# Mcpskillsio

> Use the MCPSkills pre-install trust layer from Claude Code, Cursor, or any MCP client. Accepts GitHub repos, npm packages, Smithery URLs, and OpenClaw skills. 15 signals (incl. OSV/KEV/EPSS vulnerability intelligence), safety scanning, OpenClaw frontmatte

## Facts
- Page: https://tashan.sh/capability/pkg-mcpskillsio-server
- tashan id: pkg:@mcpskillsio/server
- Source: https://github.com/BeBraveBeKind/mcpskills-server
- npm: https://www.npmjs.com/package/@mcpskillsio/server
- Type: npm
- Category: security
- tashan score: 44.0 / 100
- Adoption: 29.0
- Upkeep: 58.0
- Freshness: 71.0
- Evidence coverage: 100% of the inputs this score can use
- Health: active
- Instruction depth: not yet graded
- npm downloads: 123/week
- License: MIT
- Official: no

## Install

```sh
claude mcp add mcpskillsio-server -- npx -y @mcpskillsio/server
```

## Security audit
- Known advisories: 0
- Install-time script: none declared
- Build provenance: attested

Permissions are read from DECLARED dependencies only. Nothing is executed, so an empty result means "nothing declared", never "nothing possible".

---
Measured 2026-09-12 by tashan (https://tashan.sh) from public evidence. Scorer s5.
