skillbox — security grade SAFE, quality 63/100

Security audit verdict: SAFE · quality 63/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by kitze · MCP Server · ★ 208

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is skillbox safe to install? View the security audit →

About skillbox

skillbox Self\-hosted, versioned skills library for AI agents\. MCP, scoped clients, and optional Jev recommendations\. Made by Kitze kitze.io · X · YouTube More projects by Kitze Zero To Shipped A full-stack starter kit for web and mobile apps. Sotto Voice-to-text for macOS. Local AI, one-time purchase. <a href="htt

Quick Facts

Stars208
Forks16
LanguageTypeScript
CategoryMCP Server
LicenseMIT
Quality Score63.0283928703831/100
Open Issues4
Last Updated2026-09-19
Created2026-09-17
Platformscli, mcp, node
Est. Tokens~18k

More MCP Server Tools

Explore other popular mcp server tools:

View all MCP Server tools →

Popular TypeScript Agent Tools

Frequently Asked Questions

What is skillbox?

skillbox is Self-hosted, versioned skills library for AI agents. MCP, scoped clients, and optional Jev recommendations.. It is categorized as a MCP Server with 208 GitHub stars.

What programming language is skillbox written in?

skillbox is primarily written in TypeScript.

How do I install or use skillbox?

You can find installation instructions and usage details in the skillbox GitHub repository at github.com/kitze/skillbox. The project has 208 stars and 16 forks, indicating an active community.

What license does skillbox use?

skillbox is released under the MIT license, making it free to use and modify according to the license terms.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse MCP Server tools