skills/wrangler cloudflare | | The skill executes unpinned packages and performs unauthorized network and file operations while accessing sensitive environment variables without declaring necessary tool constraints or security permissions. | 2.0k | 26.8k | 5 | 40Medium |
mcp-use/mcp-apps-builder mcp-use | | The skill executes unpinned packages and accesses sensitive environment variables without defined tool constraints, creating significant supply chain risks and potential for unauthorized data exfiltration. | 10.1k | 15.4k | 10 | 40Medium |
claude-code/mcp-integration anthropics | | The skill violates naming conventions, lacks a license, and poses a significant security risk by accessing sensitive environment variables without justification. | 135.0k | 11.5k | 3 | 40Medium |
claude-code/plugin-structure anthropics | | The skill violates naming conventions, lacks a license, and improperly accesses sensitive environment variables, posing a significant risk of credential exfiltration. | 135.0k | 9.9k | 3 | 40Medium |
mcp-use/mcp-builder mcp-use | | The skill lacks defined tool constraints, executes unpinned packages, and accesses sensitive environment variables, creating significant supply chain and data exfiltration risks. | 10.1k | 9.3k | 10 | 40Medium |
mcp-use/chatgpt-app-builder mcp-use | | This skill poses significant risks by executing unpinned packages, accessing sensitive environment variables, and performing unconstrained system operations while lacking transparency regarding its purpose and security controls. | 10.1k | 9.1k | 11 | 40Medium |
claude-plugins-official/mcp-integration anthropics | | The skill poses a security risk by accessing sensitive environment variables, potentially exposing credentials and configuration data to unauthorized processes. | 31.3k | 3.7k | 2 | 40Medium |
claude-plugins-official/plugin-structure anthropics | | The skill poses a security risk by accessing sensitive environment variables, potentially exposing critical system credentials and configuration data. | 31.3k | 3.6k | 2 | 40Medium |
skills/skill-scanner getsentry | | The skill attempts to access sensitive credential files and perform unauthorized file writes while actively bypassing mandatory human oversight protocols. | 804 | 1.8k | 4 | 100Critical |
agent-skills/first-flag launchdarkly | | The skill exposes hardcoded credentials, executes unpinned packages, and performs unauthorized network and file operations without declaring necessary tool constraints, creating significant security and supply chain risks. | 19 | 1.7k | 5 | 100Critical |
agent-skills/aws-ami-builder hashicorp | | The skill poses a security risk by attempting to access sensitive credential file paths, potentially leading to unauthorized exposure of AWS access keys and environment secrets. | 677 | 1.5k | 2 | 100Critical |
antigravity-awesome-skills/gcp-cloud-run sickn33 | | This skill executes arbitrary commands, exposes hardcoded credentials, lacks necessary security declarations for network and tool access, and contains vulnerabilities to supply chain and cross-site scripting attacks. | 41.2k | 1.2k | 10 | 100Critical |
knowledge-work-plugins/zoom-cobrowse-sdk anthropics | | The skill contains hardcoded credentials, lacks necessary tool and network constraints, uses insecure dependency management, and references missing documentation, creating significant security and supply chain risks. | 22.2k | 1.1k | 11 | 100Critical |
agent-skills/claimable-postgres neondatabase | | The skill lacks defined tool constraints and network permissions while accessing sensitive environment variables, creating an unmonitored attack surface that risks unauthorized data exfiltration and system compromise. | 71 | 1.1k | 5 | 40Medium |
skills/launch-nemo-rl nvidia | | The skill exhibits suspicious behavior by attempting to access sensitive credential files while simultaneously initiating unauthorized network connections, indicating a high risk of data exfiltration. | 2.2k | 1.1k | 2 | 100Critical |
skills/vss-deploy-dense-captioning nvidia | | The skill insecurely exfiltrates sensitive environment variables via network commands and lacks necessary tool declarations, creating an unconstrained and high-risk attack surface for credential theft. | 2.2k | 1.1k | 8 | 100Critical |
antigravity-awesome-skills/code-review-checklist sickn33 | | The skill exhibits unauthorized access to sensitive environment variables, posing a significant risk of credential exfiltration and data exposure. | 41.2k | 999 | 5 | 40Medium |
