Agentic Skills

Skills your AI agents can load and follow. Made-to-order skills, researched and tested on your own questions, and standards packs that keep AI-written code to ISO, OWASP and in-house rules.

Open Agent Skills format
Read by around forty agent products
Tested with and without the skill
50+ pre-built standards packs
Skill packs from £39 + VAT

Two routes. One open format.

Both routes deliver skills in the open Agent Skills format: a folder of plain Markdown your agents load when the task calls for it. Pick the route that fits what your agents are missing.

Any subject, made to order
Skill Publisher

Tell us what your agents should get better at. Our research team analyses your subject and any material you send, writes the skill, and tests it on your own questions with the skill loaded and without it.

  • For any team putting AI agents to work, and for authors and trainers with a method to pass on
  • Fixed price, ordered online, from £39 + VAT
  • Turnaround of ten working days from an accepted brief
  • Assess and refresh for skills you already run, plus bespoke agentic framework builds
Published standards and house rules
Code Standards

Standards your AI agents can actually follow. Pre-built and bespoke skills packs that keep AI-written code in line with ISO, OWASP, regulatory and in-house engineering rules.

  • For engineering and security leaders whose developers use coding agents at scale
  • 50+ pre-built packs, including ISO 25010, ISO 27001, ISO 42001, OWASP, PCI-DSS, NIST and GDPR
  • Bespoke rulesets for your architecture, security posture and house style
  • Starts with a conversation about which standards apply to you

Skill Publisher in under a minute and a half. Narrated, with captions. Watch the other films at skillpublisher.com.

Skill Publisher, skills made to order

Skills your agents can actually use.

Your AI tools are good. They do not know how your organisation works. A skill is worth loading when it carries what the model lacks: your conventions, your exceptions, the way the work is done where you are.

Buy a skill

Researched, Not Generated

Ask a model to write its own skill and it writes what it already knows. Our research team analyses the field (the talks, the books, the reports) and any material you send, and writes only what your agents lack.

Tested on Your Questions

You set three to ten test questions. We run each one with the skill loaded and without it, and hand you both answers side by side, so you can see what changed before you deploy it.

Yours, and Portable

One folder of plain Markdown in your repository. Around forty agent products read the format, including Claude Code, ChatGPT and Codex, GitHub Copilot, Cursor and Gemini CLI. It keeps working whether or not you ever speak to us again.

Fixed Price, Ordered Online

Skill packs start from £39 + VAT, with a turnaround of ten working days from an accepted brief. Already running skills? Assess and refresh scores them and updates them. Current prices are at skillpublisher.com.

Code Standards, skills for coding agents

Standards your AI agents can actually follow.

Apply standards proactively as agents write code, or assess existing codebases retroactively with gap analysis. Use both together across the whole lifecycle.

Proactive, Skills Packs for Coding Agents

Skills packs are loaded into your AI coding agent's context before it writes a single line. Standards are applied as code is generated, not after the fact.

Skills Packs

Pre-built rulesets for ISO 25010, OWASP, PSR-12, PEP 8 and dozens of industry frameworks, written for an agent to read directly.

Custom Rulesets

Define your own in-house coding standards and conventions, and layer them on top of any standards pack. Your agents follow both together.

Agent Integration

Works with Claude, GitHub Copilot, Cursor and other agents that read structured rules. One set of rules across the tools your team already runs.

In Context, Every Time

The relevant standards are in front of the agent as it writes, not applied afterwards as a clean-up pass. Human review still matters; it starts from code that was written to the rules.

Retroactive, Assess an Existing Codebase

Already have a codebase? Our assessment tools analyse existing code against any combination of standards and produce detailed gap analysis reports with prioritised remediation guidance. This assesses your code. To assess a skill you already run, see Assess and refresh at Skill Publisher.

Gap Analysis

Scan your existing codebase against selected standards. Identify exactly where code falls short, which standards are violated, and the severity of each gap, file by file, rule by rule.

Remediation Plans

Each gap analysis produces a prioritised remediation roadmap: critical security issues first, then compliance gaps, then quality improvements. Feed the plan to your coding agents to work through the fixes.

Compliance Reports

Audit-ready reports for stakeholders, regulators, and QA teams. Document which standards were assessed, what was found, what was remediated, and what remains outstanding.

Continuous Assessment

Repeat the assessment at release or sprint boundaries. Track compliance trends over time and catch regressions before they reach production.

Need more than a skill?

Where the gap is the whole setup and not one skill, we build agentic frameworks: named steps your team runs in order, sub-agents on the parts that are independent, and checks that can come back negative. Framework builds are scoped in conversation before any price is agreed. See the frameworks we have built.

