Signed skill registries
Publish installable capability packs with product-neutral `host_requirements`, manifest hash checks, trust tiers, action classes, secret requirements, and confirmation policy. Hosts decide what to install; models never become the security boundary.