Product Roadmap
Last Updated: February 2026
Roadmap Philosophy
Section titled “Roadmap Philosophy”Wedge → Expand → Dominate
Start with the most urgent pain (security), use it to attract developers (discovery), layer on value capture (monetization), and lock in enterprises (governance). Each phase builds on the previous one’s distribution.
Phase 0: Foundation (Months 1-2)
Section titled “Phase 0: Foundation (Months 1-2)”Theme: Build the core infrastructure and scanning engine
Deliverables
Section titled “Deliverables”| # | Feature | Priority | Effort |
|---|---|---|---|
| 0.1 | SKILL.md parser (support full spec + all 26 platforms) | P0 | 2 weeks |
| 0.2 | Security scanner v1 (API key detection, known malware patterns, prompt injection checks) | P0 | 3 weeks |
| 0.3 | GitHub/ClawHub/SkillsMP ingestion pipeline | P0 | 2 weeks |
| 0.4 | Trust Score algorithm v1 | P0 | 1 week |
| 0.5 | Basic web UI (search + scan results) | P0 | 2 weeks |
| 0.6 | CLI tool v1 (agentforge scan <path>) | P0 | 1 week |
| 0.7 | Developer accounts (GitHub OAuth) | P1 | 1 week |
| 0.8 | Landing page + docs site | P1 | 1 week |
Key Decisions
Section titled “Key Decisions”- Build vs. Buy for scanning: Build our own static analyzer (proprietary moat) + integrate VirusTotal and Semgrep for known patterns
- Database: PostgreSQL + pgvector for semantic search
- Hosting: Start on managed cloud (AWS/GCP); plan for self-hosted enterprise later
- Open source: Open-source the CLI scanner; keep the web platform proprietary
Exit Criteria
Section titled “Exit Criteria”- Can scan any SKILL.md file for security issues
- Can ingest and index 100K+ skills from all major registries
- Basic search works across all indexed skills
Phase 1: Security Wedge (Months 3-6)
Section titled “Phase 1: Security Wedge (Months 3-6)”Theme: Become the trust layer for the agent skills ecosystem
Deliverables
Section titled “Deliverables”| # | Feature | Priority | Effort |
|---|---|---|---|
| 1.1 | Security Scanner v2 (deep analysis: dependency scanning, data flow analysis, permission mapping) | P0 | 4 weeks |
| 1.2 | Public Trust Score badges (embeddable — like “Snyk verified”) | P0 | 1 week |
| 1.3 | Scanning API (for platforms to integrate) | P0 | 2 weeks |
| 1.4 | Vulnerability disclosure and alerting system | P0 | 2 weeks |
| 1.5 | Verified Publisher program (identity verification + code signing) | P1 | 3 weeks |
| 1.6 | ”State of Agent Skills Security” report (Q2 2026) | P1 | 2 weeks |
| 1.7 | Browser extension (show trust score on ClawHub/SkillsMP/GitHub) | P1 | 2 weeks |
| 1.8 | CLI integration: agentforge install --verified-only | P1 | 1 week |
| 1.9 | Partnership outreach to ClawHub, SkillsMP, Smithery | P1 | Ongoing |
| 1.10 | Security blog + thought leadership content | P2 | Ongoing |
Go-to-Market
Section titled “Go-to-Market”- Publish “State of Agent Skills Security” report — drives PR and awareness
- Open-source the CLI scanner — drives developer adoption
- Offer free scanning to ClawHub and SkillsMP — partnership play
- Target security-conscious developers and early enterprise adopters
Metrics Target
Section titled “Metrics Target”| Metric | Target |
|---|---|
| Skills scanned | 50,000+ |
| CLI downloads | 10,000+ |
| Scanning API integrations | 3+ platforms |
| Verified publishers | 500+ |
