{"_id":"@certaworks/agent-skill-marketplace-plugin","name":"@certaworks/agent-skill-marketplace-plugin","dist-tags":{"latest":"0.1.0"},"versions":{"0.1.0":{"name":"@certaworks/agent-skill-marketplace-plugin","version":"0.1.0","description":"Discover, verify, install, and run trusted local agent skills through an SDK and MCP plugin.","type":"module","main":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./mcp":{"types":"./dist/mcp/server.d.ts","import":"./dist/mcp/server.js"}},"bin":{"agent-skill-marketplace-mcp":"dist/mcp/server.js"},"scripts":{"build":"tsc","typecheck":"tsc --noEmit","test":"npm run build && vitest run","test:unit":"vitest run","mcp":"node dist/mcp/server.js"},"devDependencies":{"@types/node":"^22.0.0","tsx":"^4.19.0","typescript":"^5.8.0","vitest":"^3.2.0"},"engines":{"node":">=18"},"license":"MIT","author":{"name":"CertaWorks Labs LLC"},"homepage":"https://certaworks.dev","bugs":{"url":"https://github.com/plantBase369/certaworks-site/issues","email":"blair.hall@certaworks.dev"},"repository":{"type":"git","url":"git+https://github.com/plantBase369/certaworks-site.git"},"publishConfig":{"access":"public"},"keywords":["certaworks","mcp","ai-agent","agent-safety","skill-marketplace","plugin","agent-skills"],"_id":"@certaworks/agent-skill-marketplace-plugin@0.1.0","_nodeVersion":"24.11.1","_npmVersion":"11.6.2","dist":{"integrity":"sha512-fVs/gX4HaB4m1asH0bAwdEmnymvh8I5dmy2xgc2c0C2+YhClSCknx8ZB6gkAUqatX4uA5LjKXCwAo+BscgWuFA==","shasum":"60e92213ab1bb8aab537666cdb7d9f43061a640e","tarball":"https://registry.npmjs.org/@certaworks/agent-skill-marketplace-plugin/-/agent-skill-marketplace-plugin-0.1.0.tgz","fileCount":14,"unpackedSize":62814,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIDBX6o4LlPbfIRb3XzxCKi+Iu1FOB6aXEZHhe3WPnLkpAiACYCMEhdEumHd5DrSjvCDtkW9BiAV3mNahTIOkXOBlGw=="}]},"_npmUser":{"name":"blairhall","email":"Blair.Hall@certaworks.dev"},"directories":{},"maintainers":[{"name":"blairhall","email":"Blair.Hall@certaworks.dev"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/agent-skill-marketplace-plugin_0.1.0_1779947834423_0.8124425925844896"},"_hasShrinkwrap":false}},"time":{"created":"2026-05-28T05:57:14.170Z","0.1.0":"2026-05-28T05:57:14.564Z","modified":"2026-05-28T05:57:14.809Z"},"maintainers":[{"name":"blairhall","email":"Blair.Hall@certaworks.dev"}],"description":"Discover, verify, install, and run trusted local agent skills through an SDK and MCP plugin.","homepage":"https://certaworks.dev","keywords":["certaworks","mcp","ai-agent","agent-safety","skill-marketplace","plugin","agent-skills"],"repository":{"type":"git","url":"git+https://github.com/plantBase369/certaworks-site.git"},"author":{"name":"CertaWorks Labs LLC"},"bugs":{"url":"https://github.com/plantBase369/certaworks-site/issues","email":"blair.hall@certaworks.dev"},"license":"MIT","readme":"# Agent Skill Marketplace Plugin\n\n**Type:** Local SDK / MCP Plugin\n\n**Value:** Lets agents discover, inspect, install, verify, and run trusted skills from a local registry-style capability layer.\n\n## Current Status\n\nComplete as a local SDK / MCP plugin slice. It supports a local registry, durable installed-skill manifests, checksum verification, and permission-gated local execution.