PogCode Open the app
Contents

Skills, servers and secrets

Added once to your account, installed on the Computers you choose, and delivered to every agent. Secret values stay on the Computer that holds them.

One catalog

Skills.sh and the official MCP Registry are copied continuously into a catalog PogCode keeps itself, so search is instant and keeps working when a source is down. Deprecated, deleted or incomplete entries say so instead of offering an action that would fail. A server that is not in the Registry can always be entered by hand.

Skills

Skills come from the catalog, by a stable identity — skill:<owner/repo/slug> — or from a folder you reviewed. An installation records that identity together with the digest of the package you reviewed, so an upstream change can never silently replace what you installed.

The Computer fetches the package over its authenticated connection, checks the digest, and only then adds the Skill to its library. A verified copy is kept, so installing keeps working while the source is offline. Project defaults and Thread overrides can select only Skills that are actually installed on that Computer. A Skill you add reaches every harness in the form it understands: a session-local plugin for Claude Code, a folder inside the private configuration for Codex. There is nothing to keep in sync by hand.

MCP servers belong to the Computer

Remote servers that support OAuth are authorized with OAuth 2.1 (authorization code with PKCE), registering the client automatically. Tokens stay on the Computer that owns the connection; they never enter the account, an Agent definition, the browser or a prompt. Servers without OAuth take headers and typed Secret references; local servers keep their command, arguments and environment.

Each connection has a small inspector: its identity and protocol, its authorization and connection state, then its tools, resources and prompts. From there you can call a tool with JSON arguments, read a resource, authorize, disconnect or refresh, and errors stay attached to the connection they belong to.

A gateway, not a pile of schemas

Agents do not receive every tool schema of every server on every turn. The daemon runs a gateway that offers one constant search-and-call surface over all selected servers, and can run a short composition of several calls in a sandbox whose only power is calling a named tool. Credentials stay with the server connections, never with the code being run.

Secrets

A Secret is defined once for the account: a name and a type. That definition reaches every Computer; the value does not. You set a value over a direct, one-time connection to the Computer that will hold it, and it is never shown again — not in the account, not in the browser, not in a prompt. Afterwards you see that a value is set, not what it is.

MCP servers refer to Secrets by name in typed fields, and a server is installed only after the Secrets it needs are defined. At run time the daemon fills in the value on the Computer where it lives. Agents, the browser and the account log only ever see the name.