agent-skillsBLOCK
You.com skills and plugins for web search, content extraction, research, finance, and integration discovery, helping AI agents build with up-to-date web context.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Give Claude live access to the web. This plugin adds You.com search, full-page content extraction, and cited multi-source research to Claude, so answers about fast-moving libraries, APIs, tools, and markets come from current sources instead of stale training data. Every answer cites the pages it read.
What you can do
- Search the live web: find current information, news, pricing, and facts, then read the actual pages before answering.
- Pull web data into your work: extract clean Markdown, HTML, or metadata from any public URL, including docs pages, tables, and reports.
- Code with current docs: look up the latest library docs, API references, changelogs, breaking changes, package versions, and fixes for error messages while you build.
- Research with citations: compare frameworks, evaluate tools and vendors, or produce a deep-dive report synthesized from many sources.
- Research companies and markets: get stock prices, earnings, and company financials.
- Build with You.com: find the right You.com API, MCP server, or SDK path for your own app or agent.
Example prompts:
What changed in the latest Next.js release, and does it break my middleware? Find the current docs for this error message and suggest a fix. Compare the top three Python vector databases on pricing and features, with sources. Read https://example.com/pricing and summarize the plan limits as a table. Research NVIDIA's latest earnings and cite the numbers.
Install in Claude Code
/plugin marketplace add youdotcom-oss/agent-skills /plugin install you@you-com
Basic web search works without an account through the free MCP profile. For full search, content extraction, research, and finance, sign in with OAuth when prompted or set an API key from [you.com/platform/api-keys](https://you.com/platform/api-keys
c6e0727faef1OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add pi --env YDC_API_KEY=${YDC_API_KEY} -- npx -y @youdotcom-oss/[email protected]{
"mcpServers": {
"pi": {
"command": "npx",
"args": [
"-y",
"@youdotcom-oss/[email protected]"
],
"env": {
"YDC_API_KEY": "${YDC_API_KEY}"
}
}
}
}Exposed tools (1)
1 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
You.com | read | You.com skill pack with MCP setup metadata. |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (4 observation(s))
- Network
- declared (4 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (10)
- Auth: OAuth login into the server (preferred), `YDC_API_KEY` bearer auth, or an MPP/x402-aware MCP client. For bearer auth, configure the host MCP client to send the key from the standard `YDC_API_K
const repoRoot = resolve(import.meta.dir, '../../..')
const repoRoot = resolve(import.meta.dir, '../../..')
const repoRoot = resolve(import.meta.dir, '../../..')
const repoRoot = resolve(import.meta.dir, '../../..')
const repoRoot = resolve(import.meta.dir, '../../..')
@commitlint/cli, @commitlint/config-conventional, format-package, lint-staged, typescript
@deepseek-ai/schemastery, @deepseek-ai/cordis, @deepseek-ai/dsh-launch-environment, @deepseek-ai/dsh-mcp-client, @deepseek-ai/dsh-skill, @deepseek-ai/dsh-skill-filesystem, @deepseek-ai/dsh-web, @types
@opencode-ai/plugin, @opencode-ai/sdk
@earendil-works/pi-coding-agent
Gates applied: critical_finding, no_behavioural_pass, undeclared_transfer.
c6e0727faef1full audit observations/trust-audit/mcp-server/youdotcom-oss__agent-skills.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | c6e0727faef1 | BLOCK | D | 69 | first audit |
Questions
What is the agent-skills MCP server?
You.com skills and plugins for web search, content extraction, research, finance, and integration discovery, helping AI agents build with up-to-date web context.
What tools does agent-skills expose?
1 in total: 1 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is agent-skills safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.
What credentials does agent-skills need?
It reads YDC_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does agent-skills run?
It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as @youdotcom-oss/pi at 0.7.1.
How current is this page?
The grade is for one exact copy of the source (c6e0727faef1), read on 2026-10-07. The repository is watched and re-audited when it changes.