Beyond Open Source

Curated skills that go further than public repositories.

Writing a skill looks easy. It is a Markdown file. That is exactly why most of them do not work. Open source coding rules are a starting point. Code Standards is where enterprise teams go when they need depth, precision, and accountability.

Interpreted, Not Copied

Public repos typically paste a standard's table of contents into a prompt. Our packs are written from the full specification, distilling hundreds of pages into actionable, context-aware rules that an AI agent can apply correctly.

Conflict Resolution

Real codebases operate under multiple overlapping standards: ISO 25010, OWASP, PCI-DSS, and your own house rules. Our packs resolve conflicts and define precedence so your agents don't generate contradictory code or silently ignore one standard in favour of another.

Maintained & Versioned

Standards evolve: OWASP Top 10 changes, ISO publishes amendments, frameworks release new versions. Our packs are actively maintained, versioned, and updated. Open source rules are often abandoned after their initial commit, leaving your agents enforcing outdated guidance. For skills you wrote yourselves, Skill Publisher's Assess and refresh scores the skill, updates it, and shows old and new answers on your own questions.

Framework-Aware

A generic "use parameterised queries" rule is useless if your agent doesn't know whether you're in Laravel, Django, or Express. Our packs are framework-specific. They know how your ORM works, where middleware sits, and what your testing conventions look like.

Audit-Ready Provenance

Every rule traces back to a specific clause in a published standard. When a regulator or auditor asks "why does your code do this?", the answer is documented, not "because an AI suggested it" but "because ISO 25010 clause 4.2.3 requires it."

Enterprise Customisation

Open source packs are one-size-fits-all. We work with your team to layer organisation-specific conventions on top of industry standards: naming patterns, architectural boundaries, security policies, and domain rules that reflect how your engineers actually build software.

The Code Standards Library

Skills packs across the full spectrum of software standards.

From quality management to security, accessibility to sustainability, every pack is interpreted from the source specification and tailored for AI-assisted code generation.

ISO Standards

ISO 25010

Software product quality model, reliability, security, maintainability, performance efficiency, compatibility, usability, functional suitability, and portability requirements translated into enforceable coding rules.

ISO 27001

Information security management, Annex A controls implemented as code-level rules covering access control, cryptography, input validation, secure session handling, logging, and data protection patterns.

ISO 9001

Quality management systems, process-oriented coding practices including documentation requirements, traceability, change management conventions, and consistent code review patterns.

ISO 12207

Software lifecycle processes, rules covering implementation, integration, testing, maintenance, and disposal phases. Enforces traceability between requirements and code artefacts.

ISO 15408

Common Criteria, security evaluation rules for systems requiring formal assurance levels (EAL). Enforces structured security arguments, boundary definitions, and vulnerability analysis patterns.

ISO 25023

Software quality measurement, quantitative measures for the quality characteristics in ISO 25010. Translates measurement functions into code-level metrics and testable assertions.

ISO 42001

AI management systems, the first international standard for responsible AI. Rules covering bias detection, transparency requirements, human oversight patterns, and AI-specific risk controls in generated code.

ISO 14971

Risk management for medical devices, hazard analysis patterns, risk control coding conventions, and traceability requirements for software in regulated medical and health-tech environments.

ISO 26262

Functional safety for automotive, ASIL-aware coding rules for safety-critical software. Defensive programming patterns, fault tolerance, and diagnostic coverage requirements for vehicle systems.

Security & Compliance

OWASP Top 10

Web application security, injection prevention, broken authentication, XSS, CSRF, SSRF, and insecure deserialization rules interpreted for each supported framework.

OWASP ASVS

Application Security Verification Standard, three levels of security verification (L1, L2, L3) translated into code-level checks for authentication, session management, access control, and cryptography.

PCI-DSS

Payment card industry data security, rules covering cardholder data handling, encryption at rest and in transit, secure key management, and audit logging for payment processing code.

NIST SP 800-53

Security and privacy controls, federal-grade security patterns for access control, audit accountability, incident response, and system integrity in government and defence applications.

CWE / SANS Top 25

Most dangerous software weaknesses, buffer overflows, race conditions, improper authentication, and privilege escalation prevention rules tailored to each programming language.

GDPR & UK GDPR

Data protection by design, consent management patterns, data minimisation, right-to-erasure implementation, privacy-by-default architecture, and lawful basis enforcement in code.

Language & Framework Standards

PSR-1/4/12

PHP coding standards, autoloading, basic coding style, and extended coding style for modern PHP development.

PEP 8 / PEP 257

Python style guide and docstring conventions, formatting, naming, imports, and documentation standards.

