MCP.so
Sign In
M

Mcp Skills

@BeBraveBeKind

About Mcp Skills

Pre-install trust scoring & safety scanning for MCP servers, AI skills & npm packages — 15 signals incl. OSV/KEV/EPSS vuln intel and an auto-gate go/no-go.

Config

Add this server to your MCP-compatible client using the configuration below.

{
  "mcpServers": {
    "mcpskills": {
      "command": "npx",
      "args": [
        "-y",
        "@mcpskillsio/server"
      ]
    }
  }
}

Tools

9

Score any AI skill, MCP server, or GitHub repo for trustworthiness. Returns a trust score (0-10) across 4 dimensions: Alive, Legit, Solid, Usable. Accepts: owner/repo, GitHub URL, npm package (npm:@scope/name or @scope/name), Smithery URL, or OpenClaw URL. AI skills get enhanced safety scanning. Set MCPSKILLS_API_KEY for full reports.

Run a focused safety scan on an AI skill or MCP server. Checks for prompt injection, shell execution, network exfiltration, credential theft, obfuscated payloads, public network binding (0.0.0.0), and risky npm lifecycle scripts (preinstall/install/postinstall). Accepts any input format (owner/repo, npm package, Smithery URL, etc.).

Browse curated, pre-scored AI skill packages organized by use case. Each package contains vetted skills with trust scores. Available packages: Claude Power User, Full-Stack Vibe Coder, Data & Research, DevOps & Infrastructure, Content & Marketing.

Get a trust badge URL for any repo or package. Returns a shields.io-style SVG badge showing the trust score and tier. Embed in READMEs. Badge auto-updates hourly.

Start monitoring a repo or package for trust score changes. Alerts when score changes significantly (±0.3 points or tier change). Requires a paid API key.

Re-scan all watched repos and check for score changes. Returns any repos whose trust score changed significantly since last check.

Check up to 5 repos or packages in one call. Returns a trust assessment for each. Requires a Developer Pro or Team API key. Accepts any mix of formats (owner/repo, npm packages, registry URLs).

Should I install this? Returns a simple go/no-go decision with reasoning. Accepts any format: owner/repo, npm package, Smithery URL, etc. Returns { proceed: true/false, reason: "..." }.

Recommend a vetted stack of trusted tools for a described task. Describe what you're building (e.g., "Next.js app with auth, payments, and AI chat") and get back a curated list of the highest-scoring repos in each relevant category, pre-scored and ready to install. Returns tool names, trust scores, tiers, and install hints. Use this instead of guessing which tools to recommend — every suggestion is backed by live trust data.

Overview

What is Mcp Skills?

Mcp Skills provides pre-install trust scoring and safety scanning for MCP servers, AI skills, and npm packages. It uses 15 signals including OSV/KEV/EPSS vulnerability intelligence and an auto-gate go/no-go decision mechanism.

How to use Mcp Skills?

Key features of Mcp Skills

  • Pre-install trust scoring for MCP servers, AI skills, npm packages
  • Safety scanning using 15 distinct signals
  • Includes OSV/KEV/EPSS vulnerability intelligence
  • Auto-gate go/no-go decision mechanism

Use cases of Mcp Skills

  • Evaluate trust of an MCP server before installation
  • Scan npm packages for vulnerabilities prior to use
  • Assess safety of AI skills before deployment
  • Automate go/no-go decisions based on risk signals

FAQ from Mcp Skills

Comments

More Other MCP servers