Live index · 8 sources

One endpoint.
Every agent skill.

Connect any MCP client to SkillsRegistry and your agent can search 142,490 skills and MCP servers by what they do — and get back the endpoint or repository it needs to actually use one. Trust score and scan coverage on every result. No key, no signup.

claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp

Any MCP client — Claude Code, Cursor, Continue, Windsurf. Streamable HTTP at https://api.skillsregistry.net/mcp. Setup for other clients →

142,490 skills indexed
114,185 security-scanned
A–F trust tiers

Where listings come from

Listings are indexed from public registries, including the official MCP Registry, and from GitHub. Every skill page links to its source listing and its code repository.

The problem

Your agents are only as safe as the tools they call

Enterprise AI agents autonomously reach for third-party skills — MCP servers, tools, scripts — at runtime. Most are unsigned, unscanned, and unowned. One skill that reads credentials it never declared, or writes to files it shouldn't, is a production incident, a data-exfil path, or a compliance finding waiting to happen.

Unvetted supply chain

Skills pulled from public marketplaces carry prompt-injection, credential-harvest, and command-injection risk. No one scored them before your agent ran them.

No control plane

Which tools can your agents use? At what trust level? From which sources? Without a registry, the answer is "whatever they find."

No provenance or audit

When something goes wrong, you need to know what ran, which version, from where, and whether it was signed. Marketplaces don't keep receipts.

SkillsRegistry is the control plane in between: one governed catalog with scan coverage stated per listing and first-party skills signed — and where you set the rules your agents follow.

Built to trust every tool your agents use

Every skill is semantically indexed. Skills we have analysed are security-scanned, and each listing states its scan coverage.

Semantic Search

Agents describe the job in natural language; the right tool surfaces ranked by confidence — not keyword luck. One query across every source.

Multi-dimensional Trust

Analysed skills scored 0-100 on security, supply chain, quality, reliability, compliance, and provenance — one verdict tier your policies can gate on. Human and agent signals kept separate.

Version control you own

The most reliable version surfaces first (trust-weighted), or pin the exact one you've certified. No surprise upgrades reaching production agents.

Provenance & lineage

Complex jobs decompose into multi-skill workflows, with lineage preserved back to every upstream source — a complete audit trail of what ran and from where.

For enterprise

Run your own private registry

A tenant-scoped catalog for your organization — your internal skills alongside the curated public ones, under policies you control. Hosted overlay, self-hosted, or fully air-gapped.

Enforce a trust floor

Set the minimum verdict tier ("A-tier only") and agents simply can't resolve anything below it. Allow / block lists per source, publisher, or skill.

Your private skills

Publish internal skills scoped to your tenant through the same signed handler. They never leave your catalog, and rank on their own trust.

Pin the versions you trust

Freeze exact versions and control upgrades, or let the most reliable version auto-surface. No surprise changes reaching production agents.

One search, public + private

Query your private catalog, the public catalog, or both in a single call. Same MCP + REST surface your agents already use.

Signed & auditable

First-party skills are Ed25519-signed; crawled listings carry source provenance and lineage. A complete audit trail of what ran, which version, and from where.

Deploy your way

A private overlay on the hosted service, or docker run the whole registry on-prem / air-gapped. Same code, same endpoints, nothing leaves your network.

This is what your agent sees

Real MCP calls, real responses — no mocking. Captured on this page build. Streams on load so you can watch it land.

agent — mcp session — api.skillsregistry.net/mcp live · ⌘K for your own query
▸ POST /mcp {"method":"tools/list"}
→ 7 tools · 228ms
  • ▪ search_skills
  • ▪ get_skill
  • ▪ list_leaderboard
  • ▪ get_trust_breakdown
  • ▪ resolve_composition
  • ▪ search
  • ▪ fetch
▸ POST /mcp {"tool":"search_skills", "query":"pdf parsing", "limit":3}
→ 3 results · confidence high · 3859ms
  • ▪ algonacci-unlock-pdf 99% verified
  • ▪ pspdfkit-nutrient-pdf-mcp-server 90% verified
  • ▪ lisabrennan1996-liteparse-mcp 94% verified
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
Works with Claude Code, Cursor, Continue, Windsurf, or any MCP client. Full setup guide → REST docs →

The score is not a vibe

Every deeply-scanned skill decomposes into six measurable dimensions from 27 analyzer passes. A skill can score 96 overall and still get blocked — because one axis dips where it matters.

