# Getting started with the Chainguard Skills Registry

URL: https://deploy-preview-4029--ornate-narwhal-088216.netlify.app/chainguard/agent-skills/skills-registry.md
Last Modified: September 28, 2026
Tags: Agent Skills, Overview

Enable the Chainguard Skills Registry, then upload, harden, install, and run an agent skill scoped to your organization.

The Chainguard Skills Registry lets you publish, manage, and distribute skills scoped to your organization. Use chainctl to upload original skills to uploads.cgr.dev, submit them for hardening, and install the hardened results from skills.cgr.dev.
This guide walks through enabling the registry for your organization, then uploading, hardening, installing, and running a skill. For job tracking, digest-based submissions, and browsing user folders, see Getting started with skill hardening.
Note: Chainguard Skills Registry is in beta.
Prerequisites To follow this guide, you need:
An installed and authenticated chainctl that includes skills harden and skills status. Check with chainctl skills harden --help and chainctl skills status --help. Refer to How to install chainctl if you don&rsquo;t have it yet. An active Chainguard organization. Owner access on the organization. In the commands below, replace your-organization with your organization&rsquo;s name or UIDP (its unique identifier).
Enabling the skills entitlement Before your org can push or install skills, create a skills entitlement.
Note: You must have the owner role in your organization to create a skills entitlement and accept the Skills Registry terms of service.
chainctl skills entitlements create --parent your-organizationCreated skills entitlement for org example.dev (717b474ac6972745c5706a898aa6e67ffba97dad)Next, accept the Skills Registry terms of service for your org:
chainctl skills accept-terms --group your-organizationThis opens an interactive prompt:
Chainguard Legal Agreements To continue, please review and accept the following: ▶ [] I agree to the Skills Registry Terms of Service https://www.chainguard.dev/legal/agent-skills-disclosure ↑/↓ navigate • space toggle • enter confirm • q cancelPress SPACE to accept the terms of service and ENTER to confirm.
Creating an example skill A skill is a directory containing a SKILL.md file. The SKILL.md frontmatter declares the skill&rsquo;s name and a description that tells an agent when to use it. The rest of the file contains the instructions the agent follows.
The next section has a few examples that refer to a skill named hello-world. You can create a sample hello-world skill with the following command:
mkdir hello-world cat &gt; hello-world/SKILL.md &lt;&lt; &#39;EOF&#39; --- name: hello-world description: A simple hello world skill. Use this to verify your skills registry setup is working end to end. --- When this skill is invoked, greet the user with: &#34;Hello from Chainguard Agent Skills! Your skill installed and loaded successfully.&#34; If the user provides their name, greet them by name instead: &#34;Hello, &lt;name&gt;! Welcome to Chainguard Agent Skills.&#34; EOFAfter running this command, your directory will have the following structure:
hello-world/ └── SKILL.mdThe directory name (hello-world/) must match the name field in the frontmatter (name: hello-world). If they don&rsquo;t match, the skill will fail to push.
Manage skills with chainctl This section outlines some of the chainctl commands you can use to manage skills in your organization&rsquo;s private Skills Registry. The following commands use the hello-world skill as an example, but you can use any other skills you&rsquo;ve created in its place.
Refer to the chainctl skills reference documentation for more information.
Validate the skill Before you publish, check that the skill directory meets the spec with the validate subcommand. It runs locally and makes no network calls:
chainctl skills validate hello-world✓ SKILL.md found ✓ Frontmatter valid ✓ name: &#34;hello-world&#34; (matches directory basename) ✓ description: 96 chars ✓ Total size: 387 B / 10 MB ✓ 1 file(s) will be published: SKILL.md Validation passed.validate confirms that the directory contains a SKILL.md, that its frontmatter is valid, that the name field matches the directory name, and that the skill is within the size limit. It also lists the files that push will publish.
To also flag optional fields that Chainguard recommends, add the --strict flag:
chainctl skills validate hello-world --strict✓ SKILL.md found ✓ Frontmatter valid ✓ name: &#34;hello-world&#34; (matches directory basename) ✓ description: 96 chars ✓ Total size: 387 B / 10 MB ✓ 1 file(s) will be published: SKILL.md ⚠ license field is recommended Validation passed.Here, --strict warns that the skill omits the recommended license field. Warnings don&rsquo;t cause validation to fail, but addressing them produces a more complete skill.
Push the skill to your organization&rsquo;s uploads registry From the parent directory of hello-world/, push the skill to your organization&rsquo;s uploads registry with a version tag:
chainctl skills push hello-world --group your-organization --tag v1.0.0 REFERENCE | DIGEST ----------------------------------|------------------------ uploads.cgr.dev/example.dev/hello-world:v1.0.0 | sha256:3196...Keep the versioned reference for the hardening submission below.
List your uploads Confirm the upload with the list subcommand and --source uploads:
chainctl skills list --group your-organization --source uploads SOURCE | TYPE | NAME | TAGS | UPDATED -----------------|-------|-------------|--------|---------- uploads.cgr.dev | skill | hello-world | v1.0.0 | just nowWithout --source uploads, list shows the hardened registry. A successful push does not mean a hardened result is available there. Submit the upload for hardening in the next step.
