The safety standard for AI skills
Like UL for electronics, MFKVault Verified is an open assessment that tells developers what they're installing into their AI assistant. Five pillars, automated weekly, free to inspect.
License verification
Every skill's source license is parsed and recorded. Skills without a discoverable OSS-compatible license are flagged.
Safety scanning
Static checks for known dangerous patterns. Source URL must resolve. No obfuscated payloads or remote code execution shims.
Compatibility testing
Per-agent install commands generated for Claude, Cursor, Codex, Windsurf. Manifests linted before publication.
Quality assessment
Five-signal score (source resolves Β· skill.md exists Β· content non-trivial Β· install command works Β· description specific) recomputed weekly.
Continuous monitoring
Weekly cron rescans every approved skill. Failures demote to /unverified within 24h.
What "Verified" does and doesn't mean
- Passed automated MFKVault scans
- License discoverable in source
- Source URL resolves at last check
- Install command syntax is valid
- Bug-free / production-ready
- Endorsed by Anthropic / Cursor / OpenAI / Codeium
- Audited line-by-line
- Always safe β verify independently
References to UL, ISO, and SOC 2 are comparison only. MFKVault is not affiliated with or endorsed by those bodies. Use verified skills at your own risk.