Terms of Service
Last updated 2026-05-29 · v1.0
These terms govern your use of skillox.io and every related SkillOx surface (hosted scanner, public catalog, creator portal, API, CLI). Important up front: SkillOx grades are best-effort security signals, not certifications. We do not — and cannot — guarantee that a skill we labelled "A" is safe for your specific situation, or that a skill we labelled "F" is impossible to use safely. You remain responsible for what you install and run. The rest of this page explains how that works.
1. Who we are
SkillOx is operated by ATOMIRA TECHNOLOGIES, S.L. (CIF B27662717), registered office at Calle Lepant 270, 08013 Barcelona, Spain, registered with the Registro Mercantil de Barcelona. Throughout these terms "SkillOx", "we", "us" or "our" means Atomira Technologies S.L.
You can reach us at hello@skillox.io for general queries, legal@skillox.io for legal matters, and privacy@skillox.io for data-protection requests.
2. What SkillOx is
SkillOx is a security and curation layer for the AI-agent SKILL.md ecosystem. The hosted scanner accepts a SKILL.md URL or content, runs static and (optionally) semantic checks against it, and produces a letter grade between A and F together with a list of findings.
A public catalog, per-skill Report Cards, a creator portal, an OSS command-line tool, and a Pro tier subscription extend the core scanner with discovery, claim, and continuous-rescan features. Specific features available at any time are documented at /docs and may change.
3. Who can use SkillOx
You must be at least 16 years old to create an account or submit content. By using SkillOx you confirm that you meet that minimum and that you are not legally restricted from accepting these terms.
You may use SkillOx on behalf of an organisation only if you have authority to bind that organisation to these terms.
4. Accounts, claims and verification
A signed-in account is optional for scanning. It is required to claim a listing as your own, follow skills for grade-drop alerts, manage API keys, or subscribe to Pro.
We currently sign you in through GitHub OAuth. Other identity providers may be added. By signing in you authorise us to read the minimum profile data we need to identify you (your GitHub username, primary email, display name and avatar URL).
Verification levels (L0 through L4) reflect how much we have been able to confirm about a creator. L1 is automatic on first GitHub sign-in; higher levels rely on additional checks described at /docs/concepts/verified-creators. A higher level is a trust signal, never a warranty.
5. Pricing, billing and refunds
The hosted scanner, the public catalog, the CLI, and basic creator-portal features are free. Pro and higher tiers are paid subscriptions billed via Stripe; the current price for each tier is on /pricing and is incorporated into these terms when you subscribe.
All payments are processed by Stripe Payments Europe Ltd. We do not see or store your full payment card number — only the Stripe customer and subscription identifiers, the last four digits, and brand.
You may cancel your subscription at any time from /account/billing or via the Stripe customer portal. Cancellation takes effect at the end of the current billing period and Pro features remain active until then. We do not pro-rate refunds for unused time within a paid month except where required by law.
EU consumer right of withdrawal: if you are an EU consumer (not a business or sole trader acting in your professional capacity), you have 14 days to withdraw from a new paid subscription. You expressly request that we make Pro features available immediately upon subscription, which means once you use a Pro-only feature you accept that your withdrawal right is consumed. Unused subscriptions can be cancelled with a full refund by emailing hello@skillox.io within the 14-day window.
6. Your content and submissions
When you submit a SKILL.md URL to be scanned, you confirm that fetching that URL is lawful for us to do, and that publishing a scan report referencing it does not infringe anyone's rights. The scanned content is treated according to our Privacy Policy.
When you claim a listing as your own, you grant SkillOx a worldwide, non-exclusive, royalty-free licence to display, link to, summarise and re-scan that public SKILL.md and its parent repository metadata for as long as the listing is live. You can take down your own listing at any time from the creator dashboard.
You retain all underlying rights in your SKILL.md and your codebase. Nothing in these terms transfers ownership.
7. Acceptable use
You must not use SkillOx to:
- Submit content you do not have the right to share, or content that infringes third-party rights;
- Attempt to evade the rate limit, abuse protection, billing system, or API-key revocation; or share API keys outside your own systems;
- Reverse-engineer scanner signals to deliberately produce a grade that does not reflect the underlying skill's real behaviour (manifest-padding, capability obfuscation, etc.);
- Run automated scans that disproportionately load our infrastructure beyond fair-use of the free tier;
- Use SkillOx to plan, coordinate or facilitate unlawful activity — including targeting any specific individual, system or organisation without their authorisation;
- Misrepresent yourself, your organisation, or the identity of the author of a SKILL.md you have claimed.
We may rate-limit, throttle, suspend or terminate any account or scan that we reasonably believe is engaged in any of the above.
8. API and CLI
API keys identify your account to our servers and are subject to the per-tier quotas published at /docs/api. You are responsible for any request issued with one of your keys. If you believe a key has been compromised, revoke it from /account/billing immediately.
