Atlas / Skills / blazeup-ai / Observal Registry

Observal RegistrySAFE

skills/blazeup-ai/observal-registry

Observal is self-hosted registry for your coding agent extensions with a built in insight engine. Setup Observal, define the scope and share your Skills, MCPs and Agents with your peers.

Verdict
SAFE
Grade
B
Trust score
89 /100
Version
2.5.0
Hosts
1 documented
License
Apache-2.0
Stars
4,245
01

Overview

Observal is self-hosted registry for your coding agent extensions with a built in insight engine. Setup Observal, define the scope and share your Skills, MCPs and Agents with your peers.

Read from source at commit 6ae7cbfc894cOBSERVED · 2026-10-08
02

Host compatibility

What the documentation claims. We have not run a compatibility test.

HostStatusNotes
cursormentioned
03

What it tells the agent

The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.

---
# SPDX-FileCopyrightText: 2026 Hemalatha Madeswaran <[email protected]>
<!-- SPDX-FileCopyrightText: 2026 Shaan Narendran <[email protected]> -->
<!-- SPDX-FileCopyrightText: 2026 Lokesh <[email protected]> -->
# SPDX-License-Identifier: Apache-2.0
name: observal-registry
command: observal
description: "Searches, recommends, bulk-submits, installs, edits, versions, archives, restores, transfers, and manages co-authors for Observal MCP servers, skills, hooks, prompts, sandboxes, and registered remote A2A agents. Use when the user wants to find components, publish one or many they control, install them into a harness, or manage their lifecycle."
version: 2.5.0
owner: observal
---

# Managing Registry Components

## Execution contract

1. Execute commands with a 60 second timeout.
2. **Use machine output by default:** add `--output json` whenever supported. Parse list results from `items` and pagination fields.
3. Run the leaf command's `--help` when any path, flag, enum, or payload shape is uncertain.
4. Supply all required inputs and confirmation flags. Do not leave an agent waiting at a prompt.
5. Reuse returned UUIDs and `qualified_name` values. Never automate with row numbers or ambiguous bare names.
6. Verify installs, submissions, edits, versions, ownership changes, and lifecycle transitions.
7. Submit or modify only components the user owns or is authorized to manage.
8. Never expose environment values, headers, tokens, private source data, or submitted secret fields.
9. Mutations are sent once. After an uncertain transport failure, read component state before retrying.
10. Authentication is optional for approved public content when the server setting `deployment.public_registry_enabled` is enabled; it is disabled by default on self-hosted deployments. Public list, show, install, and prompt render commands use `https://public.observal.io` by default. Authenticate before submitting, editing, reviewing, rating, or accessing private team content.

## Choose the workflow

| User intent | Read |
| --- | --- |
| Find, inspect, recommend, or install components | [Discovery and installation](references/discovery-and-installation.md) |
| Submit one component or a mixed bulk file, or register a remote A2A agent | [Component submission](references/component-submission.md) |
| Edit, version, archive, restore, transfer, or manage co-authors | [Registry lifecycle](references/registry-lifecycle.md) |

Read only the selected reference, and read it completely before executing.

## Registry rules

- Search with the user's natural-language terms, then narrow by type, namespace, team, harness, or category only when useful.
- Open-ended requests such as "what am I missing?" use personalized recommendations before keyword search.
- `personalized: false` means popularity fallback, not a personal recommendation.
- Team members can see authorized private teamspace items. Use `TEAM_HANDLE/ITEM_SLUG` for direct references.
- Draft, pending, rejected, and approved items have different edit behavior. Read status before mutating.
- A successful submit can still be pending review. Report the returned status instead of saying it is published.
- Bulk files are structurally validated before mutation. Inspect every per-entry result and verify uncertain retries by canonical identity.
- Prefer an existing installed dependency or native CLI path. Do not invent wrappers or telemetry variables.

## Completion

Report component type, canonical identity, version, status, target harness or scope when applicable, warnings, and any review or setup step still required.
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeNA
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (0)

No findings outside the package's declared scope.

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 6ae7cbfc894cfull audit observations/trust-audit/skill/blazeup-ai__observal-registry.json · Report an issue / request a re-scan
05

Audit history

Every audit this skill has had.

DateSourceVerdictGradeScoreChange
2026-10-086ae7cbfc894cSAFEB89first audit
06

Questions

What does the Observal Registry skill do?

Observal is self-hosted registry for your coding agent extensions with a built in insight engine. Setup Observal, define the scope and share your Skills, MCPs and Agents with your peers.

Is Observal Registry safe to install?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.

What can Observal Registry access on my machine?

The audit observed no filesystem, network or shell use at all in its source.

Which assistants does Observal Registry work with?

Its documentation mentions cursor. That is what the text claims, not a compatibility test we ran.

How current is this page?

The grade is for one exact copy of the source (6ae7cbfc894c), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.

Advertisement