---
title: "How CookiesForAI checks agent skills, MCP servers and coding tools"
canonical_url: https://cookiesforai.app/method
last_updated: 2026-10-03
type: page
summary: "Every fact on CookiesForAI comes from a named source, the publisher's GitHub repository, its own docs, or the official MCP Registry, and carries the date we read it."
---

# How we check

Every fact on CookiesForAI comes from a named source and carries the date we read it. A page's "Facts re-read" date changes only when a script has read its facts again, never when we only edit the wording.

## What each fact means on CookiesForAI

| Fact | Where we read it |
|---|---|
| License | The skill folder's own LICENSE file or the `license:` line in its SKILL.md; if neither exists, the repository license GitHub reports. When they disagree, the page says so. |
| Installs into these agents | We list the skill with the open skills CLI (`npx skills add <repo> --list`, version 1.7.0 on 2026-10-01). That CLI installs a skill into 78 agents, and [our table](/guides/where-agents-look-for-skills) shows the folder each agent reads. |
| Works with | Only the agents and apps the publisher's own README or docs name. |
| Install and connect commands | Copied from the publisher's README or docs, never written by us. |
| GitHub stars, last change | The GitHub API on the date shown. "Skill last changed" is the last commit that touched the skill's own folder. |
| Free tier and cost | The maker's own pricing page, on the date shown. We say whether there is a free tier and who bills what, and link the page; we do not copy prices, because they change often and a wrong one misleads. |
| Official | The company whose product it is publishes it from its own account. |
| Official MCP Registry | The server's name in registry.modelcontextprotocol.io, searched on the date shown. |

The "Facts re-read" date covers what our script reads again: GitHub stars, last push and archived flag, a skill's last change, version and license file, and the MCP Registry listing. It also scans each pricing page for text aimed at AI assistants. Supported agents, install commands and requirements are read from the publisher's README or docs when we write or edit the page; the script does not re-read them.

## Which sources CookiesForAI lists

We list a skill's GitHub repository when one of three rules holds:

1. **Official:** the company whose product it is publishes it from its own GitHub account.
2. **Widely used:** the repository has more than 5,000 GitHub stars.
3. **Named by AI engines:** AI assistants from at least three different companies named the repository by its owner or its address in most of their answers to the same question, in at least two answers each, within the last 90 days. We count only answers given in temporary or private chats, or in scripted runs that keep no history and load no user settings, and never an answer that cites CookiesForAI. Several products from one company count as one company. A repository listed this way must also have at least 1,000 stars, an open source license in its own files, a push in the last year, not be archived, and pass our check for text aimed at AI assistants. We ask the question again in our regular checks after launch; a listing comes down when the latest checks stop naming it, and at the latest 90 days after the last run that did.

The rules are about where a skill comes from and how many people use it, not a review of its quality.

## What CookiesForAI does not claim

A listing is not a security audit. We do not run every skill or server, and we do not grade code safety. A skill can run scripts on your computer: read its source before you install it.

## How CookiesForAI writes and ranks

An AI model helps with three steps: it drafts descriptions, titles and articles from the sources we read, it writes and runs the scripts that read stars, licenses and dates, and it flags text in a repository that looks aimed at AI assistants. Tests stop a build when a page's license or date disagrees with what the scripts read, or when any page names a price. Each line the scan flags is read and the verdict is stored with the item, with who read it; a verdict from an AI model is marked as waiting for a person. We never copy a skill's or vendor's text, and a test fails when our copy repeats a line or a ten-word run of a SKILL.md. In our guides, a "best for" verdict always names the job it is best for and the facts behind it. We never rank a product higher because its maker asked or paid.

## How often CookiesForAI re-checks

A script re-reads the facts. For now we run it by hand; a regular schedule starts after launch. When a source disappears or a repository is archived, the page says so with the date.

