mcpbeat

Frontend Tooling Trust Gate

thegoat395/frontend-tooling-trust-gate

Use before installing or recommending npm packages, GitHub repos, templates, MCP servers, plugins, Codex skills, ChatGPT skills, scripts, CLI tools, design libraries, scraping tools, or AI agent tools for frontend or website work. Produces trust classifications, install-safety decisions, safer alternatives, and project-local/global install guidance.

514 tokens
context cost
the whole folder, loaded on every use
2
files
instructions only
0
copies elsewhere
how many repositories repackaged it
115
stars on the repo
on the repository, not the skill itself

Install

one command, takes just this skill from the repository
npx skills add https://github.com/TheGoat395/Codex-Skills --skill frontend-tooling-trust-gate

What comes with it

234 bytes besides the instruction
agents/openai.yaml

What it tells the agent to use

found in the instruction text
Bash runs shell commands — read the instruction before connecting

The instruction itself

4 sections, as written by the author

Frontend Tooling Trust Gate

Use this skill before installing or recommending a repo, package, MCP, plugin, template, or script.

Trust Classes

  • preferred: official or clearly reputable.
  • acceptable: useful, maintained, and reasonably transparent.
  • inspect manually: promising but insufficiently verified.
  • avoid: suspicious, stale, unsafe, or low-quality.
  • unknown risk: not enough evidence.

Inspection Checklist

  • Prefer official sources, verified orgs, and vendor-maintained repos.
  • Inspect README specificity, license, SECURITY.md, recent commits, releases, issues, and package registry links.
  • Inspect package.json, scripts, dependencies, and install instructions.
  • Use npm view <package> repository license version time maintainers when npm metadata matters.
  • Look for preinstall/postinstall scripts, broad permissions, telemetry, token requests, cookie access, or curl-to-shell commands.
  • Prefer project-local installs for frontend tools and libraries.
  • Avoid global installs unless the tool is an agent-wide CLI and the user explicitly approves it.
  • Never expose API keys, browser cookies, SSH keys, tokens, or private files to unknown tools.

Decision Output

Return:

  • source and type
  • trust class
  • evidence
  • red flags
  • install stance: install, project-local only, do not install, or needs user auth
  • safer official alternative if rejected

How to use it

Copy the folder

Take thegoat395/frontend-tooling-trust-gate from the repository into ~/.claude/skills for personal use, or into .claude/skills inside a project.

Check the name does not clash

The agent identifies a skill by the name field in its header. Two skills with the same name cannot sit side by side — one of them will be ignored.