SkillPass

Public API

Everything the directory and the CLI show comes from a public, read-only JSON API. No account and no key are needed. The base URL is:

https://api.skillpass.dev

Every response is an envelope. A success carries "success": true and the payload in data; a failure carries "success": false and a message in error, with a matching HTTP status.

{ "success": true, "data": <payload> }
{ "success": false, "error": "not found" }

The API only answers browser requests from skillpass.dev, so another site's front end cannot call it directly. Call it from a server, a script, or the CLI.

The Skill Passport

The passport is the public, immutable validation record generated for each published version. It arrives asdata.passport on the skill and version endpoints below. Permission keys are listed with their meanings in the permission taxonomy.

FieldTypeMeaning
schemaVersion"0.1"Passport format version.
validationStatus"passed" | "warning" | "failed"Overall validation result for this version.
riskLevel"low" | "medium" | "high" | "critical"Risk level the validator assigned to this version.
permissionsSummary{ declared: string[], detected: string[] }Permission keys the manifest declares and the ones the validator detected in the files. A gap between the two is itself a signal.
warningsSummary{ code, message, location? }[]Advisory findings. location is { path, line?, snippet? } when the finding points at a file.
distribution"skill" | "cli" | "system"How the listing is obtained; the skill page uses it to pick the install call to action.
homepagestring (URL), optionalHomepage from skill.json, if the author gave one.
installstring, optionalInstall instruction from skill.json, if the author gave one.
manifestInferredbooleanTrue when there was no skill.json and the manifest was built from SKILL.md, so permissions were inferred rather than declared.
sourceHashstringHash of the exact files that were validated, as "sha256:<hex>". Downloads and the CLI check against it.
resolvedCommitShastring, optionalGit commit a GitHub submission was pinned to. Missing for zip uploads.
engineVersionstringVersion of the validator that produced the passport.
generatedAtstring (ISO 8601)When the passport was generated.
signaturestring, optionalNot set today.

An example passport, from the pdf skill:

{
  "schemaVersion": "0.1",
  "validationStatus": "passed",
  "riskLevel": "low",
  "permissionsSummary": {
    "declared": [],
    "detected": [
      "shell.execute"
    ]
  },
  "warningsSummary": [],
  "distribution": "skill",
  "manifestInferred": true,
  "sourceHash": "sha256:6a01b6dc757b8856d7eba5e9985d8550783f946d7afdf86402ba324b93239fc0",
  "resolvedCommitSha": "fa0fa64bdc967915dc8399e803be67759e1e62b8",
  "engineVersion": "0.1.0",
  "generatedAt": "2026-07-21T17:18:10.773Z"
}

List skills

GET /skills

curl https://api.skillpass.dev/skills

Every published skill in one array, with no pagination. Featured listings come first in their curated order, then everything else, newest first. Each item is a summary:

FieldTypeMeaning
slugstringDirectory identifier, used in every per-skill path.
namestringSkill name from the package.
summarystringDescription from the package.
targets("codex" | "claude-code" | "cursor" | "cowork" | "aider")[]Agent tools the skill declares.
validationStatus"passed" | "warning" | "failed"Validation result of the latest published version.
riskLevel"low" | "medium" | "high" | "critical"Risk level of the latest published version.
noteCountinteger, optionalNumber of advisory findings on the latest version.
categorystring | null, optionalOne of 12 browse category slugs, such as "security-review". Null until classified.
displayNamestring | null, optionalDisplay name written at publish. Null until generated.
taglinestring | null, optionalOne-line tagline written at publish. Null until generated.
integrationsstring[] | null, optionalServices the skill works with, from 18 integration slugs such as "github". Null when never classified, empty when none.
packSkillsstring[] | null, optionalMember skill names when the listing is a multi-skill pack. Null for a single skill.
versionstringLatest published version, as semver.
maintainerstringGitHub login of the account that listed the skill.
attributedTostring | nullGitHub login of the source repo owner when someone else listed the skill. Null otherwise.
featuredbooleanOn the curated Featured list.
verifiedbooleanAdmin-set curation flag. Every curated listing carries it, so it does not by itself mean first-party.
publishedAtstring (ISO 8601)When the latest version was published.
{
  "success": true,
  "data": [
    {
      "slug": "pdf",
      "name": "pdf",
      "summary": "Use this skill whenever the user wants to do anything with PDF files.",
      "targets": [
        "claude-code",
        "codex"
      ],
      "validationStatus": "passed",
      "riskLevel": "low",
      "noteCount": 0,
      "category": "docs-writing",
      "displayName": "PDF Processing",
      "tagline": "Read, extract, merge, split, transform, and create PDF files.",
      "integrations": [
        "pdf"
      ],
      "packSkills": null,
      "version": "1.0.0",
      "maintainer": "bradtraversy",
      "attributedTo": "anthropics",
      "featured": true,
      "verified": true,
      "publishedAt": "2026-07-21T17:18:10.773Z"
    }
  ]
}

Get a skill

GET /skills/:slug

curl https://api.skillpass.dev/skills/pdf

The latest published version: every summary field above, plus these. A slug that is not published returns 404.

FieldTypeMeaning
packMembers{ name, description?, entry, targets?, permissions?, variants? }[] | null, optionalFull member entries for a pack, including per-target variant paths. Null for a single skill.
githubRepoUrlstring | nullSource repository URL for GitHub submissions. Null for zip uploads.
passportSkillPassportThe Skill Passport for this version (see above).
maintainerInfo{ username, displayName, avatarUrl }Public profile of the maintainer.
versionsVersion[]Every published version, newest first.
aiReview{ summary, verdict, reasoning, model, reviewedAt } | nullThe AI review of this version's files; verdict is "clear" | "caution" | "concern". Advisory, never a guarantee. Null until generated.

