Integration index
The canonical machine-readable surface for SkillsRegistry — everything an AI agent or LLM crawler needs to query the skill catalog. Human-readable, but written for programmatic consumption. Prefer the raw llms.txt or agents.json if you're a machine.
- skills
- 141,843
- verified
- 45,274
- sources
- 8
MCP server
Streamable HTTP. Point any MCP client at the endpoint; tenant scope via X-Tenant-Id (default public).
https://api.skillsregistry.net/mcp | tool | args |
|---|---|
| search_skills Semantic search across the catalog. Confidence-tiered (T1/T2/T3), trust-scored. Each hit carries mcpUrl / repositoryUrl / installMethod so it can be acted on without a second call. | query* · tenant_id · appetite · limit · tags · category · runtime_env · visibility · min_trust · require_signed * required |
| get_skill Full manifest for one skill — trust breakdown, verification tier, publisher signature, mcpUrl, agentProfile/sandbox. | slug* · version * required |
| list_leaderboard Ranked by trust score, or by agent invocations. Human and agent signals stay separate. trending/composed/forked are rejected — no usage signal is collected for them yet. | kind* (trust|agents) · limit · category · ecosystem * required |
| get_trust_breakdown Trust slice only — score, verification tier, badge, content-safety, signature status. | slug* * required |
| resolve_composition Resolve a composite skill to its constituent steps + workflow DAG. | slug* * required |
REST API
Base https://api.skillsregistry.net. No auth for reads.
| POST | /v1/search | Semantic search. Body: { query, tenant_id?, appetite?, min_trust?, limit?, ... } |
| POST | /v1/search/instant | Keyword-only (no embedding) — ~50ms. Stage 1 of two-stage search. |
| GET | /v1/skills/:slug | Single skill — full manifest + trust + signature + sandbox. |
| GET | /v1/skills/lookup?name= | Resolve by display name or flat slug. |
| GET | /v1/leaderboards/:kind | trust · trending · agents · most-composed · most-forked |
| GET | /v1/analytics/heartbeat | Live corpus stats — totals, per-source counts, trust histogram. |
| GET | /v1/analytics/audited-skills | Deeply-scanned skills with 6-dimension trust breakdown. |
| GET | /v1/sync/revocations?since= | Cursor-paginated revocation-event feed for keeping a local mirror fresh. |
| GET | /v1/catalog/export | NDJSON snapshot of the full public catalog. |
Self-host
The same registry runs locally — on-prem, air-gapped, or your own catalog. Endpoints move to localhost:3000.
git clone https://github.com/cogniumhq/skillsregistry && cd skillsregistry/apps/local && docker compose up -d Runs via compose, which builds from source. The image is also published publicly, but needs Postgres and an embedder alongside it. Source: github.com/cogniumhq/skillsregistry (Apache-2.0).
Discovery descriptors
Machine-first formats. Fetch these directly.
- MCP descriptor api.skillsregistry.net/.well-known/mcp.json
- Agent surface (JSON) skillsregistry.net/.well-known/agents.json
- LLM index (markdown) skillsregistry.net/llms.txt
- OpenAPI spec api.skillsregistry.net/openapi.json
- API docs (Scalar) api.skillsregistry.net/docs
Trust model
Skills we have analysed are security-scanned by Cognium — scan coverage is stated per listing, so an unexamined skill is never presented as a clean one. Deeply-scanned skills carry 0-100 scores across six dimensions (security, supply chain, quality, reliability, compliance, and provenance) plus an overall verdict tier. Human and agent signals are tracked separately — bot invocations can't pollute human rankings. First-party skills carry Ed25519 publisher signatures; crawled third-party listings are unsigned, and require_signed filters to the signed set. Filter search by min_trust, require_signed, or verification_tiers.