# Getting started with the Chainguard Skills Registry

URL: https://deploy-preview-4106--ornate-narwhal-088216.netlify.app/chainguard/agent-skills/skills-registry.md
Last Modified: September 28, 2026
Tags: Agent Skills, Overview

Enable the Chainguard Skills Registry, then upload, harden, install, and run an agent skill scoped to your organization.

The Chainguard Skills Registry lets you publish, manage, and distribute skills scoped to your organization. Use chainctl to upload original skills to uploads.cgr.dev, submit them for hardening, and install the hardened results from skills.cgr.dev.
This guide walks through enabling the registry for your organization, then uploading, hardening, installing, and running a skill. For job tracking, digest-based submissions, and browsing user folders, see Getting started with skill hardening.
Note: Chainguard Skills Registry is in beta.
Prerequisites To follow this guide, you need:
chainctl v0.2.364 or later, installed and authenticated. Check your version with chainctl version. Refer to How to install chainctl if you don&rsquo;t have it yet. An active Chainguard organization. Owner access on the organization. In the commands below, replace your-organization with your organization&rsquo;s name or UIDP (its unique identifier).
Enabling the skills entitlement Before your org can push or install skills, create a skills entitlement.
Note: You must have the owner role in your organization to create a skills entitlement and accept the Skills Registry terms of service.
chainctl skills entitlements create --parent your-organizationCreated skills entitlement for org example.dev (717b474ac6972745c5706a898aa6e67ffba97dad)The entitlements subcommands take the organization with --parent, while the other skills subcommands use --group. Omit --parent to pick the organization from an interactive list.
Next, accept the Skills Registry terms of service for your org:
chainctl skills accept-terms --group your-organizationThis opens an interactive prompt:
Chainguard Legal Agreements To continue, please review and accept the following: ▶ [ ] I agree to the Agent Skills Terms of Service https://www.chainguard.dev/legal/agent-skills [ ] I agree to the Data Privacy Agreement https://www.chainguard.dev/legal/supplemental-dpa ↑/↓ navigate • space toggle • enter confirm • q cancelPress SPACE to check each agreement, using the arrow keys to move between them, then press ENTER to confirm. The prompt doesn&rsquo;t continue until you accept both.
In CI, where no interactive terminal is available, pass --yes instead. By using --yes, you confirm that you have read and agreed to the Agent Skills Terms of Service and the Data Privacy Agreement.
Creating an example skill A skill is a directory containing a SKILL.md file. The SKILL.md frontmatter declares the skill&rsquo;s name and a description that tells an agent when to use it. The rest of the file contains the instructions the agent follows.
The next section has a few examples that refer to a skill named hello-world. You can create a sample hello-world skill with the following command:
mkdir hello-world cat &gt; hello-world/SKILL.md &lt;&lt; &#39;EOF&#39; --- name: hello-world description: A simple hello world skill. Use this to verify your skills registry setup is working end to end. --- When this skill is invoked, greet the user with: &#34;Hello from Chainguard Agent Skills! Your skill installed and loaded successfully.&#34; If the user provides their name, greet them by name instead: &#34;Hello, &lt;name&gt;! Welcome to Chainguard Agent Skills.&#34; EOFAfter running this command, your directory has the following structure:
hello-world/ └── SKILL.mdThe directory name (hello-world/) must match the name field in the frontmatter (name: hello-world). If they don&rsquo;t match, both validate and push fail.
Manage skills with chainctl This section outlines some of the chainctl commands you can use to manage skills in your organization&rsquo;s private Skills Registry. The following commands use the hello-world skill as an example, but you can use any other skills you&rsquo;ve created in its place.
Refer to the chainctl skills reference documentation for more information.
Validate the skill Before you publish, check that the skill directory meets the spec with the validate subcommand. It runs locally and makes no network calls:
chainctl skills validate hello-world✓ SKILL.md found ✓ Frontmatter valid ✓ name: &#34;hello-world&#34; (matches directory basename) ✓ description: 96 chars ✓ Total size: 387 B / 10 MB ✓ 1 file(s) will be published: SKILL.md Validation passed.validate confirms that the directory contains a SKILL.md, that its frontmatter is valid, that the name field matches the directory name, and that the skill is within the size limit. It also lists the files that push publishes.
To also flag optional fields that Chainguard recommends, add the --strict flag:
chainctl skills validate hello-world --strict✓ SKILL.md found ✓ Frontmatter valid ✓ name: &#34;hello-world&#34; (matches directory basename) ✓ description: 96 chars ✓ Total size: 387 B / 10 MB ✓ 1 file(s) will be published: SKILL.md ⚠ license field is recommended Validation passed.Here, --strict warns that the skill omits the recommended license field. Warnings don&rsquo;t cause validation to fail, but addressing them produces a more complete skill.
Push the skill to your organization&rsquo;s uploads registry From the parent directory of hello-world/, push the skill to your organization&rsquo;s uploads registry with a version tag:
chainctl skills push hello-world --group your-organization --tag v1.0.0 REFERENCE | DIGEST ------------------------------------------------|---------------- uploads.cgr.dev/example.dev/hello-world:v1.0.0 | sha256:3196...You can repeat --tag to publish one artifact under several tags, such as --tag v1.0.0 --tag latest. If you omit --tag, chainctl publishes the skill as latest and warns that you didn&rsquo;t pin a version. To build and validate the artifact without publishing it, add --dry-run.
Keep the versioned reference for the hardening submission below.
List your uploads Confirm the upload with the list subcommand and --source uploads:
chainctl skills list --group your-organization --source uploads SOURCE | TYPE | NAME | TAGS | UPDATED -----------------|-------|-------------|--------|---------- uploads.cgr.dev | skill | hello-world | v1.0.0 | just nowWithout --source uploads, list shows the hardened registry. A successful push does not mean a hardened result is available there. Submit the upload for hardening in the next step.
