Open registry vs curated marketplace vs private registry

The three shapes an Agent Skills registry can take, what each one is actually optimising for, and which one fits a solo developer, a team and a regulated company.

Contents

Every registry of Agent Skills is one of three shapes. They get described in the same language, which hides the fact that they are optimising for different things and suit different people.

Open registry

Indexes everything it can find, usually by crawling public repositories. Coverage is the product.

Optimising for: the chance that the skill you want exists here at all.

The trade: an open index cannot vouch for what is in it by choosing, so the quality signal has to be mechanical. That means metadata: does it declare a licence, does it run scripts, does it reach the network, what did a scanner say, where did it come from. A skill page that shows only the file has moved that work onto you.

What goes wrong: duplication and noise. Roughly 47 percent of the SKILL.md files on public GitHub are byte-identical copies, so an index that has not deduplicated buries the thing you want under fifteen copies of it. And the quality floor is whatever the crawler let through.

Suits: developers who already know roughly what they want, and anyone who needs something niche enough that a curated list will not have it.

Examples: skillmd.com (ours), skillsmp.com, skills.sh, skillsdirectory.com.

Curated marketplace

A person chose the contents. Usually a few hundred entries rather than hundreds of thousands.

Optimising for: the first ten minutes. It answers “what should I use” instead of “does this exist”.

The trade: coverage. If your problem is unusual, a curated list will not have it, and a curated list that grew to a million entries would no longer be curated.

What goes wrong: curation is invisible work with no obvious funding, so the list goes stale quietly. A curated marketplace that has not moved in six months is worse than an open index, because staleness looks like selectivity.

Suits: people new to skills, and anyone who would rather read twenty good options than search eight hundred thousand.

Examples: agenticskills.io, explainx.ai/skills, the curated sections of larger marketplaces.

Private registry

Your organisation runs it, for skills it does not publish.

Optimising for: control. Versioning, access control, an audit trail, and a review gate before a skill reaches anyone’s agent.

The trade: it only contains what you put in it. A private registry is a distribution mechanism, not a source, so you still need somewhere to get skills from.

What goes wrong: it becomes the place skills go to be forgotten unless someone owns keeping it current.

Suits: teams with skills encoding internal process, and any company where “an engineer pasted an unlicensed instruction file into the repository” is a compliance problem rather than a shrug.

Examples: JFrog Agent Skills Registry, TrueFoundry, Portkey, localskills.sh.

Choosing

Open registryCurated marketplacePrivate registry
SizeVery largeHundredsWhatever you add
Quality signalMechanical: flags, licence, scansEditorial judgementYour own review
Finds niche skillsYesNoNo
Internal skillsNoNoYes
Staleness riskLowHighMedium
CostFreeFreePaid or self-hosted

Solo developer. Open registry, with a curated list as a starting point. A private registry solves a problem you do not have.

Small team. Open registry plus a shared project directory checked into the repository. .claude/skills/ in git is a private registry that costs nothing, and it is enough until someone needs access control.

Company with a compliance function. Private registry for internal skills, open registry as the upstream source, and a policy about what may cross between them. The licence question is the one to write the policy around: 83.4 percent of public Agent Skills declare no licence at all, which is the part most procurement processes already prohibit without realising it applies here.

The thing all three share

None of them own the format. Agent Skills are an open standard published at agentskills.io and stewarded through the Agentic AI Foundation, a Linux Foundation body co-founded by Anthropic, OpenAI and Block with over 170 member organisations.

That is worth knowing before you commit to any of these. A SKILL.md is a text file in a documented format, and moving a hundred of them between an open registry, a curated list and something you host yourself is a file copy. There is no lock-in to worry about, which means the decision is reversible and not worth agonising over.

If you want the specific sites rather than the categories, the agent skills directory landscape has the full table. If you have chosen a shape and now want to judge an individual registry, how to evaluate a skills registry is the checklist.

Frequently asked questions

What is an open skills registry?

An index that lists every Agent Skill it can find, usually by crawling public repositories, and filters by checking rather than by choosing. Breadth is the product, and the quality signal has to come from metadata such as capability flags, licence and audit results.

What is a curated skills marketplace?

A much smaller list where a human decided what goes in. You trade coverage for the assurance that someone looked. It answers 'what should I use' rather than 'does this exist'.

What is a private skills registry?

A registry your organisation runs for skills it does not publish, with versioning, access control and an audit trail. Vendors in this space include JFrog, TrueFoundry and Portkey, and there are self-hosted options.

Can you use more than one?

Yes, and most teams end up doing it. A private registry for internal skills, an open registry for everything else, and a curated list as a starting point when nobody knows what to look for.