The trusted directory for your AI’s toolbox
95,574 tools and skills for your AI. 12,662 measured.
npx tashan-cli doctor checks
the toolbox you already have ›
Upkeep, freshness, real adoption, and known advisories. Four measures, every input public.
- 12,662
- measured, of 95,574 tracked
- 6,345
- audited at the version you would install today
- 3,436
- mapped to the work they do
- $247k
- settled agent payments, median $0.52
measured Sep 13, 2026 · recomputed nightly, every input public · how ›
Start here
What do you do?
Pick the work. The board re-ranks to what we have measured for it.
The Index
Ranked by the tashan score
| # | Capability | tashan | Evidence | Health |
|---|---|---|---|---|
| 1 | Supabase npm | 98 | 112k/wk | active |
| 2 | Context7 npm | 98 | 1.1M/wk | active |
| 3 | Memory npm | 96 | 152k/wk | active |
| 4 | 94 | 109k/wk | active | |
| 5 | Chrome DevTools npm | 92 | 3.3M/wk | active |
| 6 | Everything npm | 92 | 243k/wk | active |
| 7 | Filesystem npm | 90 | 627k/wk | active |
| 8 | Hostinger API npm | 90 | 119k/wk | active |
| 9 | Discovery npm | 87 | 149k/wk | active |
| 10 | Admin npm | 87 | 124k/wk | active |
#1 Check
Nothing rots unseen
Claude Code, Claude Desktop, Cursor, VS Code, Windsurf,
~/.claude/skills/. Read on your machine. Named if it is deprecated, archived,
abandoned, running an install script, or shadowing an official package name. Nothing is
uploaded.
npx tashan-cli doctor ›
#2 Ask
Your agent checks first
Every score in a 50 KB lookup, the full set in MCP-registry shape, a SKILL.md so checking is a tool call. A name we have never seen comes back unmeasured, never bad.
curl tashan.sh/v0.1/scores ›
#3 Follow
The money is public
998 of 1,079 x402 services have ever been paid — and the median one has earned $0.52 in its life.
Who gets paid ›
How the ranking works
What goes into the number.
#4 Rank
Kept, current, used
Maintainer count, release cadence, deprecation and registry status; days since the last publish, push or release; npm downloads and public config reach as the gate.
Instruction depth is graded separately and never folded in. “Well kept” and “well documented” are different questions.
#5 Read
Somebody opened the docs
Per-tool documentation, two worked examples, setup and auth, a stated limitation. All four, or it is not deep. That is a read of the documentation, never of the running code.
#6 Prove
Every number, sourced
No black box. Each signal points back at where it came from: the MCP registry, npm, git history, OSV. If you don’t believe a number, go and check it.
What we have checked, of — ranked capabilities
- — checked for known advisories, install-time scripts and permissions
- — read and graded against the documentation rubric
- — mapped to the work they are for, with the evidence for each mapping
The rest carry adoption and upkeep signal only. We publish what is measured and name what is not. The gaps are the roadmap.
This board is a snapshot. Your stack is not.
Every score, finding and advisory above is free, forever, no account. An index cannot know which of them you run. Paste your config and see — free, nothing to install. Pro adds the series behind each row, and names the replacement when something you depend on is dying.
- The whole series behind any row, back to the first day we measured it
- The replacement, named — not just the news that something died
tashan doctorover your own config, on your own machine
Start a 7-day trial › Everything measured on this page stays free.
他山之石,可以攻玉 — a stone from another mountain can polish your jade. Every tool your AI uses was made on somebody else’s. Why we are called tashan ›