AgentStack
MCP unreviewed Apache-2.0 Self-run

Saferskills

mcp-openlatch-saferskills · by OpenLatch

Every AI skill, independently scanned. Public, open-source trust scoring for skills, MCP servers, hooks, and plugins across every agent platform. Apache-2.0. saferskills.ai

No reviews yet
0 installs
7 views
0.0% view→install

Install

$ agentstack add mcp-openlatch-saferskills

Open-source listing — not yet scanned by AgentStack. Follow the source repository for install instructions.

Security review

⚠ Flagged

1 finding(s); flagged for manual review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures
  • high Pipes remote content directly into a shell (remote code execution).

What it can access

  • Network access Used
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets Used
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

Are you the author of Saferskills? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

SaferSkills

Every AI capability, independently scanned. A free, open, public trust-scoring service for the skills, MCP servers, hooks, plugins & rules you install into Claude Code, Cursor, Windsurf, Copilot, Codex, Gemini, Cline & OpenClaw.

[](https://github.com/OpenLatch/saferskills/stargazers) [](https://github.com/OpenLatch/saferskills/actions/workflows/pr-checks.yml) [](https://securityscorecards.dev/viewer/?uri=github.com/OpenLatch/saferskills) [](https://www.npmjs.com/package/saferskills) [](./LICENSE) [](https://github.com/OpenLatch/saferskills/discussions) [](https://saferskills.ai/slack)

saferskills.ai · Methodology · Discussions · Slack · Security


See it in 15 seconds

Quick start

No install needed — npx runs the prebuilt native binary:

npx saferskills info mcp-server-github      # score, four-axis breakdown, findings & report URL
npx saferskills install mcp-server-github   # install to your detected agents — score re-checked, severity-gated
npx saferskills capability ./my-skill       # scan a local file/dir — or a public GitHub URL
npx saferskills agent                       # behaviorally scan a running agent against ~20 adversarial tests

Prefer it installed? npm install -g saferskills or cargo install saferskills. No terminal at all? Everything the CLI does is in your browser at saferskills.aibrowse the catalog, scan a capability, or run a behavioral agent scan, with no account and nothing to install. Full command + flag reference: [cli/README.md](./cli/README.md).

> SaferSkills is v0.x, built in the open — the catalog is filling in as ingestion scales toward the public launch._

Why this exists

You install a Claude skill, an MCP server, a Cursor rules file, or a Codex hook. It runs with your file-system access. It can read your .env. It can curl | bash. It can quietly ship your repo to a paste site. And across the tens of thousands of such items now circulating, there is no public, transparent record of what each one actually does.

SaferSkills is that record. Anyone — a developer, a vendor, a researcher — submits a GitHub URL (or uploads a file), and a ~30-second deterministic scan returns a Yuka-style report: an aggregate trust score (0–100), a four-axis breakdown, every detector that fired, the rule that fired it, the exact line of evidence, the remediation, and a permalink the vendor can dispute.

> Methodology, not opinion. Every rule is documented. Every score is reproducible. Every appeal is public.

How it works

The verdict path is fully deterministic — there is no LLM deciding your score. Every finding carries a static rule_id and a quotable line of evidence, so a verdict is reproducible from the trace alone. The result is a public report permalink:

Trust-score rubric

| Tier | Range | Meaning | |---|---|---| | 🟢 Green | 80–100 | Indexed, signed, behaviorally clean, provenance-verified | | 🟡 Yellow | 60–79 | Known author, no critical findings, some lower-severity flags | | 🟠 Orange | 40–59 | Anonymous author or mid-severity finding or provenance unclear | | 🔴 Red | 0–39 | Critical finding — prompt injection / shell RCE / secret exfil / supply-chain |

Sub-scores are weighted: Identity 25% · Integrity 25% · Behavior 30% · Provenance 20%. A single critical finding floors the aggregate into the red tier regardless of the other axes. Full rubric and every detection rule → saferskills.ai/methodology.

