Search the live registry, inspect each record's source and scanner state, and keep incomplete scans visibly separate from completed ones.
Registry stats loading…
Search the registry by what you're trying to do — security scanning, SEO checks, deployment, and more. Each record shows its current evidence tier and scan state.
Review scanner findings, verdict reason, provenance state, and source evidence for free. Where qualified, non-standalone SKILL.md source snapshots include exact bytes, a pinned commit, and applicable license or notice evidence.
Inspect a single skill, or start from a free Blueprint — a reference manifest for designing an agent workflow. Adapt and validate it in your own environment before production.
Alex Wauters (ex-Uber Staff Engineer) ran a browser game for three months where you play the human-in-the-loop approving AI agent commands under time pressure. 40,000+ plays, 409,000+ decisions. The result: mean accuracy 66.3%, 32.9% of sessions ended with a negative score, and 7% of players approved every single prompt. The most-missed command was npm run analyze at 64.7% miss rate, even with the malicious script body visible in the history log. The single most-divisive command was cat ~/.zshrc at 45.9%, because the risk depends entirely on setup the agent cannot see. The human-in-the-loop permission model is not a security boundary. It is a UI affordance that gives the user the feeling of safety while the actual boundary lives elsewhere. Here is the data, the threat-category breakdown, the npm run blind spot, the contested commands, the fatigue curve, the mitigation ladder, and what you do this week.
Most AI registries stop at links. We expose recorded evidence—and the gaps—record by record.
Completed scans combine source metadata, secret detection, dependency checks, and static-analysis findings where that evidence is available. Pending and incomplete records stay visibly marked.
Scanner outputs, timestamps, source links, verdict reasons, and a plain-English summary are shown when that evidence exists.
Tired of starting from a blank page? A Blueprint gives you a curated workflow manifest to inspect, adapt, and validate in your own environment.
Browse the registry and public API without an account. Commission a scoped one-time audit when automated evidence is not enough for a shipping decision.
A guide to dependency review, supply-chain risk triage, and remediation workflows.
A practical walkthrough of Model Context Protocol server structure, authentication, and tool registration.
A technical guide to turning SEO findings into concrete implementation work.
Browse registry entries for assistant workflows, gateway operations, security review, and local automation. Check each record's evidence before installing it in your environment.
Use public evidence at no charge. Buy a fixed-scope assessment when a human-reviewed release decision matters.
No signup. Browse the registry, read the blog, and copy blueprint manifests.