ECMAScript / TypeScript

JavaScript and TypeScript conventions, ES6+ patterns, strict type safety, async/await handling, and Node.js security practices.

Go / Rust / C#

Official language conventions, Effective Go, Rust API guidelines, .NET framework design guidelines, and Microsoft C# conventions.

Accessibility & Sustainability

WCAG 2.2

Web content accessibility, Level A, AA, and AAA compliance rules for HTML, ARIA, colour contrast, keyboard navigation, and screen reader compatibility in generated frontend code.

GreenCode / SCI

Green Software Foundation's Software Carbon Intensity specification, energy-efficient coding patterns, resource optimisation rules, and sustainability-aware architecture guidance.

EU AI Act

European AI regulation, risk classification, transparency requirements, human oversight patterns, and technical documentation rules for high-risk AI systems as defined by the regulation.

Sector-Specific Standards

We build and maintain skills packs for regulated industries where software must meet domain-specific safety, quality, and compliance requirements. If your sector has a standard, we can create a pack for it.

Automotive, ISO 26262 / ASPICE

Functional safety and process maturity for vehicle software. ASIL-aware coding rules, defensive programming, fault tolerance, and Automotive SPICE process compliance for ECU and ADAS systems.

Aerospace, DO-178C / DO-326A

Software considerations in airborne systems. Design assurance levels (DAL A-E), structural coverage analysis, requirements traceability, and airborne security rules for certified avionics software.

Medical, IEC 62304 / ISO 14971

Software lifecycle for medical devices. Safety classification (A/B/C), risk management integration, validation requirements, and regulatory traceability for FDA and MDR submissions.

Defence, DEF STAN / MIL-STD

UK and NATO defence software standards. Secure coding for classified systems, safety-critical patterns, TEMPEST considerations, and MOD procurement compliance requirements.

Rail, EN 50128 / CENELEC

Software for railway control and protection systems. SIL-based coding techniques, formal verification patterns, and safety case evidence generation for signalling and train control software.

Financial, SOX / MiFID II / Basel

Regulatory compliance for financial software. Audit trail requirements, transaction integrity, data retention rules, algorithmic trading safeguards, and regulatory reporting patterns.

Don't see your sector? We create bespoke skills packs for any domain-specific standard. Get in touch to discuss your requirements.

Advanced Capabilities

Built for serious engineering teams.

A skill that never triggers has no value, and one that triggers on everything is a tax on every prompt. We tune each skill to load for the work it is meant for and stay quiet on the rest, and we show you the evidence.

"AI agents generate code at extraordinary speed. Without standards enforcement, that speed becomes a liability."
Chris Dean , CEO and Founder, Digital Tactics
Code Standards workflow, from ISO standards through interpretation and skill packaging to maintained coding skills packs used by agentic coding teams
Evidence

With and Without

Your test questions are run twice, with the skill loaded and without it, and you get both answers side by side. If a question came out the same either way, you will see that.

Detection

Drift Detection

Alerts when agent outputs deviate from your defined standards. Monitors AI agent outputs over time, identifies when generated code begins to drift due to model updates, context window changes, or prompt modifications, and provides root cause analysis with corrective actions.

Provenance

Audit-Ready Evidence

Every claim in a skill is checked against the source it came from before delivery, and standards rules trace to the clause they implement. Compliance reports give stakeholders, regulators, and quality assurance teams exportable evidence for governance reviews and regulatory submissions.

Portability

No Lock-In

Plain Markdown in a published open format. Switch editor, model or vendor and the skill comes with you. Nothing to install, nothing calling home, and your team can read it, edit a line and version it like any other file.

Library

Standards Library

A growing catalogue of 50+ pre-built standards packs covering ISO 25010, OWASP Top 10, PSR-12, PEP 8, and dozens of industry-specific frameworks. New packs are added as standards evolve, and any pack can be tailored to suit your organisation.

Brief, research, write, test.

How a Skill Publisher order runs, from your brief to a skill your agents can load, with the evidence it worked at the end.

Send Your Brief

What your agents should get better at, and three to ten real questions the skill has to handle. The questions are how the work gets marked.

We Research the Field

Our research team analyses the people who know your subject, and anything you send: documents, handbooks, recordings by link.

We Write the Skill

Only what your agents do not already know, tuned to trigger on the right work. Every claim is checked against its source.

We Test and Hand Over

Your questions, run with the skill and without it. You get the folder, both sets of answers, and the install path for each tool you use.

How a Skill Publisher order works, start to finish. Narrated, with captions. Read the detail at skillpublisher.com.

Code Standards

Choose, tailor, connect, monitor.

