MCP server that lets any AI agent discover, search, and install agent skills from across the GitHub ecosystem (Anthropic, Superpowers, wshobson, antigravity, Composio, and 9,000+ more).
skills-mcp demonstrates solid definition quality with well-structured tools, clear naming conventions, and comprehensive parameter descriptions. All 7 tools follow verb_noun naming patterns (search_skills, get_skill, list_domains, list_repos, recommend_skills, install_skill, catalog_stats). Descriptions are generally informative and action-oriented, ranging 100-250 characters. Input schemas are visible and properly typed using Zod validation. However, output schemas are not explicitly documented in the source, and some parameter descriptions could be more prescriptive about constraints. The install_skill tool handles a sensitive write operation (downloading and writing to filesystem) but lacks confirmation/dry-run patterns. Error handling is present but recovery guidance is minimal.
Print catalog metadata: total skills, repos, build timestamp.
Fetch the full SKILL.md content for a skill by its id. Returns the raw markdown including YAML frontmatter and instructions.
Download a skill folder from its upstream GitHub repo and write it to a target directory (default: your IDE's skills folder, e.g. ~/.cursor/skills/<slug>/). Set GITHUB_TOKEN env var to avoid rate limits.
List all logical domains in the catalog (testing, security, devops, ai-ml, frontend, etc.) with the number of skills tagged in each.
List all source repositories in the catalog with skill counts and upstream URLs.
Given a free-text task description (e.g. 'I need to add Stripe payments to a Next.js app'), suggest the most relevant skills, ranked by relevance.
install_skill lacks confirmation/dry-run pattern for destructive filesystem write operation. Tool accepts target_dir and writes skill folders to disk without explicit user confirmation, creating risk of accidental overwrites or installations to unexpected locations.
Output schemas not explicitly documented in source code. While tools clearly return structured data (skills with IDs/descriptions/tags, catalog metadata), the response shapes are not formally defined as JSON Schema. LLMs cannot reliably parse response structure for chaining.
Error recovery guidance is minimal. Tool descriptions mention prerequisites (e.g., 'Set GITHUB_TOKEN env var to avoid rate limits' for install_skill) but do not provide recovery steps if errors occur. Error messages from failed operations are not shown in source.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | C | 64 | 2026-07-28+ | v2 |
Search the skills catalog by free-text query and/or filters. Returns matching skills with their IDs, descriptions, tags and source repos. Use this first to find candidates, then call get_skill to fetch full SKILL.md content.
Parameter constraints partially missing. search_skills 'query' parameter lacks format guidance (what kind of text is matched?). recommend_skills 'task' parameter could specify minimum length or format expectations. Descriptions state some constraints but not all are machine-parseable.
install_skill permits arbitrary target_dir paths without clear sanitization guidance in description. Risk of path traversal or installation to system-critical directories. Description mentions 'Absolute path' and 'safe target' but validation logic is not visible in source excerpt.