llms.txt Content
# MCP Skills
> The pre-install trust layer for MCP servers and AI skills. 15 signals across 4 dimensions with safety scanning, OSV/KEV/EPSS-backed vulnerability intelligence, prompt-injection detection, supply-chain analysis, public score pages, trust badges, monitoring, and API workflows. Know before you install.
## What This Is
MCP Skills is the public trust layer for AI skills and MCP servers. It scores publishers, source code, dependencies, vulnerabilities, and supply-chain risk so developers, agents, and teams can decide what to install before running anything locally. 15 signals across 4 dimensions (Alive, Legit, Solid, Usable), 4 trust tiers (Verified, Established, New, Blocked), 7 safety pattern checks (prompt injection, shell execution, network exfiltration, credential access, obfuscation, public network binding, npm lifecycle-script risk), and vulnerability intelligence from OSV.dev, CISA KEV, and EPSS exploit-probability scoring. Accepts GitHub repos, npm packages, Smithery servers, and OpenClaw skills. Available as a website, API, and MCP server.
## Docs
- [Trust Scanner](https://mcpskills.io): Paste any repo URL, npm package name, or registry URL and get a trust score. Free tier shows trust tier + dimension scores. Paid reports unlock all 15 signals and safety findings.
- [Scored MCP Server Directory](https://mcpskills.io/servers): Public trust directory for scored MCP servers, AI skills, and packages. Use it to check install risk before running unknown code.
- [Original Research Index](https://mcpskills.io/research): Canonical landing page for original-research and analysis articles on AI skill / MCP server / ClawHub trust. Reproducible methodology, real GitHub data, no AI hand-waving.
- [Trust Scoring Glossary](https://mcpskills.io/glossary): Canonical definitions for every term used in the MCP Skills trust scoring engine — tiers, dimensions, signals, disqualifiers, scoring modes, vulnerability intelligence, and engine concepts. ~30 terms with