capa — security grade SAFE, quality 71/100

Security audit verdict: SAFE · quality 71/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by infragate · MCP Server · ★ 728

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is capa safe to install? View the security audit →

About capa

Agentic Capabilities and Package Manager CAPA is the package manager for AI coding agents. Declare your skills, tools, rules, sub-agents, MCP servers, and plugins once in , run capa inst

agentic-workflowcapabilitiesmcpmcp-gatewaymcp-serverpackage-managerskills

Quick Facts

Stars728
Forks97
LanguageTypeScript
CategoryMCP Server
LicenseMIT
Quality Score71.2648923458563/100
Open Issues11
Last Updated2026-09-23
Created2026-02-08
Platformsclaude-code, codex, mcp, node
Est. Tokens~16k

Compatible Skills

These tools work well together with capa for enhanced workflows:

  • craftdesk — semantic(0.40)+complementary+rare_topics+same_lang+similar_pop+shared_platform (64%)
  • agent-rules — semantic(0.20)+complementary+same_lang+similar_pop+shared_platform (52%)
  • skillfile — semantic(0.26)+complementary+rare_topics+similar_pop+shared_platform (49%)

capa alternative? Top 6 similar tools

Looking for a capa alternative? If you're comparing capa with other mcp server tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • gram by speakeasy-api · ⭐ 271

    Securely scale AI usage across your organization. A single stack to Connect, Secure, Observe and Distribute ag

  • metamcp by metatool-ai · ⭐ 2.7k

    MCP Aggregator, Orchestrator, Middleware, Gateway in one docker

  • mcphub by samanhappy · ⭐ 2.5k

    Self-hosted MCP gateway and control plane for connecting, controlling, and operating MCP servers.

  • Unla by AmoyLab · ⭐ 2.2k

    🧩 MCP Gateway - A lightweight gateway service that instantly transforms existing MCP Servers and APIs into MC

  • pg-aiguide by timescale · ⭐ 1.9k

    MCP server and Claude plugin for Postgres skills and documentation. Helps AI coding tools generate better Post

  • MCPJungle by mcpjungle · ⭐ 1.2k

    One place to manage & connect to all your MCP servers

More MCP Server Tools

Explore other popular mcp server tools:

View all MCP Server tools →

Popular TypeScript Agent Tools

Frequently Asked Questions

What is capa?

capa is One capabilities.yaml wires skills, tools, rules, sub-agents, MCP servers, and plugins into Cursor, Claude Code, Codex, Windsurf, GitHub Copilot, and 30+ other AI coding agents. It is categorized as a MCP Server with 728 GitHub stars.

What programming language is capa written in?

capa is primarily written in TypeScript. It covers topics such as agentic-workflow, capabilities, mcp.

How do I install or use capa?

You can find installation instructions and usage details in the capa GitHub repository at github.com/infragate/capa. The project has 728 stars and 97 forks, indicating an active community.

What license does capa use?

capa is released under the MIT license, making it free to use and modify according to the license terms.

What are the best alternatives to capa?

The top alternatives to capa on Agent Skills Hub include gram, metamcp, mcphub. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse MCP Server tools