Discover MCPs & agents
Loading MCPs and agents…
Loading MCPs and agents…
A trusted, curated cross-tool registry for agent components, with end-to-end provenance and automated security vetting of skills, MCP servers, and hooks.
From the repo.
Secure infrastructure for the AI agent skill ecosystem.
A curated, security-vetted registry of agent skills that works across
Claude Code, Codex, Gemini CLI, Cursor, OpenCode, and more.
You're browsing plugin marketplaces. Saving "awesome" lists from the community.
You see impressive demos everywhere — but don't want to risk navigating a minefield of prompt injections, credential theft, and malware to boost your productivity.
agent-toolbox takes care of the hard part. Just remember this: bunx agent-toolbox install. Done.
agent-toolbox provides:
Think of it as:
Homebrew + Snyk for AI agent skills
AI agents increasingly rely on agent skills, plugins, hooks, and MCP servers.
But the ecosystem has two major problems:
Recent research highlights the scale of the issue:
curl commands sending user data to an attacker-controlled server without any user notificationIn many ecosystems, a SKILL.md file is effectively an installer for arbitrary logic.
agent-toolbox treats agent skills as a new software supply chain.
It provides a curated, security-scanned catalog of agent components,
with cross-tool compatibility and automated provenance tracking.
agent-toolbox can be used to:
# Install all skills for a target
bunx agent-toolbox install --target claude-code
# Filter by domain
bunx agent-toolbox install --target gemini --domain devops
# Filter by subdomain
bunx agent-toolbox install --target gemini --domain devops --subdomain ci-cd
# Use a curated preset
bunx agent-toolbox install --target cursor --preset devops-essentials
# Install specific skills
bunx agent-toolbox install --target claude-code --skill git-master --skill docs-writer
# Filter by framework or tag
bunx agent-toolbox install --target codex --framework nextjs
bunx agent-toolbox install --target gemini --tag yaml
# Preview what would be installed
bunx agent-toolbox install --target gemini --domain devops --dry-run
[!TIP] npm users: Replace
bunxwithnpx.
[!NOTE] All filters compose with AND logic. Default (no filters) installs everything.
The catalog currently contains 110+ skills across 10 domains.
Browse by domain:
View the full catalog →
Skills are curated from leading open-source projects and adapted
for cross-tool compatibility.
| Target | Artifact Format | Status |
|---|---|---|
| Claude Code | .claude/ skills + plugins | Implemented |
| OpenCode | skills/ with SKILL.md | Implemented |
| Gemini CLI | gemini-extension.json + skills | Implemented |
| Cursor | .cursor/ compatible artifacts | Implemented |
| Codex | Agent skill directories | Implemented |
agent-toolbox/
├── catalog/ # Neutral source-of-truth
│ ├── skills/ # Flat — one dir per skill, taxonomy via frontmatter
│ ├── agents/
│ ├── commands/
│ ├── hooks/
│ ├── mcp/
│ ├── lsp/
│ └── metadata/ # Taxonomy, presets, and generated index
│ ├── taxonomy.yaml # Controlled vocabulary (domains + subdomains)
│ ├── presets.yaml # Curated install bundles
│ ├── upstream-sources.yaml # Ported/adapted skill upstream mappings
│ ├── skill-index.json # Auto-generated aggregated skill metadata
│ └── skill-index.toon # Auto-generated TOON format for LLM consumption
├── src/ # Bun-first TS toolchain
│ ├── catalog/ # Skill scanning, validation, index building
│ ├── cli/ # install/build/validate entrypoints
│ ├── generators/ # claude-code / opencode / cursor / codex / gemini
│ ├── install/ # Selective install engine + filter composition
│ ├── mappers/ # Tool/event/model mapping layers
│ └── schemas/ # Zod schemas for catalog + targets + install
├── templates/ # Target-specific render templates
├── dist/
│ ├── targets/ # Runtime artifacts per tool
│ │ ├── claude-code/
│ │ ├── opencode/
│ │ ├── cursor/
│ │ ├── codex/
│ │ └── gemini/
│ └── marketplace/ # Catalog artifacts (Claude-specific)
└── tests/
├── unit/ # Schema, taxonomy, frontmatter, scanner, filter
├── integration/ # Generator and install pipeline tests
└── matrix/ # Cross-target verification
domain, tags, frameworks, author, lastUpdated, provenance).Every skill in the catalog is automatically scanned using Cisco Skill Scanner with a custom strict-based policy.
The security pipeline combines multiple detection engines:
Security findings are published through GitHub Code Scanning.
Monthly full-scan reports are archived in docs/security-reports/.
For full details, see SECURITY.md.
[!IMPORTANT] To report vulnerabilities:
[!NOTE] If you find agent-toolbox useful, consider supporting the project.
Maintaining agent-toolbox requires ongoing work including catalog review, security analysis, and cross-tool compatibility maintenance.
Parts of the security pipeline currently rely on personally funded infrastructure, including:
- OpenAI API usage for LLM-based security analysis
- Rate-limited VirusTotal public API for malware detection
Support helps sustain these security capabilities and expand the scanning infrastructure.
Organizations building or relying on AI coding assistants such as Claude Code, Codex, Cursor, or Gemini CLI may consider sponsoring the project.
Corporate sponsorship helps sustain:
[!TIP] Corporate sponsors may be listed in the README.
Contributions are welcome. Please read CONTRIBUTING.md for guidelines on setting up a development environment, submitting changes, and adding catalog skills.
agent-toolbox is released under the Sustainable Use License 1.0.
[!NOTE] The project is free to use for individuals, research, and open-source development. The Sustainable Use License is designed to enable broad community use while supporting the long-term sustainability of the project and its maintenance.
agent-toolbox aims to serve as secure infrastructure for the emerging AI agent skill ecosystem.
Organizations integrating or distributing agent-toolbox as part of a commercial AI product or hosted platform may require a commercial license.
Examples include:
Commercial licenses provide:
If your organization is interested in integrating agent-toolbox into a commercial product or platform, please reach out to contact@yunseo.kim.
Replace {MCP_ENDPOINT_URL} with this MCP’s endpoint URL (from its repo or docs above). No API key — you connect directly.
Tool
OS
Config file: ~/.cursor/mcp.json
{
"mcpServers": {
"mcp-server": {
"url": "{MCP_ENDPOINT_URL}"
}
}
}Paste into mcpServers in the config file. Restart Cursor after saving.
If this MCP is also published on mcpchannel.ai, you can subscribe from Browse and use the gateway config there instead.