SuperSkill agent guide
1. Search with GET https://superskill.sh/api/resources?q={terms} or the public MCP tools.
2. Open the exact resource detail and inspect provenance, permissions, risk and installability.
3. Use the returned action. Upstream-only resources remain open-only; hosted releases require the exact version and digest.
4. Ask for explicit consent before a managed install, publish or workspace mutation.
5. Treat catalog inclusion, popularity and community activity as discovery signals, not verification.
Public reads are anonymous. Protected actions use the local SuperSkill browser authorization broker. It opens the connect page for explicit approval and retries the same idempotent action. Do not put access tokens, refresh credentials, browser proofs, task text or private prompts in tool arguments, URLs, project files, analytics or logs.
Canonical machine guide: https://superskill.sh/llms.txt
Full public catalog guide: https://superskill.sh/llms-full.txt