Major Wave 15 makes portable handoff and trust continuity explicit: the durable 2,948 / 2,501 snapshot remains the honest fallback; live Excel exports contain only the catalog actually loaded in this browser; My Skills.md contains only reviewed Skills you explicitly added; every AI handoff stays user-initiated and least-privilege; and manual restore/import remains visibly unvetted until reviewed rather than silently installing instructions. Existing search, sd1_my_skills_v1 storage, safety gates, download behavior and Founder completion-return behavior remain intact.
SKILL DESK ONE · SD1
Find the right AI Skill. Trust it. Use it anywhere.
Skill Desk One · SD1 turns a large AI-Skills ecosystem into something people can actually use: searchable, categorized, portable and safer to adopt. Find a reusable Skill once, check its trust status, then deploy the same SKILL.md into ChatGPT, Claude, Microsoft Copilot, GitHub Copilot, Cursor, Gemini or Codex. SD1 is the only public product name; engine details stay in administrator release records.
Choose ChatGPT, Claude, Copilot, Cursor, Gemini or Codex. SD1 copies the selected Skill instructions and opens that AI for you. No AI account password is shared with SD1.
Last verified durable catalog snapshot: 2,948 published Skills, including 2,501 security-reviewed. Browse broadly, trust narrowly, and add only the Skills you actually need to My Skills.
Download truth: the purple and green controls now use SD1's in-page Excel .xlsx generator against the loaded live catalog. Download My Skills.md builds one portable Markdown collection from the security-reviewed Skills you explicitly added to local My Skills. If the upstream catalog or an individual source is unavailable, SD1 reports that state instead of pretending the export succeeded.
Important: All Skills is a discovery index, not 2,948 installed agents. A reviewed Skill becomes local only when you choose Add or import a SKILL.md and it passes the safety gate.
CURATION QUALITY GATE · WEB v1.60
Grow toward 10,000 by promotion quality, not raw intake.
A candidate is promoted only when its name is distinct, taxonomy is valid, metadata is complete, instructions are usable, capabilities and risk are understandable, and no alias or near-duplicate already covers the same job.
Naming
Clear action + outcome; no vague or duplicate titles.
Taxonomy
One primary practical domain plus useful secondary tags.
Safety
Least privilege, transparent external actions, no hidden credential flow.
Usability
Inputs, steps, outputs, limits, and success criteria are explicit.
Current durable truth remains 2,948 published / 2,501 reviewed. The separate curated pipeline remains 360 candidates until additional candidates pass these gates.
Searches Skill name, description, category, framework and slug.
Portable handoff targets: ChatGPT, Claude, Microsoft Copilot, GitHub Copilot, Cursor, Gemini and Codex. Select a Skill first; SD1 packages the instructions for your own authorized AI account.
Loads discovery metadata from the canonical Agent Skill Exchange index. Nothing is installed or executed just by browsing.
Loading catalog…
Manual SKILL.md
Upload a local SKILL.md for private browser review. It is not vetted and is not sent anywhere automatically.
ALL SKILLS SNAPSHOT
2,948
Last verified durable Agent Skill Exchange catalog snapshot.
SECURITY-REVIEWED
2,501
Reviewed by the upstream source and still subject to SD1 risk/capability checks before Add.
SD1 CURATED PIPELINE
360
New SD1-curated candidates tracked separately from the discovery catalog across six 60-Skill review batches. Candidates remain outside the verified live count until promotion gates pass.
CATALOG GOAL
10,000
Useful, deduplicated, categorized Skills with transparent trust status.
1. Discover
Search approved internal knowledge and systems without changing them.
2. Understand
Build inventories, dependency maps, current-state architecture and metrics.
3. Improve
Recommend target-state architecture, migrations, integrations and tests.
4. Prove & Roll Back
Capture screenshots, test results, packages, checksums and a rollback point before promotion.
The Skill contains the reusable method. The Agent Adapter translates that method for Microsoft Copilot Studio, GitHub Copilot, Cursor, Claude Code, Gemini or another approved runtime. This prevents the workflow from being locked to one vendor.
Skill Desk One · Enterprise Agent Playbooks
This is the enterprise-agent lane inside SD1. The main Skill Desk One product also includes reusable Skills, local My Skills / SKILL.md bundles, Founder workflows, safety checks, documentation and release management.
Skill
What it does
Safe default output
Enterprise Knowledge Discovery
Search SharePoint, Confluence, service catalogs, architecture repositories and approved folders for a defined topic.
Cited source inventory, gaps, owners and confidence.
MDM Estate Discovery
Master Data Management (MDM): identify products, domains, hubs, interfaces, data models, match/merge rules, stewardship and dependencies.
Current-state MDM map plus modernization candidates.
MQ Estate Discovery
IBM MQ / message-queue discovery: document queue managers, channels, producers, consumers, flows, service-level needs and known pain points.
Messaging inventory and dependency map; no queue changes.
MQ Modernization Advisor
Compare retain, integrate, wrap, migrate or replace options such as event streaming, managed messaging or API-based integration.
Decision matrix with risks, sequencing and coexistence plan.
Service / Host / Config Inventory
Correlate approved configuration-management data, documentation and repositories to identify services, hosts, environments and configuration references.
Sanitized inventory that never copies passwords, tokens or private keys.
