Account identity
When you sign in, AIPM uses your GitHub identity to connect publishing actions to your account.
Privacy
AIPM is built for public AI skill packages. This page explains what data is used for accounts, publisher profiles, package metadata, tokens, and project files.
When you sign in, AIPM uses your GitHub identity to connect publishing actions to your account.
Your display name and profile image help users see who owns an org or package.
Org names, package names, metadata, versions, and public package files are stored by the registry.
Publish tokens are used by the CLI, expire quickly, and should not be saved in project files.
The registry may process request metadata to run the service, fix abuse, and keep it available.
The website can save your theme choice in your browser. This is not needed for publishing.
Package names, descriptions, targets, versions, manifests, and included skill files are public registry content. Check them before you publish.
AIPM does not need private source code, secrets, customer records, internal documents, or unrelated project files. A good package includes only the manifest, main skill file, examples, and tool files the skill needs.
AIPM should add account deletion, package owner transfer, stronger audit logs, verified publisher labels, private packages, and a privacy contact channel.