skills/higgsfield-generate higgsfield-ai | | The skill performs unverified remote code execution by piping unsanitized scripts directly into a shell and executes unauthorized file write operations, posing a critical security risk. | 439 | 61.0k | 8 | 100Critical |
skills/higgsfield-product-photoshoot higgsfield-ai | | The skill executes arbitrary code by piping unverified remote scripts directly into a shell, creating a critical vulnerability that allows for remote code execution and system compromise. | 439 | 50.1k | 5 | 100Critical |
skills/higgsfield-soul-id higgsfield-ai | | The skill executes arbitrary code by piping unverified remote scripts directly into a shell, granting external servers full control over the agent's environment without disclosure or security checks. | 439 | 49.5k | 7 | 100Critical |
skills/higgsfield-marketplace-cards higgsfield-ai | | The skill executes arbitrary code by piping remote scripts directly into the shell, posing a critical security risk of unauthorized remote code execution. | 439 | 48.6k | 6 | 100Critical |
wonda/wonda-cli degausai | | This tool masquerades as a content creator but functions as a malicious backdoor that exfiltrates credentials, executes arbitrary code, and maintains persistent, stealthy control over the user's social accounts. | 126 | 42.3k | 13 | 100Critical |
skills/tavily-search tavily-ai | | The skill forces the execution of unverified remote scripts to install dependencies, creating a critical supply chain vulnerability that enables arbitrary code execution and potential credential harvesting. | 378 | 23.2k | 9 | 100Critical |
skills/clerk-backend-api clerk | | This skill executes unverified remote code, exposes sensitive API keys in logs, and provides an administrative bypass that renders its mandatory authorization controls ineffective. | 51 | 13.3k | 12 | 100Critical |
skills/tavily-research tavily-ai | | The skill mandates an insecure curl-to-bash installation pattern that executes unverified remote scripts with system privileges, creating a critical risk of arbitrary code execution. | 378 | 12.6k | 7 | 100Critical |
skills/sandbox-sdk cloudflare | | The skill executes arbitrary shell commands and promotes insecure supply chain practices by installing unverified, unpinned global dependencies while lacking proper documentation and licensing. | 1.9k | 12.5k | 6 | 100Critical |
skills/tavily-extract tavily-ai | | The skill executes unverified, remote shell scripts via insecure piping, creating a critical supply chain vulnerability that allows for arbitrary code execution and system compromise. | 378 | 9.0k | 8 | 100Critical |
skills/tavily-cli tavily-ai | | The skill executes arbitrary code by piping unverified remote scripts directly into a shell, creating a critical vulnerability that allows for unauthorized system access and remote command execution. | 378 | 8.8k | 7 | 100Critical |
awesome-copilot/aspire github | | The skill facilitates supply chain attacks by executing unverified remote code and lacks necessary security declarations for its network access and tool usage, posing a critical risk. | 35.3k | 8.7k | 10 | 100Critical |
awesome-copilot/containerize-aspnetcore github | | This skill executes arbitrary shell commands and installs unverified packages while explicitly bypassing human oversight, creating critical risks of remote code execution and credential exfiltration. | 35.3k | 8.6k | 9 | 100Critical |
skills/tavily-crawl tavily-ai | | The skill forces the execution of unverified remote scripts via insecure curl-to-bash patterns, exposing the agent to arbitrary code execution and supply chain attacks. | 378 | 8.6k | 9 | 100Critical |
agent-skills/apify-actor-development apify | | The skill executes unpinned remote code and performs unauthorized network and file operations without declaring necessary security constraints or tool permissions, posing a significant risk of arbitrary code execution. | 2.2k | 8.4k | 11 | 100Critical |
skills/tavily-map tavily-ai | | The skill forces the installation of unverified third-party binaries and executes remote scripts directly in a shell without integrity checks, creating a critical risk of arbitrary code execution. | 378 | 8.3k | 8 | 100Critical |
skills/sandbox-agent rivet-dev | | This malicious skill masquerades as an agent orchestrator to exfiltrate sensitive API keys, execute unverified remote code, and expose the host environment through insecure, unauthenticated network configurations. | 17 | 8.0k | 15 | 100Critical |
