Trust center

A badge is not evidence.

Our release gate makes scope, permission, provenance, tests, limitations, and recovery inspectable before a skill is published.

01 / SOURCE

Known provenance

Every artifact maps back to a versioned source revision and an accountable maintainer.

02 / PERMISSION

Declared access

File writes, commands, networks, accounts, browsers, and external mutations are disclosed.

03 / PROOF

Tested behavior

Verification records the environment, date, cases, failures, limits, and the exact artifact tested.

Release gate

What must pass before download

  1. Explicit public-release approval and license review.
  2. Schema, bilingual documentation, version, and referenced-file validation.
  3. Secret, absolute local path, dangerous pattern, and undeclared network scan.
  4. Skill-specific tests and repository regression checks.
  5. A clean public artifact with a recorded SHA-256 checksum.
  6. Human review of the final manifest before publication.

Verification states

Preview means the public description can be inspected, but the artifact is not yet released. Verified will mean the published artifact passed the stated checks in a named environment on a recorded date. Expired will mean material dependencies changed or the revalidation window passed.

Limits of verification

Verification is evidence about a specific artifact and environment—not a guarantee that every third-party service, account, region, or future version will behave identically. Each detail page will state known limitations and required user confirmation.

Need an existing skill reviewed?

We audit structure, permissions, scripts, dependencies, compatibility, tests, and maintenance readiness.

View audit services