SkillHQ

Marketplace for selling AI agents skills

Visit Website
June 7, 2026 SkillHQ now ships with no-KYC seller onboarding (60 seconds, PayPal payouts) and free skill support — here's why we changed direction

Hey IH 👋 — quick update from the SkillHQ build.

Six weeks ago I launched here as a paid-only marketplace for Claude Code SKILL.md packages with 85% revenue share and Stripe Connect KYC for sellers. Today we're shipping two changes that I think materially shift the product:

1. Starter tier — no KYC, 60-second seller onboarding
Default sellers no longer go through Stripe Connect verification. PayPal email is the only requirement. Live in under 60 seconds.

- 80% revenue share (was 85% with required KYC)
- PayPal payouts on demand: €20 minimum, 1 free per calendar month
- SkillHQ acts as Merchant of Record (we collect Stripe Tax, handle cross-border)
- Auto-upgrade to Pro tier (the original 85% / Stripe Connect setup) at the DAC7 threshold

2. Free skills supported
Sellers can publish €0 listings now. Free and paid live in the same catalog. Useful for audience building or for builders who want discoverability without monetizing.

Why we changed:
Almost every prospective seller conversation ended with the same objection: "I'd try this but I don't want to do full KYC just to find out if my skill will sell." That's a fair concern. Expected revenue from a brand-new listing doesn't justify a 30-minute compliance flow.

The original framing — paid-only, 85% revenue share, Stripe Connect for everyone — was built around the seller who already knows their skill is worth selling. That seller exists, but they're not the median seller. The median seller is testing the waters.

The Merchant of Record decision:
Letting Starter sellers skip KYC means SkillHQ becomes the legal seller-of-record for those transactions. That puts the tax/compliance burden on us, not on each individual seller. It's more work for us. It's a 5% commission swap (Starter 20% vs Pro 15%) to fund it.

The bet: more sellers listing → more catalog supply → more buyer interest → tier-upgrades when sellers cross DAC7 anyway. We'd rather take the marketplace economics than the compliance margin.

What hasn't changed:
- Anti-piracy fingerprinting on every install
- Multi-layered automated validation
- One-command CLI install for buyers
- 45+ countries supported

Honest ask:
For other marketplace builders here — has anyone else tried the MoR-for-default-tier model? Curious what edges I'm not anticipating, especially around tax remittance at scale and the Pro upgrade pathway.

For potential sellers — what's still in the way? If "no KYC + 60 seconds + free skills supported" still doesn't move you to list, I want to know what would.

skillhq.dev/become-seller

Comment

May 2, 2026 We killed our KYC requirement and started allowing free skills. Here's why.

Quick update from building https://skillhq.dev — the marketplace for Claude Code skills.

When we launched, every seller had to complete Stripe Connect KYC before publishing a single skill. Bank details, ID verification, the works. We thought it was the responsible move.

It wasn't. It was a wall.

The casual builder who just wrote a useful skill on a Sunday afternoon doesn't want to upload their passport to find out if anyone will pay €5 for it.

They close the tab.

So we rebuilt seller onboarding around two tiers:

Starter (default)
- No KYC. No bank details. Just an email and a PayPal address for payouts.
- Publish in under 60 seconds.
- 80% revenue share.
- SkillHQ acts as Merchant of Record (we handle Stripe Tax for buyers).
- On-demand PayPal payouts (€20 minimum, 1 free per month).

Pro
- Full Stripe Connect KYC.
- 85% revenue share, payouts straight to your bank.
- Auto-upgrades when you hit the EU DAC7 threshold (€2k/yr or 30 transactions).

The bet: lower the activation energy for the long tail of casual sellers, then graduate the serious ones to better economics once they have proof of demand.

We also turned on free skills (€0).

This was harder for me to greenlight — we're a paid marketplace, why list free stuff?

Two reasons:

1. ClawHub creators are reportedly making €600–€20k/month selling skills off-platform via Gumroad, but the discovery layer is the free directories. Free skills are how builders earn an audience before they earn money.
2. "Free with a paid premium version" is one of the most natural funnels in software. We were blocking it for ideological reasons.

Now you can ship a free skill, build install count + reviews, then publish a Pro version next to it. Same creator, same surface, no friction.

Lessons for other marketplace builders:

- The compliance work you do upfront (KYC, tax, payouts) is the platform's job, not the seller's. Push it into the platform until you literally can't (DAC7 forced our hand at scale, not at zero).
- "Free tier on a paid marketplace" sounds like cannibalization. It's actually top-of-funnel.
- The friction you tolerate when you're the seller is much higher than the friction your sellers will tolerate. Onboard yourself as if you'd never heard of your product.

Anyone else moved from a single-tier seller model to a tiered one? Curious how you handled the auto-upgrade UX — that's the part we're still iterating on.

Comment

April 24, 2026 How we built piracy protection for plain-text files — and why traditional DRM doesn't work for SKILL.md packages

One of the first problems we had to solve at SkillHQ was one that sounds simple but is surprisingly nuanced: how do you protect a text file?


