stacklok/toolhive-catalog

ToolHive's registry catalog of MCP servers

21Stars on the repository
7Mods indexed here, across every type
4d agoLast push, which is what freshness is scored on
Apache-2.0Licence, which decides whether bodies are shown

add-mcp-server

01

stacklok/toolhive-catalog

Skill Claude CodeCodex

Add new MCP server entries to the ToolHive registry. Creates server.json and icon.svg files with correct schema, meta extensions, and validation. Use when adding a server, creating a registry entry, onboarding an MCP server, or writing server.json. NOT for reviewing existing entries (use mcp-review).

21 4d ago A 66 tokens original Apache-2.0

catalog-audit

02

stacklok/toolhive-catalog

Skill Claude CodeCodex

Audit existing ToolHive catalog server entries for drift: whether the pinned image still exists, the upstream repo is still alive and active, and the declared env vars and network-permission profile still match what the server actually needs. Use whenever asked to audit, health-check, sweep, or spot-check catalog…

21 4d ago A 137 tokens original Apache-2.0

mcp-review

03

stacklok/toolhive-catalog

Skill Claude CodeCodex

Review MCP server specifications and updates for compliance, security, and quality. Use when evaluating server.json files, PRs adding/updating servers, or assessing MCP server changes. NOT for creating new entries (use add-mcp-server instead).

21 4d ago A 51 tokens original Apache-2.0

skill-review

04

stacklok/toolhive-catalog

Skill Claude CodeCodex

Review skill submissions and updates for compliance, security, and quality. Use when evaluating skill.json files, SKILL.md content, PRs adding/updating skills, or assessing skill changes in the ToolHive registry. NOT for reviewing MCP server entries (use mcp-review) or creating new skills (use add-mcp-server).

21 4d ago A 68 tokens original Apache-2.0

ci-agent-hardening

05

stacklok/toolhive-catalog

Skill Claude CodeCodex

Audit and harden GitHub Actions workflows against prompt injection, pullrequesttarget exploits (Pwn Requests), expression injection, cache poisoning, credential theft, and supply chain attacks. Based on Clinejection and hackerbot-claw campaigns. Use when reviewing CI/CD security, securing AI agent workflows, hardening…

21 4d ago A 108 tokens original Apache-2.0