SkillForge — security grade SAFE, quality 55/100

Security audit verdict: SAFE · quality 55/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by HaddenHunter · MCP Server · ★ 105

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is SkillForge safe to install? View the security audit →

About SkillForge

SkillForge English Documentation SkillForge 是一个给 AI Coding Agent 使用的本地优先技能运行时。它把技能定义成可校验、可组合、可暴露为 MCP 的独立单元,让 Agent 能像“安装包”一样复用能力,同时通过白名单沙箱约束读写范围。 当前仓库处于 Phase 1 MVP 阶段,已经具备以下核心能力: Rust CLI:、、 严格校验,禁止未声明字段 基于白名单的本地文件读写沙箱 macOS 上自动接入 Seatbelt 平台沙箱,可用性受宿主环境约束 面向技能执行的 Plan - Act - Observe - Reflect 流程 更细粒度的工具执行轨迹与观察结果 技能评测与 CI 门禁:批量校验、批量评测、clippy、测试 Token 预算截断,避免超预算模型调用 Ollama 与 OpenAI-compatible 模型接入 通过 HTTP 暴露 MCP / / 能力 TypeScript Registry CLI,支持本地 ,以及 GitHub Release 分发与同步 为什么是 SkillForge 很多 Agent 技能方案停留在“提示词片段”或“仓库模板”层面,缺少版本、依赖、权限与运行边界。SkillForge 试图补上这些基础设施: 技能有结构化清单: 技能有执行边界: / / 技能有可复用入口: 技能有评测基线: 技能能被本地 Agent 和 MCP 客户端共同消费 整体架构图 下面这张图展示了 SkillForge 当前仓库里已经落地的节点,以及它们之间的调用方向和关键链路(签名、鉴权、审计、缓存回填): text ┌───────────────────────────────────────────────────────────┐ │ SkillForge(本仓库已全部实现) │ └───────────────────────────────────────────────────────────┘ ┌──────────────────────┐ ┌───────────────────────────────┐ │ MCP 客户端 / │◀─MCP────▶│ core/ (Rust) │ │ Claude Code/Cursor │ :18080 │ serve/run/validate/eval │ └───────────────────

Quick Facts

Stars105
Forks4
CategoryMCP Server
LicenseApache-2.0
Quality Score54.845716480524/100
Last Updated2026-08-10
Created2026-08-04
Platformsclaude-code, cli, codex, gemini, mcp
Est. Tokens~19k

Compatible Skills

These tools work well together with SkillForge for enhanced workflows:

  • viberank — semantic(0.39)+complementary+same_lang+similar_pop+shared_platform (64%)

More MCP Server Tools

Explore other popular mcp server tools:

View all MCP Server tools →

Frequently Asked Questions

What is SkillForge?

SkillForge is 给 AI Coding Agent(Claude Code / Cursor / Codex / Gemini CLI)用的 **技能版 npm** —— 本地优先、模型无关、MCP 原生。. It is categorized as a MCP Server with 105 GitHub stars.

How do I install or use SkillForge?

You can find installation instructions and usage details in the SkillForge GitHub repository at github.com/HaddenHunter/SkillForge. The project has 105 stars and 4 forks, indicating an active community.

What license does SkillForge use?

SkillForge is released under the Apache-2.0 license, making it free to use and modify according to the license terms.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse MCP Server tools