agent-skills-discovery-rfc — security grade SAFE, quality 68/100

Security audit verdict: SAFE · quality 68/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by cloudflare · Agent Tool · ★ 345

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is agent-skills-discovery-rfc safe to install? View the security audit →

About agent-skills-discovery-rfc

Agent Skills Discovery via Well-Known URIs Status: Draft Version: 0.2.0 Published Date: 2026-01-17 Updated Date: 2026-03-12 Table of Contents Abstract Changelog Terminology Problem Solution URI Structure Skill Directory Contents Progressive Disclosure Discovery Index Integrity and Verification Archive Distribution Examples HTTP Considerations Client Implementation Security Considerations Relationship to Existing Specifications References Abstract This document defines a mechanism for discovering Agent Skills using the URI path prefix as specified in RFC 8615. Skills are currently scattered across GitHub repositories, documentation sites, and other sources. A well-known URI provides a predictable location for agents and tools to discover skills published by an organization or project. Changelog v0.2.0 rename well-known URI from to replace field with URI (

agent-skillsagentsrfc8615skills

Quick Facts

Stars345
Forks21
CategoryAgent Tool
LicenseApache-2.0
Quality Score67.9819053566817/100
Open Issues7
Last Updated2026-04-23
Created2026-01-21
Est. Tokens~3k

agent-skills-discovery-rfc alternative? Top 6 similar tools

Looking for a agent-skills-discovery-rfc alternative? If you're comparing agent-skills-discovery-rfc with other agent tool tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • skillkit by rohitg00 · ⭐ 1.5k

    Supercharge AI coding agents with portable skills. Install, translate & share skills across Claude Code, Curso

  • claude-workflow-v2 by CloudAI-X · ⭐ 1.4k

    Universal Claude Code workflow plugin with agents, skills, hooks, and commands

  • mcp-gateway-registry by agentic-community · ⭐ 939

    Enterprise-ready MCP Gateway & Registry that centralizes AI development tools with secure OAuth authentication

  • copilot-mcp by VikashLoomba · ⭐ 506

    A VSCode extension that lets you find and install Agent Skills and MCP Apps to use with GitHub Copilot, Claude

  • agents by astronomer · ⭐ 445

    AI agent tooling for data engineering workflows.

  • skillport by gotalab · ⭐ 406

    Bring Agent Skills to Any AI Agent and Coding Agent — via CLI or MCP. Manage once, serve anywhere.

More Agent Tool Tools

Explore other popular agent tool tools:

View all Agent Tool tools →

Frequently Asked Questions

What is agent-skills-discovery-rfc?

agent-skills-discovery-rfc is A mechanism for discovering Agent Skills using the .well-known URI path prefix as specified in RFC 8615 for discovering Agent Skills.. It is categorized as a Agent Tool with 345 GitHub stars.

How do I install or use agent-skills-discovery-rfc?

You can find installation instructions and usage details in the agent-skills-discovery-rfc GitHub repository at github.com/cloudflare/agent-skills-discovery-rfc. The project has 345 stars and 21 forks, indicating an active community.

What license does agent-skills-discovery-rfc use?

agent-skills-discovery-rfc is released under the Apache-2.0 license, making it free to use and modify according to the license terms.

What are the best alternatives to agent-skills-discovery-rfc?

The top alternatives to agent-skills-discovery-rfc on Agent Skills Hub include skillkit, claude-workflow-v2, mcp-gateway-registry. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse Agent Tool tools