No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by kitze · MCP Server · ★ 208
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is skillbox safe to install? View the security audit →
skillbox Self\-hosted, versioned skills library for AI agents\. MCP, scoped clients, and optional Jev recommendations\. Made by Kitze kitze.io · X · YouTube More projects by Kitze Zero To Shipped A full-stack starter kit for web and mobile apps. Sotto Voice-to-text for macOS. Local AI, one-time purchase. <a href="htt
| Stars | 208 |
| Forks | 16 |
| Language | TypeScript |
| Category | MCP Server |
| License | MIT |
| Quality Score | 63.0283928703831/100 |
| Open Issues | 4 |
| Last Updated | 2026-09-19 |
| Created | 2026-09-17 |
| Platforms | cli, mcp, node |
| Est. Tokens | ~18k |
Explore other popular mcp server tools:
skillbox is Self-hosted, versioned skills library for AI agents. MCP, scoped clients, and optional Jev recommendations.. It is categorized as a MCP Server with 208 GitHub stars.
skillbox is primarily written in TypeScript.
You can find installation instructions and usage details in the skillbox GitHub repository at github.com/kitze/skillbox. The project has 208 stars and 16 forks, indicating an active community.
skillbox is released under the MIT license, making it free to use and modify according to the license terms.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: