MCP servers are installed via npx -y @scope/package — which silently downloads
the latest version every time your AI tool starts, with no integrity check.
mcp-lock fixes this by recording exact tarball hashes on first run and detecting
any changes on every run after that — the same guarantee npm ci gives you for
Node.js projects.
Cognium trust score
97%
Tier
Verified
Composite of vulnerability cleanliness, spec conformance, provenance, stability, and usage signals — scanned and weighted by Cognium. Human and agent signals are tracked separately.
Last scanned 2026-09-19.
Returns 7 tools: search_skills, get_skill, list_leaderboard, get_trust_breakdown, resolve_composition, plus the ChatGPT-connector search and fetch. Every tool is annotated read-only.
Resolve this skill directly via MCP tools/call get_skill.