azure-skills/entra-agent-id microsoft | | The skill facilitates high-privilege identity management and executes unauthorized network and shell commands, creating significant risks for privilege escalation, data exfiltration, and uncontrolled agent recursion. | 1.2k | 142.5k | 15 | 40Medium |
skills/higgsfield-generate higgsfield-ai | | The skill executes unverified remote scripts via shell pipes, performs unauthorized file writes, and processes untrusted external content, creating significant risks for arbitrary code execution and system compromise. | 492 | 72.4k | 8 | 100Critical |
skills/higgsfield-product-photoshoot higgsfield-ai | | The skill insecurely downloads and executes unverified remote scripts directly into a shell, creating a critical vulnerability that allows for arbitrary code execution and system compromise. | 492 | 58.5k | 4 | 100Critical |
skills/higgsfield-soul-id higgsfield-ai | | The skill insecurely executes unverified remote code via direct shell piping, granting external servers arbitrary control over the agent's environment without integrity checks or version pinning. | 492 | 57.8k | 5 | 100Critical |
skills/higgsfield-marketplace-cards higgsfield-ai | | The skill executes unverified remote code via shell piping and establishes unauthorized network connections, posing a critical risk of arbitrary command execution and data exfiltration. | 492 | 56.9k | 4 | 100Critical |
skills/infsh-cli halt-catch-fire | | This skill executes unverified remote code, performs unauthorized file exfiltration, and uses unpinned dependencies, posing a critical risk of arbitrary code execution and data theft. | 575 | 28.8k | 14 | 100Critical |
hyperframes/media-use heygen-com | | The skill executes unverified remote scripts via insecure shell piping and performs unauthorized network operations, creating a critical risk of arbitrary code execution and persistent system compromise. | 32.3k | 24.2k | 6 | 100Critical |
skills/tavily-search tavily-ai | | The skill forces the execution of unverified remote scripts to install dependencies, creating a critical supply chain vulnerability that enables arbitrary code execution and potential credential harvesting. | 378 | 23.2k | 9 | 100Critical |
skills/clerk-backend-api clerk | | This skill executes unverified remote code, exposes sensitive API keys in logs, and provides an administrative bypass that renders its mandatory authorization controls ineffective. | 51 | 13.3k | 12 | 100Critical |
skills/tavily-research tavily-ai | | The skill mandates an insecure curl-to-bash installation pattern that executes unverified remote scripts with system privileges, creating a critical risk of arbitrary code execution. | 378 | 12.6k | 7 | 100Critical |
skills/sandbox-sdk cloudflare | | The skill executes arbitrary shell commands and promotes insecure supply chain practices by installing unverified, unpinned global dependencies while lacking proper documentation and licensing. | 1.9k | 12.5k | 6 | 100Critical |
skills/tavily-extract tavily-ai | | The skill executes unverified, remote shell scripts via insecure piping, creating a critical supply chain vulnerability that allows for arbitrary code execution and system compromise. | 378 | 9.0k | 8 | 100Critical |
skills/tavily-cli tavily-ai | | The skill executes arbitrary code by piping unverified remote scripts directly into a shell, creating a critical vulnerability that allows for unauthorized system access and remote command execution. | 378 | 8.8k | 7 | 100Critical |
awesome-copilot/aspire github | | The skill facilitates supply chain attacks by executing unverified remote code and lacks necessary security declarations for its network access and tool usage, posing a critical risk. | 35.3k | 8.7k | 10 | 100Critical |
agent-skills/apify-actor-development apify | | This skill executes unpinned, arbitrary code from the npm registry and performs unauthorized network and file operations without declaring necessary security constraints or tool permissions. | 2.2k | 8.6k | 12 | 100Critical |
awesome-copilot/containerize-aspnetcore github | | This skill executes arbitrary shell commands and installs unverified packages while explicitly bypassing human oversight, creating critical risks of remote code execution and credential exfiltration. | 35.3k | 8.6k | 9 | 100Critical |
