07 · Plugin · Local Registry
Let agents discover, inspect, install, and run trusted skills from a local registry-style capability layer. SHA256 checksum verification, permission gates, and 7 MCP tools — no cloud, no accounts, no hosted runtime required.
Agents accumulate capabilities informally — functions pasted in prompts, scripts loaded from uncertain paths, ad-hoc code run without any record of what was executed. There is no discovery, no version tracking, no checksum, and no permission model. When something breaks or behaves unexpectedly, there is nothing to audit.
The Agent Skill Marketplace Plugin brings registry discipline to local skill management. Skills carry a manifest with declared permissions and a SHA256 checksum. Agents browse the registry, install skills by manifest, and the loader refuses to execute any skill whose code does not match the pinned hash. Permission gates prevent undeclared network, filesystem, shell, or secrets access from running silently.
The result is a local capability layer your agent can trust: browsable, verifiable, inspectable, and fully auditable from a durable local store.
Three phases: register a skill with a manifest, install it to the local store, then load and run it with explicit permission grants.
Use list_skills to search the built-in registry by name, tag, or
permission type. Use skill_info to inspect a specific skill's full
manifest including permissions required before committing to install.
Submit a manifest with a pinned URL and a SHA256 checksum. The loader
validates the manifest schema, writes it to the durable local store, and verifies
the checksum at load time — refusing to execute if the code has changed.
Call run_skill with a grant_permissions list. Any permission
declared in the manifest but not explicitly granted at runtime causes the load to abort
before any skill code executes — no silent privilege escalation.
Every skill is described by a typed manifest. Required fields are validated before
persistence; the URL must use builtin:, file:, or https: schemes.
The checksum must be a 64-character lowercase SHA256 hex digest (or builtin for built-in skills).
| Field | Type | Status | Description |
|---|---|---|---|
id |
string |
Required | 2–80 URL-safe characters. Used as the stable skill identifier across install/run/uninstall. |
name |
string |
Required | Human-readable display name shown in registry listings. |
version |
string |
Required | Semantic version string, e.g. 1.0.0 or 2.1.0-beta.1. |
description |
string |
Required | Short description used in search and skill_info output. |
author |
string |
Required | Publisher or author identifier. Not validated against a registry — informational. |
permissions |
SkillPermission[] |
Required | Non-empty array of network, filesystem, secrets, shell, or none. Cannot mix none with others. |
url |
string |
Required | Skill source URL. Must be builtin:, file:, or https:. Pin to an immutable commit SHA for reproducibility. |
checksum |
string |
Required | SHA256 hex digest of the skill file content. Set to builtin for built-in skills only. |
tags |
string[] |
Required | Lowercase tag array used for filtering in list_skills. |
loaderVersion |
string |
Optional | Minimum loader version required. Install is rejected if the declared version exceeds the current loader (1.0.0). |
Four built-in skills are included and require no installation. All declare
permissions: ["none"] and run entirely in-process with no side effects.
Pretty-print or minify a JSON string. Accepts a json string and an optional minify boolean.
Count words, characters, chars-without-spaces, and lines in a text string. Returns all four metrics.
Encode or decode a string as Base64. Pass mode: "encode" or mode: "decode" with the text input.
Get the current UTC timestamp in ISO, Unix epoch seconds, or human-readable format. Pass format: "iso" | "unix" | "human".
Each skill declares its permissions upfront in the manifest. Any permission
not explicitly granted in run_skill's grant_permissions
field causes the loader to abort before the skill code runs.
Permission checks are manifest gates, not OS-level sandboxing — skill code
still executes inside the current Node.js process.
No external access. Safe for pure transformation utilities. Default for all built-in skills.
Skill may make outbound HTTP/HTTPS requests. Must be granted explicitly at runtime.
Skill may read or write local files. Requires explicit grant; scope is not further restricted.
Skill may access environment variables or credential stores. High-risk — grant with caution.
Skill may invoke shell commands. Highest-risk permission — grant only to verified local skills.
Package source is published as @certaworks/agent-skill-marketplace-plugin (v0.1.0) on npm as shown below.
Import the SDK directly for programmatic skill management without MCP.
All functions accept an optional storePath to override the default store location.
Seven tools exposed over the MCP protocol. All callable from any MCP-compatible agent runtime.
Browse the skill registry. Returns built-in, installed, and optionally remote registry skills matching the provided filters.
Get full manifest details about a specific skill — permissions required, URL, checksum, tags, and version — before installing.
Install a trusted local or remote skill manifest into the local marketplace store. Validates the manifest schema before persisting.
List all skills currently installed in the local marketplace store, including their install timestamps and full manifests.
Remove a skill from the local marketplace store and unload it from the in-process cache. Returns a boolean indicating success.
Load and execute a skill with the given input object. Permissions declared in the manifest but absent from grant_permissions abort execution before the skill runs.
List the IDs of skills currently cached in the in-process skill cache. Useful for inspecting loader state after a run session.
Installed skill manifests are persisted as versioned JSON at a configurable local path.
The store is created automatically on first install. Override the default path with an
environment variable or a storePath option in any SDK call.
By default the store lives at .agent-skill-marketplace/installed-skills.json
relative to the current working directory. Override with either environment variable:
{ "version": 1, "installed": [ ...InstalledSkillRecord ] }
— manifests are validated on every read.
network, filesystem, secrets, shellregistry_url at query time@certaworks/agent-skill-marketplace-pluginAgent Skill Marketplace Plugin ships as a local MCP server. No hosted endpoint required to get started.
Once running locally, agents can call `list_skills`, `install_skill`, and `run_skill` to discover and execute trusted skills from the local registry.
View on npm →npm install -g @certaworks/agent-skill-marketplace-plugin
{
"mcpServers": {
"agent-skill-marketplace-plugin": {
"command": "npx",
"args": ["-y", "@certaworks/agent-skill-marketplace-plugin"]
}
}
}
Early Access
Get early access to Agent Skill Marketplace Plugin — local-first, checksum-verified capability management for agents that need to trust what they run.