| Monthly website visitors | 50,000+ |
Phase 2: Discovery Engine (Months 6-9)
Section titled “Phase 2: Discovery Engine (Months 6-9)”Theme: Become the default place to find agent skills
Deliverables
Section titled “Deliverables”| # | Feature | Priority | Effort |
|---|---|---|---|
| 2.1 | Semantic search v2 (intent-based: “I need to automate email follow-ups”) | P0 | 3 weeks |
| 2.2 | Category taxonomy (20+ categories, human-curated) | P0 | 2 weeks |
| 2.3 | User reviews and ratings system | P0 | 3 weeks |
| 2.4 | Curated collections (“Best DevOps skills”, “Top productivity skills”) | P0 | 2 weeks |
| 2.5 | Skill comparison view (side-by-side feature comparison) | P1 | 2 weeks |
| 2.6 | ”Similar skills” recommendation engine | P1 | 2 weeks |
| 2.7 | Developer profiles and portfolios | P1 | 2 weeks |
| 2.8 | Weekly “Trending Skills” newsletter | P2 | 1 week |
| 2.9 | API for agents to search Findable programmatically | P1 | 2 weeks |
| 2.10 | Findable MCP server (agents can discover skills through us) | P0 | 2 weeks |
Critical Milestone: Findable MCP Server
Section titled “Critical Milestone: Findable MCP Server”Build an MCP server that any agent (Claude, OpenClaw, Codex) can connect to. When a user asks their agent to “find a skill for X,” the agent queries Findable directly. This makes us the discovery layer inside the agent itself — not just a website humans visit.
Metrics Target
Section titled “Metrics Target”| Metric | Target |
|---|---|
| Monthly active searchers | 100,000+ |
| Skills indexed | 500,000+ |
| Reviews submitted | 10,000+ |
| Agent-initiated searches (via MCP) | 50,000/mo |
| Average session duration | 3+ minutes |
Phase 3: Monetization Engine (Months 9-14)
Section titled “Phase 3: Monetization Engine (Months 9-14)”Theme: Let developers make money from their skills
Deliverables
Section titled “Deliverables”| # | Feature | Priority | Effort |
|---|---|---|---|
| 3.1 | Stripe Connect integration (developer payouts) | P0 | 3 weeks |
| 3.2 | Pricing models: one-time, subscription, usage-based, freemium | P0 | 4 weeks |
| 3.3 | In-agent purchasing (agent-initiated buy/subscribe flow) | P0 | 4 weeks |
| 3.4 | Developer revenue dashboard | P0 | 3 weeks |
| 3.5 | License key generation and management | P1 | 2 weeks |
| 3.6 | UPI/India payments support | P1 | 2 weeks |
| 3.7 | Promoted listings (self-serve ad platform) | P1 | 3 weeks |
| 3.8 | Affiliate/referral program for skill recommendations | P2 | 2 weeks |
| 3.9 | Tax handling and invoicing (US, EU, India) | P1 | 2 weeks |
| 3.10 | Monthly payouts with detailed breakdowns | P0 | 1 week |
Key Design Decision: Take Rate
Section titled “Key Design Decision: Take Rate”- 15% for individual developers (lower than App Store’s 30%, competitive)
- 20% for SaaS-connected skills (higher value, more infrastructure needed)
- 10% for first year (promotional rate to bootstrap supply)
Metrics Target
Section titled “Metrics Target”| Metric | Target |
|---|---|
| Paid skills listed | 5,000+ |
| Monthly GMV | $500K+ |
| Developers earning revenue | 1,000+ |
| Average developer monthly payout | $200+ |
| Promoted listing revenue | $50K/mo |
Phase 4: Enterprise Governance (Months 14-20)
Section titled “Phase 4: Enterprise Governance (Months 14-20)”Theme: Win enterprise budgets with governance and compliance
Deliverables
