Quiver — Agent Skill inspection and orchestration
Local-first, provider-agnostic ecosystem for inspecting Agent Skills and orchestrating AI agents with control over permissions, budgets and provenance. Early-stage project: no runnable release is available yet.
Quiver is a local-first, provider-agnostic ecosystem for Agent Skills — the packages of instructions, scripts and references used by AI agents. The idea is to let you verify a skill’s origin, contents, capabilities and exact version before using it, and to coordinate multiple agents while keeping their permissions and spending under control.
Status: early development. The repository is at the scaffold stage: no release or runnable product is available yet. Inspection, scanning, installation, agent execution and the web interface are specified but not operational.
The two products
- Skills Hub — designed to discover, inspect, scan, version and install immutable skill snapshots, with content-bound trust and provenance tracking.
- Orchestrator — designed to coordinate agents, roles, permissions, workflows, schedules and budgets across providers.
- Integration Bridge — an optional bridge that attaches skill snapshots to agents, reconciling capabilities with permissions. Neither product depends on the other.
Current foundations
A pnpm monorepo with application, domain, shared, provider and bridge
packages; strict TypeScript configuration; ESLint, Prettier and
security-lint fixture checks; pinned tooling and dependency-install restrictions
in .npmrc; a product specification, roadmap and engineering decisions;
bilingual (IT/EN) public documentation.
Design goals
Static skill inspection, trust bound to exact content, explicit per-provider permissions, controlled spending and auditable actions. The README is explicit: these runtime controls still require implementation and verification, and a scan result must never be presented as a universal safety guarantee. Source code licensed under GPL-3.0.