Skip to content

Executive Summary (Validated)

AI agents (OpenClaw, Claude Code, Codex CLI, Gemini CLI) are becoming the primary interface for knowledge workers. An ecosystem of 8,600-17,800 MCP servers and ~130-150K agent skills has emerged — but with no unified infrastructure for discovery, trust, monetization, or governance.

Findable is the platform where AI agent skills are discovered, trusted, monetized, and governed.

MetricValueConfidenceSource
AI agents market 2025$7.6-8.0BHIGHGrand View Research, Fortune BI
AI agents market 2030$48-53BHIGHGVR, MarketsandMarkets, BCC Research (three independent firms)
MCP monthly SDK downloads97M+MEDIUMPento (downloads ≠ active users; CI/CD inflation likely)
MCP servers (curated registries)8,610+HIGHPulseMCP
MCP servers (all directories)17,000-17,800HIGHMCP.so, Glama
Quality-verified MCP servers~1,200HIGHmcp-awesome curated list
Agent skills (all SKILL.md registries)~130-150K uniqueMEDIUMSkillsMP (~97K) + skills.sh (57K) minus ~28% duplicates
Servers with critical security issues32-41%HIGHEnkrypt AI (32%), earezki.com (41% lack auth)
Skills leaking credentials7.1% of ClawHubHIGHSnyk (283 of 3,984 scanned)
Total paid-skill revenue (entire ecosystem)<$100K/monthMEDIUMCline/Ritza analysis

Key correction: Prior “370K+ skills” figure was inflated. SkillsMP claims 270K but verified ~97K. With ~28% duplication and ~12% empty, real unique quality count is ~130-150K.

LayerDescriptionRevenue ModelDemand Validated?
DiscoveryCross-platform search: MCP + SKILL.mdFree (funnel)YES — fragmented registries, poor search
Trust/SecurityScanning, trust scores, verified publishersFreemium + EnterpriseYES — 32-41% servers have critical vulns
CommerceMarketplace for paid skillsCommission (15-20%)NOT YET — <$100K/mo ecosystem revenue
EnterprisePrivate registries, policy engine, governance$30-80/user/monthEMERGING — Composio has $2M ARR
DimensionScoreNotes
Problem real?8/10Discovery fragmented, security crisis proven, trust absent
Commerce viable now?3/10Almost nobody sells skills. Open-source culture dominates
Security/governance timing8/10OWASP, CoSAI, NIST publishing. Compliance demand real
Commerce timing4/1012-24 months away from meaningful GMV
Competitive moat5/10Snyk acquired Invariant Labs. Composio $29M. Vercel skills.sh
CompetitorFundingThreatWhy
Snyk (+ Invariant Labs)$1.7B raised, $408M ARRCRITICALThey ARE “Snyk for agent skills”
Composio$29M (Lightspeed)HIGH$2M ARR, 200+ enterprise customers
Vercel skills.shVercel backingHIGH57K skills, 110K installs in 4 days
SmitherySeed (South Park Commons)MEDIUM-HIGH7,300 servers, 322K monthly visits
Stacklok/ToolHiveFundedMEDIUMCryptographic verification, enterprise
MicrosoftN/AHIGH (long-term)microsoft/skills, Copilot plugins, VS Code distribution

Lead with security, not commerce. Security is the most validated, most urgent, least competitive-from-incumbents wedge.

Sequence:

  1. Months 1-4: Open-source security scanner → community + brand
  2. Months 4-8: Cross-platform discovery with trust scores → free, become the reference
  3. Months 8-14: Enterprise governance → first revenue
  4. Months 14-24: Commerce → only when ecosystem GMV justifies it
MetricPrior TargetRealistic TargetBasis
Year 1 ARR$500K$200KEnterprise governance early adopters
Year 3 ARR$8-12M$3-5MEnterprise expansion + API
Year 5 ARR$40-63M$10-20MFull platform + early commerce
  1. Snyk is the actual Snyk — acquired Invariant Labs, entering MCP security with $408M revenue and 5,000 customers
  2. Vercel skills.sh — developer trust + distribution; 110K installs in 4 days
  3. Anthropic could build more — official registry deliberately minimal now, but could change
  4. Commerce premature — building Stripe Connect for <$100K/mo market is engineering without customers
  5. Microsoft/GitHub distribution — microsoft/skills + Copilot plugins marketplace
  6. OpenClaw uncertainty — creator joined OpenAI (Feb 14, 2026)
  7. 40% of agentic AI projects may be canceled by 2027 — Gartner