Code Standards engagements start with a conversation about which standards apply to you, then follow a structured pipeline.

Choose Standards

Select from 50+ pre-built standards packs covering ISO, OWASP, PSR, PEP 8, and industry frameworks. Or start from your own in-house conventions.

Tailor the Rules

We work with you to set severity levels, add organisation-specific conventions, and combine multiple packs into one ruleset that matches your requirements.

Connect Agents

Load your rulesets into Claude, GitHub Copilot, Cursor, or any agent that reads structured rules. The standards are in the agent's context as it writes.

Monitor Compliance

Track adherence in real time across agents and projects. Get drift alerts when generated code starts to deviate, and produce audit reports for governance reviews.

Built for teams putting agents to real work.

Whether you are a regulated enterprise, a scaling agency, or a team whose best practice lives in people's heads, Agentic Skills gives your agents what they are missing.

Enterprise Engineering

Large engineering teams adopting AI agents at scale. Keep consistent standards across hundreds of developers and multiple AI tools.

Regulated Industries

Financial services, healthcare, defence, and government teams that must demonstrate compliance with ISO, OWASP, and sector-specific coding standards in audit.

Agencies & Consultancies

Digital agencies managing multiple client codebases with different standards requirements, and advisory firms helping clients adopt AI-assisted development. Apply client-specific rulesets to each project and demonstrate compliance in delivery reviews.

Teams with Unwritten Know-How

The way your best estimator prices a job, the checks your senior engineer runs without being asked. We turn handbooks, past deliverables and recordings into something an agent can apply.

Authors, Trainers & Course Creators

If you teach a method, ship a skill with it, built from your own manuscript, back catalogue or course notes, so the method your audience loads is the one you teach.

Teams Already Running Skills

A stale skill still loads and still answers. Assess and refresh gives you a score, an updated skill with a line-by-line diff, and proof of which changes improved an answer.

Frequently Asked Questions

A folder containing a SKILL.md file: Markdown instructions with a short block of metadata saying what the skill is for and when an agent should use it, plus any reference files it needs. It follows the Agent Skills specification, which Anthropic published in December 2025 and released as an open standard. An agent reads the description, decides whether the skill is relevant, and loads the rest only when it is.

Both deliver skills in the same open format. Skill Publisher writes a skill to your brief on any subject, at a fixed price, ordered online at skillpublisher.com. Code Standards covers published standards such as ISO 25010 and OWASP, and your in-house engineering rules, for coding agents. It starts with a conversation: see codestandards.ai or get in touch.

Around forty agent products read the format, including Claude and Claude Code, ChatGPT and Codex, GitHub Copilot, VS Code, Cursor, Gemini CLI and JetBrains Junie. Tools differ a little in where they expect skills to live, so a Skill Publisher skill arrives with the exact path for each one your team runs. If you build on a framework such as LangGraph, CrewAI or n8n, the delivery includes the loader code for it.

Yes. While we provide 50+ pre-built standards packs covering frameworks like ISO 25010, OWASP, PSR-12, and PEP 8, we also write bespoke rulesets that reflect your organisation's own coding conventions, naming standards, architectural patterns, and security requirements. Handbooks, style guides, review comments and past deliverables all help.

For something small, do. A model writing a skill writes from what it already knows, which is the one thing the agent did not need telling. The value is the part the model does not have: your business, the practitioners in your field, and a test of whether the answer changed.

You set the test questions. We run each one twice, with the skill loaded and without it, and hand you both answers side by side. If a question came out the same either way, you will see that.

Drift detection monitors your AI agents' outputs over time to identify when generated code begins to deviate from your defined standards. This can happen due to model updates, context window changes, or prompt modifications. Our drift detection alerts you when compliance drops, provides root cause analysis, and suggests corrective actions.

Skill Publisher skill packs start from £39 + VAT, with a turnaround of ten working days from the point we accept the brief. Current prices for every pack, and for Assess and refresh, are at skillpublisher.com/pricing. Framework builds are scoped in conversation before any price is agreed, and Code Standards work is quoted after a conversation about which standards apply to you.

You own it, in your repository, to edit and version like any other file. Material you send is used to build your skill and nothing else, and documents you upload are parsed in an isolated environment with no network access.

Yes. We have been teaching machines to do jobs for a long time. Our first Skill Publisher was a platform for building Amazon Alexa skills, described in our voice and conversational AI case study. The format has improved since then. The hard part has not changed: deciding what the machine needs to be told.

Your know-how. Your standards. Your agents.

Tell us what your agents should get better at. Buy a skill pack online, or talk to us about standards packs and framework builds.

Contact us