Skip to content

Frequently asked questions

What's the difference between a skill, a plugin/marketplace, and an MCP server?

A skill is a reusable instruction set (usually a SKILL.md file) that teaches an agent how to do a specific task. A plugin marketplace is a curated repo that bundles multiple skills/plugins together. An MCP server is different in kind — it exposes tools/APIs to an agent via the Model Context Protocol, and is installed by registering it in your client's config rather than dropping a skill folder into place.

How do I install a skill, marketplace, or MCP Server that looks interesting?

See “Using This Site”.

How are listings found?

A crawler searches GitHub, GitLab, npm, and other sources on a recurring schedule. Anyone can also submit a listing directly.

Is every listing reviewed before it appears?

No — findsafeskills auto-publishes listings that pass basic validation (the repo resolves, required fields are present) rather than gating on manual review. This keeps the catalog comprehensive and up to date; it also means you should use your own judgment before running code from a listing you haven't vetted. Listings do get an automated safety rating — see below for what it does and doesn't tell you.

How does search work?

Search uses a vector embedding of your query compared against each listing's embedding, so you can describe what you need in plain language rather than guessing exact keywords. If that service is temporarily unavailable, search falls back to keyword matching and tells you so.

How do I narrow the results?

On the search page you can filter by type (skill, marketplace, or MCP server), safety rating (including "Not flagged"), minimum GitHub stars, how recently the repo was updated, whether it has a recognized license, and whether the author has verified ownership. A search with its filters lives in the address bar, so you can bookmark or share it.

Is findsafeskills free? Who runs it?

It's free, and you don't need an account to search. It's run by Leading in the AI Era, an AI and management-oriented Substack for current and aspiring C-suite professionals. We intend to add advertising eventually; ads will always be labeled and will never influence search results or safety ratings.

What do the safety ratings mean?

A rating comes from an automated static scan of a listing's own text. The badge says which text was read: No issues found by itself means both the manifest and the README were scanned, while "description only" means just the name and one-line description were, because that listing's files have not been read yet (we are working through the catalog in batches). Either way, a clean result means the scan found nothing — not that the listing is safe. Review suggested and Flagged mean it found something worth a look; click the rating on a listing to see exactly what and where. A listing whose repository GitHub has blocked for a terms-of-service violation is flagged too, and Not yet scanned means no rating exists yet. The scan never runs any code and can miss novel attacks — see what we check and what we don't. Install instructions on a listing page are the repo author's own words from its README; findsafeskills has not verified them.

A listing is flagged and I think that's wrong. What can I do?

Sign in, open the listing, click its safety rating, and use the dispute form to say which finding is a false positive and why. A reviewer looks at it. If the dispute is accepted, that finding stops counting toward the rating; it stays visible, marked as dismissed after review.

What does "Author verified" mean?

It means someone with permissions to change the repo has either submitted or claimed this item. It does not tell you who they are, what they intend, or that the code is safe, and it is never combined with the safety rating. More about verification.

How do I get my listing verified?

Open the listing, sign in and click Claim this listing. You can prove you can change the repository with GitHub push access (if you signed in with GitHub) or by adding a validation key to the README or a .findsafeskills file. This works for listings we discovered ourselves too. See how verification works.

How do I report a listing that looks malicious or fake?

Sign in, open the listing and click "Report this listing". Pick a reason and say what you saw. Reports go to a single reviewer, are not shown publicly, and do not hide or flag the listing automatically. There is no promised response time. For general feedback, use the suggest page.

Can my coding agent search findsafeskills?

Yes. There's a skill and an MCP server (see the About page). The MCP tool takes the same filters as the website and returns each result's safety rating and findings, so an agent can, for example, ask for MCP servers that aren't flagged.

Do sponsorships affect search results?

No. Sponsored placements, if and when they exist, are clearly labeled and never influence search ranking, results, or safety ratings — see the About page.

I found a skill for the wrong platform. Now what?

Check out port-skill on the DIY page — it's built to port a skill/plugin between Claude Code, Codex, Antigravity, and Gemini CLI.