Section titled “Deliverables”| # | Feature | Priority | Effort |
|---|---|---|---|
| 4.1 | Private skill registries (org-only visibility) | P0 | 4 weeks |
| 4.2 | Policy engine (allowlists, blocklists, category restrictions, trust score thresholds) | P0 | 4 weeks |
| 4.3 | SSO integration (Okta, Azure AD, Google Workspace) | P0 | 3 weeks |
| 4.4 | SCIM provisioning | P1 | 2 weeks |
| 4.5 | Approval workflows (request → review → approve → install) | P0 | 3 weeks |
| 4.6 | Audit log (comprehensive: who installed what, when, data accessed) | P0 | 3 weeks |
| 4.7 | Compliance reports (SOC2, GDPR, DPDPA auto-generation) | P1 | 4 weeks |
| 4.8 | Cost management dashboard | P1 | 2 weeks |
| 4.9 | Admin console with role-based access | P0 | 3 weeks |
| 4.10 | Self-hosted deployment option | P2 | 6 weeks |
Enterprise GTM
Section titled “Enterprise GTM”- Target: Companies already using Claude Code, Codex, or OpenClaw at scale
- Sales motion: PLG (start with free scanning) → team upgrade → enterprise contract
- Initial verticals: Tech companies, financial services, consulting firms
Metrics Target
Section titled “Metrics Target”| Metric | Target |
|---|---|
| Enterprise customers | 100+ |
| Average contract value | $3,000/mo |
| Enterprise ARR | $3.6M |
| Net revenue retention | 130%+ |
| Self-hosted deployments | 10+ |
Phase 5: Agent Commerce Platform (Months 20-30)
Section titled “Phase 5: Agent Commerce Platform (Months 20-30)”Theme: Power the transaction layer of the agentic economy
Deliverables
Section titled “Deliverables”| # | Feature | Priority | Effort |
|---|---|---|---|
| 5.1 | Agent-to-agent commerce protocol support (ACP, UCP, A2A) | P0 | 6 weeks |
| 5.2 | SaaS vendor skill optimization suite (Agent SEO) | P0 | 4 weeks |
| 5.3 | Transaction analytics for SaaS vendors | P1 | 3 weeks |
| 5.4 | Agent recommendation API (agents ask “which CRM skill should I use?”) | P0 | 4 weeks |
| 5.5 | Bid-based ranking for commercial skills | P1 | 3 weeks |
| 5.6 | Multi-agent skill orchestration (chain skills into workflows) | P1 | 6 weeks |
| 5.7 | Vertical skill catalogs (finance skills, healthcare skills, etc.) | P2 | 4 weeks |
| 5.8 | India market expansion (vernacular skill support) | P2 | 4 weeks |
Vision
Section titled “Vision”By Phase 5, Findable is not just a marketplace — it’s the commerce infrastructure for the agentic economy. When AI agents need to select tools, services, or products to complete a task, they query Findable. SaaS vendors pay to be discovered and recommended. Enterprises govern what their agents can purchase. Developers earn revenue from their skills.
Roadmap Summary Timeline
Section titled “Roadmap Summary Timeline”Month: 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 ... 30 ├──────┤ Phase 0: Foundation ├───────────────┤ Phase 1: Security Wedge ├───────────────┤ Phase 2: Discovery ├──────────────────┤ Phase 3: Monetization ├───────────────────┤ Phase 4: Enterprise ├──────────┤ Phase 5: CommerceResource Requirements by Phase
Section titled “Resource Requirements by Phase”| Phase | Engineers | Design | Biz/GTM | Total Team |
|---|---|---|---|---|
| Phase 0 | 3 | 1 | 0 | 4 |
| Phase 1 | 4 | 1 | 1 (DevRel) | 6 |
| Phase 2 | 5 | 1 | 2 | 8 |
| Phase 3 | 6 | 1 | 3 | 10 |
| Phase 4 | 8 | 2 | 4 (incl. sales) | 14 |
| Phase 5 | 10 | 2 | 6 | 18 |