ABOUT · 07 · /ABOUT

About SaferSkills.

A public, free, open-source trust-scoring service for AI skills, MCP servers, hooks, and plugins. We index them. We audit them. We publish the report.

Why we built this.

AI agent skills, MCP servers, hooks, and plugins have exploded across eight platforms in eighteen months. There is no shared audit, no shared methodology, no shared trust signal. Every install is a leap of faith — and the data we have suggests that faith is misplaced.

36%
of AI agent skills tested contain prompt-injection patterns. Snyk ToxicSkills · 2026
NO·1
No public audit methodology existed for skills, MCPs, or hooks before SaferSkills. Every registry trusted vendors to self-certify.
NO·2
Existing registries (mcp.so, Smithery, ClawHub, etc.) don't disclose what criteria — if any — they apply before listing a skill.
NO·3
Verification of "works with my agent" is left entirely to the user. There is no install-time gate, no version-locked review, no reproducible audit.

SaferSkills is the answer to that gap. Anyone submits a public GitHub URL; thirty seconds later, a deterministic security report appears at a permalink. The rules are open. The methodology is open. The findings cite a rule ID and a line of evidence. Vendors get a right-of-reply on every public verdict.

Think VirusTotal, but for AI capabilities.

Who's behind it.

Luc Delsalle
Luc Delsalle Founder & CEO

20+ years in cybersecurity and enterprise infrastructure. Previously: CTO Ailevate · VP of Engineering Tenable (NASDAQ: TENB) · Co-Founder + CTO Alsid, identity security company acquired by Tenable. Deep background in identity security, attack-path analysis, and runtime enforcement.

How to reach us.

Email is the right channel for security disclosures, press, partnerships, and methodology proposals. Each address routes to a real person, not a contact-form queue.

Try the scanner.

~30 seconds. Free. No account. The report URL is bookmarkable and persists for 90 days.