cargo-hosting skillB
cargo-hosting is agent-read markdown (skill) from getcargohq/cargo-skills: Put something on the internet from Cargo — Vite single-page apps served at https://<slug>.cargo.app and serverless edge workers that answer HTTP requests, plus the deployments that build and promote them. Triggers: "build me a dashboard for this", "host this app", "give me a URL to share", "deploy this", "I need a webhook endpoint", "make it live", "promote to production", "put it on cargo.app", "ship a UI for my team". Skip when: the app or worker should be declared as committed workspace code .
Indexed from public GitHub and served as immutable, content-addressed versions. Install it pinned to an exact SHA-256 with the mdr CLI, and every file is verified against the hash recorded here before it reaches your agent. The deterministic audit below grades the latest version, and the same file always earns the same grade.
How to install
mdr add getcargohq/cargo-skills/cargo-hosting@v1.0.2mdr add getcargohq/cargo-skills/cargo-hosting@sha256:22473739d5700afePin to a label to follow the author's releases, or to a sha256 to freeze the exact bytes forever. Either way the resolved hash is written to mdr.lock, and mdr install reproduces it on any machine.
[](https://markdownregistry.com/a/art_r7iyyaigs7m2ziwi)
0 badge views in 30 days
Versions
| version | committed | commit | size | audit | |
|---|---|---|---|---|---|
| v1.0.2 latest | 2026-09-14 | addc862 | 9,391 B | B | view · diff |
| v1.0.1 | 2026-08-12 | 3708f8c | 9,387 B | B | view · diff |
| v1.0.1 | 2026-08-11 | e28aabd | 8,503 B | B | view · diff |
| v1.0.0 | 2026-06-15 | 53a1a86 | 8,455 B | B | view |
Audit of the latest version
- fail: No instruction to read or print local credentials (matched: Print .env)
- pass: Frontmatter block present
- pass: Frontmatter declares a name
- pass: Frontmatter declares a description
- pass: Size between 200 bytes and 200 KB (9391 bytes)
- pass: No zero-width or bidi control characters
- pass: No instruction hidden inside an HTML comment
- pass: No link to an exfiltration or paste host
- pass: No credential-shaped string
- pass: No instruction to send local credentials anywhere
- pass: No text hidden with inline styles
- pass: No prompt-injection phrasing
- pass: No curl or wget piped into a shell
- pass: No recursive delete of root, home or parent
- pass: No base64 blob over 200 characters
- pass: No link to a raw IP address
- pass: No script tag
Source
getcargohq/cargo-skills · 18 stars · license MIT · pushed 2026-09-14 · branch main
API
GET https://markdownregistry.com/api/v1/artifacts/art_r7iyyaigs7m2ziwi GET https://markdownregistry.com/api/v1/resolve?ref=getcargohq/cargo-skills/cargo-hosting GET https://markdownregistry.com/api/v1/blob/22473739d5700afe486e64166127232eda3aa5bd7037a6c5b949fc340ea7a8b5