Today's GitHub Trending tells an interesting story about where the Agent ecosystem is heading.
Three repos caught my eye:
-
paperclipai/paperclip(87k+ stars, +2,589 today): "The open-source app everyone uses to manage agents at work" — a unified dashboard for managing multiple agents. -
zhaoxuya520/reverse-skill(37k+ stars, +409 today): "AI-powered routing + on-demand toolchain bootstrapping" — a skill router pack that supports Claude Code, Cursor, Cline, and other AI coding clients. -
openbao/openbao(8k stars, +360 today): "Manage, store, and distribute sensitive data including secrets, certificates, and keys."
Each solves a real problem. But together they reveal a gap:
Who governs the skills themselves?
The Gap
paperclip manages agents — which agent is running, what it's doing.
reverse-skill routes skill calls — when an agent needs a skill, it routes the request to the right toolchain.
openbao manages secrets — API keys, certificates, sensitive data.
But none of them answers:
- Which version of a skill pack is currently in production?
- Which agent role has permission to call the OCR skill?
- Who called the translation skill at 3 AM last Tuesday, and what did they send?
- When a skill pack is updated from v1.2 to v1.3, who approved the rollback?
These are governance questions, not routing questions. And in enterprise environments, they're non-negotiable.
Enter skillhub
This is where iflytek/skillhub comes in — a self-hosted, open-source skill registry for AI agents.
Think of it as the missing governance layer:
| Concern | Tool | What it manages |
|---|---|---|
| Agent lifecycle | paperclip | Which agents exist, what they're doing |
| Skill routing | reverse-skill | How to route a skill call to the right toolchain |
| Secrets & keys | openbao | Sensitive data storage and distribution |
| Skill governance | skillhub | Skill pack publishing, versioning, RBAC, audit logs |
skillhub provides:
- Skill pack publishing & version management: Register skill packs, track versions, roll back when needed.
- RBAC permissions: Define which agent roles can call which skills. The finance bot shouldn't call the DevOps deploy skill.
- Audit logs: Every skill call is logged — who called what, when, with what input. Essential for compliance.
- Self-hosted: Your skill registry stays on your infrastructure. No third-party dependency.
But skills need to exist first
A registry is only useful if there are skills to register. That's where iflytek/iFly-Skills comes in — iFLYTEK's official skill collection:
- Speech recognition
- OCR
- Translation
- Proofreading
- Multimodal capabilities
These are production-ready skills that can be published to skillhub, versioned, and distributed to agents with proper permission controls.
The bigger picture
The Agent ecosystem is maturing past the "it works in my demo" phase. Enterprises need:
- Agent management (paperclip)
- Skill routing (reverse-skill)
- Secret governance (openbao)
- Skill governance (skillhub)
If you're building an agent stack and skipping #4, you're one audit failure away from a bad day.
Check out skillhub: https://github.com/iflytek/skillhub
And the official skill packs: https://github.com/iflytek/iFly-Skills


Top comments (0)