Security Supply chain Code quality Reliability Compliance Provenance

Every skill carries a trust score, but they are not all the same claim: an unscanned skill is scored from source provenance alone, while these 27 are taken to full six-axis depth. Scan coverage is stated on every listing so you can tell them apart, and the deep-scan backfill widens the analysed set continuously. Full breakdown via API →

109,671 published skills, placed by trust

Every point is a published skill. Most land at the baseline every source starts from — the trustworthy few earn their place on the right, where scans come back clean and signatures check out.

← lower trust verified · higher trust →

What the catalog is made of · by category

ai-ml
17,127
search
9,466
database
8,218
finance
6,858
media
6,503
file-system
4,595
api-integration
4,255
cloud-infra
4,216
browser-automation
3,956
communication
3,941

Category & domain derived from each skill's name and description. Filter the full catalog by them on browse.

Find skills by task

Click a category to explore top-ranked skills for that task.

Static analysis, formatting, and lint enforcement.

pulsemcp
100%
GitHub Code Review Assistant

Use this tool when you need to streamline code review workflows and enforce coding standards across teams. It analyzes pull requests, checks code patterns, and ensures consistency with team standards, providing automated code analysis, security checks, and suggestions for improvements. The tool accepts GitHub repository data as input and outputs detailed code review information, including files, diffs, and compliance validation results.

sanjanaspanda-github-code-review
glama
94%
code-quality-mcp

Use this tool when you need to analyze Python code quality and enforce coding standards, solving problems such as detecting syntax errors, type inconsistencies, and complex code structures. It takes in Python code as input and outputs detailed reports on linting and type checking results, using tools like flake8 and mypy. Utilize it in development contexts where maintaining high-quality, readable, and reliable code is crucial.

javier-morenosa-code-quality-mcp
pulsemcp
88%
MegaLinter

Use this tool when you need to analyze code quality, formatting, and security issues across multiple programming languages and formats. It solves problems related to code maintenance, security vulnerabilities, and consistency by providing comprehensive linting and analysis. The MegaLinter tool takes in code files as input and outputs detailed reports on code quality, formatting, and security issues, making it ideal for use in development workflows and continuous integration pipelines.

gh-downatthebottomofthemolehole-megalinter
pulsemcp
88%
Checkstyle

Use this tool when you need to automate code quality checks and fixes across multiple programming languages, including Go, Java, and Lua, with support for local IDE integration and remote access. It solves problems related to code consistency, formatting, and best practices, providing a standardized way to lint and format code. The tool accepts code files as input and outputs formatted code with diagnostics and audit logs, making it ideal for development teams seeking to improve code quality and collaboration.

liuhua1307-checkstyle
glama
100%
mcp-lint-tools

Use this tool when you need to enforce coding standards and best practices in your AI agent's codebase, solving problems such as inconsistent styling, complex code, and dead code. It takes in code files as input and outputs reports on style violations, complexity issues, and other code quality metrics. Ideal for use in development and testing contexts to ensure maintainable and efficient code.

rog0x-mcp-lint-tools

Crawl pages and extract structured data from the web.

pulsemcp
100%
Web Browser

Use this tool when you need to interact with web content programmatically, extract specific data, or automate web-based tasks. It provides a robust interface for web scraping, content extraction, and navigation, integrating with popular Python libraries to simplify HTTP requests and HTML parsing. Ideal for applications requiring real-time web data, such as research assistants, content aggregators, or dynamic information retrieval systems.

blazickjp-web-browser
glama
99%
ScrapingDog MCP Server

Use this tool when you need to extract data from websites, search engines, or social media platforms, and require a comprehensive web scraping solution. The ScrapingDog MCP Server provides a robust interface for inputting scraping requests and outputs structured data for further analysis. Ideal for use cases involving e-commerce data collection, market research, and data mining, where large-scale web data extraction is necessary.

nvrunx-scrapingdog-mcp-server
github
99%
mcp-scrapingant

mcp-scrapingant — pipeworx-io-mcp-scrapingant. Use this tool when you need to extract data from websites, as it provides a simple interface to the ScrapingAnt web scraping API, accepting URLs and parameters as input and returning scraped data as output, ideal for automating data collection tasks in various contexts, such as market research or data analysis. It solves problems like handling anti-scraping measures and rotating proxies, making it a reliable solution for web data extraction. By integrating with git, it enables version control and collaboration for web scraping projects.

