GitHub 101

Every AI tool lives on GitHub. Here's how to read it.

Skills, MCP servers, plugins and the agents themselves are all shared as GitHub "repos". You don't need to code to use them, but you do need to read a repo page and tell a solid project from a risky one.

1microsoft / playwright-mcp 2 37.7k 3.1k
src3 2 hours ago
README.mdlast week
LICENSEApache-2.0 5
package.json2 hours ago
4Releases · v0.0.626Issues 38

7 README: what it is, how to install, examples…

Anatomy of a repo

Seven things on every repo page

  1. 1
    Owner / name.

    Who publishes it. microsoft/, github/, anthropics/ are the real companies. A random user copying a famous name is a red flag.

  2. 2
    Stars and forks.

    Stars = bookmarks, a rough popularity signal. Forks = people who copied it to modify. Both can be gamed; don't trust them alone.

  3. 3
    Last commit.

    When code last changed. Months of silence on a fast-moving AI tool usually means abandoned.

  4. 4
    Releases.

    Stable, numbered versions. Handy to see what changed and how often.

  5. 5
    License.

    What you're allowed to do. MIT and Apache-2.0 are permissive. No license means no permission.

  6. 6
    Issues.

    Bug reports and questions. Look at whether maintainers actually answer.

  7. 7
    README.

    The manual. Install steps are almost always here. If it's vague or pushy, move on.

60-second check

Can I trust this repo?

Run through this before installing any skill, plugin or MCP server. Skills and servers run on your machine with your logins.

Copycats exist. Fake repos with a near-identical name ("playwrigth-mcp") or a package that doesn't match the README. Always start from the official link on the company's site or from a trusted list.
  • Official owner, or a known person?

    Company orgs and people with a track record beat anonymous accounts.

  • Active in the last 1–3 months?

    Check the latest commit date and releases.

  • Stars growing, not just high?

    A steady climb with real issues and discussion is healthier than a sudden spike.

  • Clear README and license?

    What it does, how to install, what it needs access to.

  • Package name matches?

    The npx / pip name in the README should match the repo. Search it on npmjs.com.

  • Skim the scripts.

    For skills: open SKILL.md and scripts/. Anything that downloads more code, reads your keys or sends data somewhere unexpected is a no.

Installing from GitHub

Three ways tools get from GitHub to you

1 · Marketplace command

easiest

Plugin marketplaces are just GitHub repos. Claude Code pulls them for you.

Claude Code
/plugin marketplace add owner/repo
/plugin install name@marketplace

2 · Package runner

MCP servers

npx (Node) and uvx (Python) download and run the published package. The code comes from npm/PyPI, built from the repo.

what your app runs
npx @playwright/mcp@latest

3 · Copy the folder

skills

Clone (or "Code → Download ZIP") and copy the skill folder into your skills directory.

Terminal
git clone https://github.com/owner/repo
cp -r repo/skills/x ~/.claude/skills/
Vocabulary

GitHub words, decoded

Repository (repo)
A project folder with its full history. owner/name.
Clone
Download a copy of a repo to your computer (git clone).
Fork
Your own copy on GitHub, to change without touching the original.
Commit
One saved change, with a message and a date.
Pull request (PR)
A proposed change to someone's repo, reviewed before it's merged.
Issue
A bug report, question or idea. On this site, issues are also how you vote.
Release / tag
A named version like v2.1.0, with notes on what changed.
Actions
Automation that runs on GitHub's servers. Our news agent is one.
Star
A public bookmark. Rough popularity, easy to fake.
Awesome list
A README that's just a curated list of links on one topic.
Watched by our agent

The agents themselves

These ship new versions almost daily. Latest releases, straight from GitHub.