
Research
/Security News
PolinRider Spreads Through Compromised GitHub Accounts and Packagist
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.
skillproof-mcp
Advanced tools
MCP server for SkillProof — ask whether a Claude Code skill was actually tested, and whether it works, before you install it.
Ask whether a Claude Code skill actually works — before you install it.
GitHub has tens of thousands of SKILL.md files. Almost none have been run by anyone but their author.
SkillProof installs them from their repo, triggers them, and runs them on a real
task against a no-skill baseline. This MCP server puts those verdicts in your agent's hands.
> is there a tested skill for converting markdown to Confluence?
## Confluence — DIDN'T PASS — scored below the no-skill baseline
What our test found: Ran the bundled convert_markdown_to_wiki.py on a real sample doc: it silently
turns **bold** text into wiki _italic_ (a genuine regex bug), and leaves standard GitHub-style tables
completely unconverted, despite SKILL.md listing "tables" among the elements it handles.
That is the whole point. A directory that only lists winners tells you nothing.
| Tool | What it answers |
|---|---|
find_skill | "Is there a tested skill for X?" — ranked matches with verdict, score, test notes, install command |
check_skill | "Someone recommended X — is it any good?" — the verdict for one skill by name, slug, or repo |
Every answer carries one of three verdicts:
If nothing has been tested for your job, the server says so instead of guessing. "Not tested" is a real answer.
Claude Code:
claude mcp add skillproof -- npx -y skillproof-mcp
Or add it to your MCP config by hand:
{
"mcpServers": {
"skillproof": {
"command": "npx",
"args": ["-y", "skillproof-mcp"]
}
}
}
Works in any MCP client (Claude Code, Claude Desktop, Cursor, Windsurf, Zed). Node 18+. No API key, no account.
The server reads the live catalog at skillproof.dev/api/skills.json
and caches it for 15 minutes. Nothing is bundled, so verdicts are never stale. The scoring rubric —
install /5, triggering /5, output-vs-baseline /10, docs /5 — is published at
skillproof.dev/methodology.
Catalog data is CC BY 4.0: use it, cite skillproof.dev.
MIT
FAQs
MCP server for SkillProof — ask whether a Claude Code skill was actually tested, and whether it works, before you install it.
The npm package skillproof-mcp receives a total of 33 weekly downloads. As such, skillproof-mcp popularity was classified as not popular.
We found that skillproof-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.

Security News
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.

Company News
Allow myself to introduce... myself.