Trust / Data Handling

Data Handling

SkillHub is a registry, governance layer, and runtime gateway. This page explains the operational data needed to support those jobs.

What SkillHub stores

Account profiles, workspace membership, Skill manifests, publisher information, review decisions, install state, policy state, notification preferences, runtime logs, and audit records.

What SkillHub does not store publicly

Public pages must not expose Project Keys, OAuth secrets, private keys, raw prompts, private customer data, or unsupported compliance claims.

Project Keys and secrets

Project Keys are used for signed-in runtime calls and should be scoped, revocable, and hidden after first reveal. Secrets are never part of public manifests.

Runtime logs and audit trails

Invocation logs exist to support governance, debugging, rate limits, abuse response, and future billing reconciliation.

Launch Preview retention

Preview records are retained only as needed for security, auditability, support, and marketplace readiness. Deletion requests route through support.

SkillHub Data Handling - Logs, Manifests, Secrets, and Runtime Data | SkillHub