Skills Marketplace
Settings → Skills searches public Agent Skills catalogs and installs from them. Three kinds of package arrive through it, and each lands in its own directory:
| Kind | Installs into | What it is |
|---|---|---|
skill | skills/ | Instructions the agent reads. See Skills |
agent-plugin | plugins/ | Skills and MCP servers together. See Agent Plugins |
connector | connector-packages/ | Declared operations against one API. See Data Connectors |
A row published before the kinds existed carries none, and nanoinfra reads that as a skill, because those rows are skills.
Two catalogs
| Provider | Source |
|---|---|
skills_sh | the public skills.sh catalog |
nanoinfra | the nanoinfra skills-server, which adds a submission pipeline, a security scan and versioning |
The default searches both. One key points the second at a different deployment:
{
"skillsMarketplace": {
"nanoinfraBaseUrl": "https://skills.internal.example.com"
}
}
Point it at your own skills-server to serve an internal catalog instead of the public one.
What a catalog is trusted with
This is the part worth reading before you install anything.
A skill is instructions the agent reads and acts on. A connector declares requests
your deployment will make with a live credential. An Agent Plugin can ship an mcp.json,
and enabling that grants a new stdio process. So the catalog you point this at is a supply
chain, and nanoinfraBaseUrl decides whose.
Three things bound what an install can do:
- The download is DNS-pinned. The fetch runs through
PinnedDNSAsyncTransport. So the host that answered resolution is the host the bytes come from, and a redirect cannot move the download to another origin. - Extraction is validated, entry by entry — on the nanoinfra path. Every entry of a
skills-server archive is checked before anything is written. Zip-slip, absolute and
traversal paths are refused. So are symlinks and duplicate paths. A file-count cap
and an unpacked-size cap are enforced too, so an archive that expands to fill the disk
is refused rather than unpacked. This does not describe the
skills_shpath, which installs through the separatenpx skillsCLI and handles its own extraction. - Installing is not activating. A downloaded Agent Plugin does nothing until its identity is
in
tools.agentPlugins. A connector does nothing until it is inconnectors.active. Both are git-reviewed files. Installing puts a package on disk. A person still decides whether it runs.
The admin review screen shows four things per package. The capability class of every
operation. The hosts a token could reach. The scopes it would carry. And a runs code
mark on an Agent Plugin's MCP servers.
Related
- Agent Plugins — the package format, and why activation is bound to content rather than to a path
- Data Connectors — what a connector declares, and what the gate reads from it
- Capability Gates — what any of it meets when it acts
- Configuration — the field