MCP servers & agent skills · measured on public evidence
Find what's worth installing for your actual work
Ranked on upkeep, freshness and real adoption — with a security audit on the packages we can resolve.
e.g. review code · automate a browser · analyse a spreadsheet · every job ›
Start here
What do you do?
Pick the work and the board below re-ranks to the capabilities measured for it. Every count is capabilities on the board right now, not a catalogue total.
The Index
Ranked by the tashan score
| # | Capability | tashan | Evidence | Health |
|---|---|---|---|---|
| 1 | Supabase npm | 99 | 115k/wk | active |
| 2 | Context7 npm | 94 | 619k/wk | active |
| 3 | Everything npm | 93 | 234k/wk | active |
| 4 | Filesystem npm | 92 | 592k/wk | active |
| 5 | Chrome DevTools npm | 92 | 2.3M/wk | active |
| 6 | Memory npm | 91 | 80k/wk | active |
| 7 | Firecrawl npm | 91 | 66k/wk | active |
| 8 | 90 | 108k/wk | active | |
| 9 | Notion npm | 88 | 142k/wk | active |
| 10 | Hostinger API npm | 87 | 68k/wk | active |
| 11 | Exa npm | 87 | 37k/wk | active |
| 12 | Eve npm | 86 | 702k/wk | active |
| 13 | Figma Developer npm | 85 | 58k/wk | active |
| 14 | Cloudbase npm | 85 | 18k/wk | active |
| 15 | Superpowers plugin | 84 | 269k ★ | active |
| 16 | Tavily npm | 84 | 25k/wk | active |
| 17 | Playwright npm | 84 | 4.7M/wk | active |
| 18 | Cline npm | 84 | 142k/wk | active |
| 19 | Fiori npm | 84 | 108k/wk | active |
| 20 | Azure npm | 84 | 107k/wk | active |
| 21 | Freee npm | 84 | 90k/wk | active |
| 22 | MongoDB npm | 84 | 73k/wk | active |
| 23 | Use npm | 84 | 40k/wk | active |
| 24 | Kubernetes npm | 83 | 18k/wk | active |
| 25 | Handler npm | 83 | 803k/wk | active |
Already running things
Is anything in my stack dead or vulnerable?
One command reads your Claude Code, Cursor and Desktop configs and flags known advisories, install-time scripts, and anything deprecated, archived or abandoned. Local only — nothing is uploaded.
npx tashan-cli doctor ›
You are an agent
Can my agent check before it installs?
A 50 KB lookup of every score, the full set in MCP-registry shape, and a SKILL.md you can install so checking is a tool call. An absent name means unmeasured, never bad.
curl tashan.sh/v0.1/scores ›
How the ranking works
What goes into the number.
Upkeep, freshness, adoption
Upkeep and freshness, gated by real adoption — npm downloads and public config reach.
Instruction depth is graded separately and never folded in. “Well kept” and “well documented” are different questions.
We read the actual expertise
We open each capability and grade what it documents against a published rubric — deep domain work versus a thin wrapper or AI-slop. That is a read of the documentation, not of the running code.
Checkable at the source
No black box. Each signal is defined and points back at where it came from — the registry, npm, git history. If you don't believe a number, verify it.
What we have checked, of — ranked capabilities
- — checked for known advisories, install-time scripts and permissions
- — read and graded against the documentation rubric
- — mapped to the work they are for, with the evidence for each mapping
The rest carry adoption and upkeep signal only. We publish what is measured and say plainly what is not — the gaps are the roadmap.
This board is a snapshot. Your stack is not.
Every score, finding and advisory above is free, forever, no account. What an index cannot tell you is which of them you run.
Every score, finding and advisory above is free, forever, no account. What an index cannot tell you is which of them you run — paste your config and see, free, with nothing to install. Pro adds the series behind each one, and names a replacement when something you depend on is dying.
- Every score since we started measuring, for any capability
- The named replacement when something you run is dying — not just that it is
tashan doctorover the config you already have, on your machine
Start a 7-day trial › Everything measured on this page stays free.