amaniagent · open agent tooling

skills, gated.

A skill is executable trust — you install someone’s instructions and their scripts into an agent that can touch your files, your keys, your machine. A supply chain needs a gate — and good skills to run behind it. Here are both.

read-only by design · targets are never executed

The trust model

Evidence before confidence.

“Audited” is not a magic badge. Every result should point back to inspectable source, named checks and a report a human can challenge. The auditors read target repositories; they do not run them.

01 / INPUTREAD ONLY

Freeze the source

A report records the reviewed revision, files, scripts and declared permissions.

02 / INSPECTSTATIC

Follow capability

The auditors read the target — instructions, scripts and declared permissions. They never execute it.

03 / EXPLAINTRACEABLE

Publish the evidence

The score summarizes a report; it never replaces findings, limitations or human judgment.

Score 0–8

A shorthand,
not a verdict.

0
1
2
3
4
5
6
7
8

Score any skill, repo, or agent answer 0–8 with file:line evidence, before you trust it.

The catalog

Find the capability.
Read the caveat.

Search locally by category or skill name. Every entry remains visible without JavaScript; filtering is a progressive enhancement.

10 categories · 46 skills

Filter by area

security

7 skills

answer-verifier · dependency-auditor · mcp-auditor · prompt-injection-detector · repo-auditor · settings-auditor · skill-auditor

/security/ Open →

token-efficiency

4 skills

context-optimization · context-thrift · lean-replies · output-sandbox

/token-efficiency/ Open →

rag

1 skill

composable-wiki-rag

/rag/ Open →

memory

1 skill

layered-agent-memory

/memory/ Open →

apple

7 skills

app-integration · app-planning-per-platform · apple-fitness · healthkit · metal-shaders · widgets · xcode-mcp

/apple/ Open →

swift

5 skills

embedded-swift · react-native-to-swift · repo-to-swift-native · swift-on-android · swift-vapor

/swift/ Open →

workflow

3 skills

grill-me · superpowers-tdd · superpowers-writing-plans

/workflow/ Open →

tools-services

15 skills

cli-anything-browser · cli-anything-chromadb · cli-anything-exa · cli-anything-mermaid · cli-anything-obsidian · cli-anything-ollama · cli-anything-zotero · github-org-automation · use-cli-anything · use-crawl4ai · use-gortex · use-hermes · use-n8n · use-ntfy · use-tailscale

/tools-services/ Open →

web

2 skills

seo-white-hat · web3-wallet-integration

/web/ Open →

iot

1 skill

led-grow-controller

/iot/ Open →
No category matches this search. Try a capability, platform or risk term.

Learn the gate

Inspect before you install.

The useful question is not simply whether a repository looks suspicious. Ask what authority it requests, what code can cross the boundary and which claims you can verify yourself.