The submit form stores exactly three fields
three fields- Repository URL
- Required. Read by the next nightly scrape, and the only field that does anything automatic.
- Note
- Optional. Read by a person when a submission or a score correction needs one.
- Optional, and used for one thing: replying to you about that submission. It is never added to a mailing list, because there is no mailing list.
Analytics
Page views, the pages they came from, and two outbound actions, copying an install command and clicking through to a source repository, are recorded with PostHog, so we can tell whether the directory is actually useful rather than just visited.
No profile is built for an anonymous visitor, form inputs are masked, and nothing is joined to an identity because there is no identity to join it to. Analytics are served from this domain rather than a third-party host, which means an ad blocker does not change what is collected. It is the same first-party data either way.
Session recordings
Analytics here includes session replay: a reconstruction of how a page was used, clicks, scrolls, pointer movement, and which pages were opened in what order. Everything typed into a field is masked in the browser before it is sent, so text you enter is never captured. It exists so that a flow which breaks for someone can be watched back and fixed rather than guessed at. Recordings are processed by PostHog and deleted after 30 days.
If you sponsor a placement
Payment is handled entirely by Stripe. Card details are entered on Stripe’s own checkout page and never touch this site or its database. We receive an identifier for the subscription and the customer, never a card number.
What we do store is what the placement cannot be built without: the name to show, the address it links to, and the email address you checked out with, which is used to agree the line of copy with you and to reach you about the sponsorship. It is not a mailing list, because there is no mailing list. Those details are kept in a table the public site has no read access to, and only the name, the link and the approved line of copy are ever published.
Cancel and the panel comes down. The billing record stays, because it is a record of a payment we took and both of us may need it.
What the index itself contains
Everything on a listing page was read from a public GitHub repository: the file, its frontmatter, the repository’s own metadata, and install counts published by the skills.sh registry. Nothing is private, and nothing was obtained by any means other than reading what the repository publishes.
If you want a repository removed from the index, say so on the submit form with the listing URL and it is dropped from the next nightly rebuild.
Who runs this
SkillWorks is built and run by Compound Labs. Questions about any of the above go to hello@thecompound.tech.