Skip to content

Product Roadmap (Validated)

Security Wedge → Discovery Funnel → Enterprise Revenue → Commerce (if validated)

Start with the most urgent, most validated pain (security). Use it to build community and brand. Layer on discovery as the free funnel. Monetize through enterprise governance. Only add commerce when the ecosystem GMV justifies it.

Key revision: Original roadmap assumed 5 overlapping phases reaching $63M ARR by Year 5 with 500K registered developers. Validated targets: $10-20M ARR by Year 5, 50K-100K registered developers. Commerce phase is now conditional, not guaranteed.


Phase 1: Open-Source Security Scanner (Months 1-4)

Section titled “Phase 1: Open-Source Security Scanner (Months 1-4)”

Theme: Build community and brand through a free, open-source security tool

#FeaturePriorityEffort
1.1Security scanner v1 (API key detection, malware patterns, prompt injection checks)P03 weeks
1.2SKILL.md parser (full spec + MCP server manifest support)P02 weeks
1.3CLI tool (npx findable scan <path>)P01 week
1.4Trust Score algorithm v1P01 week
1.5GitHub repo + open-source (MIT license for scanner)P01 week
1.6Landing page + docs siteP01 week
1.7”State of Agent Skills Security” report — scan 10K+ skills, publish findingsP02 weeks
1.8Batch scanning of major registries (Smithery, PulseMCP, MCP.so)P12 weeks
  • Open-source model: Scanner CLI is MIT-licensed (like Snyk CLI was). Trust database and enterprise features are proprietary.
  • Scanner approach: Build our own static analyzer + integrate Semgrep for known patterns. LLM-based semantic analysis for prompt injection.
  • Database: PostgreSQL + pgvector for semantic search from day one.
  • Publish “State of Agent Skills Security” report — drives PR and awareness
  • Launch on HN: “Show HN: We scanned 10K MCP servers. 32% have critical vulnerabilities.”
  • Open-source the scanner CLI — drives developer adoption
  • Active presence in Claude Code, OpenClaw, and MCP communities
MetricTargetBasis
CLI downloads5,000+mcp-scan baseline adoption
Skills scanned (total)10,000+Major registries combined
GitHub stars500+Comparable security tool launches
Security report mentions3+ publicationsData-driven reports get coverage
  • Can scan any SKILL.md or MCP server manifest for security issues
  • Trust Score algorithm producing meaningful differentiation
  • At least one security finding published that gets community attention

Phase 2: Cross-Platform Discovery (Months 4-8)

Section titled “Phase 2: Cross-Platform Discovery (Months 4-8)”

Theme: Become the best place to find any agent skill across all registries

#FeaturePriorityEffort
2.1Multi-registry ingestion pipeline (Official MCP Registry, Smithery, PulseMCP, Glama, MCP.so, skills.sh, SkillsMP, ClawHub, GitHub)P03 weeks
2.2Semantic search (intent-based: “I need to automate email follow-ups”)P03 weeks
2.3Web UI with trust scores displayed on all resultsP03 weeks
2.4Findable MCP Server (agents can discover skills through us)P02 weeks
2.5Category taxonomy (20+ categories)P11 week
2.6Scanner v2 (deep analysis: dependency scanning, data flow analysis)P03 weeks
2.7Public Trust Score badges (embeddable — like “Snyk verified”)P11 week
2.8Scanning API v1 (for platforms to integrate)P12 weeks
2.9Browser extension (show trust score on Smithery, MCP.so, GitHub)P22 weeks
2.10Developer accounts (GitHub OAuth)P11 week

Build an MCP server that any agent (Claude, OpenClaw, Codex) can connect to. When a user asks their agent to “find a skill for X,” the agent queries Findable directly. This makes us the discovery layer inside the agent — not just a website.

