Security
airskills stores and distributes your AI skill files. This page explains exactly what data we handle, how we protect it, and what controls you have. The CLI is open source (MIT) so you can verify every claim on this page by reading the code.
What we store
When you push a skill, the CLI creates a tar.gz archive of your skill directory and uploads it. This includes your SKILL.md file and any supporting files in that directory. Only regular files are included; symlinks are not followed.
We do not store:
- Your source code, repositories, or git history
- Any files outside the skill directory you are pushing
- Your file system structure, project layout, or working directory
The CLI sends SHA-256 content hashes alongside uploads for conflict detection. These are computed locally from skill files only. See push.go and hash.go for the exact implementation.
Who can see your data
airskills is a small, bootstrapped company. Database access is restricted to the founder. We do not read your private skill content except to deliver the service (storing it, syncing it, serving it back to you).
- We do not train models on your data. Your skill content is never used for AI training, fine-tuning, or any purpose beyond storing and distributing it.
- We do not sell or share your data. Skill content is not shared with third parties, analytics services, or advertising platforms.
- Automated systems only. Skill content is handled by automated pipelines (upload, storage, download). There is no manual review process for private skills.
For teams that need stronger controls, use the Team trial form so we can understand the exact security requirement before promising a rollout shape.
Authentication
airskills uses OAuth via Google or Microsoft for sign-in. The CLI opens your browser to complete authentication, then stores tokens locally at ~/.config/airskills/token.json with strict file permissions (owner-only read/write).
- Token scope: tokens authenticate API requests to manage your own skills (push, pull, sync, share, publish). A token cannot access another user's private skills or perform admin operations.
- Tokens refresh automatically on expiry. If a refresh fails, the CLI prompts you to re-authenticate.
- Many commands work without an account: installing public skills, running offline, and previewing skill content.
- An account is only needed for cross-machine sync, private skills, and team features.
See login.go and config.go for the token handling implementation.
Data isolation
Skill data is stored in a PostgreSQL database with row-level security (RLS) policies on every table that holds user data. These policies enforce:
- Private by default. Skills are only visible to you unless you explicitly publish or share them.
- Owner-scoped writes. Only you can create, update, or delete your own skills.
- Organization-scoped access. Organization members see organization skills. Non-members cannot.
- Share-scoped reads. Shared skills are visible only to the specific people you share them with (by email).
Skill file archives are stored in a private storage bucket. Upload access is scoped to the owner. Public download access applies only to skills you have explicitly published. RLS policies are defined in the Supabase migrations.
MCP endpoint
The MCP server at airskills.ai/mcp supports both authenticated and anonymous access.
- Without login: the MCP server returns only public skills. No private or team data is accessible.
- With login: pass a Bearer token (from
airskills login) to access your private and team skills through MCP. The token carries the same scope as the CLI: your own skills only. - Read-only. The MCP endpoint exposes three tools: list-skills, load-skill, and load-skill-file. It cannot modify, delete, or create skills.
- Row-level security acts as the backend safety net. Even if the application layer were bypassed, the database enforces visibility rules.
See app/mcp/route.ts for the MCP handler source.
Telemetry
Opt out completely: set AIRSKILLS_NO_TELEMETRY=1 in your environment. The CLI will send nothing.
With telemetry enabled, the CLI sends lightweight usage data to PostHog (EU endpoint). Help, version, and quiet-mode commands never send telemetry regardless.
What we collect
- Command usage (push, pull, sync, add)
- CLI version, OS, and architecture
- Success/failure counts (not content)
What we do not collect
- Skill content or file contents
- File paths or directory structures
- Any data from your codebase
See telemetry.go for the full list of events and properties.
Binary distribution
CLI binaries are cross-compiled for Linux, macOS, and Windows (amd64 + arm64) using goreleaser. Every release includes:
- SHA-256 checksums for all archives, published alongside the release.
- Cosign keyless signing (via Sigstore) of the checksum file, using GitHub Actions OIDC identity. Verify against the Sigstore transparency log.
- Statically linked binaries (CGO disabled) with no external runtime dependencies.
The install script and self-update mechanism verify SHA-256 checksums before installing. You can also install via npm install -g airskills (which downloads the same signed binary) or build from source.
Larger-team requirements
Some teams will need extra controls before they put proprietary skills into a shared service. The current launch product is the hosted Team plan; larger governance, compliance, and deployment requirements are handled case by case rather than promised as shipped features.
Apply for the Team trial and include the security constraint in the use-case field.
Questions
If you have security questions or want to report a vulnerability, email security@airskills.ai.