Each versions entry:

FieldTypeMeaning
versionstringThe version, as semver.
validationStatus"passed" | "warning" | "failed"Validation result of this version.
riskLevel"low" | "medium" | "high" | "critical"Risk level of this version.
publishedAtstring (ISO 8601)When this version was published.
{
  "success": true,
  "data": {
    "slug": "pdf",
    "name": "pdf",
    "summary": "Use this skill whenever the user wants to do anything with PDF files.",
    "targets": [
      "claude-code",
      "codex"
    ],
    "validationStatus": "passed",
    "riskLevel": "low",
    "noteCount": 0,
    "category": "docs-writing",
    "displayName": "PDF Processing",
    "tagline": "Read, extract, merge, split, transform, and create PDF files.",
    "integrations": [
      "pdf"
    ],
    "packSkills": null,
    "version": "1.0.0",
    "maintainer": "bradtraversy",
    "attributedTo": "anthropics",
    "featured": true,
    "verified": true,
    "publishedAt": "2026-07-21T17:18:10.773Z",
    "packMembers": null,
    "githubRepoUrl": "https://github.com/anthropics/skills/tree/main/skills/pdf",
    "passport": {
      "schemaVersion": "0.1",
      "validationStatus": "passed",
      "riskLevel": "low",
      "permissionsSummary": {
        "declared": [],
        "detected": [
          "shell.execute"
        ]
      },
      "warningsSummary": [],
      "distribution": "skill",
      "manifestInferred": true,
      "sourceHash": "sha256:6a01b6dc757b8856d7eba5e9985d8550783f946d7afdf86402ba324b93239fc0",
      "resolvedCommitSha": "fa0fa64bdc967915dc8399e803be67759e1e62b8",
      "engineVersion": "0.1.0",
      "generatedAt": "2026-07-21T17:18:10.773Z"
    },
    "maintainerInfo": {
      "username": "bradtraversy",
      "displayName": "Brad Traversy",
      "avatarUrl": "https://avatars.githubusercontent.com/u/5550850?v=4"
    },
    "versions": [
      {
        "version": "1.0.0",
        "validationStatus": "passed",
        "riskLevel": "low",
        "publishedAt": "2026-07-21T17:18:10.773Z"
      }
    ],
    "aiReview": {
      "summary": "A skill for common PDF operations: reading, extracting text and tables, merging, splitting, and OCR.",
      "verdict": "caution",
      "reasoning": "The skill documents command-line tools that run external processes, so review its scripts first.",
      "model": "claude-haiku-4-5",
      "reviewedAt": "2026-07-26T13:17:38.386Z"
    }
  }
}

Get a pinned version

GET /skills/:slug/:version

curl https://api.skillpass.dev/skills/pdf/1.0.0

The same shape as the skill endpoint, with the version, status, risk, and passport of the requested version instead of the latest. An unknown version returns 404.

Pre-flight

GET /skills/:slug/:version/preflight

curl https://api.skillpass.dev/skills/pdf/1.0.0/preflight

The check the CLI runs before every install: the pinned verdict, the source hash re-verified against the stored snapshot, and the permission changes since the previous version.

FieldTypeMeaning
versionstringThe pinned version.
validationStatus"passed" | "warning" | "failed"Validation result of the pinned version.
riskLevel"low" | "medium" | "high" | "critical"Risk level of the pinned version.
sourceHashstringThe pinned source hash from the passport.
sourceVerifiedbooleanTrue when the stored snapshot still hashes to sourceHash.
resolvedCommitShastring | nullGit commit a GitHub submission was pinned to. Null for zip uploads.
generatedAtstring (ISO 8601)When the passport was generated.
permissions{ declared: string[], detected: string[] }Declared and detected permission keys.
diff{ previousVersion, declared: { added, removed }, detected: { added, removed } } | nullPermission changes against the previous published version. Null for the first version.
blockedbooleanTrue when validation failed; the download route refuses it.
blockedReasonstring | nullWhy the version is blocked. Null when not blocked.
{
  "success": true,
  "data": {
    "version": "1.0.0",
    "validationStatus": "passed",
    "riskLevel": "low",
    "sourceHash": "sha256:6a01b6dc757b8856d7eba5e9985d8550783f946d7afdf86402ba324b93239fc0",
    "sourceVerified": true,
    "resolvedCommitSha": "fa0fa64bdc967915dc8399e803be67759e1e62b8",
    "generatedAt": "2026-07-21T17:18:10.773Z",
    "permissions": {
      "declared": [],
      "detected": [
        "shell.execute"
      ]
    },
    "diff": null,
    "blocked": false,
    "blockedReason": null
  }
}

Search

GET /skills/search?q=<query>

curl -G https://api.skillpass.dev/skills/search --data-urlencode "q=fill in a PDF form"

Semantic search: the query is embedded and matched against every published skill. q must be 1 to 500 characters. The response is the same summary array as the list endpoint, up to 20 skills ordered by similarity. There is no relevance cutoff, so the 20 closest skills come back even when none is a strong match.

Errors and rate limits

Of these endpoints, only search is rate limited, at 20 requests per minute per client IP. Every failure uses the envelope above with one of these statuses:

StatusWhenerror
400Search q is missing or longer than 500 charactersq must be 1-500 characters
404The slug is not a published skill, or the version does not existnot found
429More than 20 searches in a minute from one IPToo many requests, slow down.
500Unexpected server errorinternal error
502Pre-flight could not read the stored snapshotcould not fetch the source snapshot; try again
502Search could not embed the queryAI search is temporarily unavailable
503AI search is not configured on the serverAI search is not configured

Compatibility

New fields can appear in any response, so ignore keys you do not recognize. Fields marked optional can be missing entirely. Fields typed with null are always present but can be null.