SuperSkill gives your company one private, vetted catalog of AI skills — your internal tools and the public ones you trust — served to each team with role-based access. Every skill is checked before it's published, so nothing from an unknown source reaches your agents.
Reviewed and published to the catalog — ready for every team.
A trusted public skill, vetted and added to your catalog.
Hidden instructions told the agent to ignore its rules and leak the conversation.
Read local API keys and .env files, then called out to an unknown host.
Shipped usage and file contents to a third-party endpoint no one approved.
Pulls in a package already flagged as malware.
One vetted catalog for every skill your company runs — no more unknown sources.
Add your internal tools — your ERP assistant, your deploy scripts — alongside the public skills you trust. One source of truth for the whole company.
Before a skill is published, SuperSkill scans it and runs it in a sealed sandbox. A skill that misbehaves never makes it in.
Request a skill, and once it's cleared it's in the catalog — the agent pulls it straight from there, with no GitHub and no unvetted code.
Five independent checks run on every skill before it reaches the catalog — and every finding is mapped to the standards your security team already works in.
Reads the code for risky behavior and the capabilities it asks for.
Scans every package it pulls in against known-bad advisories.
Matches live indicators of attacks seen in the wild.
Detonates it in an isolated microVM and watches what it does.
Optional model pass for intent and hidden instructions.
Every finding is mapped to CWE, MITRE ATLAS and OWASP — so you get one clear verdict, with the full report a click away.
The skills people most want to install are exactly where today's attacks hide. Every skill is checked for the threats that actually matter:
Built to run for an organization. Admins get a single console to curate the catalog, review and approve skills, sign and audit, and control who sees what.
Publish your internal skills and the public ones you trust. You decide exactly what's in the catalog your company serves.
People ask for a skill; you review and approve in a dashboard. In enforce mode, only approved skills are ever served.
OAuth sign-in with roles and skill groups decides which teams see — and who can publish — which skills.
Every served skill is signed, with provenance and a bill of materials, so you can prove exactly what shipped and from where.
A hash-chained log with an outside witness records every approval, override and revocation — it can't be quietly rewritten.
A published skill turns out bad? Open an incident and pull it from every team at once.
Internal and public skills, vetted and served from one place you control. Open, self-hosted, and fully compliant with SEP-2640 — the MCP skills standard.
https://mcp.ss.domendio.com/mcp