One endpoint.
Every agent skill.
Connect any MCP client to SkillsRegistry and your agent can search 142,490 skills and MCP servers by what they do — and get back the endpoint or repository it needs to actually use one. Trust score and scan coverage on every result. No key, no signup.
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
Any MCP client — Claude Code, Cursor, Continue, Windsurf. Streamable HTTP at
https://api.skillsregistry.net/mcp.
Setup for other clients →
Where listings come from
Listings are indexed from public registries, including the official MCP Registry, and from GitHub. Every skill page links to its source listing and its code repository.
The problem
Your agents are only as safe as the tools they call
Enterprise AI agents autonomously reach for third-party skills — MCP servers, tools, scripts — at runtime. Most are unsigned, unscanned, and unowned. One skill that reads credentials it never declared, or writes to files it shouldn't, is a production incident, a data-exfil path, or a compliance finding waiting to happen.
Unvetted supply chain
Skills pulled from public marketplaces carry prompt-injection, credential-harvest, and command-injection risk. No one scored them before your agent ran them.
No control plane
Which tools can your agents use? At what trust level? From which sources? Without a registry, the answer is "whatever they find."
No provenance or audit
When something goes wrong, you need to know what ran, which version, from where, and whether it was signed. Marketplaces don't keep receipts.
SkillsRegistry is the control plane in between: one governed catalog with scan coverage stated per listing and first-party skills signed — and where you set the rules your agents follow.
Built to trust every tool your agents use
Every skill is semantically indexed. Skills we have analysed are security-scanned, and each listing states its scan coverage.
Semantic Search
Agents describe the job in natural language; the right tool surfaces ranked by confidence — not keyword luck. One query across every source.
Multi-dimensional Trust
Analysed skills scored 0-100 on security, supply chain, quality, reliability, compliance, and provenance — one verdict tier your policies can gate on. Human and agent signals kept separate.
Version control you own
The most reliable version surfaces first (trust-weighted), or pin the exact one you've certified. No surprise upgrades reaching production agents.
Provenance & lineage
Complex jobs decompose into multi-skill workflows, with lineage preserved back to every upstream source — a complete audit trail of what ran and from where.
For enterprise
Run your own private registry
A tenant-scoped catalog for your organization — your internal skills alongside the curated public ones, under policies you control. Hosted overlay, self-hosted, or fully air-gapped.
Enforce a trust floor
Set the minimum verdict tier ("A-tier only") and agents simply can't resolve anything below it. Allow / block lists per source, publisher, or skill.
Your private skills
Publish internal skills scoped to your tenant through the same signed handler. They never leave your catalog, and rank on their own trust.
Pin the versions you trust
Freeze exact versions and control upgrades, or let the most reliable version auto-surface. No surprise changes reaching production agents.
One search, public + private
Query your private catalog, the public catalog, or both in a single call. Same MCP + REST surface your agents already use.
Signed & auditable
First-party skills are Ed25519-signed; crawled listings carry source provenance and lineage. A complete audit trail of what ran, which version, and from where.
Deploy your way
A private overlay on the hosted service, or docker run the whole registry on-prem / air-gapped. Same code, same endpoints, nothing leaves your network.
This is what your agent sees
Real MCP calls, real responses — no mocking. Captured on this page build. Streams on load so you can watch it land.
- ▪ search_skills
- ▪ get_skill
- ▪ list_leaderboard
- ▪ get_trust_breakdown
- ▪ resolve_composition
- ▪ search
- ▪ fetch
- ▪ algonacci-unlock-pdf 99% verified
- ▪ pspdfkit-nutrient-pdf-mcp-server 90% verified
- ▪ lisabrennan1996-liteparse-mcp 94% verified
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp The score is not a vibe
Every deeply-scanned skill decomposes into six measurable dimensions from 27 analyzer passes. A skill can score 96 overall and still get blocked — because one axis dips where it matters.
