Know the risk before you install the skill.
Skill Trust scores MCP skills 0–100 for supply-chain risk — one endpoint, one badge, and an evidence page behind every number. Maintainers opt in; nobody gets scored without consent.
Look up a skill
Free lookups are rate-limited to 10 per day per connection.
Add the badge to your README
One line, next to your install instructions:
[](https://skilltrust.example.com/evidence/acme/docs-helper/<sha>)
The badge links to the skill's evidence page. Badges render only for opted-in skills in good standing — withdrawn during disputes, never stamped “untrusted”.
How scoring works
A static pass over the manifest, tool descriptions, and code at a pinned revision — dangerous calls, exfiltration shapes, permission overreach, provenance — plus one bounded judge call. No sandbox runs, no live probing. Read the full methodology, including the rule catalog, severity weights, and grade bands.
Lowest-risk skills right now seed data
- acme/docs-helper — 4/100 · Low · Verified
- globex/report-writer — 8/100 · Low
- github/example-skill — 12/100 · Low
Maintainers: make it official
Verified ($199/yr) binds the badge to your domain and re-scores on every commit. Scores are assessments, not guarantees — see the no-warranty terms on the checkout page.
API base: https://skilltrust.example.com