<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>skill-verification on tomrochette.com</title>
    <link>https://tomrochette.com/tags/skill-verification/</link>
    <description>Recent content in skill-verification on tomrochette.com</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>en</language>
    <managingEditor>tom@tomrochette.com (Tom Rochette)</managingEditor>
    <webMaster>tom@tomrochette.com (Tom Rochette)</webMaster>
    <copyright>© 2026 Tom Rochette</copyright>
    <lastBuildDate>Tue, 06 Oct 2026 00:03:56 -0400</lastBuildDate><atom:link href="https://tomrochette.com/tags/skill-verification/index.xml" rel="self" type="application/rss+xml" />
    
    <item>
      <title>SkillMD</title>
      <link>https://tomrochette.com/agents/skills/skillmd/</link>
      <pubDate>Mon, 05 Oct 2026 00:00:00 +0000</pubDate>
      <author>tom@tomrochette.com (Tom Rochette)</author>
      <guid>https://tomrochette.com/agents/skills/skillmd/</guid>
      <category>research-note</category><category>agent-curated</category><category>fully-ai-generated</category><category>llm=glm-5.3-flash</category><category>skills</category><category>registries</category><category>skill-verification</category>
      <description>&lt;p&gt;SkillMD is an open skills registry at skillmd.com that indexes public SKILL.md files at scale and differentiates on published verification: per-skill lint verdicts, capability flags, and third-party scanner results (NVIDIA SkillSpector and Cisco AI Defense Skill Scanner) shown on each skill page, installable through its own MIT CLI, MCP server, Claude Code plugin marketplace, or GitHub Action.&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;The verification-first registry now operates at the scale where it competes with skills.sh, but its verified core is a rounding error of its index: 1,948 safety-reviewed skills out of about 1.13 million listed as of 2026-10-05, so the verdict badge is an aspiration, not a guarantee.&lt;/strong&gt;&lt;/p&gt;&#xA;&#xA;&lt;h2 class=&#34;relative group&#34;&gt;What it is&#xA;    &lt;div id=&#34;what-it-is&#34; class=&#34;anchor&#34;&gt;&lt;/div&gt;&#xA;    &#xA;    &lt;span&#xA;        class=&#34;absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none&#34;&gt;&#xA;        &lt;a class=&#34;text-primary-300 dark:text-neutral-700 !no-underline&#34; href=&#34;#what-it-is&#34; aria-label=&#34;Anchor&#34;&gt;#&lt;/a&gt;&#xA;    &lt;/span&gt;&#xA;    &#xA;&lt;/h2&gt;&#xA;&lt;p&gt;The registry (skillmd.com) crawls and accepts SKILL.md files and reports 1,132,702 skills from 30,609 authors as of 2026-10-05.&#xA;The toolchain (github.com/skillmds/skillmd, MIT) is what runs on your machine: a &lt;code&gt;skillmd&lt;/code&gt; CLI (npm &lt;code&gt;skillmds&lt;/code&gt;, v1.3.3, 2,102 downloads in the month to 2026-10-03), an MCP server (&lt;code&gt;npx -y skillmds&lt;/code&gt;), a Claude Code plugin marketplace, and a GitHub Action, plus a JSON search API and OAuth-protected endpoints aimed at agents.&#xA;Skills land in each detected agent&amp;rsquo;s own directory (&lt;code&gt;.claude/skills/&lt;/code&gt;, &lt;code&gt;.cursor/skills/&lt;/code&gt;, &lt;code&gt;.agents/skills/&lt;/code&gt;), and every listed skill is pinned to a commit.&#xA;The maintainer also publishes the ecosystem&amp;rsquo;s most self-critical data: their directory-landscape post estimates 83.4 percent of indexed skills declare no license and roughly 47 percent of public SKILL.md files are byte-identical copies of another file.&lt;/p&gt;&#xA;&#xA;&lt;h2 class=&#34;relative group&#34;&gt;Status&#xA;    &lt;div id=&#34;status&#34; class=&#34;anchor&#34;&gt;&lt;/div&gt;&#xA;    &#xA;    &lt;span&#xA;        class=&#34;absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none&#34;&gt;&#xA;        &lt;a class=&#34;text-primary-300 dark:text-neutral-700 !no-underline&#34; href=&#34;#status&#34; aria-label=&#34;Anchor&#34;&gt;#&lt;/a&gt;&#xA;    &lt;/span&gt;&#xA;    &#xA;&lt;/h2&gt;&#xA;&lt;p&gt;&lt;strong&gt;Active and growing, with a thin independent footprint.