Production operating terms

SkillHub operating terms.

These operating terms cover public discovery, review, project-scoped runtime permissions, audit logs, Stripe or PayPal payment capture, Stripe Connect payouts, notifications, and account security.

Current operating policy for public launch
ScopeRegistry, marketplace, runtime gateway
MoneyStripe or PayPal checkout, ledger posting, Stripe Connect payouts
TrustReview, incidents, reports, takedowns
DataManifest, runtime, billing, notification records
01

Buyer and developer use

Developers may discover, save, install, test, and invoke skills only through projects and project-scoped credentials.

  • Developers should inspect manifest schemas, permissions, pricing, version, review status, incidents, and published feedback before installation.
  • Project owners remain responsible for approving high-risk permissions, setting budgets, rotating API keys, and adopting reviewed version updates.
  • Runtime test calls from the console are non-billable unless the product explicitly marks them as paid provider execution.
02

Publisher responsibilities

Publishers must provide accurate skill contracts and maintain public listings as operational products, not one-time uploads.

  • Every listing must include display name, description, version, runtime, input/output schemas, permissions, examples, changelog, and support path.
  • Verified or installed versions are immutable; publishers must create a new semantic version for behavior, schema, permission, pricing, or runtime changes.
  • Paid publishing requires an active publisher profile, verified Stripe Connect payout readiness, approved pricing, and accepted refund/dispute terms before public activation.
03

Review, safety, and takedown

SkillHub may review, reject, restrict, suspend, deprecate, or remove listings to protect developers, publishers, and the marketplace.

  • Verification requires automated manifest, runtime, example, and security checks plus a reviewer decision.
  • Abuse reports, critical incidents, undeclared permissions, malicious runtime behavior, privacy issues, or billing abuse can trigger restriction or suspension.
  • Suppressed distribution is a ranking action, not a takedown; publishers can use the marketplace appeal workflow when quality gaps are fixed.
04

Pricing, commission, and paid marketplace

Commercial records are created by real Stripe or PayPal payment events, SkillHub ledger posting, and Stripe Connect payout state.

  • Billable usage and subscriptions post transactions, transaction splits, publisher balance rows, and auditable notifications.
  • The default split model is 20% platform fee and 80% publisher share unless a newer active commission rule applies to future posting.
  • Payment capture uses Stripe Checkout or PayPal where available. Publisher payout readiness and payout references use Stripe Connect, with finance review where risk or threshold rules require it.
05

Refunds and disputes

Refunds and disputes are handled as auditable Stripe and ledger adjustments instead of editing historical transactions.

  • Finance operators can approve, reject, post, fail, warn, win, or lose adjustment records with required reasons.
  • Posted refunds create negative adjustment transactions, negative splits, and reversed publisher balance entries.
  • Dispute losses can post refund adjustments automatically, while publishers and project operators can inspect scoped adjustment history.
06

Data retention and privacy posture

SkillHub stores operational records needed for registry trust, call permissions and logs, billing traceability, and account safety.

  • Stored records include manifests, versions, review decisions, runtime checks, installs, policies, invocations, usage, ledger entries, notifications, and audit logs.
  • Raw user tokens, API keys, email verification codes, OAuth secrets, webhook signing secrets, and provider keys must not be exposed after first reveal or through admin lists.
  • Publishers must declare data retention notes when skills handle user, business, secret, financial, or sensitive operational data.
07

Incidents, deprecation, and support

Operational failures should create durable signals for developers, publishers, and trust operators.

  • Runtime incidents can move through open, monitoring, resolved, and postmortem states with severity and decision reason.
  • Installed-skill update inboxes should show new versions, deprecations, security notes, and incident recovery states before agents are moved.
  • Publishers should maintain support paths, changelogs, and replacement guidance when versions are deprecated or skills are suspended.
08

Notifications and webhooks

In-app, email, and webhook notification states are delivered through configured production providers.

  • Users can manage notification preferences for review, update, runtime, billing, payout, buyer-request, and account-security events.
  • External email and webhook queues expose attempts, provider metadata, retry scheduling, signed webhook delivery, and redacted payload summaries.
  • Email provider delivery and webhook network delivery must never expose verification codes, tokens, secrets, or sensitive payload fields through admin views.
09

Production integrations

Provider integrations must be configured before the related product surface is treated as available.

  • Stripe Checkout, PayPal checkout, payment webhooks, Stripe Connect onboarding, email delivery, OAuth providers, webhook delivery, and model-provider keys are production dependencies.
  • If a dependency is not configured, the affected API returns a stable configuration_required error and the UI shows a real unavailable or empty state.
  • Terms may be updated as provider, region, tax, refund-window, KYC, and minimum-payout decisions change.
SkillHub - AI Agent Skill Registry