{"_id":"@agentskillshub/mcp","_rev":"2-9d81e315650a527670015c3bd042f47b","name":"@agentskillshub/mcp","dist-tags":{"latest":"0.2.0"},"versions":{"0.1.0":{"name":"@agentskillshub/mcp","version":"0.1.0","keywords":["mcp","model-context-protocol","mcp-server","ai-agent","claude","claude-code","cursor","skills","security-audit","agent-tools"],"author":{"url":"AgentSkillsHub","name":"Jason Zhu"},"license":"MIT","_id":"@agentskillshub/mcp@0.1.0","maintainers":[{"name":"jasonzhu0526","email":"m17551076169@gmail.com"}],"homepage":"https://agentskillshub.top","bugs":{"url":"https://github.com/zhuyansen/agentskillshub-mcp/issues"},"bin":{"agentskillshub-mcp":"src/index.mjs"},"dist":{"shasum":"f2c86d0114d371ff2bad177cd1bd67c26145b0ad","tarball":"https://registry.npmjs.org/@agentskillshub/mcp/-/mcp-0.1.0.tgz","fileCount":5,"integrity":"sha512-glHzz0dSbIbm2G6q57axLevqDCj1cjDtNxxPevqzUghKwCaXGHL6JDLn7Hizw7oe9pMg+xpcpSyIdQluN/SN8g==","signatures":[{"sig":"MEUCIQCX9f9lVcbD9Sybs56jNFK6ndOCWoQqr+LQJ5uBLHxCDAIgPRaknHtUaEvttOebG5009zC+0KXOsLdhmys1gOVah40=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":23101},"main":"src/index.mjs","type":"module","engines":{"node":">=18"},"gitHead":"0a6db7e7c2d0207422e5c77f3ac2ffbe127ffb11","scripts":{"test":"node test/smoke.mjs","start":"node src/index.mjs"},"_npmUser":{"name":"jasonzhu0526","email":"m17551076169@gmail.com"},"repository":{"url":"git+https://github.com/zhuyansen/agentskillshub-mcp.git","type":"git"},"_npmVersion":"11.6.2","description":"MCP server for AgentSkillsHub — search, audit, and install open-source AI agent skills & MCP servers from inside your agent. Security-graded, quality-scored. Zero backend load.","directories":{},"_nodeVersion":"24.11.1","dependencies":{"zod":"^3.25.76","@modelcontextprotocol/sdk":"^1.29.0"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/mcp_0.1.0_1783063317680_0.7781773318036596","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@agentskillshub/mcp","version":"0.2.0","description":"MCP server for AgentSkillsHub — search, audit, and install open-source AI agent skills & MCP servers from inside your agent. Security-graded, quality-scored. Zero backend load.","type":"module","bin":{"agentskillshub-mcp":"src/index.mjs"},"main":"src/index.mjs","engines":{"node":">=18"},"scripts":{"start":"node src/index.mjs","test":"node test/smoke.mjs"},"author":{"name":"Jason Zhu","url":"AgentSkillsHub"},"repository":{"type":"git","url":"git+https://github.com/zhuyansen/agentskillshub-mcp.git"},"bugs":{"url":"https://github.com/zhuyansen/agentskillshub-mcp/issues"},"keywords":["mcp","model-context-protocol","mcp-server","ai-agent","claude","claude-code","cursor","skills","security-audit","agent-tools"],"homepage":"https://agentskillshub.top","license":"MIT","dependencies":{"@modelcontextprotocol/sdk":"^1.29.0","zod":"^3.25.76"},"gitHead":"ffebc67272e0cc74b864eb0cee1e0fa2799bd98f","_id":"@agentskillshub/mcp@0.2.0","_nodeVersion":"24.11.1","_npmVersion":"11.6.2","dist":{"integrity":"sha512-7KHw2KOrS3fiVLiwKn6nOTiI3MqLZPXWiY6LuwyNCf8REtS7aeCYKT33GgvGY5jAi1Fb0RKZpWEq9TVG8sHQjg==","shasum":"709d98db8a70d583b1e116935c23534dfcd78ae7","tarball":"https://registry.npmjs.org/@agentskillshub/mcp/-/mcp-0.2.0.tgz","fileCount":5,"unpackedSize":26264,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQC7eb6+UnZBbPoQ4df0UYxC1Pb8plqANbCs9q56D7r6tQIgMOK81BAdEDArncoyZQwUHYN5VhGUmX8/yUK46M14IIA="}]},"_npmUser":{"name":"jasonzhu0526","email":"m17551076169@gmail.com"},"directories":{},"maintainers":[{"name":"jasonzhu0526","email":"m17551076169@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/mcp_0.2.0_1783821821803_0.6986357295911101"},"_hasShrinkwrap":false}},"time":{"created":"2026-07-03T07:21:57.442Z","modified":"2026-07-12T02:03:42.083Z","0.1.0":"2026-07-03T07:21:57.836Z","0.2.0":"2026-07-12T02:03:41.949Z"},"bugs":{"url":"https://github.com/zhuyansen/agentskillshub-mcp/issues"},"author":{"name":"Jason Zhu","url":"AgentSkillsHub"},"license":"MIT","homepage":"https://agentskillshub.top","keywords":["mcp","model-context-protocol","mcp-server","ai-agent","claude","claude-code","cursor","skills","security-audit","agent-tools"],"repository":{"type":"git","url":"git+https://github.com/zhuyansen/agentskillshub-mcp.git"},"description":"MCP