07 · Plugin · Local Registry

Agent Skill
Marketplace

Let agents discover, inspect, install, and run trusted skills from a local registry-style capability layer. SHA256 checksum verification, permission gates, and 7 MCP tools — no cloud, no accounts, no hosted runtime required.

Local slice · v0.1.0 · Node ≥ 18
← Product 06: Cognitive Memory Next: Product 08 Audit & Replay Logger →

Skills without a marketplace are a liability

Agents accumulate capabilities informally — functions pasted in prompts, scripts loaded from uncertain paths, ad-hoc code run without any record of what was executed. There is no discovery, no version tracking, no checksum, and no permission model. When something breaks or behaves unexpectedly, there is nothing to audit.

The Agent Skill Marketplace Plugin brings registry discipline to local skill management. Skills carry a manifest with declared permissions and a SHA256 checksum. Agents browse the registry, install skills by manifest, and the loader refuses to execute any skill whose code does not match the pinned hash. Permission gates prevent undeclared network, filesystem, shell, or secrets access from running silently.

The result is a local capability layer your agent can trust: browsable, verifiable, inspectable, and fully auditable from a durable local store.

How it works

Three phases: register a skill with a manifest, install it to the local store, then load and run it with explicit permission grants.

Browse & Inspect

Use list_skills to search the built-in registry by name, tag, or permission type. Use skill_info to inspect a specific skill's full manifest including permissions required before committing to install.

Install & Verify

Submit a manifest with a pinned URL and a SHA256 checksum. The loader validates the manifest schema, writes it to the durable local store, and verifies the checksum at load time — refusing to execute if the code has changed.

Grant Permissions & Run

Call run_skill with a grant_permissions list. Any permission declared in the manifest but not explicitly granted at runtime causes the load to abort before any skill code executes — no silent privilege escalation.

Skill Manifest Format

Every skill is described by a typed manifest. Required fields are validated before persistence; the URL must use builtin:, file:, or https: schemes. The checksum must be a 64-character lowercase SHA256 hex digest (or builtin for built-in skills).

Field Type Status Description
id string Required 2–80 URL-safe characters. Used as the stable skill identifier across install/run/uninstall.
name string Required Human-readable display name shown in registry listings.
version string Required Semantic version string, e.g. 1.0.0 or 2.1.0-beta.1.
description string Required Short description used in search and skill_info output.
author string Required Publisher or author identifier. Not validated against a registry — informational.
permissions SkillPermission[] Required Non-empty array of network, filesystem, secrets, shell, or none. Cannot mix none with others.
url string Required Skill source URL. Must be builtin:, file:, or https:. Pin to an immutable commit SHA for reproducibility.
checksum string Required SHA256 hex digest of the skill file content. Set to builtin for built-in skills only.
tags string[] Required Lowercase tag array used for filtering in list_skills.
loaderVersion string Optional Minimum loader version required. Install is rejected if the declared version exceeds the current loader (1.0.0).

Starter Registry — Built-in Skills

Four built-in skills are included and require no installation. All declare permissions: ["none"] and run entirely in-process with no side effects.

utility
format-json

Pretty-print or minify a JSON string. Accepts a json string and an optional minify boolean.

✓ permissions: none
text · analysis
word-count

Count words, characters, chars-without-spaces, and lines in a text string. Returns all four metrics.

✓ permissions: none
encoding
base64

Encode or decode a string as Base64. Pass mode: "encode" or mode: "decode" with the text input.

✓ permissions: none
time · utility
timestamp

Get the current UTC timestamp in ISO, Unix epoch seconds, or human-readable format. Pass format: "iso" | "unix" | "human".

✓ permissions: none

Permission Gates

Each skill declares its permissions upfront in the manifest. Any permission not explicitly granted in run_skill's grant_permissions field causes the loader to abort before the skill code runs. Permission checks are manifest gates, not OS-level sandboxing — skill code still executes inside the current Node.js process.

none

No external access. Safe for pure transformation utilities. Default for all built-in skills.

network

Skill may make outbound HTTP/HTTPS requests. Must be granted explicitly at runtime.

filesystem

Skill may read or write local files. Requires explicit grant; scope is not further restricted.

secrets

Skill may access environment variables or credential stores. High-risk — grant with caution.

shell

Skill may invoke shell commands. Highest-risk permission — grant only to verified local skills.

Install & Configure

Package source is published as @certaworks/agent-skill-marketplace-plugin (v0.1.0) on npm as shown below.