&lt;/strong&gt;&#xA;The toolchain repo was created 2026-08-25 and shows 1 star and 8 open issues, pushed 2026-09-29; the npm CLI has shipped 33 versions since 2026-06-29.&#xA;The site&amp;rsquo;s own claimed index grew from 860,000 skills (its September 19 directory post) to 1,132,702 as of 2026-10-05, and that post itself warns that directory counts are claims, not measurements, skills.sh included.&#xA;No Hacker News thread surfaced under its name in my searches as of 2026-10-05; the largest near-match is the 48-point &amp;ldquo;Skill.md: An open standard&amp;rdquo; story about the format, not this registry.&#xA;The business model is unstated; installing needs no account and the site quotes no price.&lt;/p&gt;&#xA;&#xA;&lt;h2 class=&#34;relative group&#34;&gt;Strengths&#xA;    &lt;div id=&#34;strengths&#34; class=&#34;anchor&#34;&gt;&lt;/div&gt;&#xA;    &#xA;    &lt;span&#xA;        class=&#34;absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none&#34;&gt;&#xA;        &lt;a class=&#34;text-primary-300 dark:text-neutral-700 !no-underline&#34; href=&#34;#strengths&#34; aria-label=&#34;Anchor&#34;&gt;#&lt;/a&gt;&#xA;    &lt;/span&gt;&#xA;    &#xA;&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;strong&gt;It is the only directory of its size that publishes what it checked and how, per skill, instead of a claimed security stance.&lt;/strong&gt;&lt;/li&gt;&#xA;&lt;li&gt;Install paths that go beyond a copy button: CLI, MCP server, plugin marketplace, and CI action, all writing into the agents&amp;rsquo; native skills directories.&lt;/li&gt;&#xA;&lt;li&gt;Agent-facing surface: JSON API, OpenAPI spec, &lt;code&gt;.well-known&lt;/code&gt; agent-skills index, and an MCP server card, so an agent can search and install without a human.&lt;/li&gt;&#xA;&lt;li&gt;The self-published ecosystem data (license gaps, duplication rates) is decision-useful even for people who never install from it.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&#xA;&lt;h2 class=&#34;relative group&#34;&gt;Cautions&#xA;    &lt;div id=&#34;cautions&#34; class=&#34;anchor&#34;&gt;&lt;/div&gt;&#xA;    &#xA;    &lt;span&#xA;        class=&#34;absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none&#34;&gt;&#xA;        &lt;a class=&#34;text-primary-300 dark:text-neutral-700 !no-underline&#34; href=&#34;#cautions&#34; aria-label=&#34;Anchor&#34;&gt;#&lt;/a&gt;&#xA;    &lt;/span&gt;&#xA;    &#xA;&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;strong&gt;The safety-review claim does not survive contact with its own numbers: the homepage says every skill passes a safety review before it becomes publicly visible, while the same page reports 1,948 reviewed out of 1,132,702 listed, so treat the verdicts as a curated subset, not a property of the catalog.&lt;/strong&gt;&lt;/li&gt;&#xA;&lt;li&gt;The toolchain repo&amp;rsquo;s 1 star and the near-zero HN footprint mean no independent security eyes on the verification pipeline itself.&lt;/li&gt;&#xA;&lt;li&gt;Its blog states Agent Skills is stewarded through the Agentic AI Foundation, but the AAIF&amp;rsquo;s own project list carries AGENTS.md, MCP, goose, and agentgateway, not Agent Skills, so treat the blog&amp;rsquo;s ecosystem claims as unverified.&lt;/li&gt;&#xA;&lt;li&gt;Index counts are self-reported and the site says so itself; the 860k-to-1.13M jump in two weeks is crawl churn as much as ecosystem growth.&lt;/li&gt;&#xA;&lt;li&gt;A registry this young is one team&amp;rsquo;s roadmap; skills.sh at least has Vercel behind it.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&#xA;&lt;h2 class=&#34;relative group&#34;&gt;Pricing&#xA;    &lt;div id=&#34;pricing&#34; class=&#34;anchor&#34;&gt;&lt;/div&gt;&#xA;    &#xA;    &lt;span&#xA;        class=&#34;absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none&#34;&gt;&#xA;        &lt;a class=&#34;text-primary-300 dark:text-neutral-700 !no-underline&#34; href=&#34;#pricing&#34; aria-label=&#34;Anchor&#34;&gt;#&lt;/a&gt;&#xA;    &lt;/span&gt;&#xA;    &#xA;&lt;/h2&gt;&#xA;&lt;p&gt;Free.&#xA;&lt;strong&gt;No account is needed to search or install, the toolchain is MIT, and the site quotes no paid tier as of 2026-10-05.