Skip to content

Naming & Positioning (Validated)

Domain: findable.sh Tagline: “The trust layer for AI agent skills”

Revised tagline: Prior tagline was “The trusted infrastructure for the agent skills economy.” The new tagline leads with what’s most validated (trust/security) rather than the full vision (economy/commerce).

CriterionAssessment
MemorableOne word, plain English, easy to remember
DescriptiveStates the value prop: make skills findable (and safe)
Domainfindable.sh — clean, developer-friendly TLD
UniqueNo major brand conflicts in this space
ExtensibleWorks for discovery, trust, governance, and eventually commerce

TermWhat It MeansLimitation for Findable
GEO (Generative Engine Optimization)Get cited in AI answersPassive — about mentions, not agent actions
AEO (Agentic Engine Optimization)Optimize for agentic AINewest term (WEF, Microsoft), but we’re infrastructure, not optimization
Agent SEOOptimize for agent discoveryPromising but 18-24 months from mainstream
Agent Skill RegistryDirectory of skillsCommodity — Smithery, MCP.so already exist

Our Category: “Agent Skill Trust Infrastructure”

Section titled “Our Category: “Agent Skill Trust Infrastructure””

Rather than creating a buzzword category, we position as infrastructure:

  • npm is “package infrastructure”
  • Snyk is “security infrastructure”
  • Stripe is “payment infrastructure”
  • Findable is “trust infrastructure for agent skills”

This avoids competing with GEO/AEO tools (different market) and positions us correctly as developer infrastructure, not a marketing tool.


Positioning (Revised for Validated Reality)

Section titled “Positioning (Revised for Validated Reality)”

For developers:

“Scan, search, and verify AI agent skills across every registry. Open-source security scanner + cross-platform discovery.”

For enterprises:

“Govern what AI agents can discover and use inside your organization. Security scanning, trust scores, private registries, and compliance — for agent skills.”

For investors:

“We’re building the security and discovery infrastructure for the agent skills ecosystem — 130K+ skills with 32-41% having critical vulnerabilities. Open-source wedge, enterprise revenue.”

What changed: Prior positioning led with “npm + Snyk + Stripe.” Revised positioning leads with security (most validated) and drops the commerce comparison (premature).

CompetitorTheir StrengthOur Counter-PositionHonest Risk
Snyk$408M ARR, acquired Invariant Labs, enterprise distributionThey scan and report. We scan, score, AND integrate with discovery. They don’t build registries or governance.If Snyk adds registry + governance, our security positioning erodes
Composio$2M ARR, 200+ enterprise customers, $29M fundingThey’re a managed integration platform. We’re a trust + discovery layer. They’re vendor-specific; we’re neutral.If they add public discovery, they’d combine enterprise + developer
Vercel skills.sh110K installs in 4 days, Vercel distributionNo security, no trust scores, no enterprise features. SKILL.md focused; we’re cross-platform.They could add security and make our discovery redundant
Smithery7,300 servers, 322K monthly visits, hostingMCP-only, no security, no enterprise. We’re cross-platform with trust.Best pure-registry UX; hard to out-execute on their niche
ClawHubIntegrated with OpenClaw installationSingle-platform. Post-security-crisis (ClawHavoc). Creator left for OpenAI.If they clean up security AND stay relevant, strong lock-in for OpenClaw users
Stacklok/ToolHiveCryptographic verification (Sigstore)We’re broader (discovery + trust + governance). They’re enterprise-only.Their cryptographic approach may be more secure than our scoring approach

ACT 1: The Crisis (What’s Happening — PROVEN)

Section titled “ACT 1: The Crisis (What’s Happening — PROVEN)”

“AI agents are the new interface for knowledge workers. 97M+ monthly MCP SDK downloads. 130-150K agent skills across 9+ fragmented registries. But the ecosystem has a trust crisis: 32-41% of MCP servers have critical vulnerabilities. 7.1% of ClawHub skills leak credentials. 341 malicious skills were found on ClawHub in February 2026.”