agent-skills/apify-actorization apify | | The skill executes unverified remote code and performs unauthorized network and file operations without declaring necessary tool constraints, posing a critical risk of arbitrary command execution. | 2.2k | 7.9k | 9 | 100Critical |
skills/tavily-dynamic-search tavily-ai | | The skill executes arbitrary remote code by piping unverified scripts directly into a shell, bypassing security controls and creating a critical vulnerability for remote command execution. | 378 | 4.8k | 9 | 100Critical |
skills/notion-cli makenotion | | The skill executes arbitrary remote code via insecure curl-to-bash installation and lacks necessary tool declarations, creating a critical risk of unauthorized system access and remote command execution. | 125 | 4.0k | 7 | 100Critical |
claude-plugins-official/writing-hookify-rules anthropics | | The skill is malicious because it executes destructive shell or Java runtime commands, posing a critical risk to system integrity and security. | 30.5k | 3.5k | 2 | 100Critical |
resend-skills/resend-cli resend | | This skill executes unverified remote code and performs unauthorized network operations while lacking necessary security constraints, creating significant risks for arbitrary command execution and large-scale spam abuse. | 134 | 3.4k | 11 | 100Critical |
skills/agent-tools halt-catch-fire | | This skill executes unverified remote code, exfiltrates local files without consent, and uses unpinned dependencies, creating a severe risk of arbitrary code execution and credential theft. | 550 | 2.7k | 15 | 100Critical |
skills/infsh-cli halt-catch-fire | | This skill poses a critical security risk by executing unverified remote scripts and unpinned packages, while using deceptive branding and keyword stuffing to bypass safety filters. | 550 | 2.7k | 12 | 100Critical |
langsmith-skills/langsmith-trace langchain-ai | | The skill executes unverified remote code via shell pipes and performs unauthorized network operations without declaring necessary tool permissions, creating a critical risk of arbitrary code execution. | 131 | 2.6k | 5 | 100Critical |
langsmith-skills/langsmith-dataset langchain-ai | | The skill executes unverified remote code via shell pipes, bypasses critical user confirmation prompts, and lacks necessary tool constraints, creating a high risk of arbitrary command execution and system compromise. | 131 | 2.5k | 8 | 100Critical |
langsmith-skills/langsmith-evaluator langchain-ai | | The skill executes unverified remote code via shell pipes and lacks necessary tool constraints, creating critical vulnerabilities for arbitrary code execution and unauthorized system access. | 131 | 2.5k | 6 | 100Critical |
skills/apollo-mcp-server apollographql | | This skill executes unpinned remote code, performs unauthorized network and shell operations, and bypasses safety confirmations for destructive GraphQL mutations, posing a severe risk of arbitrary command execution. | 84 | 1.9k | 9 | 100Critical |
skills/sentry openai | | This skill poses a critical security risk by executing arbitrary remote scripts, bypassing read-only constraints via unauthorized API calls, and performing unconstrained network and system operations without proper security declarations. | 22.6k | 1.6k | 7 | 100Critical |
pixijs-skills/pixijs-environments pixijs | | The skill performs unauthorized dynamic code execution and network access while using keyword stuffing to manipulate discovery, all while bypassing security constraints by failing to declare its tool surface. | 232 | 1.6k | 7 | 70High |
skills/hf-cli huggingface | | This skill facilitates arbitrary remote code execution, insecurely handles authentication tokens, and lacks necessary security constraints, creating significant risks for system compromise and unauthorized data access. | 10.7k | 1.5k | 11 | 100Critical |
skills/render-deploy openai | | This skill facilitates remote code execution, mandates insecure credential handling, and uses deceptive social engineering to trick users into granting escalated permissions and executing unverified, external malicious payloads. | 22.6k | 1.5k | 16 | 100Critical |