Current → Future Architecture
Turn discovered facts into current-state diagrams, pain points, principles, transition states and a target architecture.
Architecture pack with assumptions explicitly separated from verified facts.
Observability Catalog
List logs, metrics, traces, alerts, dashboards, Service Level Indicators (SLIs) and Service Level Objectives (SLOs).
Coverage matrix and missing-observability backlog.
Architecture Drift Checker
Compare approved architecture/design documents with repositories, inventories and deployed evidence.
Drift report; never auto-remediates production.
Release Evidence Pack
For WordPress/plugins/apps: capture version, changed files, tests, screenshots, package and checksum.
Immutable release folder / ZIP and rollback instructions.
Visual Regression Reviewer
Open the development build, capture key screenshots, compare with the prior accepted version and report layout/function changes.
PASS / REVIEW / FAIL with before-after evidence.
Microsoft Copilot first
For businesses standardized on Microsoft, start with Copilot Studio because it can ground agents in approved enterprise knowledge such as SharePoint, Confluence, ServiceNow, Jira, Azure DevOps, Dataverse and Azure AI Search. Keep user permissions intact: an agent should not reveal information the signed-in user cannot normally read.
Example: MDM Discovery Agent
Scope one business domain and approved repositories.
Search architecture documents, operational runbooks, SharePoint/Confluence, service catalogs and approved source repositories.
Extract MDM products, versions, domains, interfaces, data owners, match/merge processes, stewardship workflows and known incidents.
Build a source-cited current-state inventory.
Identify contradictions and missing evidence instead of guessing.
Produce a future-state option set: optimize existing MDM, expand domains, integrate with cloud platforms, or replace components.
Require human approval before any write, configuration change, deployment or ticket creation.
Cursor without runaway cost
Cursor is useful, but it should not become the only runtime. Use it as an implementation workstation while keeping Skills and project evidence portable. For normal work, prefer lower-cost models / routing for repetitive edits, tests, documentation and searches. Escalate to expensive frontier models only for difficult debugging, architecture, security review or large refactors.
Feature implementation, multi-file changes, routine debugging and integration work.
Expert lane
Architecture, difficult defects, migrations, security-sensitive changes and final review.
Top approachable runtimes / model routes
Do not standardize the Skills themselves on these vendors. Standardize the adapter contract, then select the runtime that your employer, client or budget allows.
Microsoft Copilot Studio / Microsoft 365 Copilot — strongest first choice for Microsoft-governed internal knowledge and business agents.
GitHub Copilot — practical coding hub with agent mode and access to multiple model families.
Cursor — strong interactive coding experience; control cost through model tiers and route simple work cheaply.
Anthropic Claude Code / Sonnet — strong coding, tool use and large-change reasoning.
Google Gemini developer tools — useful alternative for coding, multimodal review and Google-oriented environments.
Visual Studio Code agent ecosystem — keeps the editor familiar while allowing Copilot and other agent integrations.
Open-source / bring-your-own-model IDE agents — valuable as a cost-control and vendor-fallback lane when company policy allows.
Local/private model runtimes — useful for sensitive internal workloads when approved infrastructure and model quality are sufficient.
Specialist review agents — security, testing, documentation and visual-quality agents that inspect another agent's output rather than writing the main feature.
Two-hour development loop
Checkpoint — assign version and create a recoverable package before changes.
Plan — convert the request into acceptance tests.
Implement — one agent makes the smallest coherent change.
Test — automated functional checks plus security/static checks.
See — browser agent opens the development site and captures defined screenshots.
Compare — visual reviewer compares against the previous accepted screenshots.
Package — create versioned ZIP, manifest, checksums, changed-file list and rollback instructions.
Review — a second model/agent critiques the implementation and evidence.
Accept or roll back — only accepted versions become the new baseline.
Promote — development → staging → production through an explicit controlled step.
Required release evidence
Version number and timestamp.
Goal / acceptance criteria.
Changed-file inventory.
Tests executed and results.
Before and after screenshots for important user flows.
Internal Skills may contain useful company-specific logic, but they must never become a secret-exfiltration mechanism. Before saving or sharing, run automated and human checks for credentials, API keys, tokens, certificates, private keys, passwords, connection strings, personally identifiable information, hidden Unicode/control characters, destructive shell commands, privilege escalation, security-control disabling, unexplained external network destinations and instructions that bypass company policy.
Default rule
Discovery agents are read-only. Production changes, deletes, queue modifications, database writes, firewall changes, credential operations and deployments require a separate write-capable Skill with explicit authorization, preview, validation and rollback.
Definition of done
A feature is not done because an agent says it finished. It is done when the acceptance tests pass, the development site was actually inspected, screenshots exist, the package is recoverable, a second review found no blocking issue, and the result can be rolled back cleanly.
Skill Desk One · current production truth
The installed SD1 engine/runtime remains v3.9.3; the public web workbench is now tracked separately as Major Wave 10. Staged v3.12/v3.13 transport artifacts are not installed and must not be presented as live. Portable SKILL.md bundles, cross-engine prompt packs and Bring Your Own Account (BYOA) remain core SD1 principles.
Skill Desk One · SD1 · runtime v3.9.3 · enterprise playbooks · portable SKILL.md · direct AI handoff · least privilege · evidence-first delivery · human-controlled production promotion.