PRICING / ONE-TIME SECURITY WORK

Buy evidence.
Not access.

The public registry stays free. Paid work produces a scoped, human-reviewed security assessment tied to the source you authorize—not a recurring subscription to the same data.

PUBLIC RESEARCH

Free Registry

$0

Browse indexed skills, inspect available evidence, follow upstream source, and use the public API.

  • No signup required
  • Scanner status and timestamps where available
  • Conditional non-standalone SKILL.md source snapshots
  • Public API capped at 5,000 rows per request
Browse registry →
FOUNDING ONE-TIME OFFER

Publisher Audit

$299one time

A human-reviewed security assessment for one authorized repository, up to 10 AI skill directories, and one exact pinned revision.

Target: 3 business days after complete intake and source access

  • One authorized repository at one exact pinned revision
  • Up to 10 AI skill directories
  • gitleaks, Semgrep, and Trivy evidence
  • Commit, source-path, and SHA-256 inventory
  • Prioritized findings and remediation guidance
  • Human-reviewed PDF report and evidence JSON
  • One post-fix rescan within 30 days
PILOT — LIMITED AVAILABILITY

Team Monitor

$249per month

Continuous scanner coverage for up to 30 tracked repositories with weekly evidence diff, drift alerts, and a quarterly human review. Designed for security leads managing a portfolio of agent skills.

We are running a small pilot with up to 10 teams. Request access and we will confirm scope, evidence contract, and pricing before any charge.

Target: Pilot onboarding within 5 business days; weekly evidence thereafter

  • Up to 30 authorized repositories with pinned revisions
  • Up to 200 AI skill directories tracked
  • Weekly scheduled rescan with evidence diff
  • Drift alerts when new findings or upstream commits change a tracked skill
  • Quarterly human-reviewed summary report
  • One-off manual scan request per month
  • Cancel any time; no pro-rated refunds within an active cycle
Request pilot access
WHAT RUNS TODAY

Evidence, with limits visible.

Audits use gitleaks, Semgrep, and Trivy, then receive human review. Reports identify source path, commit when captured, content hash, scanner versions, findings, and any missing evidence.

An audit is not a certification, warranty, or proof of universal safety. Runtime sandbox evidence is not currently part of the standard offer.

NEXT PRODUCT

Team Monitor is a pilot.

Recurring private inventory, drift alerts, policy, and CI gates will launch only after paid assessments validate the workflow. No subscription is being sold ahead of capability.

Join the pilot list →

Before you buy

Do I need an account?

Yes. A free account binds payment, intake, report delivery, and the included rescan to one authenticated owner.

When does work begin?

After Stripe confirms payment and you submit complete intake with authorization for every source location.

How is private code handled?

Do not send credentials in checkout or the intake form. We establish a separate read-only transfer process before requesting private source.

What if the scope is larger?

Email editor@mr.technology before purchase. A larger scope requires a separate written engagement; the $299 audit covers one authorized repository and up to ten skill directories at one pinned revision.

Can this certify my product?

No. The report is decision support based on the captured source and evidence; it is not certification or a guarantee against future vulnerabilities.