Skip to main content

Skills Marketplace

Settings → Skills searches public Agent Skills catalogs and installs from them. Three kinds of package arrive through it, and each lands in its own directory:

KindInstalls intoWhat it is
skillskills/Instructions the agent reads. See Skills
agent-pluginplugins/Skills and MCP servers together. See Agent Plugins
connectorconnector-packages/Declared operations against one API. See Data Connectors

A row published before the kinds existed carries none, and nanoinfra reads that as a skill, because those rows are skills.

Two catalogs​

ProviderSource
skills_shthe public skills.sh catalog
nanoinfrathe nanoinfra skills-server, which adds a submission pipeline, a security scan and versioning

The default searches both. One key points the second at a different deployment:

{
"skillsMarketplace": {
"nanoinfraBaseUrl": "https://skills.internal.example.com"
}
}

Point it at your own skills-server to serve an internal catalog instead of the public one.

What a catalog is trusted with​

This is the part worth reading before you install anything.

A skill is instructions the agent reads and acts on. A connector declares requests your deployment will make with a live credential. An Agent Plugin can ship an mcp.json, and enabling that grants a new stdio process. So the catalog you point this at is a supply chain, and nanoinfraBaseUrl decides whose.

Three things bound what an install can do:

  • The download is DNS-pinned. The fetch runs through PinnedDNSAsyncTransport. So the host that answered resolution is the host the bytes come from, and a redirect cannot move the download to another origin.
  • Extraction is validated, entry by entry — on the nanoinfra path. Every entry of a skills-server archive is checked before anything is written. Zip-slip, absolute and traversal paths are refused. So are symlinks and duplicate paths. A file-count cap and an unpacked-size cap are enforced too, so an archive that expands to fill the disk is refused rather than unpacked. This does not describe the skills_sh path, which installs through the separate npx skills CLI and handles its own extraction.
  • Installing is not activating. A downloaded Agent Plugin does nothing until its identity is in tools.agentPlugins. A connector does nothing until it is in connectors.active. Both are git-reviewed files. Installing puts a package on disk. A person still decides whether it runs.

The admin review screen shows four things per package. The capability class of every operation. The hosts a token could reach. The scopes it would carry. And a runs code mark on an Agent Plugin's MCP servers.