Install & run locally
# Install from npm npm install -g @certaworks/agent-skill-marketplace-plugin # Run the MCP server npm run mcp # or: node dist/mcp/server.js # or via bin after local install: agent-skill-marketplace-mcp
MCP client config
{ "mcpServers": { "agent-skill-marketplace": { "command": "node", "args": ["dist/mcp/server.js"], "env": { "AGENT_SKILL_MARKETPLACE_STORE_PATH": "./.agent-skill-marketplace/installed-skills.json" } } } }

SDK Surface

Import the SDK directly for programmatic skill management without MCP. All functions accept an optional storePath to override the default store location.

Core imports
// ESM import (Node ≥ 18) import { installSkill, listSkills, runSkill, uninstallSkill, findSkill, listInstalledSkills, loadedSkillIds } from '@certaworks/agent-skill-marketplace-plugin';
Install & run example
// Install a local skill await installSkill({ id: 'upper-case', name: 'Upper Case', version: '1.0.0', description: 'Uppercase input text.', author: 'CertaWorks', permissions: ['none'], url: 'file:///path/upper-case.mjs', checksum: '<64-char sha256 hex>', tags: ['text'] }); // Search and run const skills = await listSkills({ query: 'upper' }); const result = await runSkill( 'upper-case', { text: 'ship it' }, [] // grant_permissions );

MCP Tools

Seven tools exposed over the MCP protocol. All callable from any MCP-compatible agent runtime.

list_skills

Browse the skill registry. Returns built-in, installed, and optionally remote registry skills matching the provided filters.

query? tags? permission? registry_url?
skill_info

Get full manifest details about a specific skill — permissions required, URL, checksum, tags, and version — before installing.

id
install_skill

Install a trusted local or remote skill manifest into the local marketplace store. Validates the manifest schema before persisting.

manifest
installed_skills

List all skills currently installed in the local marketplace store, including their install timestamps and full manifests.

(no params)
uninstall_skill

Remove a skill from the local marketplace store and unload it from the in-process cache. Returns a boolean indicating success.

id
run_skill

Load and execute a skill with the given input object. Permissions declared in the manifest but absent from grant_permissions abort execution before the skill runs.

id input? grant_permissions?
loaded_skills

List the IDs of skills currently cached in the in-process skill cache. Useful for inspecting loader state after a run session.

(no params)

Durable Local Store

Installed skill manifests are persisted as versioned JSON at a configurable local path. The store is created automatically on first install. Override the default path with an environment variable or a storePath option in any SDK call.

Local store path

By default the store lives at .agent-skill-marketplace/installed-skills.json relative to the current working directory. Override with either environment variable:

AGENT_SKILL_MARKETPLACE_STORE_PATH=/path/to/installed-skills.json AGENT_SKILL_MARKETPLACE_STORE=/path/to/installed-skills.json
Store schema: { "version": 1, "installed": [ ...InstalledSkillRecord ] } — manifests are validated on every read.

Scope

What this does
  • Local skill registry with 4 built-in skills and extensible install store
  • SHA256 checksum verification for all non-builtin skills before execution
  • Manifest-level permission gates for network, filesystem, secrets, shell
  • 7 MCP tools: discover, inspect, install, list, uninstall, run, and cache-check
  • Durable versioned JSON store with configurable local path
  • Optional remote registry merging via registry_url at query time
  • In-process skill cache for fast repeated execution within a session
  • Published to npm as @certaworks/agent-skill-marketplace-plugin
What this does not do
  • No public marketplace network, accounts, ratings, or payments
  • No hosted registry moderation or install analytics
  • No OS-level sandboxing — permission gates are manifest checks, not process isolation
  • No signed publisher identity or certificate chain for remote skills
  • No remote registry caching — remote merges happen on-demand each call

Run it locally in under 5 minutes

Agent Skill Marketplace Plugin ships as a local MCP server. No hosted endpoint required to get started.

Once running locally, agents can call `list_skills`, `install_skill`, and `run_skill` to discover and execute trusted skills from the local registry.

View on npm →
npm package
npm install -g @certaworks/agent-skill-marketplace-plugin
Claude Desktop config
{
  "mcpServers": {
    "agent-skill-marketplace-plugin": {
      "command": "npx",
      "args": ["-y", "@certaworks/agent-skill-marketplace-plugin"]
    }
  }
}

Early Access

Build your skill registry

Get early access to Agent Skill Marketplace Plugin — local-first, checksum-verified capability management for agents that need to trust what they run.

← Product 06: Cognitive Memory Next: Product 08 Audit & Replay Logger →