server for AgentSkillsHub — search, audit, and install open-source AI agent skills & MCP servers from inside your agent. Security-graded, quality-scored. Zero backend load.","maintainers":[{"name":"jasonzhu0526","email":"m17551076169@gmail.com"}],"readme":"# AgentSkillsHub MCP Server\n\n**[🌐 Website](https://agentskillshub.top)** · **[🔎 Browse Skills](https://agentskillshub.top)** · **[🛡️ Security Report](https://agentskillshub.top/blog/securing-117k-ai-skills/)** · **[🏢 Enterprise](https://agentskillshub.top/enterprise/)**\n\nSearch, audit, and install open-source **AI agent skills & MCP servers** from inside your agent — Claude Code, Cursor, Cline, Cherry Studio, or any MCP client. Every result is **security-graded** and **quality-scored** by [AgentSkillsHub](https://agentskillshub.top), a directory of 100K+ skills. The trust signal comes *before* you install.\n\n```jsonc\n// add to your MCP client config\n{\n  \"mcpServers\": {\n    \"agentskillshub\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"@agentskillshub/mcp\"]\n    }\n  }\n}\n```\n\nThat's it — no API key, no signup. The server downloads a static catalog index once (~1.7 MB, cached locally) and does all searching **locally**, so it's fast, works offline after the first run, and puts **zero load** on the Hub backend.\n\n## Why an MCP server\n\nDiscovering a skill is easy. Knowing whether it's *safe to run against your credentials* is not. This server puts search + a trust check right in the agent's tool loop:\n\n```\nneed a capability → search_skills → audit_skill → get_skill_install → install\n```\n\nYour agent sees the **security grade** and **estimated token cost** of a skill *before* it picks one — signals other directories don't give it.\n\n## Tools\n\n| Tool | What it does |\n|---|---|\n| **`search_skills`** | Find skills by natural-language query + filters (`category`, `platform`, `min_stars`, `min_quality`, `verified_only`, `max_security_risk`, `limit`). Returns each result's `security_grade` and `estimated_tokens`. |\n| **`audit_skill`** | Free basic trust check for an `owner/repo`: security grade, plain-English verdict, quality score. |\n| **`get_skill_install`** | Install commands for a runtime + a \"check before you install\" safety line. Returns instructions; it does **not** run anything. |\n\n### Example\n\n> **User:** find me a safe way to query Postgres from Claude Code\n\nThe agent calls `search_skills({ query: \"query postgres\", category: \"mcp-server\", max_security_risk: \"safe\" })` and gets back graded results:\n\n```\ncall518/MCP-PostgreSQL-Ops   150★   🟢 SAFE     quality 75/100\nsgaunet/postgresql-mcp         6★   🟡 CAUTION  ~17.2k tok\n```\n\nthen `audit_skill` / `get_skill_install` before it installs anything.\n\n## Security grades\n\n🟢 SAFE · 🟡 CAUTION · 🔴 UNSAFE · ⛔ REJECT · ⚪ UNAUDITED\n\n⚪ **UNAUDITED** is not \"probably fine\" — it means *no one has audited it*. The `search_skills` filter `max_security_risk` excludes un-audited skills, never silently treats them as safe.\n\nWe security-graded the whole catalog and wrote up what we found: **[We security-graded 117,854 AI agent skills](https://agentskillshub.top/blog/securing-117k-ai-skills/)**.\n\n## Free vs. Pro\n\n- **Free (this server):** `search_skills` · `audit_skill` (basic) · `get_skill_install`, for any catalogued skill.\n- **Pro / Enterprise:** 5-dimension deep audit (code · credentials · vendor · supply-chain · operational), any GitHub URL (incl. <5★ / private), CI/batch auditing, compliance evidence → <https://agentskillshub.top/enterprise/>\n\n## Env\n\n| Var | Default |\n|---|---|\n| `AGENTSKILLSHUB_BASE` | `https://agentskillshub.top` |\n| `AGENTSKILLSHUB_CACHE` | `~/.cache/agentskillshub` (shared with the `ash` CLI) |\n\n## Related\n\n- **CLI:** [`@agentskillshub/cli`](https://www.npmjs.com/package/@agentskillshub/cli) — the same search/audit/install from your terminal (`npx @agentskillshub/cli search \"…\"`).\n\nMIT © AgentSkillsHub\n","readmeFilename":"README.md"}