pipeworx-io-mcp-scrapingant
pulsemcp
93%
Silkworm

Use this tool when you need to build and manage web scrapers with advanced features like async crawling and structured data extraction. It solves problems of extracting specific data from websites, handling complex HTML structures, and scaling crawling tasks. The Silkworm server takes in website URLs and CSS/XPath selectors as input and outputs extracted, structured data.

bitingsnakes-silkworm
glama
98%
scrapling-mcp

Use this tool when you need to extract data from websites using CSS or XPath selectors, and require features like stealth mode and batch processing for efficient web scraping. It solves problems of data extraction from complex websites, handling anti-scraping measures, and processing large volumes of URLs. The tool takes URLs and selector inputs, and outputs extracted data, making it ideal for use cases involving automated data collection and monitoring.

goodmartins-scrapling-mcp

Query, migrate, and inspect SQL and NoSQL stores.

github
100%
genpark-database-migration-sql-optimizer-skill

genpark-database-migration-sql-optimizer-skill — alphaparkinc-genpark-database-migration-sql-optimizer-skill. Use this tool when you need to optimize SQL queries and migrate database schemas efficiently. It solves problems related to slow query performance and complex schema migrations, providing a streamlined interface for inputting SQL code and outputting optimized queries. Ideal for use in development environments with git version control, where database performance and schema consistency are crucial.

alphaparkinc-genpark-database-migration-sql-optimizer-skill
glama
97%
mcp-server-database

Use this tool when you need to interact with relational databases, such as PostgreSQL, MySQL, or SQLite, to execute SQL queries, inspect database schemas, or run migrations. It provides a comprehensive interface for database management, accepting SQL queries and schema definitions as inputs and producing query results and migration reports as outputs. Ideal for use cases requiring database setup, data analysis, or schema updates, this tool streamlines database operations and simplifies data management tasks.

citadel-cloud-management-mcp-server-database
glama
96%
db-legacy-migration-agent

db-legacy-migration-agent — felipeassis10-db-legacy-migration-agent. Use this tool when you need to migrate legacy relational databases to PostgreSQL, as it parses schemas from Oracle, DB2, MySQL, and MSSQL, and generates Prisma schemas and TypeScript query helpers. It solves database compatibility issues and simplifies migration processes. Ideal for use cases involving database modernization, consolidation, or cloud migration, where a seamless transition from legacy systems to PostgreSQL is required.

felipeassis10-db-legacy-migration-agent
github
100%
Migrating-Databases-Using-ORMCP

Migrating-Databases-Using-ORMCP — astronaut012-migrating-databases-using-ormcp. Use this tool when you need to migrate databases from one system to another, such as from Oracle to PostgreSQL, and require a streamlined process for transferring data. It solves problems related to data compatibility and transfer, providing a seamless transition for systems like flight management. The tool takes database credentials and schema as input and outputs a migrated database, utilizing ORMCP and AI agents for efficient data transfer.

astronaut012-migrating-databases-using-ormcp
glama
87%
MigratorXpress MCP Server

Use this tool when you need to migrate databases between different systems, such as Oracle, PostgreSQL, or SQL Server, to streamline data transfer and minimize manual errors. It solves problems of data incompatibility and transfer complexity by providing AI-assisted command preview, execution, and validation. The tool takes database schema and data as inputs and outputs migrated databases, making it ideal for use cases involving heterogeneous system integration and data consolidation.

arpe-io-migratorxpress-mcp

Read, transform, and extract content from PDFs and docs.

glama
95%
PDF Reader MCP Server

Use this tool when you need to process and analyze PDF documents, as it provides comprehensive capabilities such as text extraction, image extraction, and metadata retrieval. It solves problems related to document parsing, data extraction, and content analysis, making it ideal for use cases like document indexing, data mining, and content management. The tool accepts PDF files as input and outputs extracted data, images, and metadata, making it a versatile solution for various applications.

averagejoeslab-pdf-reader-mcp
glama
100%
PDF MCP Server

Use this tool when you need to extract content from PDF files with precise layout and LaTeX recognition, solving problems of inaccessible or unstructured data in large documents. It takes PDF files as input and outputs extracted content, utilizing a Python-based engine with a Node.js fallback for robust processing. Ideal for use cases requiring efficient and accurate text extraction from complex PDFs.

wowuz-mcppdf
pulsemcp
99%
PDF Reader

Use this tool when you need to extract content from PDF files, whether protected or unprotected, to analyze documents, index content, or extract data. It provides functionality to read and parse PDFs, handle password-protected documents, and format extracted content. Ideal for workflows requiring PDF parsing and text extraction, such as document analysis or data extraction from PDF sources.

