MCP servers & agent skills · audited before you install
Find what's worth installing for your actual work
Checked before you install — known advisories, what runs at install time, and what it can reach on your machine.
e.g. review code · automate a browser · analyse a spreadsheet · every job ›
Start here
What do you do?
Pick the work and the board below re-ranks to the capabilities measured for it. Every count is capabilities on the board right now, not a catalogue total.
The Index
Ranked by the tashan score
| # | Capability | tashan | Evidence | Health |
|---|---|---|---|---|
Loading measured data… | ||||
Already running things
Is anything in my stack dead or vulnerable?
One command reads your Claude Code, Cursor and Desktop configs and flags known advisories, install-time scripts, and anything deprecated, archived or abandoned. Local only — nothing is uploaded.
npx tashan-cli doctor ›
You are an agent
Can my agent check before it installs?
A 50 KB lookup of every score, the full set in MCP-registry shape, and a SKILL.md you can install so checking is a tool call. An absent name means unmeasured, never bad.
curl tashan.sh/v0.1/scores ›
How the ranking works
What goes into the number.
Upkeep, freshness, adoption
The score combines how actively a capability is maintained and how recently it moved, gated by real adoption — npm downloads and public config reach. Instruction depth — how well it documents itself — is graded separately and never folded in, because "well kept" and "well documented" are different questions.
We read the actual expertise
We open each capability and grade what it documents against a published rubric — deep domain work versus a thin wrapper or AI-slop. That is a read of the documentation, not of the running code.
Checkable at the source
No black box. Each signal is defined and points back at where it came from — the registry, npm, git history. If you don't believe a number, verify it.
What we have checked, of — ranked capabilities
- — checked for known advisories, install-time scripts and permissions
- — read and graded against the documentation rubric
- — mapped to the work they are for, with the evidence for each mapping
The rest carry adoption and upkeep signal only. We publish what is measured and say plainly what is not — the gaps are the roadmap.