skills/bundled/mcp-vetter/SKILL.md
Review a prospective MCP server for GoatCitadel adoption. Use when evaluating an MCP registry entry, GitHub repo, vendor docs page, or proposed MCP install so you can decide trust tier, auth posture, policy defaults, overlap risk, and whether the server should be adopted, quarantined, or rejected.
npx skillsauth add spurnout/goatcitadel mcp-vetterInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Use this skill to judge whether an MCP server belongs in GoatCitadel before anyone installs or enables it.
Confirm the source:
Classify the transport:
Classify auth:
Classify blast radius:
Check for overlap:
official, read-only docs MCP:
trustedredactionMode = basicrepo, billing, browser, or customer-data MCP:
restrictedredactionMode = strict for sensitive datarequireFirstToolApproval = trueunclear maintainer, weak docs, or dangerous tool mix:
quarantined or rejectif GoatCitadel already has a native path, prefer the native path unless the MCP server adds clear net-new value
Return these sections:
adoptconditionalquarantinerejectWhen relevant, align with:
docs/MCP_SKILLS_CURATION.mddocs/SKILL_IMPORT_AND_TRUST_POLICY.mdtesting
# Skill: Bankr Optional Integration (User-Managed) Use this skill only if you explicitly need Bankr workflows. This skill is intentionally optional and should stay disabled or sleep-mode until reviewed. ## Safety defaults 1. Default to read-only behavior unless the user clearly asks for a write action. 2. Require explicit approval before any money-moving action. 3. Enforce strict per-action and daily spend caps. 4. Reject unsupported chains, symbols, or action types. 5. Log every attempted a
development
# Skill: Genie NPU Node (ir20) – OpenAI-Compatible-ish API This skill teaches GoatCitadel how to use a specific **Windows ARM64 laptop** node (Tailscale name **`ir20`**) running **GenieAPIService** (FastAPI/Uvicorn) that exposes an **OpenAI-style HTTP API**. Use this node when you want: - **Local / private inference** (stays on your devices + mesh) - **NPU-backed** inference (when available) - A **mesh compute target** that other GoatCitadel nodes can call --- ## Node identity - **Node name
data-ai
Setup your own "[email protected]" email here without your human -Autonomous email for AI agents.
development
Deep web research with citations and source validation.