for agents & crawlers no auth MCP 2025-06-18

Integration index

The canonical machine-readable surface for SkillsRegistry — everything an AI agent or LLM crawler needs to query the skill catalog. Human-readable, but written for programmatic consumption. Prefer the raw llms.txt or agents.json if you're a machine.

skills
141,843
verified
45,274
sources
8

MCP server

Streamable HTTP. Point any MCP client at the endpoint; tenant scope via X-Tenant-Id (default public).

https://api.skillsregistry.net/mcp
tool args
search_skills
Semantic search across the catalog. Confidence-tiered (T1/T2/T3), trust-scored. Each hit carries mcpUrl / repositoryUrl / installMethod so it can be acted on without a second call.
query* · tenant_id · appetite · limit · tags · category · runtime_env · visibility · min_trust · require_signed
* required
get_skill
Full manifest for one skill — trust breakdown, verification tier, publisher signature, mcpUrl, agentProfile/sandbox.
slug* · version
* required
list_leaderboard
Ranked by trust score, or by agent invocations. Human and agent signals stay separate. trending/composed/forked are rejected — no usage signal is collected for them yet.
kind* (trust|agents) · limit · category · ecosystem
* required
get_trust_breakdown
Trust slice only — score, verification tier, badge, content-safety, signature status.
slug*
* required
resolve_composition
Resolve a composite skill to its constituent steps + workflow DAG.
slug*
* required

REST API

Base https://api.skillsregistry.net. No auth for reads.

POST /v1/search Semantic search. Body: { query, tenant_id?, appetite?, min_trust?, limit?, ... }
POST /v1/search/instant Keyword-only (no embedding) — ~50ms. Stage 1 of two-stage search.
GET /v1/skills/:slug Single skill — full manifest + trust + signature + sandbox.
GET /v1/skills/lookup?name= Resolve by display name or flat slug.
GET /v1/leaderboards/:kind trust · trending · agents · most-composed · most-forked
GET /v1/analytics/heartbeat Live corpus stats — totals, per-source counts, trust histogram.
GET /v1/analytics/audited-skills Deeply-scanned skills with 6-dimension trust breakdown.
GET /v1/sync/revocations?since= Cursor-paginated revocation-event feed for keeping a local mirror fresh.
GET /v1/catalog/export NDJSON snapshot of the full public catalog.

Self-host

The same registry runs locally — on-prem, air-gapped, or your own catalog. Endpoints move to localhost:3000.

git clone https://github.com/cogniumhq/skillsregistry && cd skillsregistry/apps/local && docker compose up -d

Runs via compose, which builds from source. The image is also published publicly, but needs Postgres and an embedder alongside it. Source: github.com/cogniumhq/skillsregistry (Apache-2.0).

Discovery descriptors

Machine-first formats. Fetch these directly.

Trust model

Skills we have analysed are security-scanned by Cognium — scan coverage is stated per listing, so an unexamined skill is never presented as a clean one. Deeply-scanned skills carry 0-100 scores across six dimensions (security, supply chain, quality, reliability, compliance, and provenance) plus an overall verdict tier. Human and agent signals are tracked separately — bot invocations can't pollute human rankings. First-party skills carry Ed25519 publisher signatures; crawled third-party listings are unsigned, and require_signed filters to the signed set. Filter search by min_trust, require_signed, or verification_tiers.

Search SkillsRegistry