Governed capability control plane
Every capability your agents can use — signed, scanned, and accounted for.
Skillfile turns the skills and MCP tools your AI agents reach for into signed .skill manifests: scanned for risk, optimized for every agent, approved by a human, and tracked from first session to production.
Connect a repo → generate a manifest in < 10 minutes.
repository.readRead source for refactor contextrepository.writeApply edits to working treeproduction.deployPush to prod — denied by policypolicy org/default-agent-policy@4
The problem
Agent access is growing faster than anyone can review it.
Skills, MCP tools, and shell scripts land in .mcp.json, .cursorrules, and env vars — ungoverned, unscanned, invisible to the people accountable for them.
Today — scattered
- Skills copied from marketplaces, unverified
- Permissions buried across five config formats
- No record of who approved what, or when
- Same skill re-tuned by hand for each agent
With Skillfile — one ledger
- Every capability a signed, scanned manifest
- One
.skillfile, optimized for every agent - Human approval with a full chain of custody
- Live updates synced back as your team works
The lifecycle
Six steps, one place.
Scanner verdict
2 permissions narrowed to human-gate. No secret access. No external egress.
Approval timeline
- Approvedby m.reyes · 2h ago
- Scannedverdict: needs review
- Submittedvia repo scan
Audit row
actor m.reyes
SF-2026-0042 → synced
policy@4 · sha256:9f3a…
An open standard
One portable manifest, readable by every agent.
The .skill spec is public and versioned. Own your capabilities in a format no single vendor controls — Skillfile is the control plane on top.
Start with a free audit.
See every ungoverned capability your agents already have — in one signed report.