About findsafeskills
findsafeskills helps people find skills, plugins, and MCP servers for any coding agent — Claude Code, Codex, Gemini CLI, and others — and see what an automated check found before installing one. There's no central registry, update convention, or semantic discovery layer for this ecosystem today; discovery is mostly brute-force GitHub search and scattered awesome-lists. findsafeskills exists to fix that.
Using This Site
Search describes what you want to do in plain words and returns skills, plugin marketplaces and MCP servers. Each result is a card, and everything on it is there to help you decide quickly whether a listing is worth installing. The example below is made up; the guide under it walks through each part.
pdf-forms
Fill, merge and extract text from PDF forms from the command line.
What each part of a card means
- Name
- pdf-forms
- Type chip
- SkillMarketplaceMCP server
- Safety badge
- No issues foundNo issues in descriptionReview suggestedFlaggedNot yet scanned
- Host chip
- GitHub
- Official chip
- Official: Example Org
- Author verified
- Author verified
- Price chip
- FreeFreemiumPaid
- Incomplete
- Incomplete
- Stars, version, updated
- 1,284v2.1.0Updated 3 days ago
- Thumbs up and down
- 40
- Copy install prompt
- Copy clone command
- Client buttons
- Details
The listing's name. It opens the repository on its host (GitHub, GitLab and so on) in a new tab.
What kind of thing it is, and the card is tinted to match. A skill is a set of instructions your agent loads (usually a SKILL.md file). A marketplace is a curated collection that bundles several skills or plugins. An MCP server is a program that gives your agent tools, and you register it in your client's configuration.
The result of an automated scan of the listing's own text. The wording says what was read: “No issues found” means the manifest and README were scanned, while “No issues in description” means only the one-line description was. Yellow suggests a review and red means flagged. Open Details to see every finding, with the line and the reason. It is a screen for known risky patterns, not a guarantee. What is and isn't checked.
Where the code lives. Hover over it to see the repository link.
Published from a known organization's own account.
Someone who can change the repository asked us to list it and proved it. This is about ownership, never about safety. How verification works.
Whether the project is free, freemium or paid. It appears only when we could tell.
The listing is missing some basics, such as a license or a README. Hover over it to see what is there and what is missing. It is about completeness, not safety.
GitHub stars, the latest version when the project declares one, and when the repository last changed.
Votes from people who use the site. Sign in to cast one.
Copies a ready-made request for your coding agent, such as Please install the skill hosted at https://github.com/example-org/pdf-forms. Paste it into Claude Code, Codex, Gemini CLI or a similar agent. The agent asks you where to install it, for just you or for a single project.
Copies git clone with the repository address, for when you would rather install by hand.
Marketplaces and MCP servers that publish an npm package get a button per client instead, each copying the exact command or configuration for that client.
Opens the listing page: every safety finding, the install steps from the project's README, version history, and ways to flag a mistake, report a problem or claim the listing.
Installing a skill
- Check the safety badge. If it is yellow or red, open Details and read the findings first.
- Select Copy install prompt.
- Paste it into your coding agent. It fetches the skill, asks whether to install it for you or for the current project, and puts it in the right place.
Please install the skill hosted at https://github.com/example-org/pdf-forms.
Installing a marketplace
- Select the Claude Code button, which copies one command.
- Paste it into Claude Code. It adds the marketplace; then use
/pluginto browse and install what it contains.
/plugin marketplace add example-org/example-marketplace
Installing an MCP server
- Pick the button for the client you use. Each copies the exact command or configuration for that client.
- Run the command in your terminal, or add the configuration snippet to the client's MCP settings file. Many servers also need API keys or other settings, so check the server's own README if it does not work as it is.
- If there is no client button, use Copy install prompt and let your agent work out the setup.
claude mcp add example-server -- npx -y @example/example-server
Who runs it
findsafeskills is a free service from Leading in the AI Era, an AI and management-oriented Substack that informs current and aspiring C-suite professionals.
Free today, ad-supported eventually
Searching and browsing are free, and you don't need an account to do either. We intend to support the service with advertising eventually. If and when ads appear, these rules apply:
- Every ad is clearly labeled as sponsored and looks different from organic content.
- Advertising never influences search rankings, results, or safety ratings.
- We plan to use privacy-respecting ads, not ads targeted at you individually from your searches.
How it works
A crawler continuously searches GitHub, GitLab, npm, and other sources for repos that look like skills, plugins, or MCP servers, and indexes them with a vector embedding so search understands what you're describing, not just keyword matches. Anyone can also submit a listing directly at /submit.
Safety ratings
Listings carry a rating from an automated static scan of their own text — manifest and README — for prompt-injection phrasing, data-exfiltration URLs, hidden characters, hardcoded secrets, and destructive commands. We also flag repositories GitHub itself has blocked for a terms-of-service violation. Click a yellow or red rating on a listing to see exactly what was found and where. Listings we haven't scanned yet are labeled "Not yet scanned" rather than shown as clean.
The scan doesn't run any code and can miss novel or contextual attacks, so a green rating means "no issues found," not "safe." If you think a finding is a false positive, you can dispute it from the listing page. Read what we check and what we don't.
What makes it different
- Semantic search — describe what you need in plain language, not just keywords.
- Filters that matter: skill, marketplace, or MCP server; safety rating; minimum GitHub stars; recently updated; licensed; author-verified.
- A visible safety rating on listings, with the reasons behind it and a way to contest it.
- An "Author verified" badge, kept separate from the safety rating, for listings whose author has proved they can change the repository — how it works.
- Exhaustive, multi-source crawling (GitHub, GitLab, npm, and more) rather than a single curated list.
- port-skill — found the right skill for the wrong platform? Port it instead of rewriting it.
- Honest, verifiable numbers — the listing count on the home page is real and growing, not a marketing figure.
Use findsafeskills from your own agent
findsafeskills is itself usable programmatically, so your coding agent can search it directly instead of you copy-pasting results:
- A skill (findsafeskills-skill) — instructs an agent to call findsafeskills's own search API.
- An MCP server at
/api/mcp— exposes asearch_skillstool over the Model Context Protocol for any MCP-capable client. It takes the same filters as this website, including safety rating, and returns each result's safety findings.