Every AI tool lives on GitHub. Here's how to read it.
Skills, MCP servers, plugins and the agents themselves are all shared as GitHub "repos". You don't need to code to use them, but you do need to read a repo page and tell a solid project from a risky one.
7 README: what it is, how to install, examples…
Seven things on every repo page
- 1Owner / name.
Who publishes it.
microsoft/,github/,anthropics/are the real companies. A random user copying a famous name is a red flag. - 2Stars and forks.
Stars = bookmarks, a rough popularity signal. Forks = people who copied it to modify. Both can be gamed; don't trust them alone.
- 3Last commit.
When code last changed. Months of silence on a fast-moving AI tool usually means abandoned.
- 4Releases.
Stable, numbered versions. Handy to see what changed and how often.
- 5License.
What you're allowed to do. MIT and Apache-2.0 are permissive. No license means no permission.
- 6Issues.
Bug reports and questions. Look at whether maintainers actually answer.
- 7README.
The manual. Install steps are almost always here. If it's vague or pushy, move on.
Can I trust this repo?
Run through this before installing any skill, plugin or MCP server. Skills and servers run on your machine with your logins.
- Official owner, or a known person?
Company orgs and people with a track record beat anonymous accounts.
- Active in the last 1–3 months?
Check the latest commit date and releases.
- Stars growing, not just high?
A steady climb with real issues and discussion is healthier than a sudden spike.
- Clear README and license?
What it does, how to install, what it needs access to.
- Package name matches?
The
npx/pipname in the README should match the repo. Search it on npmjs.com. - Skim the scripts.
For skills: open
SKILL.mdandscripts/. Anything that downloads more code, reads your keys or sends data somewhere unexpected is a no.
Three ways tools get from GitHub to you
1 · Marketplace command
easiestPlugin marketplaces are just GitHub repos. Claude Code pulls them for you.
/plugin marketplace add owner/repo
/plugin install name@marketplace2 · Package runner
MCP serversnpx (Node) and uvx (Python) download and run the published package. The code comes from npm/PyPI, built from the repo.
npx @playwright/mcp@latest3 · Copy the folder
skillsClone (or "Code → Download ZIP") and copy the skill folder into your skills directory.
git clone https://github.com/owner/repo
cp -r repo/skills/x ~/.claude/skills/GitHub words, decoded
- Repository (repo)
- A project folder with its full history.
owner/name. - Clone
- Download a copy of a repo to your computer (
git clone). - Fork
- Your own copy on GitHub, to change without touching the original.
- Commit
- One saved change, with a message and a date.
- Pull request (PR)
- A proposed change to someone's repo, reviewed before it's merged.
- Issue
- A bug report, question or idea. On this site, issues are also how you vote.
- Release / tag
- A named version like
v2.1.0, with notes on what changed. - Actions
- Automation that runs on GitHub's servers. Our news agent is one.
- Star
- A public bookmark. Rough popularity, easy to fake.
- Awesome list
- A README that's just a curated list of links on one topic.
The agents themselves
These ship new versions almost daily. Latest releases, straight from GitHub.
New and rising this month
Repos created in the last 30 days tagged MCP, skills, Claude Code or Codex, sorted by stars. New does not mean safe: run the 60-second check.