Assay
Description
An open, reproducible trust layer for AI artifacts — skills, MCP servers, agents, and plugins. Assay inspects code, runs sandboxed behavioral audits, and generates verifiable reports. Help us build the open standard for AI ecosystem security.
Installation
This entry records only its repository, not the path inside it, so there is no
exact command to give. Open the source below and copy the folder into
~/.claude/skills/, or the file into ~/.claude/agents/.
README
Assay
**An open, reproducible framework for evaluating AI artifacts**
skills · MCP servers · agents · plugins
[](https://github.com/metahub-ai/assay/actions/workflows/ci.yml) [](LICENSE) [](package.json)
Every registry that distributes AI artifacts answers _"where did this come from?"_ None answers _"what does it actually do?"_ as a published, auditable signal.
Assay answers the second question. It reads what is inside an artifact, and optionally **runs it** in a sandbox with a real model and judges what it did — then publishes a report that somebody who does not trust you can check.
curl -fsSL https://raw.githubusercontent.com/metahub-ai/assay/main/install.sh | sh
assay run anthropics/skills//skills/pdf
Contents
- Why · Install · Quickstart
- What you point it at · Reading the output
- Running the artifact · In CI · Signing and verifying
- How it works · Writing a check · Library use
- What Assay does not claim
Why
The gap is not an oversight. The official MCP Registry [states in writing](https://modelcontextprotocol.io/registry/moderation-policy) that consumers should "assume minimal-to-no moderation," and that it will not remove "low-quality or buggy servers" or "servers with security vulnerabilities." It relies instead on "upstream package registries (like NPM, PyPI, and Docker) or downstream subregistries."
Meanwhile every trust layer the industry does rely on has a dated counterexample.
**Provenance** — `postmark-mcp` shipped 15 clean versions, th
Related Skills
Agency Agents
A complete AI agency at your fingertips - From frontend wizards to Reddit community ninjas, from whimsy inject
AI Awesome Llm Apps
100+ AI Agents, Agent Skills and RAG Apps - Free and Open Source.
AI Firecrawl
🔥 The API to search, scrape, and interact with the web for AI
AI Artifacts Builder
Suite of tools for creating elaborate, multi-component claude.ai HTML artifacts using modern frontend web tech
AI Headroom
Compress tool outputs, logs, files, and RAG chunks before they reach the LLM. 20% fewer tokens for coding agen
AI CrewAI
Framework for orchestrating role-playing, autonomous AI agents. By fostering collaborative intelligence, CrewA
AI