algonacci-unlock-pdf
glama
96%
pdfplumber MCP Server

Use this tool when you need to extract structured data from PDF documents, such as tables, text, and metadata, to enable further analysis or processing. It solves problems of manual data entry and information retrieval from PDFs, providing outputs in a machine-readable format. Ideal for use cases where PDF data needs to be integrated into workflows, databases, or machine learning models.

nasxub-pdfplumber-mcp-server
glama
94%
liteparse-mcp

Use this tool when you need to extract text and visual information from PDFs locally and quickly, without relying on cloud services or API keys. It solves problems such as text extraction, object detection, and citation analysis, providing outputs like text, bounding boxes, and OCR results. Ideal for use cases requiring fast, self-contained PDF parsing, such as research, document analysis, and data extraction.

lisabrennan1996-liteparse-mcp

GitHub workflow tools — PR review, branch and commit operations.

glama
97%
GitHub PR Analyzer MCP Server

GitHub PR Analyzer MCP Server — punyprogrammer-pr-analyzer-mcp-server. Use this tool when you need to streamline GitHub pull request review processes and centralize feedback. It fetches GitHub pull request details and saves reviews to Notion, solving problems related to code review management and team collaboration. Ideal for development teams seeking to automate and organize their GitHub PR workflows, this tool takes GitHub pull request data as input and outputs saved reviews in Notion.

punyprogrammer-pr-analyzer-mcp-server
glama
97%
github-pr-reviewer

github-pr-reviewer — badarrasheed-github-pr-reviewer. Use this tool when you need to streamline GitHub pull request reviews and ensure code quality. It fetches pull request changes, reviews code for bugs and security issues, and saves approved reviews to Notion, automating the review process and reducing manual effort. Ideal for development teams seeking to improve code reliability and collaboration efficiency.

badarrasheed-github-pr-reviewer
github
99%
gh-self-reviewer

gh-self-reviewer — alesr-gh-self-reviewer. Use this tool when you need to streamline your GitHub workflow by automating the review of pull requests. The gh-self-reviewer tool solves the problem of manual review by providing a seamless way to self-review GitHub pull requests, taking Git repositories as input and outputting reviewed pull requests. It is ideal for use in MCP server environments where efficient code review is crucial.

alesr-gh-self-reviewer
glama
96%
gemini-pr-reviews

Use this tool when you need to streamline the review process of Gemini Code Assist reviews from GitHub pull requests. It solves the problem of manually fetching and analyzing reviews by providing smart defaults and pagination, making it easier to manage and track feedback. The tool takes GitHub pull request data as input and outputs analyzed review data, ideal for use in development workflows and code quality assurance.

mytsx-mcp-gemini-pr-reviews
glama
99%
CodeRabbit MCP Server

Use this tool when you need to automate code review processes on GitHub, enabling large language models (LLMs) to analyze and implement suggestions on pull requests. It solves problems of manual code review and resolution by providing automated workflows for processing and resolving review comments. The tool accepts GitHub pull requests as input and outputs programmatically implemented code review suggestions, streamlining developer workflows and improving code quality.

bradthebeeble-coderabbitai-mcp

Vuln scanning, secret detection, and policy checks.

manual
92%
secrets-scan

Use this tool when you need to identify exposed secrets in your codebase, such as API keys, tokens, and passwords, to prevent security breaches. The secrets-scan tool scans a specified directory or file, using regex and entropy heuristics to detect hardcoded credentials. It accepts inputs like target path, minimum entropy threshold, and exclude patterns, and outputs a list of potential secrets found, making it ideal for pre-production security checks.

secrets-scan
clawhub
100%
expanso-secrets-scan

expanso-secrets-scan — aronchick-expanso-secrets-scan. Use this tool when you need to detect and identify hardcoded secrets such as API keys, tokens, and passwords in text or code, helping to prevent security breaches and data exposure. It solves problems related to insecure coding practices and sensitive data leakage by scanning for potential vulnerabilities. The tool takes in text or code as input and outputs a list of detected secrets, making it ideal for use in secure coding and compliance contexts.

aronchick-expanso-secrets-scan
@cognium
100%
@cognium/secrets-scan

Use this tool when you need to identify hardcoded secrets in a repository, solving security risks and compliance issues by detecting sensitive information. It scans a checked-out repo using gitleaks and returns structured findings, providing a clear interface for inputting repository data and outputting potential security threats. Ideal for use cases requiring secret detection and security auditing in development environments.

