01 / ANALYSIS
Product analysis
- Maturity
- Live
- Confidence
- Partial
- Verified
- 2026-07-18
- Commercial relation
- Not sponsored
Problem solved
Agent skills, system prompts, MCP configurations, and workflows are scattered across repositories, documentation, and chat history. Before copying them, teams lack a consistent way to assess provenance, permissions, dependencies, target tools, write scope, rollback, and reusable install records.
Why it was selected
The public catalog is browsable without an account, while the official site also exposes CLI, MCP, API, trust manifests, policy packs, and evaluation evidence. Its default policy puts verification and install planning before writes, then requires confirmation or staging for code execution, network access, secrets, or global configuration. That sequence is more auditable than handing a one-line install command directly to a privileged agent.
What is genuinely novel
Registries, package managers, and hashes are not new. The more distinctive move is reshaping them into agent-callable contracts: search, detail, verification, permission envelopes, install plans, dry runs, staging, lifecycle manifests, and rollback are exposed through CLI, MCP, and machine-readable endpoints.
Best for
Developers who need reusable skills, prompts, or MCP configurations across AI coding tools and are willing to verify provenance and write scope before activation
Editorial evaluation
KEEP DISCOVERING
A few more products worth noticing
A small set selected by product shape and profile similarity, with independent verification records.

Hangar
Adithya Shreshti
What it solves
Long-lived local projects mix source, dependencies, build caches, development servers, Git worktrees, and unpushed work that exists only on one machine. Generic cleaners see file size without project meaning, while terminal scripts require developers to remember every directory, launch command, port, and backup state.

specgit
Fn First Holdings LLC
What it solves
Product specs are often written in a document tool while code lives in GitHub. Engineers read a linked doc once, implementation moves on, and the two drift apart. Plain Markdown can colocate them, but shifts Git and PR mechanics onto collaborators who may not know that workflow.

Domain Details
Uneed publisher julianengel / Julian Engel and Simple Bytes
What it solves
Domain research often means moving among registries, WHOIS/RDAP, DNS, certificates, Wayback, registrar pricing, and several aftermarket venues. Domain Details reduces that fragmentation with a shared search, browser-local history, bulk entry points, and monitoring alerts.
02 / WHAT STANDS OUT
Three product decisions worth noticing
Separate discovery, verification, and activation
Search should narrow candidates, verification should expose provenance and permissions, and only activation should gain write access. Each layer should be independently stoppable and leave evidence.
Integrity is not identity or licensing
Content hashes are useful for detecting changes, but publisher verification, source repository, signatures, and licensing need separate fields and must not be collapsed into one trust score.
Machine manifests need continuous testing too
Agents treat JSON contracts as operational truth. Version drift, polluted arrays, and schema gaps should block release rather than being tolerated because the human-facing page still works.
Product insight worth carrying forward
Separate finding an asset from allowing it into an agent context: return candidates and evidence first, produce a reviewable install plan second, and write only after policy gates pass.
03 / DO NOT COPY
What not to copy
04 / LIMITS & RISKS
Limits and risks
Sample public API records can simultaneously show an 'established' author trust level, an unverified publisher, unreviewed status, and hash-only signatures. A hash proves integrity, not publisher identity, licensing, or safety. No public terms page was found at verification, and the asset-metadata schema has no license field. The latest npm CLI was 3.23.5 while the trust manifest still named 3.23.4 and the public GitHub main branch package.json named 3.13.1; the latest CLI package exposed neither npm provenance nor a gitHead, so its exact source could not be reproduced from the public repository. Telemetry can be disabled, but package code creates a persistent machine identifier and caller hash by default and sends events, asset IDs, and limited metadata; the current privacy page does not enumerate those identifiers, providers, exact retention, or deletion path. A machine manifest also mixes repair-eval URLs into target, install-mode, and recommended-file arrays, showing that the machine-readable contracts themselves still need version validation.
Compared with alternatives
Compared with copying text from GitHub or a directory, TokRepo adds structured risk, target adapters, dry runs, and rollback. Compared with npm or PyPI, it can distribute instructional assets but lacks an equally mature publisher-identity and licensing chain. Compared with closed official plugin marketplaces, it is broader and more open, while leaving more verification responsibility to the user.
05 / EVIDENCE
Visual evidence

06 / SOURCE
Source and verification
- Original author
- Regulus K.K.
- Country / region
- Japan / global
- Maturity
- Live
- Confidence
- Partial
- Discovered
- 2026-07-18
- Last verified
- 2026-07-18
What this review checked
We verified the live site, About and Help pages, April 2026 privacy policy, public API, trust manifest, default policy, install-safety eval, GitHub repositories, npm metadata and package code, the Uneed launch page, and a current screenshot of the official interface. We did not register, generate an API key, install or run the CLI or MCP server, call the hosted MCP endpoint, write any asset locally, publish content, or provide private files, so search quality, install success, and rollback reliability remain untested independently.
Latest change
Initial profile created from the live site, privacy policy, public API, machine manifests, policy and eval evidence, GitHub, npm packages, Uneed launch page, and a real official-interface capture; no install, sign-in, or publishing occurred, and hash, identity, licensing, version, telemetry, and manifest-quality boundaries are recorded.
Ready to explore further?
Open the product, or return to the original source to verify the details.
ONE-TAP FEEDBACK
Did this profile help you judge the product?
One tap. No writing required.