Home / Trust

Trust & safety

SkillForge is a public registry of AI agent skills (SKILL.md packages) discovered on GitHub. We treat every skill as untrusted until automated checks run. The goal is transparency: clear labels, visible upstream links, and no silent promotion of blocked content.

What we scan for

Automated checks look for command-injection patterns, sensitive path access, persistence mechanisms, reverse shells, destructive filesystem commands, and insecure install pipelines. Findings are grouped by severity so operators can prioritize review.

Publish policy

Block severity prevents auto-publish. Review severity may still publish when the repository is highly starred or the owner is on the trusted publishers list. A green UI badge is not a formal security audit— teams should still read upstream code before production use.

Metrics honesty

Install metrics distinguish live CLI-reported installs from estimated figures derived from stars when real volume is low. Estimates are labeled in the UI so daily, weekly, and hot rankings stay understandable rather than inventing false precision.

What stays private

Admin review tools, cron triggers, and internal APIs are disallowed in robots.txt and are not part of the public catalog experience. Crawl jobs require a shared secret header.

Report a problem

Report a problematic skill via GitHub issues. See also Acceptable Use, Privacy, and Terms.