No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by Milktang0128 · MCP Server · ★ 53
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is myskills safe to install? View the security audit →
MySkills One window for every AI agent skill. Claude Code · Codex · Shared pool · anything that reads SKILL.md English · 中文 MySkills is a local desktop app that scans the skill directories you've registered, deduplicates by name + source, and gives you one coherent view of every AI agent skill you have. The default registry is , , and ; you can add, remove, or repath platforms in Settings. A is a Markdown file with YAML frontmatter that tools like Claude Code and Codex load as reusable capabilities — prompts, tooling profiles, agent instructions. Once you use more than one of those tools, copies start to drift across folders. MySkills makes that mess legible, and any write is explicit, reviewable, backed up, and record
| Stars | 53 |
| Forks | 9 |
| Language | TypeScript |
| Category | MCP Server |
| License | MIT |
| Quality Score | 63.4393734914862/100 |
| Open Issues | 3 |
| Last Updated | 2026-07-08 |
| Created | 2026-05-19 |
| Platforms | claude-code, codex, mcp, node |
| Est. Tokens | ~17k |
These tools work well together with myskills for enhanced workflows:
Explore other popular mcp server tools:
myskills is AI Skill Hub — a cross-platform desktop app to discover, dedupe, organize, and sync AI agent skills across Claude Code, Codex, and a shared pool. Ships an MCP server so your agent can run the whole li. It is categorized as a MCP Server with 53 GitHub stars.
myskills is primarily written in TypeScript.
You can find installation instructions and usage details in the myskills GitHub repository at github.com/Milktang0128/myskills. The project has 53 stars and 9 forks, indicating an active community.
myskills is released under the MIT license, making it free to use and modify according to the license terms.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: