Saferskills
FreeNot checkedEvery AI skill, independently scanned. Public, open-source trust scoring for skills, MCP servers, hooks, and plugins across every agent platform. Apache-2.0. sa
About
Every AI skill, independently scanned. Public, open-source trust scoring for skills, MCP servers, hooks, and plugins across every agent platform. Apache-2.0. saferskills.ai
README
SaferSkills
Every AI capability, independently scanned.
A free, open, public trust-scoring service for the skills, MCP servers, hooks, plugins & rules
you install into Claude Code, Cursor, Windsurf, Copilot, Codex, Gemini, Cline & OpenClaw.
GitHub stars CI OpenSSF Scorecard npm License: Apache 2.0 Discussions Join our Slack
saferskills.ai · Methodology · Discussions · Slack · Security
See it in 15 seconds
Quick start
No install needed — npx runs the prebuilt native binary:
npx saferskills info mcp-server-github # score, four-axis breakdown, findings & report URL
npx saferskills install mcp-server-github # install to your detected agents — score re-checked, severity-gated
npx saferskills capability ./my-skill # scan a local file/dir — or a public GitHub URL
npx saferskills agent # behaviorally scan a running agent against ~20 adversarial tests
Prefer it installed? npm install -g saferskills or cargo install saferskills. No terminal at all? Everything the CLI does is in your browser at saferskills.ai — browse the catalog, scan a capability, or run a behavioral agent scan, with no account and nothing to install. Full command + flag reference: cli/README.md.
SaferSkills is v0.x, built in the open — the catalog is filling in as ingestion scales toward the public launch.
Why this exists
You install a Claude skill, an MCP server, a Cursor rules file, or a Codex hook. It runs with your file-system access. It can read your .env. It can curl | bash. It can quietly ship your repo to a paste site. And across the tens of thousands of such items now circulating, there is no public, transparent record of what each one actually does.
SaferSkills is that record. Anyone — a developer, a vendor, a researcher — submits a GitHub URL (or uploads a file), and a ~30-second deterministic scan returns a Yuka-style report: an aggregate trust score (0–100), a four-axis breakdown, every detector that fired, the rule that fired it, the exact line of evidence, the remediation, and a permalink the vendor can dispute.
Methodology, not opinion. Every rule is documented. Every score is reproducible. Every appeal is public.
How it works
The verdict path is fully deterministic — there is no LLM deciding your score. Every finding carries a static rule_id and a quotable line of evidence, so a verdict is reproducible from the trace alone. The result is a public report permalink:
Trust-score rubric
| Tier | Range | Meaning |
|---|---|---|
| 🟢 Green | 80–100 | Indexed, signed, behaviorally clean, provenance-verified |
| 🟡 Yellow | 60–79 | Known author, no critical findings, some lower-severity flags |
| 🟠 Orange | 40–59 | Anonymous author or mid-severity finding or provenance unclear |
| 🔴 Red | 0–39 | Critical finding — prompt injection / shell RCE / secret exfil / supply-chain |
Sub-scores are weighted: Identity 25% · Integrity 25% · Behavior 30% · Provenance 20%. A single critical finding floors the aggregate into the red tier regardless of the other axes. Full rubric and every detection rule → saferskills.ai/methodology.
Use it as
| Mode | Best for | Status |
|---|---|---|
| Service — browse saferskills.ai, share a report permalink | every dev, every researcher | live — catalog + scan reports |
CLI — npx saferskills install <name> (score re-checked at install) |
individual installers | shipped — npm + crates.io |
Self-host — docker compose up (this repo) |
privacy-strict / air-gapped orgs | scan engine shipped |
Screenshots
| Catalog | Scan report | Agent report |
|
|
|
Works across 8 agents
One trust layer for every coding agent. Detect, install, and re-verify across:
claude-code · cursor · windsurf · copilot · codex · gemini · cline · openclaw
Teach your agent to use SaferSkills
One command teaches any of the 8 supported agents to use SaferSkills — and to scan a capability before it installs, adds, recommends, or trusts it:
npx saferskills install saferskills
The canonical skill lives at skills/saferskills/SKILL.md and
renders to each agent's native format (Claude Code & OpenClaw get the SKILL.md verbatim;
Cursor .mdc, Cline/Windsurf rules, Codex/Copilot AGENTS.md, Gemini GEMINI.md get a
native render). See the install guide.
