Server data from the Official MCP Registry
Trust scoring for MCP servers, AI skills & npm packages — 15 signals + safety scanning.
Trust scoring for MCP servers, AI skills & npm packages — 15 signals + safety scanning.
Valid MCP server (2 strong, 4 medium validity signals). No known CVEs in dependencies. ⚠️ Package registry links to a different repository than scanned source. Imported from the Official MCP Registry. 1 finding(s) downgraded by scanner intelligence.
5 files analyzed · 1 issue found
Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.
This plugin requests these system permissions. Most are normal for its category.
Set these up before or after installing:
Environment variable: MCPSKILLS_API_KEY
Add this to your MCP configuration file:
{
"mcpServers": {
"io-mcpskills-server": {
"env": {
"MCPSKILLS_API_KEY": "your-mcpskills-api-key-here"
},
"args": [
"-y",
"@mcpskillsio/server"
],
"command": "npx"
}
}
}From the project's GitHub README.
The pre-install trust layer for MCP servers and AI skills. MCP Skills scores install risk across 13 standard signals (15 in Skills Mode), publishes public score pages and trust badges, and supports monitoring/API workflows before unknown tools reach an agent.
Website: mcpskills.io
mcpskills scores GitHub repos across 4 dimensions:
AI skills and MCP servers get enhanced scanning with 5 safety checks based on ClawHavoc and ToxicSkills attack patterns.
Install the MCP server to score repos directly from your IDE:
claude mcp add mcpskills -- npx @mcpskillsio/server
See mcp-server/README.md for Cursor and Claude Desktop setup.
Scan any repo at mcpskills.io — free, no signup required. Browse the public pre-install trust directory at mcpskills.io/servers.
curl -X POST https://mcpskills.io/api/score \
-H "Content-Type: application/json" \
-d '{"repo": "anthropics/anthropic-sdk-typescript"}'
mcpskills/
mcp-server/ # npm package (@mcpskillsio/server) — 9 MCP tools
lib/ # Shared core: scorer (13 standard / 15 Skills Mode), skills detector, safety scanner
netlify/functions/ # Serverless API (score, badge, monitor, certify, webhook)
public/ # Static website (mcpskills.io)
data/ # Registry, score cache, curated packages
scripts/ # CLI utilities
| Component | Purpose |
|---|---|
| MCP Server | IDE integration — score repos from Claude Code, Cursor, or any MCP client |
| API | REST endpoints for scoring, badges, monitoring, certification |
| Website | Live scanner, blog, trust badge generator |
| Trust Directory | Public /servers directory and /score/* pages for install-risk discovery |
| Scheduled Functions | Nightly crawl (2am UTC), daily monitoring (8am UTC), weekly digest (Sunday 6pm UTC) |
| Tool | Description |
|---|---|
check_trust_score | Score any GitHub repo, npm package, or registry URL (0-10, 4 dimensions, up to 15 signals) |
scan_safety | Focused safety scan for AI skills (5 threat categories) |
list_packages | Browse curated, pre-scored skill packages |
get_badge | Generate SVG trust badge for READMEs |
watch_repo | Monitor repos for trust score changes |
check_watched | Re-scan all watched repos |
batch_check | Score up to 5 repos in one call (Developer Pro or Team) |
auto_gate | Boolean go/no-go decision with reasoning |
build_stack | Recommend a vetted, pre-scored stack from curated packages |
Free includes the public directory, public score pages, live trust badges, and 10 scans/day. Single Report is $2 for one full 15-signal report. Developer Pro is $19/mo or $149/yr for full reports, batch API, monitoring, trending trust data, and 1000 agent calls/day. Verified Builder is $29/mo or $249/yr for maintainer trust badges, public certified listings, recurring recertification, and priority review. Team is $99/mo for org/security workflows. Enterprise is custom.
| Tier | Score | Meaning |
|---|---|---|
| Verified | >= 7.0 | High confidence across all dimensions |
| Established | >= 4.5 | Moderate confidence, sufficient signals |
| New | < 4.5 | Insufficient data or low scores |
| Blocked | — | Disqualifiers: no license, critical CVE, dangerous workflows |
Free tier returns trust tier + dimension scores. For full reports (13 standard / 15 Skills Mode signals + safety findings):
export MCPSKILLS_API_KEY=your_key_here
Get your key at mcpskills.io/api.
MIT — Built by Michael Browne at Rise Above Partners.
Be the first to review this server!
by Modelcontextprotocol · Developer Tools
Read, search, and manipulate Git repositories programmatically
by Modelcontextprotocol · Developer Tools
Web content fetching and conversion for efficient LLM usage
by Toleno · Developer Tools
Toleno Network MCP Server — Manage your Toleno mining account with Claude AI using natural language.