{"repo":"tankpkg/tank","free":true,"listed":false,"github":"https://github.com/tankpkg/tank","clone":"git clone https://github.com/tankpkg/tank.git","description":"Security-first package manager for AI agent skills","language":"TypeScript","stars":37,"topics":["ai-agents","cli","package-manager","registry","security","skills","supply-chain-security","ai-coding-agent","claude-code","cursor"],"license":"MIT","category":"ai-agents","readme_excerpt":"Tank Security-first package manager for AI agent skills. \"I know Kung Fu.\" — but verified, locked, and scanned. --- The Problem AI coding agents (Claude Code, Codex, Cursor) can be extended with skills — reusable packages that teach agents how to perform tasks. The ecosystem is growing fast: 110,000+ installs in 4 days on one registry alone. But today's skill registries have no versioning, no lockfiles, no permissions, and no security scanning . In February 2026, the ClawHavoc incident revealed that 341 malicious skills (12% of a major marketplace) were distributing credential-stealing malware. Agent skills are more dangerous than npm packages because they execute with the agent's full authority — reading files, making API calls, running shell commands. The attack surface is fundamentally larger. What Tank Does Tank is the npm for agent skills , with security built into the foundation: Feature npm (2012) Current Registries Tank --------------- ----------------------- ------------------ ------------------------------------ Versioning Social contract Git tags / none Semver with escalation detection Lockfile package-lock.json None skills.lock with SHA-512 Permissions None None Declared + enforced at install Static analysis None built-in Basic / none 6-stage security pipeline Audit score npm audit (deps only) None Transparent 0-10 score Code signing npm provenance (2023) None Planned (Sigstore) Sandbox None None Planned (Phase 3) Quick Look All CLI Commands skills.json — declare ","default_branch":null,"files":null,"tree":[],"storefront":"/r/tankpkg","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/tankpkg/tank/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}