The TAGS column shows all tags for each skill. A latest tag is not required. If your output has a LATEST TAG column or omits the upload, see Find a skill that is missing from the listing.
Harden the skill Submit the uploaded artifact and wait for the result:
chainctl skills harden uploads.cgr.dev/your-organization/hello-world:v1.0.0 \ --group your-organization --wait --timeout 30mThe command prints a job ID, waits for hardening, and downloads the result to ./hardened/hello-world/. Review the instructions and HARDENING.md report, including any findings that remain open.
Save the exact hardened reference returned by the command. It includes a user namespace and digest, in the form skills.cgr.dev/&lt;org-uidp&gt;/users/&lt;user-namespace&gt;/hello-world@sha256:&lt;digest&gt;:
export HARDENED_REF=&#39;&lt;full-hardened-reference-returned-by-the-command&gt;&#39; chainctl skills describe &#34;$HARDENED_REF&#34;For submissions directly from a local directory, checking a job later, and resuming after a timeout, see Getting started with skill hardening.
List hardened skills Hardened results are nested under users/&lt;user-namespace&gt;/. Add --recursive to browse skills inside those folders:
chainctl skills list --group your-organization --source skills --recursiveWithout --recursive, the organization-level listing may show only a users row with TYPE set to folder. Expand the folder with --recursive, or browse it with chainctl skills list --group your-organization/users. See Browse results in user folders for the folder layout and how to show uploads alongside hardened results.
The listing includes skills with generated version tags and skills without tags. Use the exact $HARDENED_REF returned by the job to inspect and install the result you reviewed.
Install the skill Download and install the skill to make it available to agents on your machine:
chainctl skills install &#34;$HARDENED_REF&#34;This command automatically detects agents on your machine and reports where it placed the skill. The install name includes the registry namespace to distinguish skills with the same name. Copy the Install Name from chainctl skills describe &quot;$HARDENED_REF&quot; for use in the following steps:
export INSTALLED_SKILL=&#39;&lt;install-name-from-describe&gt;&#39;By default, install writes one shared copy to .agents/skills/ and symlinks each agent&rsquo;s skills directory to it, so every agent reads the same files. Add --copy to give each agent its own copy, --global to install under your home directory instead of the current project, or --agent to target specific agents instead of every detected one.
Run the skill from an agent Load the skill from the location reported by install. In Claude Code, invoke it with /&lt;installed-skill-name&gt;, replacing &lt;installed-skill-name&gt; with the value you saved in $INSTALLED_SKILL. Ask the agent to greet you, and check that its response follows the instructions you reviewed in the hardened SKILL.md.
Uninstall the skill To remove a skill from your machine, pass its install name to the uninstall subcommand:
chainctl skills uninstall &#34;$INSTALLED_SKILL&#34;The command prompts for confirmation before removing any files.
By default, uninstall removes the project-local copy from every agent directory where it&rsquo;s installed. If a global copy also exists, uninstall leaves it in place and prints a warning. Re-run the command with --global to remove that copy. Use the --agent flag to remove the skill from specific agents only, and the -y flag to skip the confirmation prompt.
uninstall operates only on the local files on your machine. It doesn&rsquo;t modify your organization&rsquo;s registry. To remove a published skill from the registry, use chainctl skills delete instead.
Delete a skill from the registry To remove a published version of a skill from your organization&rsquo;s hardened registry, first list its tags. Use the repository portion of the hardened reference, preserving its user namespace:
HARDENED_REPO=&#34;${HARDENED_REF%@*}&#34; chainctl skills versions &#34;$HARDENED_REPO&#34;Select a tag from that output and pass the full tagged reference to delete. The upload&rsquo;s v1.0.0 tag is not a substitute for a tag from the hardened repository. Digest references are not accepted by delete:
export HARDENED_TAG=&#39;&lt;tag-from-the-versions-output&gt;&#39; chainctl skills delete &#34;$HARDENED_REPO:$HARDENED_TAG&#34;The command prompts for confirmation before removing the version. Press y and ENTER to confirm. Add the -y flag to skip the prompt and delete the version non-interactively.
The command requires a tag so you don&rsquo;t delete the latest tag by accident. Deleting latest is still possible, but it prompts for an additional confirmation.
When you delete a skill&rsquo;s last remaining version, chainctl also removes the empty skill entry, so it doesn&rsquo;t linger in list output with nothing to pull. delete accepts a reference without a tag, such as &quot;$HARDENED_REPO&quot;, only for a skill with no versions left. A skill that still has versions requires an explicit tag.
Unlike uninstall, delete removes the skill from the registry for your whole organization. It doesn&rsquo;t remove copies already installed on anyone&rsquo;s machine.
Command reference Action Command Enable the entitlement chainctl skills entitlements create --parent your-organization Accept the registry terms chainctl skills accept-terms --group your-organization Validate a skill chainctl skills validate &lt;name&gt; Upload a skill chainctl skills push &lt;name&gt; --group your-organization --tag &lt;version&gt; List uploads chainctl skills list --group your-organization --source uploads Harden a local skill chainctl skills harden ./&lt;name&gt; --group your-organization --wait Check a hardening job chainctl skills status --group your-organization --id &quot;$JOB_ID&quot; List hardened skills in all folders chainctl skills list --group your-organization --recursive Describe a hardened skill chainctl skills describe &quot;$HARDENED_REF&quot; Install a hardened skill chainctl skills install &quot;$HARDENED_REF&quot; Uninstall a skill chainctl skills uninstall &quot;$INSTALLED_SKILL&quot; Delete a published version chainctl skills delete &quot;$HARDENED_REPO:$HARDENED_TAG&quot; 
