Docs
Installing from the Marketplace
How installs, updates, consent screens, the kill-switch, and private-source listings work.
The Marketplace distributes five kinds of tool: agents and skills (instructions that extend your AI team), plugins (MCP servers and CLI tools), and apps and websites (full products). Browse it in the sidebar's Marketplace tab, or publicly at wilow.team/marketplace.
Installing a tool
- Open a tool's page and choose Install.
- For anything that runs code on your machine, a consent screen appears first. It discloses: the exact source (a GitHub repository, or a “private source — escrowed with Wilow” notice), the pinned SHA-256 of the source that will be extracted, the literal setup commands that will run, and the tool's declared permissions (network hosts, connectors, whether it runs local code). Nothing runs until you approve.
- Your engine downloads the pinned source, re-verifies its hash, runs the allow-listed setup, and registers the tool. Wilow-powered tools get their own chat thread in your sidebar.
What the consent screen protects
Updates & auto-update
When a publisher ships a new version, your engine reconciles it through the same hash-pinned pipeline. Each installed tool has an auto-update setting; with it off, you get an “update available” notice and apply updates on your schedule.
The kill-switch
If a tool is unpublished — by its publisher or by Wilow moderation — it is delisted from the catalog and stopped on installers' machines on the next reconcile (minutes). For private-source tools, downloads stop immediately. This is the mechanism that lets a bad or compromised tool be pulled everywhere quickly.
Private-source listings
A listing marked 🔒 Private source means the publisher shared their code with Wilow's escrow rather than a public repository. You can still install and run it; its source is not browsable, forkable, or downloadable by anyone but the relay, which hands your engine a short-lived, hash-verified signed URL at install time. The integrity guarantee is identical to public tools.
Apps & websites
Some apps are Wilow-powered — they run locally on your own AI setup and appear as a chat in your sidebar (see the Runtime contract). Others are plain downloads or store links. The listing tells you which, and the same consent and verification rules apply to anything that executes locally.
Enterprise install controls
Enterprises can set a policy so members install only enterprise-vetted tools (enterprise-only) rather than any public tool. See the Enterprise guide.