Every skill carries a trust score, but they are not all the same claim: an unscanned skill is scored from source provenance alone, while these 27 are taken to full six-axis depth. Scan coverage is stated on every listing so you can tell them apart, and the deep-scan backfill widens the analysed set continuously. Full breakdown via API →
109,671 published skills, placed by trust
Every point is a published skill. Most land at the baseline every source starts from — the trustworthy few earn their place on the right, where scans come back clean and signatures check out.
What the catalog is made of · by category
Category & domain derived from each skill's name and description. Filter the full catalog by them on browse.
Find skills by task
Click a category to explore top-ranked skills for that task.
Static analysis, formatting, and lint enforcement.
Use this tool when you need to streamline code review workflows and enforce coding standards across teams. It analyzes pull requests, checks code patterns, and ensures consistency with team standards, providing automated code analysis, security checks, and suggestions for improvements. The tool accepts GitHub repository data as input and outputs detailed code review information, including files, diffs, and compliance validation results.
Use this tool when you need to analyze Python code quality and enforce coding standards, solving problems such as detecting syntax errors, type inconsistencies, and complex code structures. It takes in Python code as input and outputs detailed reports on linting and type checking results, using tools like flake8 and mypy. Utilize it in development contexts where maintaining high-quality, readable, and reliable code is crucial.
Use this tool when you need to analyze code quality, formatting, and security issues across multiple programming languages and formats. It solves problems related to code maintenance, security vulnerabilities, and consistency by providing comprehensive linting and analysis. The MegaLinter tool takes in code files as input and outputs detailed reports on code quality, formatting, and security issues, making it ideal for use in development workflows and continuous integration pipelines.
Use this tool when you need to automate code quality checks and fixes across multiple programming languages, including Go, Java, and Lua, with support for local IDE integration and remote access. It solves problems related to code consistency, formatting, and best practices, providing a standardized way to lint and format code. The tool accepts code files as input and outputs formatted code with diagnostics and audit logs, making it ideal for development teams seeking to improve code quality and collaboration.
Use this tool when you need to enforce coding standards and best practices in your AI agent's codebase, solving problems such as inconsistent styling, complex code, and dead code. It takes in code files as input and outputs reports on style violations, complexity issues, and other code quality metrics. Ideal for use in development and testing contexts to ensure maintainable and efficient code.
Crawl pages and extract structured data from the web.
Use this tool when you need to interact with web content programmatically, extract specific data, or automate web-based tasks. It provides a robust interface for web scraping, content extraction, and navigation, integrating with popular Python libraries to simplify HTTP requests and HTML parsing. Ideal for applications requiring real-time web data, such as research assistants, content aggregators, or dynamic information retrieval systems.
Use this tool when you need to extract data from websites, search engines, or social media platforms, and require a comprehensive web scraping solution. The ScrapingDog MCP Server provides a robust interface for inputting scraping requests and outputs structured data for further analysis. Ideal for use cases involving e-commerce data collection, market research, and data mining, where large-scale web data extraction is necessary.
mcp-scrapingant — pipeworx-io-mcp-scrapingant. Use this tool when you need to extract data from websites, as it provides a simple interface to the ScrapingAnt web scraping API, accepting URLs and parameters as input and returning scraped data as output, ideal for automating data collection tasks in various contexts, such as market research or data analysis. It solves problems like handling anti-scraping measures and rotating proxies, making it a reliable solution for web data extraction. By integrating with git, it enables version control and collaboration for web scraping projects.
Use this tool when you need to build and manage web scrapers with advanced features like async crawling and structured data extraction. It solves problems of extracting specific data from websites, handling complex HTML structures, and scaling crawling tasks. The Silkworm server takes in website URLs and CSS/XPath selectors as input and outputs extracted, structured data.
Use this tool when you need to extract data from websites using CSS or XPath selectors, and require features like stealth mode and batch processing for efficient web scraping. It solves problems of data extraction from complex websites, handling anti-scraping measures, and processing large volumes of URLs. The tool takes URLs and selector inputs, and outputs extracted data, making it ideal for use cases involving automated data collection and monitoring.
