Know the risk before you install the skill.

Skill Trust scores MCP skills 0–100 for supply-chain risk — one endpoint, one badge, and an evidence page behind every number. Maintainers opt in; nobody gets scored without consent.

Look up a skill

Free lookups are rate-limited to 10 per day per connection.

Add the badge to your README

One line, next to your install instructions:

[![risk](https://skilltrust.example.com/badge/acme/docs-helper.svg)](https://skilltrust.example.com/evidence/acme/docs-helper/<sha>)

The badge links to the skill's evidence page. Badges render only for opted-in skills in good standing — withdrawn during disputes, never stamped “untrusted”.

How scoring works

A static pass over the manifest, tool descriptions, and code at a pinned revision — dangerous calls, exfiltration shapes, permission overreach, provenance — plus one bounded judge call. No sandbox runs, no live probing. Read the full methodology, including the rule catalog, severity weights, and grade bands.

Lowest-risk skills right now seed data

See the full leaderboard

Maintainers: make it official

Verified ($199/yr) binds the badge to your domain and re-scores on every commit. Scores are assessments, not guarantees — see the no-warranty terms on the checkout page.

API base: https://skilltrust.example.com