\n\n## Shipped Local Scope\n\n- Built-in starter registry with `format-json`, `word-count`, `base64`, and `timestamp`\n- SDK APIs for discovery, manifest validation, install, uninstall, load, run, and cache inspection\n- Durable local installed-skill store with configurable path\n- Local `file:` skill loading and HTTPS skill loading with SHA256 checksum verification\n- Permission gates for declared skill permissions: `network`, `filesystem`, `secrets`, `shell`, `none`\n- MCP tools for listing, inspecting, installing, uninstalling, and running skills\n- Package bin and subpath exports for running the MCP server locally\n\n## Install And Run\n\n```bash\nnpm install\nnpm test\nnpm run mcp\n```\n\nAfter build, the package exposes:\n\n```bash\nagent-skill-marketplace-mcp\n```\n\nMCP client configuration can point at the built server:\n\n```json\n{\n  \"mcpServers\": {\n    \"agent-skill-marketplace\": {\n      \"command\": \"node\",\n      \"args\": [\"dist/mcp/server.js\"],\n      \"env\": {\n        \"AGENT_SKILL_MARKETPLACE_STORE_PATH\": \"./.agent-skill-marketplace/installed-skills.json\"\n      }\n    }\n  }\n}\n```\n\n## Local Store\n\nBy default, installed skill manifests are stored at:\n\n```text\n.agent-skill-marketplace/installed-skills.json\n```\n\nOverride with either:\n\n```bash\nAGENT_SKILL_MARKETPLACE_STORE_PATH=/path/to/installed-skills.json\nAGENT_SKILL_MARKETPLACE_STORE=/path/to/installed-skills.json\n```\n\nThe store is versioned JSON:\n\n```json\n{\n  \"version\": 1,\n  \"installed\": []\n}\n```\n\n## SDK Surface\n\n```ts\nimport {\n  installSkill,\n  listSkills,\n  runSkill,\n  uninstallSkill\n} from '@blair/agent-skill-marketplace';\n\nconst manifest = {\n  id: 'upper-case',\n  name: 'Upper Case',\n  version: '1.0.0',\n  description: 'Uppercase local text.',\n  author: 'CertaWorks',\n  permissions: ['none'],\n  url: 'file:///absolute/path/upper-case.mjs',\n  checksum: '64-character-sha256-hex-digest',\n  tags: ['text', 'local']\n};\n\nawait installSkill(manifest, { storePath: './installed-skills.json' });\nconst skills = await listSkills({ query: 'upper', storePath: './installed-skills.json' });\nconst result = await runSkill('upper-case', { text: 'ship it' }, [], { storePath: './installed-skills.json' });\nawait uninstallSkill('upper-case', { storePath: './installed-skills.json' });\n```\n\n## Manifest Format\n\n```ts\ntype SkillPermission = 'network' | 'filesystem' | 'secrets' | 'shell' | 'none';\n\ninterface SkillManifest {\n  id: string;\n  name: string;\n  version: string;\n  description: string;\n  author: string;\n  permissions: SkillPermission[];\n  url: string;\n  checksum: string;\n  tags: string[];\n  loaderVersion?: string;\n}\n```\n\nInstalled manifests are validated before they are persisted. Skill code is read only at load/run time and must match the manifest checksum. A manifest that declares permissions other than `none` requires explicit permission grants at runtime.\n\n## MCP Tools\n\n- `list_skills`\n- `skill_info`\n- `install_skill`\n- `installed_skills`\n- `uninstall_skill`\n- `run_skill`\n- `loaded_skills`\n\n## Current Limits\n\n- This is a local product slice, not a public marketplace network.\n- There is no public npm publication, live checkout, accounts, ratings, payments, take-rate billing, hosted registry moderation, or hosted install analytics.\n- Permission checks are manifest gates, not a sandbox. Remote or local skill code still executes inside the current Node process.\n- HTTPS remote skills are checksum-verified, but remote registry caching and signed publisher identity are future work.\n- Prefer `file:` skills or pinned immutable HTTPS URLs for local testing.\n\n## Verification\n\nFresh suite verification on 2026-05-28:\n\n- `npm test` passed, 33/33 tests across the registry, marketplace install, MCP, and package contract suites.\n- `npm run build` passes.\n- Package dry-run verifies only runtime artifacts and README are included.\n","readmeFilename":"README.md","_rev":"1-4dbb5167a60094649f4f71f3c2033d0a"}