The TAGS column shows all tags for each skill. A latest tag is not required. If your output has a LATEST TAG column or omits the upload, see Find a skill that is missing from the listing.
Harden the skill Submit the uploaded artifact and wait for the result:
chainctl skills harden uploads.cgr.dev/your-organization/hello-world:v1.0.0 \ --group your-organization --wait --timeout 30mThe command prints a job ID, waits for hardening, and downloads the result to ./hardened/hello-world/. Review the instructions and HARDENING.md report, including any findings that remain open.
Save the exact hardened reference returned by the command. It includes a user namespace and digest, in the form skills.cgr.dev/&lt;org-uidp&gt;/users/&lt;user-namespace&gt;/hello-world@sha256:&lt;digest&gt;:
export HARDENED_REF=&#39;&lt;full-hardened-reference-returned-by-the-command&gt;&#39; chainctl skills describe &#34;$HARDENED_REF&#34;For submissions directly from a local directory, checking a job later, and resuming after a timeout, see Getting started with skill hardening.
List hardened skills Hardened results are nested under users/&lt;user-namespace&gt;/. Add --recursive to browse skills inside those folders:
chainctl skills list --group your-organization --source skills --recursiveWithout --recursive, the organization-level listing may show only a users row with TYPE set to folder. Expand the folder with --recursive, or browse it with chainctl skills list --group your-organization/users. See Browse results in user folders for the folder layout and how to show uploads alongside hardened results.
The listing includes skills with generated version tags and skills without tags. Use the exact $HARDENED_REF returned by the job to inspect and install the result you reviewed.
Install the skill Download and install the skill to make it available to agents on your machine:
chainctl skills install &#34;$HARDENED_REF&#34;This command automatically detects agents on your machine and reports where it placed the skill. The install name includes the registry namespace to distinguish skills with the same name. Copy the Install Name from chainctl skills describe &quot;$HARDENED_REF&quot; for use in the following steps:
export INSTALLED_SKILL=&#39;&lt;install-name-from-describe&gt;&#39; Run the skill from an agent Load the skill from the location reported by install. In Claude Code, invoke it with /&lt;installed-skill-name&gt;, replacing &lt;installed-skill-name&gt; with the value you saved in $INSTALLED_SKILL. Ask the agent to greet you, and check that its response follows the instructions you reviewed in the hardened SKILL.md.
Uninstall the skill To remove a skill from your machine, pass its install name to the uninstall subcommand:
chainctl skills uninstall &#34;$INSTALLED_SKILL&#34;The command prompts for confirmation before removing any files.
By default, uninstall removes the skill from every agent directory where it&rsquo;s installed. Use the --agent flag to remove it from specific agents only, or the --global flag to remove it from global directories instead of the current project. Add the -y flag to skip the confirmation prompt.
uninstall operates only on the local files on your machine. It doesn&rsquo;t modify your organization&rsquo;s registry. To remove a published skill from the registry, use chainctl skills delete instead.
Delete a skill from the registry To remove a published version of a skill from your organization&rsquo;s hardened registry, first list its tags. Use the repository portion of the hardened reference, preserving its user namespace:
HARDENED_REPO=&#34;${HARDENED_REF%@*}&#34; chainctl skills versions &#34;$HARDENED_REPO&#34;Select a tag from that output and pass the full tagged reference to delete. The upload&rsquo;s v1.0.0 tag is not a substitute for a tag from the hardened repository. Digest references are not accepted by delete:
export HARDENED_TAG=&#39;&lt;tag-from-the-versions-output&gt;&#39; chainctl skills delete &#34;$HARDENED_REPO:$HARDENED_TAG&#34;The command prompts for confirmation before removing the version. Press y and ENTER to confirm. Add the -y flag to skip the prompt and delete the version non-interactively.
The command requires a tag so you don&rsquo;t delete the latest tag by accident. Deleting latest is still possible, but it prompts for an additional confirmation.
Unlike uninstall, delete removes the skill from the registry for your whole organization. It doesn&rsquo;t remove copies already installed on anyone&rsquo;s machine.
Command reference Action Command Enable the entitlement chainctl skills entitlements create --parent your-organization Accept the registry terms chainctl skills accept-terms --group your-organization Validate a skill chainctl skills validate &lt;name&gt; Upload a skill chainctl skills push &lt;name&gt; --group your-organization --tag &lt;version&gt; List uploads chainctl skills list --group your-organization --source uploads Harden a local skill chainctl skills harden ./&lt;name&gt; --group your-organization --wait Check a hardening job chainctl skills status --group your-organization --id &quot;$JOB_ID&quot; List hardened skills in all folders chainctl skills list --group your-organization --recursive Describe a hardened skill chainctl skills describe &quot;$HARDENED_REF&quot; Install a hardened skill chainctl skills install &quot;$HARDENED_REF&quot; Uninstall a skill chainctl skills uninstall &quot;$INSTALLED_SKILL&quot; Delete a published version chainctl skills delete &quot;$HARDENED_REPO:$HARDENED_TAG&quot; 