Query, migrate, and inspect SQL and NoSQL stores.
genpark-database-migration-sql-optimizer-skill — alphaparkinc-genpark-database-migration-sql-optimizer-skill. Use this tool when you need to optimize SQL queries and migrate database schemas efficiently. It solves problems related to slow query performance and complex schema migrations, providing a streamlined interface for inputting SQL code and outputting optimized queries. Ideal for use in development environments with git version control, where database performance and schema consistency are crucial.
Use this tool when you need to interact with relational databases, such as PostgreSQL, MySQL, or SQLite, to execute SQL queries, inspect database schemas, or run migrations. It provides a comprehensive interface for database management, accepting SQL queries and schema definitions as inputs and producing query results and migration reports as outputs. Ideal for use cases requiring database setup, data analysis, or schema updates, this tool streamlines database operations and simplifies data management tasks.
db-legacy-migration-agent — felipeassis10-db-legacy-migration-agent. Use this tool when you need to migrate legacy relational databases to PostgreSQL, as it parses schemas from Oracle, DB2, MySQL, and MSSQL, and generates Prisma schemas and TypeScript query helpers. It solves database compatibility issues and simplifies migration processes. Ideal for use cases involving database modernization, consolidation, or cloud migration, where a seamless transition from legacy systems to PostgreSQL is required.
Migrating-Databases-Using-ORMCP — astronaut012-migrating-databases-using-ormcp. Use this tool when you need to migrate databases from one system to another, such as from Oracle to PostgreSQL, and require a streamlined process for transferring data. It solves problems related to data compatibility and transfer, providing a seamless transition for systems like flight management. The tool takes database credentials and schema as input and outputs a migrated database, utilizing ORMCP and AI agents for efficient data transfer.
Use this tool when you need to migrate databases between different systems, such as Oracle, PostgreSQL, or SQL Server, to streamline data transfer and minimize manual errors. It solves problems of data incompatibility and transfer complexity by providing AI-assisted command preview, execution, and validation. The tool takes database schema and data as inputs and outputs migrated databases, making it ideal for use cases involving heterogeneous system integration and data consolidation.
Read, transform, and extract content from PDFs and docs.
Use this tool when you need to process and analyze PDF documents, as it provides comprehensive capabilities such as text extraction, image extraction, and metadata retrieval. It solves problems related to document parsing, data extraction, and content analysis, making it ideal for use cases like document indexing, data mining, and content management. The tool accepts PDF files as input and outputs extracted data, images, and metadata, making it a versatile solution for various applications.
Use this tool when you need to extract content from PDF files with precise layout and LaTeX recognition, solving problems of inaccessible or unstructured data in large documents. It takes PDF files as input and outputs extracted content, utilizing a Python-based engine with a Node.js fallback for robust processing. Ideal for use cases requiring efficient and accurate text extraction from complex PDFs.
Use this tool when you need to extract content from PDF files, whether protected or unprotected, to analyze documents, index content, or extract data. It provides functionality to read and parse PDFs, handle password-protected documents, and format extracted content. Ideal for workflows requiring PDF parsing and text extraction, such as document analysis or data extraction from PDF sources.
Use this tool when you need to extract structured data from PDF documents, such as tables, text, and metadata, to enable further analysis or processing. It solves problems of manual data entry and information retrieval from PDFs, providing outputs in a machine-readable format. Ideal for use cases where PDF data needs to be integrated into workflows, databases, or machine learning models.
Use this tool when you need to extract text and visual information from PDFs locally and quickly, without relying on cloud services or API keys. It solves problems such as text extraction, object detection, and citation analysis, providing outputs like text, bounding boxes, and OCR results. Ideal for use cases requiring fast, self-contained PDF parsing, such as research, document analysis, and data extraction.
GitHub workflow tools — PR review, branch and commit operations.
