Install
$ agentstack add mcp-jane-xiaoer-skill-vision-control Open-source listing — not yet scanned by AgentStack. Follow the source repository for install instructions.
Security review
⚠ Flagged1 finding(s); flagged for manual review. · v0.1.0 How review works →
- • Prompt-injection patterns
- • Secret / credential exfiltration
- • Dangerous shell & filesystem operations
- • Untrusted network calls
- • Known-malicious package signatures
- high Dangerous shell/eval execution.
What it can access
- ● Network access Used
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ● Dynamic code execution Used
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
About
Skill Vision Control (SVC)
[](https://badge.fury.io/js/skill-vision-control) [](https://opensource.org/licenses/MIT)
> Safe MCP Skill Version Manager - Detect updates, parallel testing, smart merge, confirm before replace
Features
- 🔍 Update Detection - Automatically detect new versions from GitHub/npm
- 🛡️ Security Scanning - Auto scan before download (Sentinel integration)
- 📦 Version Management - Keep multiple versions, switch anytime
- 🔀 Smart Merge - Merge official updates with your custom changes
- 🧪 A/B Testing - Test new versions before switching
- ⏰ Scheduled Checks - Automatic weekly/monthly update checks
- 🔔 Notifications - Desktop notifications for updates
- 🤖 MCP Server - Let AI manage your skills
Installation
npm install -g skill-vision-control
Or with yarn:
yarn global add skill-vision-control
Quick Start
# Add a skill to manage
svc add weather --source github:username/weather-mcp
# Check for updates
svc check
# Download new version (keeps old version)
svc download weather
# Test and switch
svc switch weather --version v1.1.0
# Or if you have custom changes, merge them
svc merge weather
Commands
Skill Management
| Command | Description | |---------|-------------| | svc add --source | Register a skill (github:user/repo or npm:package) | | svc list | List all managed skills | | svc info | Show detailed information | | svc remove | Remove a skill |
Version Control
| Command | Description | |---------|-------------| | svc check [name] | Check for updates | | svc download | Download new version (keep old) | | svc versions | List all local versions | | svc switch -v | Switch to specific version | | svc rollback | Rollback to previous version | | svc confirm | Confirm current version | | svc cleanup --keep | Clean old versions |
Custom Modifications
| Command | Description | |---------|-------------| | svc fork | Create custom branch for modifications | | svc save -c "comment" | Save your modifications | | svc diff | View differences from official | | svc merge | Merge official update with your changes | | svc conflicts | View merge conflicts | | svc resolve -f -u | Resolve conflicts |
Schedule
| Command | Description | |---------|-------------| | svc schedule set -i | Set check interval (1/7/14/30 days) | | svc schedule show | Show current schedule | | svc schedule enable | Enable scheduled checks | | svc schedule disable | Disable scheduled checks | | svc schedule run | Manually trigger check |
Security Scanning
| Command | Description | |---------|-------------| | svc scan | Scan any skill directory for security issues | | svc audit [name] | Audit installed skill(s) | | svc download --skip-security | Download without security scan (not recommended) |
Workflow Examples
Basic Update Flow
# 1. Check for updates
svc check
# Output: weather: v1.0.0 → v1.1.0 available
# 2. Download (old version preserved)
svc download weather
# 3. Test new version
svc switch weather -v v1.1.0 -t official
# 4. If good, confirm; if not, rollback
svc confirm weather
# or
svc rollback weather
Security Audit Before Install
# Scan a skill before installing
svc scan ~/Downloads/some-mcp-skill
# Output:
# 🛡️ Sentinel Security Scan Report
# ══════════════════════════════════════════════════
# Risk Level: MEDIUM
# Recommendation: REVIEW
#
# ⚠️ SUSPICIOUS: 3 items found
# - src/api.ts:15 - Network request (axios)
# - src/config.ts:8 - Environment variable access
# Audit all installed skills
svc audit
# Audit specific skill with details
svc audit weather -v
Custom Changes + Update
# 1. Create custom branch
svc fork weather
# 2. Make your modifications...
# 3. Save changes
svc save weather -c "Added Chinese language support"
# 4. Later, when update available
svc check
# Output: ⚠️ You have custom changes. Use "svc merge"
# 5. Download and merge
svc download weather
svc merge weather
# 6. If conflicts exist
svc conflicts weather
svc resolve weather -f src/config.ts -u custom
# 7. Test merged version
svc switch weather -v v1.1.0-merged -t merged
# 8. Confirm
svc confirm weather
Using as MCP Server
Add to your MCP configuration:
{
"mcpServers": {
"skill-vision-control": {
"command": "svc",
"args": ["serve"]
}
}
}
Available MCP tools:
svc_list_skills- List all managed skillssvc_get_skill_info- Get skill detailssvc_check_updates- Check for updatessvc_get_versions- Get local versionssvc_switch_version- Switch versionsvc_rollback- Rollback to previoussvc_download_update- Download new versionsvc_merge- Merge with custom changessvc_get_conflicts- View merge conflicts
Data Storage
All data is stored in ~/.svc/:
~/.svc/
├── skills.json # Skill registry
├── schedule.json # Schedule settings
├── config.json # Global config
└── versions/ # Version storage
└── /
├── official/
├── custom/
├── merged/
└── active -> ...
Security Scanning
SVC integrates Sentinel security patterns for automatic code scanning.
Detection Capabilities
| Level | Description | Examples | |-------|-------------|----------| | CRITICAL | High-risk patterns | eval(), exec(), rm -rf, registry access | | SUSPICIOUS | Needs review | Network requests, env vars, file operations | | WARNING | Potential issues | Long lines, high entropy files |
Risk Levels
| Level | Action | |-------|--------| | SAFE | Safe to install | | LOW | Minor concerns, review recommended | | MEDIUM | Review required before install | | HIGH | Significant risks detected | | CRITICAL | Do not install without careful review |
Auto-Scan on Download
When you run svc download, security scan runs automatically:
svc download weather
# 🛡️ Running security scan...
# ✅ Security scan passed
# ✓ Download complete
If issues found:
svc download untrusted-skill
# 🛡️ Running security scan...
# 🛑 Security scan found critical issues!
# ? Do you still want to proceed? (NOT RECOMMENDED) (y/N)
To skip (not recommended):
svc download weather --skip-security
Configuration
Supported Sources
- GitHub:
github:username/repoorusername/repo - npm:
npm:package-name
Schedule Options
1d- Daily checks7d- Weekly checks (default)14d- Bi-weekly checks30d- Monthly checks
Contributing
Contributions are welcome! Please feel free to submit a Pull Request.
License
MIT License - see [LICENSE](LICENSE) for details.
📱 关注作者 / Follow Me
如果这个仓库对你有帮助,欢迎关注我。后面我会持续更新更多 AI Skill、版本管理、A/B 对比和系统升级工作流。
If this repo helped you, follow me for more AI skills, versioning tools, A/B comparisons, and automation workflows.
- X (Twitter): @xiaoerzhan
- 微信公众号 / WeChat Official Account: 扫码关注 / Scan to follow
中文:欢迎关注我的公众号,一起研究 AI Skill、版本管理、A/B 对比和系统升级。
English: Follow my WeChat Official Account for more AI skills, version control workflows, A/B comparisons, and system upgrades.
Source & license
This open-source MCP server is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: Jane-xiaoer
- Source: Jane-xiaoer/skill-vision-control
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet — be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.