The `skillox` command-line tool is open source under the Apache-2.0 licence. Its source is at git.skillox.io/skillox/skillox; the licence at apps/cli governs your right to use, modify and distribute the binary. These terms do not restrict use of the OSS CLI offline.
9. Open source and intellectual property
Selected components — the OSS CLI and the scanner-rule pack — are released under the Apache-2.0 licence. Where a component is open source, its licence text controls. Everything else, including the SkillOx brand, the SkillOx wordmark and hex mark, the public site design, the curated catalog dataset, and the website code beyond the OSS components, remains the property of Atomira Technologies S.L.
10. No warranty — grades are signals, not certifications
SkillOx is provided "as is" and "as available", without warranties of any kind, whether express, implied or statutory. Without limiting the generality of the foregoing, we specifically disclaim any warranty that:
- A scan will detect every security issue present in a SKILL.md, its referenced scripts, or its runtime behaviour;
- A skill graded "A" is safe to install, run or grant capabilities to in your specific environment;
- A skill graded "F" cannot be used safely under appropriate controls;
- The grade for any skill will remain stable — re-scans, new rules and new probes can move grades in either direction at any time;
- The hosted scanner, catalog, API or CLI will be uninterrupted, error-free, secure, or free of viruses or other harmful components;
- Catalog metadata (source repo, stars, last-commit date, ownership) is current or accurate at any given moment.
You are solely responsible for deciding whether to install, run, integrate or rely on any skill, regardless of grade. SkillOx is one input into that decision; it does not replace your own review, your own threat model, or your own security controls. We strongly recommend reviewing the SKILL.md and its source repository yourself before granting any meaningful capability to a skill, including for skills graded A or B.
11. Limitation of liability
To the maximum extent permitted by applicable law, Atomira Technologies S.L., its directors, employees and contractors shall not be liable for any indirect, incidental, special, consequential or punitive damages, or for any loss of profits, revenue, data, business opportunity, goodwill or other intangible losses, resulting from:
- Your use of, or inability to use, SkillOx;
- Any decision you make on the basis of a SkillOx grade, finding, capability manifest, or any other signal we publish;
- Damage caused by a skill you discovered, installed, ran or integrated through SkillOx, whether the skill was graded by us or not, and whether or not the grade we assigned was accurate at the time;
- Unauthorised access to or alteration of your transmissions or data;
- Statements or conduct of any third party on the service, including other creators and their published SKILL.md content.
To the maximum extent permitted by applicable law, our total aggregate liability arising out of or in connection with these terms or your use of SkillOx is limited to the fees you actually paid us in the twelve (12) months immediately preceding the event giving rise to the claim. Because access to the free tier is provided at no cost, that amount is zero euros (€0) for free-tier users.
Nothing in these terms excludes or limits liability that cannot lawfully be excluded or limited, including liability for death or personal injury caused by our negligence, for fraud, or for any other liability that cannot be excluded under Spanish law.
12. Indemnity
You agree to indemnify, defend and hold harmless Atomira Technologies S.L. from any claims, damages, liabilities, costs and expenses (including reasonable legal fees) arising from (a) your use of SkillOx in breach of these terms, (b) content you submitted to us, (c) your infringement of any third-party right, and (d) any skill you developed, published or claimed through SkillOx.
13. Suspension and termination
We may suspend or terminate your access to SkillOx if you breach these terms, if continued service would expose us or other users to material legal or security risk, or if we discontinue the service. Where reasonably possible we will give you advance notice and an opportunity to remedy.
You can close your account at any time by emailing hello@skillox.io. Closing your account closes your subscription at the next billing date, removes your claim on every listing you owned, and deletes the personal data we are not obliged to keep — see the Privacy Policy for the full breakdown.
14. Changes to these terms
We may update these terms. When we make material changes we will (a) update the date and version at the top of this page, (b) post a notice on /docs/changelog, and (c) where you have an account, attempt to notify you by email before the change takes effect. Continued use of SkillOx after the change becomes effective constitutes acceptance.
15. Governing law and disputes
These terms are governed by the laws of Spain, without regard to conflict-of-laws principles. The courts of Barcelona, Spain shall have exclusive jurisdiction, except that EU consumers may also bring proceedings in the courts of their habitual residence as required by Regulation (EU) No 1215/2012.
EU consumers may also use the European Commission's online dispute resolution platform at https://ec.europa.eu/consumers/odr.
16. Miscellaneous
These terms together with the Privacy Policy, the Cookie Policy and any product-specific add-on (alpha agreement, Pro plan order form, etc.) constitute the entire agreement between you and Atomira Technologies S.L. concerning SkillOx. If any provision is held unenforceable, the remainder remains in effect. Failure to enforce a provision is not a waiver. You may not assign these terms without our written consent; we may assign them in connection with a merger, acquisition or sale of substantially all our assets.