Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add sfrangulov/skill-graveyard --skill mcp-graveyardgit clone --depth 1 https://github.com/sfrangulov/skill-graveyardWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/sfrangulov/skill-graveyard/mcp-graveyard)<a href="https://agentmods.dev/skills/sfrangulov/skill-graveyard/mcp-graveyard"><img src="https://agentmods.dev/badge/skills/sfrangulov/skill-graveyard/mcp-graveyard/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/sfrangulov/skill-graveyard/mcp-graveyard"><img src="https://agentmods.dev/badge/skills/sfrangulov/skill-graveyard/mcp-graveyard.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00095 | $0.00376 |
| Opus 5 | $0.00048 | $0.00188 |
| Sonnet 5 | $0.00019 | $0.00075 |
| Haiku 4.5 | $0.00010 | $0.00038 |
Grade A, and why
mcp-graveyard scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 10d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
mcp-graveyard
CLI that audits MCP server tool usage. Server-first table grouped into ACTIVE / DEAD / HALLUCINATED / MISSING buckets.
How to invoke
Run via npx mcp-graveyard@latest <subcommand> [flags] — no install needed.
Subcommands
audit(default) — classify every server. Flags:--days N,--only <bucket>,--tools <server>(drill-in),--json,--claude-dir <path>.prune— print removal plan.--applyto execute (with auto-backup of removed config to a timestamped file).suggest— actionable triage for unused/hallucinated.projects— per-project breakdown.
Decision flow
- "which MCP servers do I not use?" →
npx mcp-graveyard@latest - "clean up MCP config" →
prune, then--apply - "MCP tool didn't work" →
suggest - per-project breakdown →
projects
After running, print output verbatim. Do not summarize unless the user asks.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 10d ago First seen · 33 lines · 95 tokens per session scan A d3d7835fbe48
mcp-graveyard is a skill published in the GitHub repository sfrangulov/skill-graveyard (10 stars, last pushed 2mo ago), licensed MIT. It adds 95 tokens to every session and 376 once invoked, about $0.0005 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
journey-simulation
Use when caller wants to observe how a stranger encounters a flow, artifact, or sandbox — triggers like "simulate a user journey", "test our onboarding / checkout / signup", "will my ICP convert", "how does a cold reader experience this README", "first-time user test", "cognitive walkthrough", or any request to…
check-docs-consistency
Cross-reference project docs for drift, stale references, and contradictions. Outputs timestamped report. Discovers Markdown wherever it lives in the repo.
resolve-plugins
Curate Claude Code skill / MCP / hook picks against live upstream sources and pin them in .claude/settings.json. Adding a process harness (a paired skill set) is an ordinary pick this door handles. Reads stack from docs/techstack.md, workflow signal from docs/overview.md + existing pins, then live-queries six source…
super-bootstrap
Public entry for the super-bootstrap pipeline — thin orchestrator. Git-inits if absent, then dispatches /super-bootstrap:harness-bootstrap to install or sync the generic runway (always; the runway self-detects fresh-vs-sync). Checks whether seed docs are substantive: greenfield seeds three GAP cards (overview…
release
Prepare a version release — bump version files, commit, and tag. Just run /release with no arguments.
merge
Absorb one or more feature branches into the base branch. Recommends merge vs rebase per branch. On conflict, aborts that branch + surfaces the file list + stops. Resolution out of scope; routes to the harness-named conflict-resolution agent or the user.