Skills
Publishing a Skill
From local folder to marketplace listing, and what review actually checks.
Availability note — these docs describe both working and planned product areas. Account authentication, administrator-managed AIHK/AICA tenant regions and keys, signed-in Composer runs and public Guard scans are connected. Skills, Memory, Agents, Workflows, Apps, billing, the public SDK/CLI and the unified API are previews unless a section explicitly says otherwise.
Roadmap and package-contract reference: this page describes the intended GenCMS runtime. The current deployment persists workspace records and drafts but does not execute marketplace Skills, index Memory for retrieval, publish packages, or run Agents, Workflows or Apps. See the deployed API reference for the routes available today.
Developer profile
↓
Create Skill
↓
Upload package or connect GitHub
↓
Manifest validation
↓
Tests
↓
GenCMS Guard
↓
Pricing and permissions review
↓
Human review if required
↓
PublishPhases
- Phase 1 — GenCMS and IGEARS first-party Skills only. This is the current phase.
- Phase 2 — invited publishers, still with human review on every release.
- Phase 3 — public submissions with payouts, once moderation and Terms support it.
What holds a release
- A Guard finding at high or critical severity.
- Declared permissions narrower than observed behaviour.
- A failing test case.
- An example output that does not validate against the output schema.
- A licence that conflicts with the stated pricing.
GenCMS can disable a published Skill at any time for malware, a severe vulnerability, broken execution, licence violation, provider-policy violation or marketplace fraud. Installed users see 'Disabled by GenCMS' with the reason.