AI skills, indexed with
visible evidence limits.

Search the live registry, inspect each record's source and scanner state, and keep incomplete scans visibly separate from completed ones.

Registry stats loading…

How it works

1

Find what you need

Search the registry by what you're trying to do — security scanning, SEO checks, deployment, and more. Each record shows its current evidence tier and scan state.

2

Look under the hood

Review scanner findings, verdict reason, provenance state, and source evidence for free. Where qualified, non-standalone SKILL.md source snapshots include exact bytes, a pinned commit, and applicable license or notice evidence.

3

Adapt deliberately

Inspect a single skill, or start from a free Blueprint — a reference manifest for designing an agent workflow. Adapt and validate it in your own environment before production.

From the blog

Humans Missed 1 in 3 Threats Approving AI Agent Commands Across 40,000 Plays. The Human-In-The-Loop Has Been The Security Boundary Of Record For Six Months. That Boundary Just Failed Its Empirical Test.

Alex Wauters (ex-Uber Staff Engineer) ran a browser game for three months where you play the human-in-the-loop approving AI agent commands under time pressure. 40,000+ plays, 409,000+ decisions. The result: mean accuracy 66.3%, 32.9% of sessions ended with a negative score, and 7% of players approved every single prompt. The most-missed command was npm run analyze at 64.7% miss rate, even with the malicious script body visible in the history log. The single most-divisive command was cat ~/.zshrc at 45.9%, because the risk depends entirely on setup the agent cannot see. The human-in-the-loop permission model is not a security boundary. It is a UI affordance that gives the user the feeling of safety while the actual boundary lives elsewhere. Here is the data, the threat-category breakdown, the npm run blind spot, the contested commands, the fatigue curve, the mitigation ladder, and what you do this week.

Why teams use Mr. Technology

Most AI registries stop at links. We expose recorded evidence—and the gaps—record by record.

Recorded evidence, not five-star reviews

Completed scans combine source metadata, secret detection, dependency checks, and static-analysis findings where that evidence is available. Pending and incomplete records stay visibly marked.

You can see what's inside

Scanner outputs, timestamps, source links, verdict reasons, and a plain-English summary are shown when that evidence exists.

Blueprints you can inspect and adapt

Tired of starting from a blank page? A Blueprint gives you a curated workflow manifest to inspect, adapt, and validate in your own environment.

Free evidence. Paid human review.

Browse the registry and public API without an account. Commission a scoped one-time audit when automated evidence is not enough for a shipping decision.

Featured technical guides

See all payloads →
New

OpenClaw assistant and operations skills.

Browse registry entries for assistant workflows, gateway operations, security review, and local automation. Check each record's evidence before installing it in your environment.

// SOURCE_REVIEW_FIRST

Free registry. Paid decisions.

Use public evidence at no charge. Buy a fixed-scope assessment when a human-reviewed release decision matters.

Free

No signup. Browse the registry, read the blog, and copy blueprint manifests.

$0
  • · Full registry browse
  • · Verdicts, tiers, evidence limits, and provenance
  • · Public API (paginated, up to 5,000 records/query)
  • · License-qualified SKILL.md source snapshots where available
  • · Free blueprint manifests
  • · Blog + pillar articles
One-time

Publisher Skill Audit

For one public or privately shared repository with up to ten skill folders.

$299
  • Provenance and dependency inventory
  • Gitleaks, Semgrep, and Trivy evidence
  • Human-reviewed PDF + JSON decision report
  • One remediation rescan within 30 days

Built for security teams and the developers they unblock.

Live registryRegistry loading…Snapshot date unavailable