skill-fetch

skill-fetch is a cross-platform tool/skill that searches multiple registries for AI coding agent skills, scores and ranks results, applies security scanning/integrity hashing, and installs selected skills into supported agent environments (e.g., Claude Code, Cursor, Codex, Gemini CLI, Windsurf, Amp).

Evaluated Mar 30, 2026 (0d ago)
Homepage ↗ Repo ↗ DevTools agent-skills skill-discovery skill-installer security-scanning supply-chain-integrity mcp claude-code cursor codex
⚙ Agent Friendliness
53
/ 100
Can an agent use this?
🔒 Security
48
/ 100
Is it safe for agents?
⚡ Reliability
36
/ 100
Does it work consistently?

Score Breakdown

⚙ Agent Friendliness

MCP Quality
0
Documentation
72
Error Messages
0
Auth Simplicity
75
Rate Limits
20

🔒 Security

TLS Enforcement
50
Auth Strength
60
Scope Granularity
30
Dep. Hygiene
40
Secret Handling
55

Strengths claimed in README: pre/post installation SHA-256 integrity hash recording and tamper detection; a multi-category security scan including destructive commands, RCE, data exfiltration, system modification, obfuscation, and prompt-injection sub-types; optional permissions declarations in SKILL.md frontmatter and a mismatch-flagging scanner. Uncertainties/risks from the provided content: TLS enforcement and secure transport details are not specified; scope granularity for API keys/OAuth is not described; dependency/vulnerability hygiene is not verifiable from the README excerpt; security scanning is a stated feature but exact methodology, thresholds, and failure modes are not provided.

⚡ Reliability

Uptime/SLA
0
Version Stability
40
Breaking Changes
50
Error Recovery
55
AF Security Reliability

Best When

You want an agent workflow to discover and install third-party skills quickly, with built-in scoring, security labeling, and integrity hash tracking across several registries.

Avoid When

You have strict requirements for supply-chain security evidence beyond static scanning/integrity hashes (e.g., formal verification, signed artifacts), or you cannot tolerate that the tool will rely on external registries/APIs.

Use Cases

  • Search across multiple skill registries (GitHub + SkillsMP + others) for relevant agent skills
  • Rank results for quality (relevance/freshness/community/trust) and present a paginated list
  • Install skills across multiple agent platforms with local/user-level installation options
  • Run a pre-install security scan (categories including RCE, destructive commands, data exfiltration, prompt injection) and record SHA-256 hashes for integrity/tamper detection

Not For

  • Use as a fully automated security assurance system without human review of “Security Concerns”/high-severity findings
  • Use in environments that cannot provide outbound network access to external registries/APIs

Interface

REST API
No
GraphQL
No
gRPC
No
MCP Server
No
SDK
No
Webhooks
No

Authentication

Methods: MCP-based API key setup for SkillsMP (via Claude mcp add --scope user skillsmp ...) Optional API-key configuration via ~/.claude/skills/.fetch-config.json for SkillHub/Skills Directory
OAuth: No Scopes: No

Authentication is primarily API-key based for some registries (not all). The README also instructs an interactive command (/fetch-skill-config) for setting keys in a local JSON config. No OAuth flow is described.

Pricing

Free tier: No
Requires CC: No

Pricing for the service itself is not described. External registries (e.g., SkillsMP) may require paid/free-tier API keys depending on their own policies, but those details are not included here.

Agent Metadata

Pagination
page-based (browse 5 at a time; continue with c)
Idempotent
False
Retry Guidance
Not documented

Known Gotchas

  • Install/update behavior differs by agent integration path (Claude Code plugin vs npx vs curl/sh vs Python vs manual copy).
  • Some sources require API keys (SkillsMP MCP for Sources 1-2; Skills Directory for Source 9); without keys, fewer results are available.
  • Security scan and hash verification occur around installation/loading, but behavior of scan failures or false positives is not detailed in the README excerpt.
  • Interactive install requires mandatory prompt for local vs global installation; non-interactive environments may require alternative flows.

Alternatives

Full Evaluation Report

Comprehensive deep-dive: security analysis, reliability audit, agent experience review, cost modeling, competitive positioning, and improvement roadmap for skill-fetch.

AI-powered analysis · PDF + markdown · Delivered within 30 minutes

$99

Package Brief

Quick verdict, integration guide, cost projections, gotchas with workarounds, and alternatives comparison.

Delivered within 10 minutes

$3

Score Monitoring

Get alerted when this package's AF, security, or reliability scores change significantly. Stay ahead of regressions.

Continuous monitoring

$3/mo

Scores are editorial opinions as of 2026-03-30.

6533
Packages Evaluated
19870
Need Evaluation
586
Need Re-evaluation
Community Powered