Public API
Everything the directory and the CLI show comes from a public, read-only JSON API. No account and no key are needed. The base URL is:
https://api.skillpass.devEvery response is an envelope. A success carries "success": true and the payload in data; a failure carries "success": false and a message in error, with a matching HTTP status.
{ "success": true, "data": <payload> }
{ "success": false, "error": "not found" }The API only answers browser requests from skillpass.dev, so another site's front end cannot call it directly. Call it from a server, a script, or the CLI.
The Skill Passport
The passport is the public, immutable validation record generated for each published version. It arrives asdata.passport on the skill and version endpoints below. Permission keys are listed with their meanings in the permission taxonomy.
| Field | Type | Meaning |
|---|---|---|
schemaVersion | "0.1" | Passport format version. |
validationStatus | "passed" | "warning" | "failed" | Overall validation result for this version. |
riskLevel | "low" | "medium" | "high" | "critical" | Risk level the validator assigned to this version. |
permissionsSummary | { declared: string[], detected: string[] } | Permission keys the manifest declares and the ones the validator detected in the files. A gap between the two is itself a signal. |
warningsSummary | { code, message, location? }[] | Advisory findings. location is { path, line?, snippet? } when the finding points at a file. |
distribution | "skill" | "cli" | "system" | How the listing is obtained; the skill page uses it to pick the install call to action. |
homepage | string (URL), optional | Homepage from skill.json, if the author gave one. |
install | string, optional | Install instruction from skill.json, if the author gave one. |
manifestInferred | boolean | True when there was no skill.json and the manifest was built from SKILL.md, so permissions were inferred rather than declared. |
sourceHash | string | Hash of the exact files that were validated, as "sha256:<hex>". Downloads and the CLI check against it. |
resolvedCommitSha | string, optional | Git commit a GitHub submission was pinned to. Missing for zip uploads. |
engineVersion | string | Version of the validator that produced the passport. |
generatedAt | string (ISO 8601) | When the passport was generated. |
signature | string, optional | Not set today. |
An example passport, from the pdf skill:
{
"schemaVersion": "0.1",
"validationStatus": "passed",
"riskLevel": "low",
"permissionsSummary": {
"declared": [],
"detected": [
"shell.execute"
]
},
"warningsSummary": [],
"distribution": "skill",
"manifestInferred": true,
"sourceHash": "sha256:6a01b6dc757b8856d7eba5e9985d8550783f946d7afdf86402ba324b93239fc0",
"resolvedCommitSha": "fa0fa64bdc967915dc8399e803be67759e1e62b8",
"engineVersion": "0.1.0",
"generatedAt": "2026-07-21T17:18:10.773Z"
}List skills
GET /skills
curl https://api.skillpass.dev/skillsEvery published skill in one array, with no pagination. Featured listings come first in their curated order, then everything else, newest first. Each item is a summary:
| Field | Type | Meaning |
|---|---|---|
slug | string | Directory identifier, used in every per-skill path. |
name | string | Skill name from the package. |
summary | string | Description from the package. |
targets | ("codex" | "claude-code" | "cursor" | "cowork" | "aider")[] | Agent tools the skill declares. |
validationStatus | "passed" | "warning" | "failed" | Validation result of the latest published version. |
riskLevel | "low" | "medium" | "high" | "critical" | Risk level of the latest published version. |
noteCount | integer, optional | Number of advisory findings on the latest version. |
category | string | null, optional | One of 12 browse category slugs, such as "security-review". Null until classified. |
displayName | string | null, optional | Display name written at publish. Null until generated. |
tagline | string | null, optional | One-line tagline written at publish. Null until generated. |
integrations | string[] | null, optional | Services the skill works with, from 18 integration slugs such as "github". Null when never classified, empty when none. |
packSkills | string[] | null, optional | Member skill names when the listing is a multi-skill pack. Null for a single skill. |
version | string | Latest published version, as semver. |
maintainer | string | GitHub login of the account that listed the skill. |
attributedTo | string | null | GitHub login of the source repo owner when someone else listed the skill. Null otherwise. |
featured | boolean | On the curated Featured list. |
verified | boolean | Admin-set curation flag. Every curated listing carries it, so it does not by itself mean first-party. |
publishedAt | string (ISO 8601) | When the latest version was published. |
{
"success": true,
"data": [
{
"slug": "pdf",
"name": "pdf",
"summary": "Use this skill whenever the user wants to do anything with PDF files.",
"targets": [
"claude-code",
"codex"
],
"validationStatus": "passed",
"riskLevel": "low",
"noteCount": 0,
"category": "docs-writing",
"displayName": "PDF Processing",
"tagline": "Read, extract, merge, split, transform, and create PDF files.",
"integrations": [
"pdf"
],
"packSkills": null,
"version": "1.0.0",
"maintainer": "bradtraversy",
"attributedTo": "anthropics",
"featured": true,
"verified": true,
"publishedAt": "2026-07-21T17:18:10.773Z"
}
]
}Get a skill
GET /skills/:slug
curl https://api.skillpass.dev/skills/pdfThe latest published version: every summary field above, plus these. A slug that is not published returns 404.
