Tendrilforge
A hosted marketplace and execution layer for reusable agent skills that verifies publisher identity and rights, signs immutable bundle versions, declares dependencies and capabilities, runs static and sandbox checks plus disclosed evals, and records install and execution evidence while keeping organizational assurance, provenance, test coverage, safety, buyer approval, runtime authorization, outcome, incident, revocation, and correction separate.
Agent skills can package instructions, scripts, tools, templates, and dependencies that make teams faster but also introduce prompt injection, secret access, network calls, data exfiltration, destructive actions, supply-chain compromise, license violations, and silent behavior change. Tendrilforge creates a versioned publication and evaluation record rather than calling a scanned bundle safe. A signature proves publisher and payload integrity, not quality; a sandbox run covers only a declared environment and test set; organizational controls do not attest every skill; installation is not runtime authorization; and usage is not a successful outcome. Source rights, publisher identity, bundle, dependency, capability, scan, sandbox observation, eval result, curator judgment, procurement approval, install, runtime grant, execution, destination readback, outcome, incident, withdrawal, revocation, and correction remain distinct.
A developer team, platform engineer, security or procurement owner, agent-tool vendor, or independent publisher seeking governed distribution and execution of reusable skills.
Developer platform, security, procurement, publisher, and consumer roles are concrete.
Manifests, scans, sandboxes, evals, billing, and distribution scale through code, subject to execution cost and incident support.
Two cross-references, one inbound connection, and two direct connections provide moderate corroboration.
Two cross-references, one inbound and two direct connections, a clear developer and procurement buyer, verified large-scale skill distribution and security registries, and no supplied hosted execution marketplace with the full commercial and validation layer support the direction.
A large security registry and paid distributor already exist, sandbox and scans cannot prove safety, publisher rights and licensing are hard, execution requires strong isolation and permissions, organizational assurance can be overstated, marketplace cold start and support remain unproven, incumbents can extend, and economics are unvalidated.
Discussion
No comments yet — be the first to weigh in.
