- 01AddZIP · GitHub · connected clientDraft created
- 02ValidateSKILL.md · paths · package limitsStructure checked
- 03ScanExact package · security policyRequired
- 04ReviewPersonal release or team decisionNext
- 05ReadyImmutable approved versionAfter approval
- 06InstallGrant · signed ZIP · checksumTo your clients
[ source → review → install ]
One controlled path from SKILL.md to every AI client.
Add an existing skill, verify the exact package, approve the version and distribute only what each person or client is allowed to use.
Start with a free Personal Vault. Create a company vault only when sharing and approval become part of the job.
01 / The complete release
Every state is visible. Every transition has a reason.
The web app is the governance console. Your AI clients are where people discover, request, review and install the approved result.
Read the version model- 01
Add the skill you already have
Upload a ZIP, scan a public GitHub repository or ask a connected client to save a complete package. Every route starts as a Draft.
SKILL.md required references/ included assets/ includedDraft · v1.5 - 02
Validate the package boundary
Installskills checks the manifest, frontmatter, names, paths, sizes and file inventory without executing the package.
SKILL.md found kebab-case name safe relative paths package limits passed - 03
Test the Draft privately, if needed
The author can prepare a short-lived test package before release. It stays Unreviewed, author-only and outside collections and update checks.
Author receiptDraft test package readybrand-review · v1.5Unreviewed · author only · expires in 15 min - 04
Scan the exact version
The security gate is tied to the package hash. A changed file invalidates the old result, and high or critical risk cannot continue.
package hash trusted scan risk gate - 05
Release personally or route to review
Personal Vault owners release after the trusted gate. Team and Enterprise versions wait for an authorized reviewer and keep the exact report attached.
Personal VaultOwner releaseMedium risk requires acknowledgementTeam / EnterpriseHuman reviewApprove or return for changes - 06
Grant access and install the Ready version
Approved content becomes immutable. Connected clients see only accessible skills and receive a version-pinned signed ZIP, checksum and expiry.
Readybrand-review · v1.5workspace grant · checksum verified
02 / One control model
Govern in the web app. Work from your clients.
Installskills web app
- Import sources and organize collections
- Inspect exact security reports
- Approve versions and assign access
- Review activity and workspace policy
Connected AI clients
Discover, request, decide, download and check updates within the caller's real permissions.
03 / Release boundaries
A Ready label must be earned.
Package state, security evidence and access are separate controls. Passing one never silently bypasses another.
Ready when your first skill is
Start personal. Add company control when the workflow needs it.
No sales call is required to complete the first Draft → Ready → install loop.