&lt;/strong&gt;&lt;/p&gt;&#xA;&#xA;&lt;h2 class=&#34;relative group&#34;&gt;Compared to&#xA;    &lt;div id=&#34;compared-to&#34; class=&#34;anchor&#34;&gt;&lt;/div&gt;&#xA;    &#xA;    &lt;span&#xA;        class=&#34;absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none&#34;&gt;&#xA;        &lt;a class=&#34;text-primary-300 dark:text-neutral-700 !no-underline&#34; href=&#34;#compared-to&#34; aria-label=&#34;Anchor&#34;&gt;#&lt;/a&gt;&#xA;    &lt;/span&gt;&#xA;    &#xA;&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;skills.sh: the telemetry-ranked incumbent; SkillMD trades usage signal for published verification, and both index the same public GitHub repositories.&lt;/li&gt;&#xA;&lt;li&gt;skillregistry.io: the hosted upload registry positioning itself as definitive; tiny, no published method, and orders of magnitude smaller than either.&lt;/li&gt;&#xA;&lt;li&gt;Skilleton: the lockfile-based, telemetry-free manager; SkillMD is the hosted-registry version of the same verification-first instinct.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&#xA;&lt;h2 class=&#34;relative group&#34;&gt;Bottom line&#xA;    &lt;div id=&#34;bottom-line&#34; class=&#34;anchor&#34;&gt;&lt;/div&gt;&#xA;    &#xA;    &lt;span&#xA;        class=&#34;absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none&#34;&gt;&#xA;        &lt;a class=&#34;text-primary-300 dark:text-neutral-700 !no-underline&#34; href=&#34;#bottom-line&#34; aria-label=&#34;Anchor&#34;&gt;#&lt;/a&gt;&#xA;    &lt;/span&gt;&#xA;    &#xA;&lt;/h2&gt;&#xA;&lt;p&gt;&lt;strong&gt;Recommended as a second opinion before installing an unfamiliar skill: search it there, read the lint and scanner verdicts, then pin the commit.&lt;/strong&gt;&#xA;Not as a replacement for reading the SKILL.md yourself, and not because its catalog is bigger or safer at scale, because neither is demonstrated.&#xA;My disagreeable claim: SkillMD&amp;rsquo;s 1,948 reviewed skills matter more than either registry&amp;rsquo;s million-skill index, and the winner of this layer is whoever verifies the long tail, not whoever crawls it.&lt;/p&gt;&#xA;&#xA;&lt;h2 class=&#34;relative group&#34;&gt;Changes&#xA;    &lt;div id=&#34;changes&#34; class=&#34;anchor&#34;&gt;&lt;/div&gt;&#xA;    &#xA;    &lt;span&#xA;        class=&#34;absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none&#34;&gt;&#xA;        &lt;a class=&#34;text-primary-300 dark:text-neutral-700 !no-underline&#34; href=&#34;#changes&#34; aria-label=&#34;Anchor&#34;&gt;#&lt;/a&gt;&#xA;    &lt;/span&gt;&#xA;    &#xA;&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;2026-10-05 - Created in the daily refresh&amp;rsquo;s skills entrant scan.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&#xA;&lt;h2 class=&#34;relative group&#34;&gt;See also&#xA;    &lt;div id=&#34;see-also&#34; class=&#34;anchor&#34;&gt;&lt;/div&gt;&#xA;    &#xA;    &lt;span&#xA;        class=&#34;absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none&#34;&gt;&#xA;        &lt;a class=&#34;text-primary-300 dark:text-neutral-700 !no-underline&#34; href=&#34;#see-also&#34; aria-label=&#34;Anchor&#34;&gt;#&lt;/a&gt;&#xA;    &lt;/span&gt;&#xA;    &#xA;&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://tomrochette.com/agents/skills/skills-sh/&#34; &gt;skills.sh&lt;/a&gt; - the telemetry-ranked incumbent registry&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://tomrochette.com/agents/skills/agent-skills-open-standard/&#34; &gt;Agent Skills open standard&lt;/a&gt; - the format every directory indexes&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://tomrochette.com/agents/skills/anthropic-agent-skills/&#34; &gt;Anthropic Agent Skills&lt;/a&gt; - the vendor pack and partner directory&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://tomrochette.com/agents/agentic-coding-tools-landscape/&#34; &gt;Agentic Coding Tools Landscape&lt;/a&gt; - the map this distribution layer sits over&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&#xA;&lt;h2 class=&#34;relative group&#34;&gt;References&#xA;    &lt;div id=&#34;references&#34; class=&#34;anchor&#34;&gt;&lt;/div&gt;&#xA;    &#xA;    &lt;span&#xA;        class=&#34;absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none&#34;&gt;&#xA;        &lt;a class=&#34;text-primary-300 dark:text-neutral-700 !no-underline&#34; href=&#34;#references&#34; aria-label=&#34;Anchor&#34;&gt;#&lt;/a&gt;&#xA;    &lt;/span&gt;&#xA;    &#xA;&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://skillmd.com/&#34;  target=&#34;_blank&#34; rel=&#34;noreferrer&#34;&gt;&lt;img class=&#34;external-link-favicon&#34; src=&#34;https://www.google.com/s2/favicons?domain=skillmd.com&amp;sz=128&#34; alt=&#34;&#34; width=&#34;16&#34; height=&#34;16&#34; loading=&#34;lazy&#34;&gt;https://skillmd.com/&lt;/a&gt; - the registry surface: 1,132,702 skills, 1,948 safety-reviewed, 30,609 authors, API and MCP endpoints (fetched 2026-10-05)&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://github.com/skillmds/skillmd&#34;  target=&#34;_blank&#34; rel=&#34;noreferrer&#34;&gt;&lt;img class=&#34;external-link-favicon&#34; src=&#34;https://www.google.com/s2/favicons?domain=github.com&amp;sz=128&#34; alt=&#34;&#34; width=&#34;16&#34; height=&#34;16&#34; loading=&#34;lazy&#34;&gt;https://github.com/skillmds/skillmd&lt;/a&gt; - the toolchain repo: MIT, 1 star, 8 open issues, created 2026-08-25, pushed 2026-09-29 (GitHub API, as of 2026-10-05)&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://raw.githubusercontent.com/skillmds/skillmd/main/README.md&#34;  target=&#34;_blank&#34; rel=&#34;noreferrer&#34;&gt;&lt;img class=&#34;external-link-favicon&#34; src=&#34;https://www.google.com/s2/favicons?domain=raw.githubusercontent.com&amp;sz=128&#34; alt=&#34;&#34; width=&#34;16&#34; height=&#34;16&#34; loading=&#34;lazy&#34;&gt;https://raw.githubusercontent.com/skillmds/skillmd/main/README.md&lt;/a&gt; - CLI, MCP server, plugin marketplace, GitHub Action, per-agent install directories&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://skillmd.com/blog/agent-skills-directories-compared&#34;  target=&#34;_blank&#34; rel=&#34;noreferrer&#34;&gt;&lt;img class=&#34;external-link-favicon&#34; src=&#34;https://www.google.com/s2/favicons?domain=skillmd.com&amp;sz=128&#34; alt=&#34;&#34; width=&#34;16&#34; height=&#34;16&#34; loading=&#34;lazy&#34;&gt;https://skillmd.com/blog/agent-skills-directories-compared&lt;/a&gt; - the self-critical directory landscape post: 47 percent byte-identical duplication, 83.4 percent license gaps, counts-as-claims disclaimer (September 19, 2026, fetched 2026-10-05)&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://registry.npmjs.org/skillmds&#34;  target=&#34;_blank&#34; rel=&#34;noreferrer&#34;&gt;&lt;img class=&#34;external-link-favicon&#34; src=&#34;https://www.google.com/s2/favicons?domain=registry.npmjs.org&amp;sz=128&#34; alt=&#34;&#34; width=&#34;16&#34; height=&#34;16&#34; loading=&#34;lazy&#34;&gt;https://registry.npmjs.org/skillmds&lt;/a&gt; - CLI package: latest 1.3.3, 33 versions, created 2026-06-29 (fetched 2026-10-05)&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://api.npmjs.org/downloads/point/last-month/skillmds&#34;  target=&#34;_blank&#34; rel=&#34;noreferrer&#34;&gt;&lt;img class=&#34;external-link-favicon&#34; src=&#34;https://www.google.com/s2/favicons?domain=api.npmjs.org&amp;sz=128&#34; alt=&#34;&#34; width=&#34;16&#34; height=&#34;16&#34; loading=&#34;lazy&#34;&gt;https://api.npmjs.org/downloads/point/last-month/skillmds&lt;/a&gt; - 2,102 downloads, window 2026-09-04 to 2026-10-03 (fetched 2026-10-05)&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://hn.algolia.com/api/v1/search?query=skillmd&amp;amp;tags=story&#34;  target=&#34;_blank&#34; rel=&#34;noreferrer&#34;&gt;&lt;img class=&#34;external-link-favicon&#34; src=&#34;https://www.google.com/s2/favicons?domain=hn.algolia.com&amp;sz=128&#34; alt=&#34;&#34; width=&#34;16&#34; height=&#34;16&#34; loading=&#34;lazy&#34;&gt;https://hn.algolia.com/api/v1/search?query=skillmd&amp;tags=story&lt;/a&gt; - the footprint scan behind the missing-footprint statement (fetched 2026-10-05)&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;</description>
      
    </item>
    
  </channel>
</rss>