GitHub PR Analyzer MCP Server — punyprogrammer-pr-analyzer-mcp-server. Use this tool when you need to streamline GitHub pull request review processes and centralize feedback. It fetches GitHub pull request details and saves reviews to Notion, solving problems related to code review management and team collaboration. Ideal for development teams seeking to automate and organize their GitHub PR workflows, this tool takes GitHub pull request data as input and outputs saved reviews in Notion.
github-pr-reviewer — badarrasheed-github-pr-reviewer. Use this tool when you need to streamline GitHub pull request reviews and ensure code quality. It fetches pull request changes, reviews code for bugs and security issues, and saves approved reviews to Notion, automating the review process and reducing manual effort. Ideal for development teams seeking to improve code reliability and collaboration efficiency.
gh-self-reviewer — alesr-gh-self-reviewer. Use this tool when you need to streamline your GitHub workflow by automating the review of pull requests. The gh-self-reviewer tool solves the problem of manual review by providing a seamless way to self-review GitHub pull requests, taking Git repositories as input and outputting reviewed pull requests. It is ideal for use in MCP server environments where efficient code review is crucial.
Use this tool when you need to streamline the review process of Gemini Code Assist reviews from GitHub pull requests. It solves the problem of manually fetching and analyzing reviews by providing smart defaults and pagination, making it easier to manage and track feedback. The tool takes GitHub pull request data as input and outputs analyzed review data, ideal for use in development workflows and code quality assurance.
Use this tool when you need to automate code review processes on GitHub, enabling large language models (LLMs) to analyze and implement suggestions on pull requests. It solves problems of manual code review and resolution by providing automated workflows for processing and resolving review comments. The tool accepts GitHub pull requests as input and outputs programmatically implemented code review suggestions, streamlining developer workflows and improving code quality.
Vuln scanning, secret detection, and policy checks.
Use this tool when you need to identify exposed secrets in your codebase, such as API keys, tokens, and passwords, to prevent security breaches. The secrets-scan tool scans a specified directory or file, using regex and entropy heuristics to detect hardcoded credentials. It accepts inputs like target path, minimum entropy threshold, and exclude patterns, and outputs a list of potential secrets found, making it ideal for pre-production security checks.
expanso-secrets-scan — aronchick-expanso-secrets-scan. Use this tool when you need to detect and identify hardcoded secrets such as API keys, tokens, and passwords in text or code, helping to prevent security breaches and data exposure. It solves problems related to insecure coding practices and sensitive data leakage by scanning for potential vulnerabilities. The tool takes in text or code as input and outputs a list of detected secrets, making it ideal for use in secure coding and compliance contexts.
Use this tool when you need to identify hardcoded secrets in a repository, solving security risks and compliance issues by detecting sensitive information. It scans a checked-out repo using gitleaks and returns structured findings, providing a clear interface for inputting repository data and outputting potential security threats. Ideal for use cases requiring secret detection and security auditing in development environments.
nirwan-secret-scanner — nirwandogra-nirwan-secret-scanner. Use this tool when you need to detect and prevent sensitive information leaks in your codebase, such as API keys, tokens, and passwords. It scans files, repositories, and directories to identify exposed secrets, helping to mitigate security risks and data breaches. Ideal for use in development, testing, and deployment pipelines to ensure secure coding practices.
ggshield-scanner — amascia-gg-ggshield-scanner. Use this tool when you need to detect and protect sensitive information in your codebase, such as hardcoded secrets and credentials. The ggshield-scanner identifies over 500 types of secrets, solving problems related to security and data breaches. It takes in code files as input and outputs a list of detected secrets, making it an essential tool for securing your projects and preventing unauthorized access.
Ranked by semantic similarity, then by Cognium trust.
Get started
Start free in minutes, or set up a governed private registry for your organization.
Use the free public API
Point your agents at api.skillsregistry.net — MCP + REST, no auth, no signup. Search 100,000+ trust-scored skills today.
Self-host it
Run the whole registry on-prem or air-gapped — same code, same endpoints. Nothing leaves your network.
git clone https://github.com/cogniumhq/skillsregistry && cd skillsregistry/apps/local && docker compose up -dSelf-host guide
Get a private registry
A tenant-scoped catalog with trust policies, allow/block lists, version pinning, private skills, and SSO — hosted, self-hosted, or air-gapped. We'll help you roll it out.
Book a demoFrequently asked questions
What SkillsRegistry is, how it works, and how to use it.