Use it as

| Mode | Best for | Status | |---|---|---| | Service — browse saferskills.ai, share a report permalink | every dev, every researcher | live — catalog + scan reports | | CLInpx saferskills install (score re-checked at install) | individual installers | shipped — npm + crates.io | | Self-hostdocker compose up (this repo) | privacy-strict / air-gapped orgs | scan engine shipped |

Screenshots

Catalog Scan report Agent report

Works across 8 agents

One trust layer for every coding agent. Detect, install, and re-verify across:

claude-code · cursor · windsurf · copilot · codex · gemini · cline · openclaw

Teach your agent to use SaferSkills

One command teaches any of the 8 supported agents to use SaferSkills — and to scan a capability before it installs, adds, recommends, or trusts it:

npx saferskills install saferskills

The canonical skill lives at [skills/saferskills/SKILL.md](skills/saferskills/SKILL.md) and renders to each agent's native format (Claude Code & OpenClaw get the SKILL.md verbatim; Cursor .mdc, Cline/Windsurf rules, Codex/Copilot AGENTS.md, Gemini GEMINI.md get a native render). See the install guide.

⭐ Support the project

If SaferSkills helps you install AI capabilities more safely, star the repo — it's the cheapest way to help a free, public safety service reach the people installing risky skills. Stars are how this gets in front of the next developer about to curl | bash something they didn't read.

Community

  • 💬 Discussions — questions, ideas, show-and-tell.
  • 🐛 Issues — bugs and feature requests.
  • 📐 [Rule proposals](.github/ISSUE_TEMPLATE/03-rule-proposal.yml) — propose a new detection rule (RFC required before any rule lands).
  • ⚖️ [Vendor appeals](.github/ISSUE_TEMPLATE/04-vendor-appeal.yml) — dispute a verdict about an item we scanned. Every verified appeal gets a substantive public response within 1 hour.

Develop

git clone https://github.com/OpenLatch/saferskills.git
cd saferskills
pnpm install
pnpm run generate     # 9 generators: ingestion registry + Pydantic + SQLAlchemy + openapi.json + TS DTO + Zod + methodology + agent-pack
docker compose up     # postgres + api + webapp
curl http://localhost:8000/api/v1/health
open http://localhost:5173

Requirements: Node 24 LTS, Python 3.14, pnpm 10, uv 0.7+, Docker.

Repo map

| Path | What it is | Docs | |---|---|---| | cli/ | The saferskills Rust CLI — install + capability/agent scans | [README](./cli/README.md) | | ui/ | Design system — React 19 + Tailwind v4 tokens & components | [README](./ui/README.md) | | webapp/ | Astro 6 public site — catalog, scan/agent reports, docs | [README](./webapp/README.md) | | services/api/ | FastAPI backend — catalog, scan engine, ingestion | [README](./services/api/README.md) | | services/worker/ | Procrastinate ingestion + bulk-scan worker (same image as the API) | [README](./services/worker/README.md) | | schemas/ | JSON Schema source-of-truth for every wire/DB/type contract | [README](./schemas/README.md) | | rubric/ | The open, versioned detection-rule rubric | [README](./rubric/README.md) | | scripts/ | The codegen pipeline (pnpm run generate) | [dir](./scripts) | | tools/ | Dev + ops tooling | [data-seed](./tools/data-seed/README.md) · [e2e](./tools/e2e/README.md) · [fp-audit](./tools/fp-audit/README.md) · [admin](./tools/saferskills-admin/README.md) |

Contributing

We welcome contributions — code, detection-rule RFCs, scan-report appeals, and translations. Read [CONTRIBUTING.md](./CONTRIBUTING.md), the [Code of Conduct](./.github/CODEOFCONDUCT.md), and the [methodology summary](./contributor-docs/methodology.md) first. Detection-rule proposals go through the [rule-RFC issue template](.github/ISSUE_TEMPLATE/03-rule-proposal.yml) — don't land a rule without one.

Security

  • Vulnerabilities in SaferSkills itself → [SECURITY.md](./SECURITY.md) (GitHub Private Vulnerability Reporting or security@openlatch.ai).
  • A verdict you disagree with (incorrect finding, scope dispute, rule misapplication) → file a [vendor appeal](.github/ISSUE_TEMPLATE/04-vendor-appeal.yml) or email appeals@openlatch.ai.

License

Apache License 2.0 — see [LICENSE](./LICENSE). An OpenLatch project.

Source & license

This open-source MCP server is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet — be the first.

Versions

  • v0.1.0 Imported from the upstream source.