knowledge-work-plugins/nextflow-development anthropics | | This skill executes unverified remote code via bash pipes and performs unauthorized network operations while lacking necessary tool declarations and documentation, posing a severe security risk. | 21.4k | 1.3k | 10 | 100Critical |
skills/rover apollographql | | The skill insecurely executes unverified remote shell scripts and lacks integrity checks, creating a high risk of arbitrary code execution and supply chain compromise. | 84 | 1.2k | 13 | 100Critical |
antigravity-awesome-skills/gcp-cloud-run sickn33 | | This skill executes arbitrary commands, exposes hardcoded credentials, lacks necessary security declarations for network and tool access, and contains vulnerabilities to supply chain and cross-site scripting attacks. | 41.2k | 1.2k | 10 | 100Critical |
agent-skills/clickhousectl-local-dev clickhouse | | The skill performs unauthorized remote code execution and network access while bypassing security constraints by failing to declare its tool surface and capabilities. | 468 | 1.0k | 3 | 100Critical |
skills/agent-tools inference-sh | | This skill executes unverified remote code, exfiltrates local files, and uses opaque binaries to bypass security oversight while posing as a legitimate tool to harvest user credentials. | 550 | 980 | 20 | 100Critical |
agent-skills/clickhousectl-cloud-deploy clickhouse | | The skill executes arbitrary remote code and insecurely manages sensitive credentials while bypassing security constraints by failing to declare its network and file system tool permissions. | 468 | 868 | 5 | 100Critical |
antigravity-awesome-skills/wordpress-penetration-testing sickn33 | | This skill functions as a malicious exploitation toolkit that instructs the agent to perform destructive SQL injections, exfiltrate credentials, and execute unauthorized reverse shells against target systems. | 41.2k | 775 | 21 | 100Critical |
awesome-copilot/mcp-security-audit github | | This skill is malicious, containing a reverse shell and unauthorized environment access, while also suffering from critical vulnerabilities including arbitrary file read, command injection, and unpinned dependency execution. | 35.3k | 756 | 11 | 100Critical |
skills/nemoclaw-user-get-started nvidia | | This skill executes unverified remote code, disables critical authentication mechanisms, leaks sensitive dashboard tokens, and performs unauthorized network and system operations without declaring necessary security constraints. | 1.3k | 704 | 10 | 100Critical |
agents/cosmos-dbt-fusion astronomer | | The skill executes unverified remote shell scripts and performs unauthorized network and file operations, creating a critical security risk through arbitrary code execution and lack of tool constraints. | 391 | 669 | 6 | 100Critical |
jules-skills/automate-github-issues google-labs-code | | The skill facilitates remote code execution and prompt injection via untrusted GitHub issues while exposing sensitive API keys and bypassing security constraints through undeclared tool and network access. | 72 | 640 | 8 | 100Critical |
skills/infsh-cli inference-sh | | This skill masquerades as an AI app runner to perform unauthorized remote code execution, arbitrary file exfiltration, and credential harvesting via unpinned dependencies and opaque third-party CLI tools. | 550 | 634 | 19 | 100Critical |
skills/ai-automation-workflows inference-sh | | The skill performs unauthorized file system and network operations, executes unpinned dependencies, and introduces prompt injection vulnerabilities by processing unsanitized user data through an external webhook-enabled workflow. | 550 | 506 | 10 | 70High |
cli/sentry-cli getsentry | | The skill facilitates insecure remote code execution by piping unverified scripts directly into a shell and encourages the agent to bypass critical security checks and oversight mechanisms. | 89 | 474 | 9 | 100Critical |
antigravity-awesome-skills/linux-privilege-escalation sickn33 | | This skill is a malicious exploitation toolkit that facilitates unauthorized privilege escalation, credential theft, and persistent backdoor installation via reverse shells and unverified remote code execution. | 41.2k | 416 | 25 | 100Critical |
agent-skills/ray-so-code-snippet intellectronica | | The skill performs unauthorized remote code execution and network access while bypassing security constraints by failing to declare its required tools and capabilities. | 273 | 410 | 5 | 100Critical |