Assay banner
metahub-ai metahub-ai

Assay

AI community

Description

An open, reproducible trust layer for AI artifacts — skills, MCP servers, agents, and plugins. Assay inspects code, runs sandboxed behavioral audits, and generates verifiable reports. Help us build the open standard for AI ecosystem security.

Installation

This entry records only its repository, not the path inside it, so there is no exact command to give. Open the source below and copy the folder into ~/.claude/skills/, or the file into ~/.claude/agents/.

README

Assay

**An open, reproducible framework for evaluating AI artifacts**
skills · MCP servers · agents · plugins

[![CI](https://github.com/metahub-ai/assay/actions/workflows/ci.yml/badge.svg)](https://github.com/metahub-ai/assay/actions/workflows/ci.yml) [![License](https://img.shields.io/badge/license-Apache--2.0-blue.svg)](LICENSE) [![Node](https://img.shields.io/badge/node-%E2%89%A520-brightgreen.svg)](package.json)


Every registry that distributes AI artifacts answers _"where did this come from?"_ None answers _"what does it actually do?"_ as a published, auditable signal.

Assay answers the second question. It reads what is inside an artifact, and optionally **runs it** in a sandbox with a real model and judges what it did — then publishes a report that somebody who does not trust you can check.

curl -fsSL https://raw.githubusercontent.com/metahub-ai/assay/main/install.sh | sh
assay run anthropics/skills//skills/pdf

Contents


Why

The gap is not an oversight. The official MCP Registry [states in writing](https://modelcontextprotocol.io/registry/moderation-policy) that consumers should "assume minimal-to-no moderation," and that it will not remove "low-quality or buggy servers" or "servers with security vulnerabilities." It relies instead on "upstream package registries (like NPM, PyPI, and Docker) or downstream subregistries."

Meanwhile every trust layer the industry does rely on has a dated counterexample.

**Provenance** — `postmark-mcp` shipped 15 clean versions, th