SuperSkill how it worksmanagementwhat's MCP?
A skill management system for teams

One skill to rule them all.

SuperSkill gives your company one private, vetted catalog of AI skills — your internal tools and the public ones you trust — served to each team with role-based access. Every skill is checked before it's published, so nothing from an unknown source reaches your agents.

Try it yourself — connect your agent to the live catalog
open · self-hosted · fully SEP-2640 compliant
PUBLISHEDERP Assistantinternal

Reviewed and published to the catalog — ready for every team.

PUBLISHEDGitHub Reviewerpublic

A trusted public skill, vetted and added to your catalog.

BLOCKEDMeeting Summarizerprompt injection

Hidden instructions told the agent to ignore its rules and leak the conversation.

BLOCKEDCrypto Price Botcredential theft

Read local API keys and .env files, then called out to an unknown host.

BLOCKEDAnalytics Helpersilent telemetry

Shipped usage and file contents to a third-party endpoint no one approved.

BLOCKEDPDF Toolkit+malicious dependency

Pulls in a package already flagged as malware.

One vetted catalog for every skill your company runs — no more unknown sources.

How it works
1

Build the catalog

Add your internal tools — your ERP assistant, your deploy scripts — alongside the public skills you trust. One source of truth for the whole company.

2

Everything gets vetted

Before a skill is published, SuperSkill scans it and runs it in a sealed sandbox. A skill that misbehaves never makes it in.

3

Teams pull from one source

Request a skill, and once it's cleared it's in the catalog — the agent pulls it straight from there, with no GitHub and no unvetted code.

Every skill, fully checked

Nothing ships until it clears the full gauntlet

Five independent checks run on every skill before it reaches the catalog — and every finding is mapped to the standards your security team already works in.

Static analysis

Reads the code for risky behavior and the capabilities it asks for.

Dependencies

Scans every package it pulls in against known-bad advisories.

Threat feeds

Matches live indicators of attacks seen in the wild.

Sandbox

Detonates it in an isolated microVM and watches what it does.

AI review

Optional model pass for intent and hidden instructions.

Every finding is mapped to CWE, MITRE ATLAS and OWASP — so you get one clear verdict, with the full report a click away.

What never reaches your catalog

The skills people most want to install are exactly where today's attacks hide. Every skill is checked for the threats that actually matter:

Prompt injection & tool poisoning
Hidden instructions buried in a skill that hijack the agent — telling it to ignore its rules, leak a conversation, or quietly misuse another tool it has access to.
Credential & secret theft
Anything that reaches for private or sensitive data — credentials, API keys, access tokens, .env files, SSH keys, customer records.
Silent telemetry & exfiltration
A skill that quietly ships your data or usage out to a third party — telemetry no one agreed to, and the first step of a data leak.
Malicious dependencies
Supply-chain attacks hidden in the packages a skill pulls in, matched against known-bad advisories so a poisoned dependency never ships.
Remote code execution
Skills that download and run code at runtime, or shell out to do it — the classic way a harmless-looking skill turns into a foothold.
Persistence & config tampering
Anything that tries to plant itself, add a startup hook, or rewrite your agent, editor or tool configuration.
For platform & security teams

Management

Built to run for an organization. Admins get a single console to curate the catalog, review and approve skills, sign and audit, and control who sees what.

Curate the catalog

Publish your internal skills and the public ones you trust. You decide exactly what's in the catalog your company serves.

Approve on request

People ask for a skill; you review and approve in a dashboard. In enforce mode, only approved skills are ever served.

Roles & access

OAuth sign-in with roles and skill groups decides which teams see — and who can publish — which skills.

Signed & provable

Every served skill is signed, with provenance and a bill of materials, so you can prove exactly what shipped and from where.

Tamper-evident audit

A hash-chained log with an outside witness records every approval, override and revocation — it can't be quietly rewritten.

Incidents & revocation

A published skill turns out bad? Open an incident and pull it from every team at once.

Your company's trusted skill catalog.

Internal and public skills, vetted and served from one place you control. Open, self-hosted, and fully compliant with SEP-2640 — the MCP skills standard.

https://mcp.ss.domendio.com/mcp
one endpoint for Claude Code, Codex, Hermes, OpenClaw & any MCP client