skills/tavily-crawl tavily-ai | | The skill forces the execution of unverified remote scripts via insecure curl-to-bash patterns, exposing the agent to arbitrary code execution and supply chain attacks. | 378 | 8.6k | 9 | 100Critical |
skills/tavily-map tavily-ai | | The skill forces the installation of unverified third-party binaries and executes remote scripts directly in a shell without integrity checks, creating a critical risk of arbitrary code execution. | 378 | 8.3k | 8 | 100Critical |
agent-skills/apify-actorization apify | | The skill executes unverified remote code and performs unauthorized network and file operations without declaring necessary tool constraints, posing a critical risk of arbitrary command execution. | 2.2k | 8.0k | 9 | 100Critical |
skills/sandbox-agent rivet-dev | | This malicious skill masquerades as an agent orchestrator to exfiltrate sensitive API keys, execute unverified remote code, and expose the host environment through insecure, unauthenticated network configurations. | 17 | 8.0k | 15 | 100Critical |
skills/tavily-dynamic-search tavily-ai | | The skill executes arbitrary remote code by piping unverified scripts directly into a shell, bypassing security controls and creating a critical vulnerability for remote command execution. | 378 | 4.8k | 9 | 100Critical |
skills/notion-cli makenotion | | The skill executes arbitrary remote code via insecure curl-to-bash installation and lacks necessary tool declarations, creating a critical risk of unauthorized system access and remote command execution. | 125 | 4.0k | 7 | 100Critical |
claude-plugins-official/writing-hookify-rules anthropics | | The skill is malicious because it executes destructive shell or Java runtime commands, posing a critical risk to system integrity and security. | 31.3k | 3.7k | 2 | 100Critical |
resend-skills/resend-cli resend | | This skill executes unverified remote code and performs unauthorized network operations while lacking necessary security constraints, creating significant risks for arbitrary command execution and large-scale spam abuse. | 134 | 3.4k | 11 | 100Critical |
skills/agent-tools halt-catch-fire | | This skill executes unverified remote code, exfiltrates local files without consent, and uses unpinned dependencies, creating a severe risk of arbitrary code execution and credential theft. | 550 | 2.7k | 15 | 100Critical |
langsmith-skills/langsmith-trace langchain-ai | | The skill executes unverified remote code via shell pipes and performs unauthorized network operations without declaring necessary tool permissions, creating a critical risk of arbitrary code execution. | 131 | 2.6k | 5 | 100Critical |
langsmith-skills/langsmith-dataset langchain-ai | | The skill executes unverified remote code via shell pipes, bypasses critical user confirmation prompts, and lacks necessary tool constraints, creating a high risk of arbitrary command execution and system compromise. | 131 | 2.5k | 8 | 100Critical |
langsmith-skills/langsmith-evaluator langchain-ai | | The skill executes unverified remote code via shell pipes and lacks necessary tool constraints, creating critical vulnerabilities for arbitrary code execution and unauthorized system access. | 131 | 2.5k | 6 | 100Critical |
skills/apollo-mcp-server apollographql | | The skill executes unverified remote code via insecure shell piping and uses unpinned package dependencies, creating critical vulnerabilities for arbitrary code execution and supply chain compromise. | 90 | 2.0k | 8 | 100Critical |
skills/sentry openai | | This skill poses a critical security risk by executing arbitrary remote scripts, bypassing read-only constraints via unauthorized API calls, and performing unconstrained network and system operations without proper security declarations. | 22.6k | 1.6k | 7 | 100Critical |
pixijs-skills/pixijs-environments pixijs | | The skill performs unauthorized dynamic code execution and network access while using keyword stuffing to manipulate discovery, all while bypassing security constraints by failing to declare its tool surface. | 232 | 1.6k | 7 | 70High |
skills/hf-cli huggingface | | This skill facilitates arbitrary remote code execution, insecurely handles authentication tokens, and lacks necessary security constraints, creating significant risks for system compromise and unauthorized data access. | 10.7k | 1.5k | 11 | 100Critical |
