrets in a repository, solving security risks and compliance issues by detecting sensitive information. It scans a checked-out repo using gitleaks and returns structured findings, providing a clear interface for inputting repository data and outputting potential security threats. Ideal for use cases requiring secret detection and security auditing in development environments.

cognium-secrets-scan
100%
nirwan-secret-scanner

nirwan-secret-scanner — nirwandogra-nirwan-secret-scanner. Use this tool when you need to detect and prevent sensitive information leaks in your codebase, such as API keys, tokens, and passwords. It scans files, repositories, and directories to identify exposed secrets, helping to mitigate security risks and data breaches. Ideal for use in development, testing, and deployment pipelines to ensure secure coding practices.

nirwandogra-nirwan-secret-scanner
100%
ggshield-scanner

ggshield-scanner — amascia-gg-ggshield-scanner. Use this tool when you need to detect and protect sensitive information in your codebase, such as hardcoded secrets and credentials. The ggshield-scanner identifies over 500 types of secrets, solving problems related to security and data breaches. It takes in code files as input and outputs a list of detected secrets, making it an essential tool for securing your projects and preventing unauthorized access.

amascia-gg-ggshield-scanner

Ranked by semantic similarity, then by Cognium trust.

Get started

Start free in minutes, or set up a governed private registry for your organization.

Use the free public API

Point your agents at api.skillsregistry.net — MCP + REST, no auth, no signup. Search 100,000+ trust-scored skills today.

Read the API docs

Self-host it

Run the whole registry on-prem or air-gapped — same code, same endpoints. Nothing leaves your network.

git clone https://github.com/cogniumhq/skillsregistry && cd skillsregistry/apps/local && docker compose up -d
Self-host guide
Enterprise

Get a private registry

A tenant-scoped catalog with trust policies, allow/block lists, version pinning, private skills, and SSO — hosted, self-hosted, or air-gapped. We'll help you roll it out.

Book a demo

Frequently asked questions

What SkillsRegistry is, how it works, and how to use it.

What is SkillsRegistry?

The trust and governance layer for the tools AI agents use. It indexes 100,000+ agent skills from public registries, including the official MCP Registry, and from GitHub, security-scans and trust-scores each one via Cognium, and lets you discover, vet, and govern which tools your agents can use — including a private registry for your own organization.

How do I give enterprise AI agents safe, governed access to tools?

Point your agents at SkillsRegistry (MCP or REST) instead of letting them pull tools directly from public marketplaces. Skills we have analysed carry a security scan and a trust score, and every listing states its scan coverage so you can tell an analysed skill from an unexamined one. Set a trust floor (e.g. "A-tier only") plus allow/block lists so agents can only use vetted tools, and run a private registry for your internal skills. You get signed provenance and an audit trail of what ran, which version, and from where.

Can I run a private or internal MCP registry?

Yes. Run a tenant-scoped private registry — your internal skills alongside curated public ones, under policies you control (trust floor, allow/block lists, version pinning). Deploy it as a private overlay on the hosted service, or self-host the whole registry via Docker on-prem or air-gapped so nothing leaves your network. Book a demo at hello@cognium.net.

How do I deploy it — hosted, self-run, or private overlay?

Three modes, pick any combination (see "Get started" and "Private registry" above). (1) HOSTED: api.skillsregistry.net is the free public catalog — no auth, MCP + REST. (2) SELF-RUN: one docker command runs the whole registry locally — same code, same endpoints — for on-prem or air-gapped. (3) PRIVATE OVERLAY: a tenant-scoped catalog with your internal skills, trust policies, version pins, and allow/block lists, queryable alongside the public catalog. The runnable local node is open source at cogniumhq/skillsregistry (Apache-2.0).

How is it different from MCP Registry or ClawHub?

Those registries list skills but rely on keyword matching and don't score for security. SkillsRegistry adds semantic search, multi-dimensional trust scoring, confidence signals, and private tenant overlays. One search across all sources, with provenance preserved.

What is a trust score?

Deeply-scanned skills are scored 0-100 across six dimensions — security, supply chain, quality, reliability, compliance, and provenance — grouped from Cognium's analyzer passes, plus an overall verdict tier (verified, passing, advisory, failing, blocked). Human and agent signals are tracked separately, so bot invocations can't pollute human rankings. Full per-dimension breakdown via API wherever a deep scan exists; the breakdown is null for shallow-scanned skills, which is most of the catalog.

How do I connect my agent?

Hosted: claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp — works with Claude Code, Cursor, Continue, Windsurf, or any MCP client. Five tools: search_skills, get_skill, list_leaderboard, get_trust_breakdown, resolve_composition. No auth required, REST also available. Self-run: point the same clients at http://localhost:3000/mcp after the Docker container is up.

Search SkillsRegistry