v0.7.7 · CLAUDE CODE PLUGIN

TopGun

Best AI Skill for any Job — Security Assured

Agentic AI Skills Finder and Security Enforcer

Use TopGun to get the job done — the best AI skills in the world discovered, security scanned and cleared. TopGun searches 16 active skill registries, ranks every candidate across four dimensions, runs a SENTINEL security audit until clean, and installs the winner — automatically.

16 Active Registries 4-Factor Scoring SENTINEL Secured Auto-Install

You're Installing Skills Blind

Every manual skill install is a gamble. You don't know if there's a better option, if the code is safe, or if a newer version exists. TopGun eliminates that gamble completely.

Wrong Skill

You pick what you know, not what fits. Better options exist across dozens of registries you've never searched.

Security Unknown

No audit means trusting random code with full tool access. Any SKILL.md could exfiltrate data or phone home.

Registry Fragmentation

skills.sh, GitHub, npm, Smithery — impossible to manually check all. You miss the best option every time.

No Verification

Installed skills run with whatever allowed-tools they declare. No hash checking. No integrity guarantees.

A 4-Stage Quality Pipeline

Every /topgun invocation runs the full pipeline. No shortcuts.

1

FindSkills DISCOVER

Searches 16 active registries in parallel — skills.sh, Smithery, GitHub, npm, GitLab, LobeHub, and more. Normalizes every result to a unified schema, deduplicates by contentSha, and produces a ranked candidate list.

2

CompareSkills RANK

Scores every candidate across four weighted dimensions: capability match (55%), security posture (20%), popularity (15%), and recency (10%). Capability is decomposed into a domain-specific 5-sub-criterion rubric synthesized from the candidate field. A capability floor demotes low-fit candidates; the composite score selects the winner.

3

SecureSkills AUDIT

Runs bundled SENTINEL v2.3.0 against the top candidate. Requires 2 consecutive clean passes. Applies fixes between passes. Aborts if SHA-256 hash mismatches between passes.

4

InstallSkills INSTALL

Presents a full audit manifest for user approval. On approval, installs via /plugin install with local-copy fallback if the plugin system has a known bug.

16 Active Registries, All Searched

FindSkills queries every major skill registry in parallel. No manual searching required.

skills.sh
Primary global skill registry — curated SKILL.md packages with metadata
agentskill.sh
Agent-focused skill registry with categorized tool packs
Smithery
MCP-native marketplace — skills adapted for Claude Code workflows
GitHub Topics
Public repos tagged claude-skill — broad community coverage
GitLab
Enterprise-hosted skills and private-mirror registries
npm
Published @claude-skill scoped packages with semver versioning
LobeHub
Curated AI-agent plugins and skill bundles from the Lobe ecosystem
SkillsMP
Commercial marketplace with verified publisher badges
ClawHub
Claude-native hub for agent skills with automated compatibility checks
And 7 more…
Glama, HuggingFace Spaces, LangChain Hub, Claude Plugins, Cursor Directory, MCP.so, and OpenTools

SENTINEL-Gated Installations

Every skill is audited by bundled SENTINEL v2.3.0 before installation. No exceptions. No overrides.

Structural Envelope

All external skill content is wrapped in a structural envelope before injection into agent context, preventing prompt injection attacks.

Phone-Home Detection

Rejects any SKILL.md containing curl, wget, or fetch in executable sections.

2 Clean Passes Required

SENTINEL runs until it returns zero findings on two consecutive independent passes. No single-pass shortcuts are allowed.

Integrity Gating

SHA-256 hash of the skill content is verified between passes. Any mismatch triggers an immediate pipeline abort.

One Command. Always the Best.

Install TopGun once. From that point forward, every skill you need is one command away — always the best available, always audited.

Claude Code · Terminal
# Step 1: Install the TopGun plugin
/plugin install alo-labs/topgun
 
# Step 2: Use TopGun for any task
/topgun find me a skill for web scraping
/topgun best git workflow automation skill
/topgun code review skill with multi-pass support
 
# Optional flags
/topgun deployment pipeline skill --auto-approve
/topgun test runner skill --registries skills.sh,npm
TopGun Found 14 candidates across 9 registries in 2.3s
TopGun Top score: web-scraper-pro · composite 0.94
TopGun SENTINEL pass 1/2 — scanning…
TopGun SENTINEL pass 1 clean · SHA-256 verified
TopGun SENTINEL pass 2 clean · ready for install
TopGun Awaiting your approval…

Ready to stop installing blind?

TopGun is free, open-source, and available now. One install gives you access to every skill registry on the planet — with a security audit on every result.

Get Started ↓ View on GitHub →