How Favz handles data
Favz counts which MCP servers, skills and plugins people set up in public GitHub repos. These are the rules.
What we keep
Tool names and when they were added or removed, from the git history of agent config files. We never store file contents, environment values, headers, tokens or command arguments. They are dropped while the file is read, before anything is written.
Repos, not people
Pages are about tools and repos. They show no person's name, photo or email. A page about a person exists only if that person claims it.
Getting out
Ask for removal with no proof needed, or put favz: noindex in the
README or agent config. Removed repos are not read again.
Reporting a problem
Every page has a "Report a problem" link at the bottom. We aim to hide anything sensitive within 24 hours.
Claiming a repo
Sign in with GitHub. We ask for no extra permissions. We check once that you can push to the repo, then revoke the token. We keep your GitHub login, the repo and the date.
What the numbers mean
They describe what public repos set up, not whether a tool works. Public repos are a biased sample of all users. A removal can mean a failure, a replacement, a move to private config or a changed need, so we don't say why. Every page says where its numbers come from and when they were built.
The command line tool
npx favz-cli scans on your machine. It sends nothing unless you agree, and it shows you
exactly what it would send first.