“OWASP published the MCP Top 10. NIST published agent identity guidance. The security problem isn’t theoretical — it’s happening now.”

“Registries exist — Smithery (7,300 servers), MCP.so (17,800), skills.sh (57,000 skills). But none of them scan for security. None provide trust scores. None offer enterprise governance.”

“Snyk acquired Invariant Labs and entered MCP security — but they scan code, they don’t build registries or discovery platforms. Composio has enterprise revenue — but they’re a managed platform, not cross-platform discovery.”

“No one combines security + discovery + governance in one platform.”

ACT 3: The Solution (What We’re Building — HONEST)

Section titled “ACT 3: The Solution (What We’re Building — HONEST)”

“Findable is the trust layer for AI agent skills. We start with an open-source security scanner — find vulnerabilities before they’re deployed. We layer on cross-platform discovery — search every registry with trust scores. We monetize through enterprise governance — private registries, policies, audit logs.”

“We earn the right to add commerce only when the market proves ready. Today, <$100K/month of skills are sold across the entire ecosystem. We’re not building payments for a market that doesn’t exist yet.”

The “Why Now” (Revised — Honest Timing)

Section titled “The “Why Now” (Revised — Honest Timing)”

“Three things make this the right time:

  1. Security crisis is proven — 32-41% critical vulnerability rate, OWASP/NIST/CoSAI publishing frameworks, real malware incidents
  2. Enterprise demand is emerging — Composio has $2M ARR in agent tool governance; CrowdStrike paid $740M for SGNL (agent identity)
  3. Discovery is fragmented — 9+ registries with no unified search, no cross-platform coverage, no quality signals

We’re NOT saying commerce is ready (it’s not — <$100K/month). We’re saying security and discovery are ready NOW, and enterprise governance is ready within 6-12 months.”


PillarMessageProof PointConfidence
Trust”32-41% of MCP servers have critical vulnerabilities. We scan every one.”Enkrypt AI, earezki.com, Snyk researchHIGH
Discovery”130-150K skills across 9+ registries. We unify them with trust scores.”Registry counts verifiedHIGH
Governance”Enterprises need agent skill governance. We provide private registries, policies, and audit logs.”Composio $2M ARR, NIST guidanceEMERGING
Agent-native”Our MCP server lets agents discover and verify skills programmatically.”Findable MCP Server (to be built)PLANNED
Commerce”Developers made 0 dollars. We fix that.”DEFERRED — market not readyNOT YET

What we stopped saying: “370K+ skills” (inflated — real unique count is ~130-150K). “npm + Snyk + Stripe” (npm analogy is weak, Snyk is a competitor, Stripe is premature). “$63M Year 5 revenue” (revised to $10-20M).


AttributeOur VoiceNOT Our Voice
Data-driven, not hyperbolic”32% of MCP servers have critical vulns.""THE AGENT ECOSYSTEM IS BROKEN!”
Honest about limitations”Commerce is premature. We’re building trust first.""We’re the npm + Snyk + Stripe of agents!”
Developer-first”Install with npx findable scan ./my-server/""Schedule a demo with our enterprise team”
Security-authoritative”Based on scanning 10K+ servers…""We think security might be important…”
Open about competition”Snyk has $408M ARR. We differentiate by…""We have no real competitors.”

  1. “State of Agent Skills Security 2026” — flagship data-driven report
  2. “How to Secure Your MCP Server” — developer tutorial, drives scanner adoption
  3. “Registry Comparison: Which One Should You Use?” — positions us as the authority
Content TypeFrequencyPurpose
Security DigestMonthlyAuthority, email list
Ecosystem data updatesQuarterlyPR, citations
Developer tutorialsWeeklySEO, acquisition
Enterprise guidesMonthly (Phase 3+)Lead generation