The full upstream README, mirrored here for reference. Install config, tool schemas, adoption signals, and an original overview live on the Mcpskills Server listing page.
Use the MCPSkills pre-install trust layer from inside Claude Code, Cursor, or any MCP client.
13 standard signals (15 in Skills Mode) across 4 dimensions with safety scanning for prompt injection, credential theft, and supply chain attacks. Check install risk before an MCP server or AI skill reaches your agent.
Add to your .cursor/mcp.json:
Add to claude_desktop_config.json:
check_trust_scoreScore any GitHub repo, npm package, or registry URL. Returns trust tier, composite score, and 4 dimension scores.
scan_safetyFocused safety scan for AI skills. Checks for prompt injection, shell execution, network exfiltration, credential theft, and obfuscated payloads.
list_packagesBrowse curated, pre-scored skill packages organized by use case.
get_badgeGenerate an SVG trust badge URL for your README.
watch_repoStart monitoring a repo for trust score changes (requires API key).
check_watchedRe-scan all watched repos for score or tier changes (requires API key).
batch_checkScore up to 5 repos in a single call (Developer Pro or Team).
auto_gateGet a boolean go/no-go decision with reasoning.
build_stackRecommend a vetted, pre-scored stack from MCP Skills' curated packages.
Free tier returns trust tier + dimension scores (same as mcpskills.io free scans, 10/day).
For full reports (13 standard / 15 Skills Mode signals + safety findings) inside your IDE, set your API key:
Get your API key at mcpskills.io/api. Developer Pro is $19/mo or $149/yr. Team is $99/mo for org/security workflows.
The server calls the mcpskills.io trust scoring API, which:
MIT — Built by Michael Browne at Rise Above Partners.