Permissions and Risk
Explains the three risk levels and what each one means.
Every Skill has one of three risk levels: low, medium, or high. This value isn't chosen directly by the publisher — the registry calculates it automatically based on the registered permissions and required tools.
Risk level isn't distinguished by color alone. The badge's glyph (●○○, etc.), label, and border weight/style all signal it together.
What each level means
Low: A read-only scope that doesn't require sensitive write access or outbound network access.
Medium: Includes file writes, limited command execution, or access to a specified external service. Review the scope before running it.
High: Includes open-ended network access or access to sensitive data. Pair it with an allowlist and audit logging.