Mcpskills Server — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Mcpskills Server (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
<p align="center"> <img src="https://raw.githubusercontent.com/BeBraveBeKind/mcpskills-server/main/assets/og.png" alt="MCP Skills — the pre-install trust layer for MCP servers and AI skills" width="820"> </p>
Use the MCPSkills pre-install trust layer from inside Claude Code, Cursor, or any MCP client.
13 standard signals (15 in Skills Mode) across 4 dimensions with safety scanning for prompt injection, credential theft, and supply chain attacks. Check install risk before an MCP server or AI skill reaches your agent.
claude mcp add mcpskills -- npx @mcpskillsio/serverAdd to your .cursor/mcp.json:
{
"mcpServers": {
"mcpskills": {
"command": "npx",
"args": ["@mcpskillsio/server"]
}
}
}Add to claude_desktop_config.json:
{
"mcpServers": {
"mcpskills": {
"command": "npx",
"args": ["@mcpskillsio/server"]
}
}
}check_trust_scoreScore any GitHub repo, npm package, or registry URL. Returns trust tier, composite score, and 4 dimension scores.
"Score anthropics/anthropic-sdk-typescript"scan_safetyFocused safety scan for AI skills. Checks for prompt injection, shell execution, network exfiltration, credential theft, and obfuscated payloads.
"Is this MCP server safe? modelcontextprotocol/servers"list_packagesBrowse curated, pre-scored skill packages organized by use case.
"Show me safe AI skill packages for full-stack development"get_badgeGenerate an SVG trust badge URL for your README.
"Get a trust badge for my repo anthropics/anthropic-sdk-typescript"watch_repoStart monitoring a repo for trust score changes (requires API key).
"Watch modelcontextprotocol/servers for score changes"check_watchedRe-scan all watched repos for score or tier changes (requires API key).
"Check my watched repos"batch_checkScore up to 5 repos in a single call (Developer Pro or Team).
"Batch check these repos: anthropics/anthropic-sdk-typescript, langchain-ai/langchainjs"auto_gateGet a boolean go/no-go decision with reasoning.
"Should I install this MCP server? 21st-dev/magic-mcp"build_stackRecommend a vetted, pre-scored stack from MCP Skills' curated packages.
"Build me a stack: auth + payments + email"Free tier returns trust tier + dimension scores (same as mcpskills.io free scans, 10/day).
For full reports (13 standard / 15 Skills Mode signals + safety findings) inside your IDE, set your API key:
export MCPSKILLS_API_KEY=your_key_hereGet your API key at mcpskills.io/api. Developer Pro is $19/mo or $149/yr. Team is $99/mo for org/security workflows.
The server calls the mcpskills.io trust scoring API, which:
MIT — Built by Michael Browne at Rise Above Partners.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.