| Field | Type | Meaning |
|---|---|---|
packMembers | { name, description?, entry, targets?, permissions?, variants? }[] | null, optional | Full member entries for a pack, including per-target variant paths. Null for a single skill. |
githubRepoUrl | string | null | Source repository URL for GitHub submissions. Null for zip uploads. |
passport | SkillPassport | The Skill Passport for this version (see above). |
maintainerInfo | { username, displayName, avatarUrl } | Public profile of the maintainer. |
versions | Version[] | Every published version, newest first. |
aiReview | { summary, verdict, reasoning, model, reviewedAt } | null | The AI review of this version's files; verdict is "clear" | "caution" | "concern". Advisory, never a guarantee. Null until generated. |
Each versions entry:
| Field | Type | Meaning |
|---|---|---|
version | string | The version, as semver. |
validationStatus | "passed" | "warning" | "failed" | Validation result of this version. |
riskLevel | "low" | "medium" | "high" | "critical" | Risk level of this version. |
publishedAt | string (ISO 8601) | When this version was published. |
{
"success": true,
"data": {
"slug": "pdf",
"name": "pdf",
"summary": "Use this skill whenever the user wants to do anything with PDF files.",
"targets": [
"claude-code",
"codex"
],
"validationStatus": "passed",
"riskLevel": "low",
"noteCount": 0,
"category": "docs-writing",
"displayName": "PDF Processing",
"tagline": "Read, extract, merge, split, transform, and create PDF files.",
"integrations": [
"pdf"
],
"packSkills": null,
"version": "1.0.0",
"maintainer": "bradtraversy",
"attributedTo": "anthropics",
"featured": true,
"verified": true,
"publishedAt": "2026-07-21T17:18:10.773Z",
"packMembers": null,
"githubRepoUrl": "https://github.com/anthropics/skills/tree/main/skills/pdf",
"passport": {
"schemaVersion": "0.1",
"validationStatus": "passed",
"riskLevel": "low",
"permissionsSummary": {
"declared": [],
"detected": [
"shell.execute"
]
},
"warningsSummary": [],
"distribution": "skill",
"manifestInferred": true,
"sourceHash": "sha256:6a01b6dc757b8856d7eba5e9985d8550783f946d7afdf86402ba324b93239fc0",
"resolvedCommitSha": "fa0fa64bdc967915dc8399e803be67759e1e62b8",
"engineVersion": "0.1.0",
"generatedAt": "2026-07-21T17:18:10.773Z"
},
"maintainerInfo": {
"username": "bradtraversy",
"displayName": "Brad Traversy",
"avatarUrl": "https://avatars.githubusercontent.com/u/5550850?v=4"
},
"versions": [
{
"version": "1.0.0",
"validationStatus": "passed",
"riskLevel": "low",
"publishedAt": "2026-07-21T17:18:10.773Z"
}
],
"aiReview": {
"summary": "A skill for common PDF operations: reading, extracting text and tables, merging, splitting, and OCR.",
"verdict": "caution",
"reasoning": "The skill documents command-line tools that run external processes, so review its scripts first.",
"model": "claude-haiku-4-5",
"reviewedAt": "2026-07-26T13:17:38.386Z"
}
}
}Get a pinned version
GET /skills/:slug/:version
curl https://api.skillpass.dev/skills/pdf/1.0.0The same shape as the skill endpoint, with the version, status, risk, and passport of the requested version instead of the latest. An unknown version returns 404.
Pre-flight
GET /skills/:slug/:version/preflight
curl https://api.skillpass.dev/skills/pdf/1.0.0/preflightThe check the CLI runs before every install: the pinned verdict, the source hash re-verified against the stored snapshot, and the permission changes since the previous version.
| Field | Type | Meaning |
|---|---|---|
version | string | The pinned version. |
validationStatus | "passed" | "warning" | "failed" | Validation result of the pinned version. |
riskLevel | "low" | "medium" | "high" | "critical" | Risk level of the pinned version. |
sourceHash | string | The pinned source hash from the passport. |
sourceVerified | boolean | True when the stored snapshot still hashes to sourceHash. |
resolvedCommitSha | string | null | Git commit a GitHub submission was pinned to. Null for zip uploads. |
generatedAt | string (ISO 8601) | When the passport was generated. |
permissions | { declared: string[], detected: string[] } | Declared and detected permission keys. |
diff | { previousVersion, declared: { added, removed }, detected: { added, removed } } | null | Permission changes against the previous published version. Null for the first version. |
blocked | boolean | True when validation failed; the download route refuses it. |
blockedReason | string | null | Why the version is blocked. Null when not blocked. |
{
"success": true,
"data": {
"version": "1.0.0",
"validationStatus": "passed",
"riskLevel": "low",
"sourceHash": "sha256:6a01b6dc757b8856d7eba5e9985d8550783f946d7afdf86402ba324b93239fc0",
"sourceVerified": true,
"resolvedCommitSha": "fa0fa64bdc967915dc8399e803be67759e1e62b8",
"generatedAt": "2026-07-21T17:18:10.773Z",
"permissions": {
"declared": [],
"detected": [
"shell.execute"
]
},
"diff": null,
"blocked": false,
"blockedReason": null
}
}Search
GET /skills/search?q=<query>
curl -G https://api.skillpass.dev/skills/search --data-urlencode "q=fill in a PDF form"Semantic search: the query is embedded and matched against every published skill. q must be 1 to 500 characters. The response is the same summary array as the list endpoint, up to 20 skills ordered by similarity. There is no relevance cutoff, so the 20 closest skills come back even when none is a strong match.
Errors and rate limits
Of these endpoints, only search is rate limited, at 20 requests per minute per client IP. Every failure uses the envelope above with one of these statuses:
| Status | When | error |
|---|---|---|
400 | Search q is missing or longer than 500 characters | q must be 1-500 characters |
404 | The slug is not a published skill, or the version does not exist | not found |
429 | More than 20 searches in a minute from one IP | Too many requests, slow down. |
500 | Unexpected server error | internal error |
502 | Pre-flight could not read the stored snapshot | could not fetch the source snapshot; try again |
502 | Search could not embed the query | AI search is temporarily unavailable |
503 | AI search is not configured on the server | AI search is not configured |
Compatibility
New fields can appear in any response, so ignore keys you do not recognize. Fields marked optional can be missing entirely. Fields typed with null are always present but can be null.