MetricTargetBasis
Skills indexed50,000+Major registries aggregated
Monthly active searchers10,000+Conservative; Smithery gets 322K/mo
CLI downloads (cumulative)15,000+Growth from Phase 1
Scanning API integrations2-3 platformsPartnership pipeline
Verified publishers100+Quality over quantity

Phase 3: Enterprise Governance (Months 8-14)

Section titled “Phase 3: Enterprise Governance (Months 8-14)”

Theme: First revenue from enterprise skill management

#FeaturePriorityEffort
3.1Private skill registries (org-only visibility)P04 weeks
3.2Policy engine (allowlists, blocklists, trust score thresholds)P04 weeks
3.3SSO integration (Okta, Azure AD, Google Workspace)P03 weeks
3.4Approval workflows (request → review → approve → install)P03 weeks
3.5Audit log (who installed what, when, data accessed)P03 weeks
3.6Admin console with role-based accessP03 weeks
3.7Verified Publisher program (full identity verification)P12 weeks
3.8SCIM provisioningP12 weeks
3.9Compliance report generation (SOC2, GDPR)P13 weeks
3.10Cost management dashboardP22 weeks
  • Target: Companies already using Claude Code, Codex, or OpenClaw at scale
  • Sales motion: PLG (free scanner users → team adoption → enterprise inquiry → sales)
  • Signal triggers: 5+ users from same company domain; enterprise email signups
  • Initial verticals: Tech companies, financial services, consulting firms
  • Pricing: Team $30/user/mo, Business $60/user/mo, Enterprise custom
MetricTargetBasis
Enterprise pilot customers20-50Conservative; Composio has 200+ at $2M ARR
Average contract value$2,000-4,000/mo50-100 seats at $30-60/user/mo
Enterprise ARR run rate$200K+20+ customers
Net revenue retention120%+Seat expansion within organizations

Phase 4: Commerce Layer (Months 14-24) — CONDITIONAL

Section titled “Phase 4: Commerce Layer (Months 14-24) — CONDITIONAL”

Theme: Marketplace for paid skills — ONLY IF evidence supports it

Build Triggers (ALL must be met before starting Phase 4)

Section titled “Build Triggers (ALL must be met before starting Phase 4)”
TriggerCurrent StateRequired State
Paid MCP server generating $100K+ ARRNo known examplesAt least 1
Total ecosystem GMV<$100K/month>$500K/month
Findable enterprise customers050+
Agent-autonomous tool discoveryExperimentalEarly mainstream
#FeaturePriorityEffort
4.1Stripe Connect integration (developer payouts)P03 weeks
4.2Pricing models: subscription, usage-based, freemiumP04 weeks
4.3Developer revenue dashboardP03 weeks
4.4License key generation and managementP12 weeks
4.5Promoted listings (self-serve)P13 weeks
4.6In-agent purchasing flowP14 weeks
  • Continue deepening enterprise governance features
  • Expand scanning capabilities
  • Build partnerships with existing commerce players (Apify, MCPize)
  • Re-evaluate at Month 18 and Month 24

Month: 1 2 3 4 5 6 7 8 9 10 11 12 13 14 ... 24
├───────────────┤
Phase 1: Security Scanner (Open Source)
├──────────────────┤
Phase 2: Discovery Engine
├───────────────────┤
Phase 3: Enterprise Governance
├──────────┤
Phase 4: Commerce
(CONDITIONAL)

PhaseEngineersDesignBiz/GTMTotal
Phase 1 (Mo 1-4)2-30-102-4
Phase 2 (Mo 4-8)3-411 (DevRel)5-6
Phase 3 (Mo 8-14)4-512 (incl. sales)7-8
Phase 4 (Mo 14-24)5-6139-10

Key revision: Prior plan projected 65 headcount by Year 5. Realistic plan keeps team lean (10-15) until revenue justifies expansion. India engineering hub for cost efficiency.


These external signals determine whether we accelerate, maintain, or pivot:

SignalWatch ForImpact
Paid MCP server hits $100K+ ARRValidates commerce layerAccelerate Phase 4
Snyk launches registry productNarrows our security positioningPivot to governance-first
Anthropic expands official registryChanges discovery landscapeAdjust discovery strategy
Composio adds public discoveryDirect competition on our funnelDifferentiate on cross-platform
Enterprise RFPs for “agent skill governance”Proves enterprise budgetAccelerate Phase 3
MCP SDK downloads plateauEcosystem growth stallingRe-evaluate entire thesis