

SaferSkills independently scans every AI capability — skills, MCP servers, hooks, plugins, and rules — and publishes a public trust score with a full rule trace. These docs teach you to find and verify a capability, install it safely, publish your own and get it scanned, and read the deterministic methodology behind every score. Every verdict here is reproducible: no LLM sits in the scoring path.
Who are these docs for?
These docs serve anyone who builds with or depends on AI agents. Developers installing skills and MCP servers will want the quickstart and the CLI reference. Skill and MCP authors publishing their own work should read publish and get scanned and the right-of-reply process. Security researchers auditing the agent ecosystem will go to how scoring works and detection categories. CISOs and platform managers weighing what their teams run should start with why scanning matters and managing your agents.
Where should you start?
Start with Getting Started if SaferSkills is new to you — it covers what SaferSkills is, why independent scanning matters, a five-minute quickstart, and the core concepts that the rest of the docs assume.
What does each section cover?
- Getting Started — the orientation path: what SaferSkills is, why scanning matters, the quickstart, and the core concepts.
- Concepts — what each capability kind is and how it is scored: skills, MCP servers, hooks, plugins, the scoring overview, the Agent Scan, and the glossary.
- Find & Verify — use the running service: browse the catalog, scan a repo, read a scan report, and embed your badge.
- Agent Scan — the behavioral pack that grades a running agent rather than its static files: what it is, run one, read the report, and the behavioral scoring model.
- Install — the
saferskillsCLI: install a skill, the command reference, global flags, and per-agent guides for all eight supported platforms. - For Authors — get your capability indexed and scored: publish and get scanned, the SKILL.md spec, claim your repo, and disputing findings.
- Security & Methodology — the deep methodology: how scoring works, the five sub-scores, detection categories, finding evidence, and how to contribute a rule.
- Reference — the public API, the FAQ, and about the project.
How can you check the rules yourself?
Every detection rule is documented and auto-rendered on the live methodology page, with its severity, sub-score, framework references, and a permalink to the rule source. You can browse the catalog, submit a scan, or open the Agent Report directory on the main site at any time — the docs and the running service share one source of truth.
Where can you get help?
Have a question these docs don’t answer? Join our community Slack to ask the maintainers and other users, or open a thread in GitHub Discussions.