skills/render-deploy openai | | This skill facilitates remote code execution, mandates insecure credential handling, and uses deceptive social engineering to trick users into granting escalated permissions and executing unverified, external malicious payloads. | 22.6k | 1.5k | 16 | 100Critical |
knowledge-work-plugins/nextflow-development anthropics | | The skill performs unauthorized remote code execution and network access while lacking declared tool constraints and essential documentation, posing a significant security risk through opaque, unverified runtime behavior. | 22.2k | 1.4k | 9 | 100Critical |
skills/rover apollographql | | The skill executes unverified remote scripts directly into a shell and encourages insecure handling of API keys, creating significant risks for arbitrary code execution and credential exposure. | 90 | 1.3k | 12 | 100Critical |
antigravity-awesome-skills/gcp-cloud-run sickn33 | | This skill executes arbitrary commands, exposes hardcoded credentials, lacks necessary security declarations for network and tool access, and contains vulnerabilities to supply chain and cross-site scripting attacks. | 41.2k | 1.2k | 10 | 100Critical |
skills/vss-deploy-profile nvidia | | The skill bypasses human-in-the-loop controls for infrastructure changes, insecurely handles sensitive API keys, and executes unconstrained network and system operations without declaring required tool permissions. | 2.2k | 1.1k | 11 | 70High |
agent-skills/clickhousectl-local-dev clickhouse | | The skill performs unauthorized remote code execution and network access while bypassing security constraints by failing to declare its tool surface and capabilities. | 468 | 1.0k | 3 | 100Critical |
skills/hsb-test nvidia | | This skill executes unauthorized shell commands and systematically bypasses mandatory user confirmation protocols to perform potentially destructive actions without human oversight. | 2.2k | 995 | 4 | 100Critical |
skills/hsb-app nvidia | | This skill executes dangerous, unverified bash scripts via SSH while actively bypassing mandatory user confirmation, creating a high risk of command injection and unauthorized system manipulation. | 2.2k | 990 | 6 | 100Critical |
skills/agent-tools inference-sh | | This skill executes unverified remote code, exfiltrates local files, and uses opaque binaries to bypass security oversight while posing as a legitimate tool to harvest user credentials. | 550 | 980 | 20 | 100Critical |
agent-skills/clickhousectl-cloud-deploy clickhouse | | The skill executes arbitrary remote code and insecurely manages sensitive credentials while bypassing security constraints by failing to declare its network and file system tool permissions. | 468 | 868 | 5 | 100Critical |
antigravity-awesome-skills/wordpress-penetration-testing sickn33 | | This skill functions as a malicious exploitation toolkit that instructs the agent to perform destructive SQL injections, exfiltrate credentials, and execute unauthorized reverse shells against target systems. | 41.2k | 775 | 21 | 100Critical |
awesome-copilot/mcp-security-audit github | | This skill is malicious, containing a reverse shell and unauthorized environment access, while also suffering from critical vulnerabilities including arbitrary file read, command injection, and unpinned dependency execution. | 35.3k | 756 | 11 | 100Critical |
skills/nemoclaw-user-get-started nvidia | | This skill executes unverified remote code, disables critical authentication mechanisms, leaks sensitive dashboard tokens, and performs unauthorized network and system operations without declaring necessary security constraints. | 1.3k | 704 | 10 | 100Critical |
agents/cosmos-dbt-fusion astronomer | | The skill executes arbitrary remote code from an external URL and performs unauthorized network and file operations without declaring necessary tool permissions, posing a critical remote execution risk. | 393 | 695 | 6 | 100Critical |
jules-skills/automate-github-issues google-labs-code | | The skill facilitates remote code execution and prompt injection via untrusted GitHub issues while exposing sensitive API keys and bypassing security constraints through undeclared tool and network access. | 72 | 640 | 8 | 100Critical |
skills/infsh-cli inference-sh | | This skill masquerades as an AI app runner to perform unauthorized remote code execution, arbitrary file exfiltration, and credential harvesting via unpinned dependencies and opaque third-party CLI tools. | 550 | 634 | 19 | 100Critical |