skillhawk — security grade SAFE, quality 70/100

Security audit verdict: SAFE · quality 70/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by Berserk-hub150 · MCP Server · ★ 62

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is skillhawk safe to install? View the security audit →

About skillhawk

SkillHawk Security scanner + hands-on lab for AI Agent Skills, and MCP configs Catch dangerous agent instructions before they touch your shell, files or credentials. 🧪 5-Minute AI Agent Security Challenge Can you repair an unsafe AI Agent Skill before SkillHawk catches it? Fork → edit in the browser → push → GitHub Actions grades you automatically. 🍴 START THE CHALLENGE — FORK SKILLHAWK 10 levels · automatic progress · weekly bonus challenge · shareable Defender badge · Hall of Defenders No local setup is required for the challenge ladder. <img src="assets

agent-skillsai-agentsclaude-codecodexmcpopen-sourcesecuritystatic-analysis

Quick Facts

Stars62
Forks23
LanguageJavaScript
CategoryMCP Server
LicenseMIT
Quality Score69.834286718004/100
Open Issues60
Last Updated2026-09-20
Created2026-08-16
Platformsclaude-code, codex, mcp, node
Est. Tokens~15k

Compatible Skills

These tools work well together with skillhawk for enhanced workflows:

  • sync-skill — semantic(0.32)+complementary+same_lang+similar_pop+shared_platform (61%)
  • agent-skills — semantic(0.32)+complementary+same_lang+similar_pop+shared_platform (61%)

skillhawk alternative? Top 6 similar tools

Looking for a skillhawk alternative? If you're comparing skillhawk with other mcp server tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • agent-designer by appautomaton · ⭐ 130

    Portable SKILLs workspace for Claude Code, Codex, and Gemini — issue-driven workflows and cross-agent collabor

  • orchestkit by yonatangross · ⭐ 278

    The Complete AI Development Toolkit for Claude Code. 106 skills, 36 agents, 171 hooks. Install `ork` for stabl

  • deepcontext-mcp by Wildcard-Official · ⭐ 275

    DeepContext is an MCP server that adds symbol-aware semantic search to Claude Code, Codex CLI, and other agent

  • claudepro-directory by JSONbored · ⭐ 217

    HeyClaude (formerly Claude Pro Directory) is a searchable collection of pre-built AI skills, agents, MCP serve

  • ask-user-questions-mcp by paulp-o · ⭐ 139

    Better 'AskUserQuestion' - A lightweight MCP server/OpenCode plugin/Agent Skills + CLI tool that allows your L

  • roslyn-codelens-mcp by MarcelRoozekrans · ⭐ 51

    Roslyn-based MCP server giving AI agents deep semantic understanding of .NET/C# codebases — 67 tools for navig

More MCP Server Tools

Explore other popular mcp server tools:

View all MCP Server tools →

Popular JavaScript Agent Tools

Frequently Asked Questions

What is skillhawk?

skillhawk is Catch dangerous AI agent skills before they catch you. Zero-dependency security scanner for Agent Skills, SKILL.md and MCP configs.. It is categorized as a MCP Server with 62 GitHub stars.

What programming language is skillhawk written in?

skillhawk is primarily written in JavaScript. It covers topics such as agent-skills, ai-agents, claude-code.

How do I install or use skillhawk?

You can find installation instructions and usage details in the skillhawk GitHub repository at github.com/Berserk-hub150/skillhawk. The project has 62 stars and 23 forks, indicating an active community.

What license does skillhawk use?

skillhawk is released under the MIT license, making it free to use and modify according to the license terms.

What are the best alternatives to skillhawk?

The top alternatives to skillhawk on Agent Skills Hub include agent-designer, orchestkit, deepcontext-mcp. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse MCP Server tools