cognium-secrets-scan
clawhub
100%
nirwan-secret-scanner

nirwan-secret-scanner — nirwandogra-nirwan-secret-scanner. Use this tool when you need to detect and prevent sensitive information leaks in your codebase, such as API keys, tokens, and passwords. It scans files, repositories, and directories to identify exposed secrets, helping to mitigate security risks and data breaches. Ideal for use in development, testing, and deployment pipelines to ensure secure coding practices.

nirwandogra-nirwan-secret-scanner
clawhub
100%
ggshield-scanner

ggshield-scanner — amascia-gg-ggshield-scanner. Use this tool when you need to detect and protect sensitive information in your codebase, such as hardcoded secrets and credentials. The ggshield-scanner identifies over 500 types of secrets, solving problems related to security and data breaches. It takes in code files as input and outputs a list of detected secrets, making it an essential tool for securing your projects and preventing unauthorized access.

amascia-gg-ggshield-scanner

Ranked by semantic similarity, then by Cognium trust.

Get started

Start free in minutes, or set up a governed private registry for your organization.

Use the free public API

Point your agents at api.skillsregistry.net — MCP + REST, no auth, no signup. Search 100,000+ trust-scored skills today.

Read the API docs

Self-host it

Run the whole registry on-prem or air-gapped — same code, same endpoints. Nothing leaves your network.

git clone https://github.com/cogniumhq/skillsregistry && cd skillsregistry/apps/local && docker compose up -d
Self-host guide
Enterprise

Get a private registry

A tenant-scoped catalog with trust policies, allow/block lists, version pinning, private skills, and SSO — hosted, self-hosted, or air-gapped. We'll help you roll it out.

Book a demo

Frequently asked questions

What SkillsRegistry is, how it works, and how to use it.

What is SkillsRegistry?

The trust and governance layer for the tools AI agents use. It indexes 100,000+ agent skills from public registries, including the official MCP Registry, and from GitHub, security-scans and trust-scores each one via Cognium, and lets you discover, vet, and govern which tools your agents can use — including a private registry for your own organization.

How do I give enterprise AI agents safe, governed access to tools?

Point your agents at SkillsRegistry (MCP or REST) instead of letting them pull tools directly from public marketplaces. Skills we have analysed carry a security scan and a trust score, and every listing states its scan coverage so you can tell an analysed skill from an unexamined one. Set a trust floor (e.g. "A-tier only") plus allow/block lists so agents can only use vetted tools, and run a private registry for your internal skills. You get signed provenance and an audit trail of what ran, which version, and from where.

Can I run a private or internal MCP registry?

Yes. Run a tenant-scoped private registry — your internal skills alongside curated public ones, under policies you control (trust floor, allow/block lists, version pinning). Deploy it as a private overlay on the hosted service, or self-host the whole registry via Docker on-prem or air-gapped so nothing leaves your network. Book a demo at hello@cognium.net.

How do I deploy it — hosted, self-run, or private overlay?

Three modes, pick any combination (see "Get started" and "Private registry" above). (1) HOSTED: api.skillsregistry.net is the free public catalog — no auth, MCP + REST. (2) SELF-RUN: one docker command runs the whole registry locally — same code, same endpoints — for on-prem or air-gapped. (3) PRIVATE OVERLAY: a tenant-scoped catalog with your internal skills, trust policies, version pins, and allow/block lists, queryable alongside the public catalog. The runnable local node is open source at cogniumhq/skillsregistry (Apache-2.0).

How is it different from MCP Registry or ClawHub?

Those registries list skills but rely on keyword matching and don't score for security. SkillsRegistry adds semantic search, multi-dimensional trust scoring, confidence signals, and private tenant overlays. One search across all sources, with provenance preserved.

What is a trust score?

Deeply-scanned skills are scored 0-100 across six dimensions — security, supply chain, quality, reliability, compliance, and provenance — grouped from Cognium's analyzer passes, plus an overall verdict tier (verified, passing, advisory, failing, blocked). Human and agent signals are tracked separately, so bot invocations can't pollute human rankings. Full per-dimension breakdown via API wherever a deep scan exists; the breakdown is null for shallow-scanned skills, which is most of the catalog.

How do I connect my agent?

Hosted: claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp — works with Claude Code, Cursor, Continue, Windsurf, or any MCP client. Five tools: search_skills, get_skill, list_leaderboard, get_trust_breakdown, resolve_composition. No auth required, REST also available. Self-run: point the same clients at http://localhost:3000/mcp after the Docker container is up.

Search SkillsRegistry