01
Inspect the complete package
Submissions include all text files, an entry point, permissions, dependencies, license, publisher and release metadata. The current registry accepts text packages without network, shell or secret capabilities. Automated check results are visible; text alone is not proof of safety, and checks do not replace human testing.
02
Run the purpose and boundary cases
Before publication, a person must execute a successful primary-purpose case and a boundary case, and successfully install and read the package in every declared host. Records capture the tester, time, environment and model, input, expected and actual results, steps, limitations and evidence. Simulations do not qualify as human tests.
03
Publish a redacted summary
Public details show qualification, tested hosts, test time and a separately authored redacted summary. Raw records remain available for internal review and are not automatically copied into public content. Approval, rejection and revocation require an operator and reason.
04
Review each version independently
Updates declare changes, breaking compatibility, minimum client version, maintenance time and maintainer. Approval does not overwrite an older published version. Revoked versions are removed from the installable set, and online clients check revocations; offline operation cannot guarantee knowledge of the latest revocations.
05
Limits of the standard
Review improves traceability. It does not guarantee correct model output on every run or compatibility after third-party service or host changes. Users still need to inspect capabilities, suitability of inputs and model outputs. Declared limitations matter when choosing a skill.