SKILL.md packages and Custom GPT configs are just text. No binary to obfuscate, no executable to license-check. A buyer reads the content, copies it, pastes it somewhere — and you have no technical recourse.


Every digital goods platform we looked at either ignored the problem (Gumroad) or locked content behind a platform wall (LobeHub — the skill lives in their SaaS, not your local filesystem). Neither worked for us. Our entire value proposition is a CLI installer that drops skills into your local ~/.claude/skills/ folder. Lock-in was off the table.


The solution: detection and attribution instead of access control

We can't prevent a determined bad actor from sharing a file. What we can do is:

1. Know which buyer account a leaked file came from

2. Detect derivatives and paraphrases, not just exact copies


Layer 1: Invisible fingerprinting

Instead of delivering the canonical skill file, every skillhq install produces a buyer-specific version with a unique, invisible mark embedded in the content. The buyer can't see it. It doesn't affect functionality. But it's tied to their account.

This is text steganography: hiding information in ways that survive formatting changes and minor edits. The challenge is making the watermark robust enough to survive the buyer copying the file to a new location, reformatting it, or adding their own comments.

If a skill surfaces in a Discord server or a competing listing, we identify which purchase it came from. That changes the risk calculation for buyers thinking about sharing it — fewer pirates, more legitimate purchases.

Layer 2: SimHash paraphrase detection

Exact-copy detection is trivial. The harder problem is derivative theft: someone buys a skill, rewrites 30% of it, and lists it as original work on another platform — or on SkillHQ itself.

Standard hash comparison misses this entirely. SimHash doesn't.

SimHash generates a "fuzzy fingerprint" of a document's semantic content — similar documents produce similar hashes. We run similarity checks on every new listing submission against the existing catalog. High similarity score triggers a manual review before the skill goes live.

What we didn't build: platform lock-in

The tempting answer to piracy is "don't give them the file." Lock skills inside a web app, serve them through an API, require your SaaS to be running. This works — LobeHub does it — but it means the skill lives in someone else's platform, not your local workflow.

We decided early that was a worse product. The CLI install is the feature. Everything else is built around it.

Honest limitations:

A determined buyer with time can strip our fingerprinting. We know this. SimHash has false negatives on heavily rewritten derivatives. We don't have a legal enforcement layer beyond DMCA takedown support.

The goal isn't perfect protection. It's raising the cost of casual piracy enough to deter most of it, and giving creators a system they can trust. That shifts the risk calculus at the margins — which is enough.

Happy to go deeper on any of the implementation. Curious if others building digital goods marketplaces have solved this differently.

→ skillhq.dev

Comment

April 18, 2026 SkillHQ — a paid marketplace for Claude Code SKILL.md packages with one-command CLI install and built-in anti-piracy

Hi IH 👋

I've been building SkillHQ (skillhq.dev) — a paid marketplace for Claude Code SKILL.md packages and Custom GPT configurations, with a CLI installer and built-in anti-piracy.

The problem I kept seeing:

Developers were building genuinely useful Claude Code skills — SKILL.md packages that automate PR reviews, code generation workflows, testing pipelines — and putting them on GitHub for free.

Meanwhile, others were selling similar (often inferior) versions on Gumroad and reportedly earning $600–$20,000/month off-platform. The demand existed. The infrastructure didn't.

The gaps:

- GitHub: free distribution only, no monetization
- Gumroad: no CLI install, no piracy protection, not developer-native
- Free directories (AgentSkill.sh, Skills.sh, ClawHub): solid CLIs and even community audits — but zero creator monetization
- No existing platform combines CLI install + automated validation + piracy protection + creator payouts

What SkillHQ does:

- Buyers run skillhq install <name> — that's the entire purchase and install experience, drops directly into ~/.claude/skills/
- Sellers keep 85% of every sale, zero listing fees, zero upfront cost
- Anti-piracy: invisible fingerprinting on every install + SimHash paraphrase detection
- Automated validation before listing: structure, content, security checks

The interesting technical problem: you can't DRM a text file

SKILL.md packages are plain text. Traditional access control doesn't work — a buyer reads it, copies it, shares it in Discord, and you have no recourse.

So we went with detection and attribution instead:

Every skillhq install delivers a buyer-specific version with a unique invisible watermark — tied to that buyer's account. If a skill surfaces somewhere it shouldn't, we trace it back.

SimHash runs similarity checks on new listing submissions against the existing catalog, catching derivative theft (buy a skill, rewrite 30%, sell as original) before it goes live.

Not foolproof. But far better than crossing your fingers and hoping buyers don't share it.

Where we are:

Early. First sellers listing, waiting for first sales to happen. We're focused on finding skill creators right now — the supply side of the marketplace — before pushing hard on buyer acquisition.

Honest ask: What would make you list a skill here vs. staying on GitHub or Gumroad? What's the objection I'm not thinking about?

To list a skill: skillhq.dev/become-seller

General: skillhq.dev

Comment

About

I built Claude Code skills and gave them away for free. So did everyone else. The free ecosystem proved demand — but nobody pays creators. SkillHQ adds the economics: validated marketplace, 85% revenue share.