⭐ Support the project
If SaferSkills helps you install AI capabilities more safely, star the repo — it's the cheapest way to help a free, public safety service reach the people installing risky skills. Stars are how this gets in front of the next developer about to curl | bash something they didn't read.
Community
- 💬 Discussions — questions, ideas, show-and-tell.
- 🐛 Issues — bugs and feature requests.
- 📐 Rule proposals — propose a new detection rule (RFC required before any rule lands).
- ⚖️ Vendor appeals — dispute a verdict about an item we scanned. Every verified appeal gets a substantive public response within 1 hour.
Develop
git clone https://github.com/OpenLatch/saferskills.git
cd saferskills
pnpm install
pnpm run generate # 9 generators: ingestion registry + Pydantic + SQLAlchemy + openapi.json + TS DTO + Zod + methodology + agent-pack
docker compose up # postgres + api + webapp
curl http://localhost:8000/api/v1/health
open http://localhost:5173
Requirements: Node 24 LTS, Python 3.14, pnpm 10, uv 0.7+, Docker.
Repo map
| Path | What it is | Docs |
|---|---|---|
cli/ |
The saferskills Rust CLI — install + capability/agent scans |
README |
ui/ |
Design system — React 19 + Tailwind v4 tokens & components | README |
webapp/ |
Astro 6 public site — catalog, scan/agent reports, docs | README |
services/api/ |
FastAPI backend — catalog, scan engine, ingestion | README |
services/worker/ |
Procrastinate ingestion + bulk-scan worker (same image as the API) | README |
schemas/ |
JSON Schema source-of-truth for every wire/DB/type contract | README |
rubric/ |
The open, versioned detection-rule rubric | README |
scripts/ |
The codegen pipeline (pnpm run generate) |
dir |
tools/ |
Dev + ops tooling | data-seed · e2e · fp-audit · admin |
Contributing
We welcome contributions — code, detection-rule RFCs, scan-report appeals, and translations. Read CONTRIBUTING.md, the Code of Conduct, and the methodology summary first. Detection-rule proposals go through the rule-RFC issue template — don't land a rule without one.
Security
- Vulnerabilities in SaferSkills itself → SECURITY.md (GitHub Private Vulnerability Reporting or
[email protected]). - A verdict you disagree with (incorrect finding, scope dispute, rule misapplication) → file a vendor appeal or email
[email protected].
License
Installing Saferskills
This server has no published package — it is built from source. Open the repository and follow its README.
▸ github.com/OpenLatch/saferskillsFAQ
Is Saferskills MCP free?
Yes, Saferskills MCP is free — one-click install via Unyly at no cost.
Does Saferskills need an API key?
No, Saferskills runs without API keys or environment variables.
Is Saferskills hosted or self-hosted?
Self-hosted: the server runs locally on your machine via the install command above.
How do I install Saferskills in Claude Desktop, Claude Code or Cursor?
Open Saferskills on unyly.org, pick your client tab (Claude Desktop, Claude Code, Cursor) and press Install — the config is generated automatically, no JSON editing.
Related MCPs
Fetch
Web content fetching and conversion for efficient LLM usage.
AWS KB Retrieval
Retrieval from AWS Knowledge Base using Bedrock Agent Runtime.
by modelcontextprotocolSpring AI MCP Server
Provides auto-configuration for setting up an MCP server in Spring Boot applications.
llm-analysis-assistant
A very streamlined mcp client that supports calling and monitoring stdio/sse/streamableHttp, and can also view request responses through the /logs page. It also
by xuzexin-hzCompare Saferskills with
Not sure what to pick?
Find your stack in 60 seconds
Author?
Embed badge for your README
Browse similar
All ai MCPs
