Capabilities overview
Skills, MCP servers, plugins and integrations share one manifest format, one registry per installation, scopes, trust levels and install policies.
Four types share one manifest format:
| Type | What it is | Runtime effect |
|---|---|---|
skill | Instructions or knowledge for agents | Added to the prompt of compatible agents |
mcp | An external tool or data server (stdio, http, sse) | Passed to agents that support MCP (Claude Code) |
plugin | An extension of the orchestration platform | Code run by workers at task hooks, in a restricted process; off unless enabled |
integration | A connection to an external service | Registry only |
No mandatory marketplace
Every control-plane installation owns its registry. Self-hosted organizations register their own private capabilities, and nothing is fetched from, or sent to, vendor infrastructure. On the managed cloud we curate platform-level capabilities; the architecture is identical.
Ready-made skill, MCP and plugin manifests are optional: copy a manifest and register it in your own registry.
Scopes
Installations exist at the organization, project and task scope (and platform, for administrators). They are merged, and a more specific scope overrides — or disables — a broader one.
Install policy and trust
- Install policy:
ASK(approval required, default),AUTO(trusted, low-risk installs go straight through), orRESTRICTED(only pre-approved trust levels; anything else is blocked). - Trust:
OFFICIAL,VERIFIED,COMMUNITY,UNVERIFIED,LOCAL. Only platform administrators can assignOFFICIALorVERIFIED; manifests registered by others becomeLOCAL. - Permissions: policies can block permissions or require approval for them; see Permissions.
Versions
Versions are immutable: publish a new version to update a capability. Installations can pin a version.