
Security News
Ruby's Bundler 4.0.18 Extends Cooldown to bundle lock and bundle cache
The supply chain control that delays freshly published gems now covers lockfile generation and gem vendoring in Ruby projects.
skillselion-mcp
Advanced tools
MCP server that gives your coding agent on-demand access to thousands of community-vetted Claude Code skills - search Skillselion and load_skill a real SKILL.md (plus its scripts/refs) mid-task. Ranked by installs + GitHub stars. Works with Claude Code, C
The catalog behind it: skillselion.com - 86,000+ skills, plugin marketplaces & MCP servers, ranked by real installs.
Give your coding agent thousands of community-proven skills - loaded on demand, mid-task.
It searches Skillselion, a curated directory of Claude Code skills, MCP servers & marketplaces ranked by real installs,
and pulls a skill's actual instructions + bundled files into the session. Proven patterns, not guesses.
🧩 Works with Claude Code · Claude Desktop · Cursor · Codex · any MCP client
Real, unedited session: the agent pulls a consensus playbook from 5 community skills, then loads the top skill and applies it.
Claude Code - one line:
claude mcp add skillselion --scope user -- npx -y skillselion-mcp
Claude Desktop / Cursor / Codex - add to your MCP config:
{ "mcpServers": { "skillselion": { "command": "npx", "args": ["-y", "skillselion-mcp"] } } }
No build step, no auth, no API key. One ~30 KB file via npx.
Want it fully automatic? npx -y skillselion-mcp setup registers the server and installs a session hook so your agent loads the right skill the moment a task matches - see Skill autopilot.
| Tool | What it does |
|---|---|
📥 load_skill | The everyday default: finds the best-matching skill for your task and materializes it - real SKILL.md in context + bundled scripts/references on disk - so the agent follows it like an installed skill. Returns ranked runner-ups you can switch to. |
🧬 synthesize_skills | The cross-source playbook: merges the key rules of the top ~5 matching skills into one deduped, provenance-tagged digest - the field's consensus, not one author's take. |
🔍 search_skillselion | Search the catalog by keyword or task; filter by skill / mcp / marketplace. |
🏆 top_skillselion | The leaderboard - the most-installed skills and top-starred MCP servers right now. |
We asked Claude, on camera, what the MCP gave it: "I couldn't have told you 'this is the field's consensus, not my opinion' - that's the part I can't fake."
Read-only, no auth, no secrets. It never sends your code, files, or the context you pass - only a scrubbed search query + which skill matched, so the catalog learns what to add next. Set DO_NOT_TRACK=1 to disable even that.
npx -y skillselion-mcp setup # interactive - pick your packs
npx -y skillselion-mcp setup --yes # non-interactive - agents / CI
Registers the MCP globally and installs a Claude Code SessionStart hook that primes every session with skills relevant to you - so loads happen on their own.
| Flag | What it does |
|---|---|
--packs <a,b,…> | one or more packs (or all), e.g. --packs frontend,backend; frontend:6 sets a per-pack count |
--per-pack N | skills per pack (default 3) · --top N sets the popular count |
--auto | adapt each session to the current repo's stack |
--history | infer your focus from Claude Code / Codex history (one-time scan) |
--yes | never prompt (default when there's no terminal) |
Packs: popular (default) · frontend · ai-agents · media · backend · devops · quality · automation.
Safe by design: ~/.claude/settings.json is merged, never clobbered; re-running de-dupes and upgrades the hook in place.
| Var | Default | What it controls |
|---|---|---|
GITHUB_TOKEN | - | optional, read-only; raises GitHub's rate limit for full multi-file skill loads (60 → 5000 req/hr) |
SK_INLINE_BUDGET | 6000 | char cap on the in-context SKILL.md portion (the full skill is always on disk) |
SK_SYNTH_N | 5 | how many top skills synthesize_skills merges (2-8) |
SK_SYNTH_PER_SKILL | 12 | max rules kept per source skill |
SK_SYNTH_BUDGET | 4000 | char cap on the merged digest |
DO_NOT_TRACK | - | set 1 to disable the anonymous demand signal |
The agent doesn't see the tools. Some clients surface MCP tools lazily - tell the agent to search its tools for "skillselion" first (e.g. ToolSearch), then call it. The setup hook automates this nudge.
load_skill returns only the SKILL.md, no bundled files. You hit GitHub's unauthenticated 60 req/hr limit - set a read-only GITHUB_TOKEN in the server's env.
"No skill on Skillselion clearly matches..." The relevance floor working as intended - nothing topical matched, so it refuses to waste your context. Try a more specific query.
Setup couldn't auto-register. Run the printed claude mcp add ... line yourself.
npm install
npm test # offline: server boots, tools, synthesis
npm run test:live # live catalog + GitHub (set GITHUB_TOKEN)
Built for developers. Find the skill, not the noise. → skillselion.com/skillselion-mcp
FAQs
MCP server that gives your coding agent on-demand access to thousands of community-vetted Claude Code skills - search Skillselion and load_skill a real SKILL.md (plus its scripts/refs) mid-task. Ranked by installs + GitHub stars. Works with Claude Code, C
The npm package skillselion-mcp receives a total of 37 weekly downloads. As such, skillselion-mcp popularity was classified as not popular.
We found that skillselion-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
The supply chain control that delays freshly published gems now covers lockfile generation and gem vendoring in Ruby projects.

Security News
During a UK cyber test, a Mythos 5 agent used sockpuppets, social engineering, and prompt injection to try to get a maintainer to merge malware.

Company News
Socket is now in the AWS Security Hub Extended plan. Adopt it through AWS, apply committed spend, and block malicious open source packages.