awesome-copilot/arize-ai-provider-integration github | | This skill impersonates a reputable brand while containing unauthorized code patterns that access sensitive environment variables, posing a significant risk of credential exfiltration. | 35.3k | 921 | 3 | 40Medium |
awesome-copilot/arize-evaluator github | | The skill accesses sensitive environment variables and executes arbitrary commands without declaring allowed tools, creating an unconstrained and high-risk attack surface for potential system compromise. | 35.3k | 917 | 3 | 40Medium |
skills/tao-run-on-kubernetes nvidia | | The skill is insecure due to unauthorized file system access, potential command injection vulnerabilities, unpinned package installations, and the use of undocumented file write operations. | 2.2k | 897 | 4 | 100Critical |
skills/tao-train-depth-anything-v2 nvidia | | The skill attempts unauthorized access to sensitive credential files and performs unlisted file write operations while relying on external, unverified documentation, posing significant data exfiltration and integrity risks. | 2.2k | 891 | 3 | 100Critical |
skills/tao-train-foundation-stereo nvidia | | The skill attempts unauthorized access to sensitive credential files and performs unlisted file write operations while relying on external, unverified documentation references that pose a supply chain risk. | 2.2k | 891 | 3 | 100Critical |
awesome-copilot/mcp-security-audit github | | This skill is malicious, containing a reverse shell and unauthorized environment access, while also suffering from critical vulnerabilities including arbitrary file read, command injection, and unpinned dependency execution. | 35.3k | 756 | 11 | 100Critical |
agent-skills/auth0-express auth0 | | The skill facilitates cross-site scripting through unsanitized input, exposes sensitive environment variables, and performs unauthorized network operations without declaring necessary tool permissions or security constraints. | 37 | 727 | 9 | 100Critical |
antigravity-awesome-skills/ethical-hacking-methodology sickn33 | | This skill facilitates unauthorized access and system compromise by providing automated exploitation, credential brute-forcing, and persistence mechanisms while lacking necessary security constraints on its tool execution surface. | 41.2k | 669 | 11 | 100Critical |
antigravity-awesome-skills/file-uploads sickn33 | | This skill performs unauthorized file system traversal and credential access while deceptively misrepresenting its high-risk operations as safe in the manifest. | 41.2k | 657 | 6 | 100Critical |
antigravity-awesome-skills/kaizen sickn33 | | The skill performs unauthorized network communication and accesses sensitive environment variables while bypassing security constraints by failing to declare its tool surface or capabilities. | 41.2k | 645 | 5 | 40Medium |
antigravity-awesome-skills/api-fuzzing-bug-bounty sickn33 | | This skill lacks necessary security constraints, performs unauthorized network and file access, contains SQL injection vulnerabilities, and promotes the execution of unverified third-party code. | 41.2k | 533 | 9 | 100Critical |
agent-skills/auth0-fastify-api auth0 | | The skill lacks declared tool constraints while accessing sensitive environment variables and performing unauthorized network operations, posing a significant risk of data exfiltration and arbitrary command execution. | 37 | 486 | 3 | 40Medium |
skills/jetson-flash-image nvidia | | The skill lacks defined tool constraints, attempts to access sensitive credential files, and relies on external, unverified documentation, creating significant risks for unauthorized system access and supply chain compromise. | 2.2k | 444 | 5 | 100Critical |
skills/jetson-print-bsp-info nvidia | | The skill accesses sensitive credential files and executes unauthorized system commands without declaring necessary tool constraints, posing a significant risk of credential theft and arbitrary code execution. | 2.2k | 436 | 2 | 100Critical |
antigravity-awesome-skills/ssh-penetration-testing sickn33 | | This skill is a malicious toolkit that automates unauthorized persistent access, credential theft, and lateral movement through SSH key injection, brute-forcing, and reverse shell establishment. | 41.2k | 427 | 22 | 100Critical |
antigravity-awesome-skills/linux-privilege-escalation sickn33 | | This skill is a malicious exploitation toolkit that facilitates unauthorized privilege escalation, credential theft, and persistent backdoor installation via reverse shells and unverified remote code execution. | 41.2k | 416 | 25 | 100Critical |
antigravity-awesome-skills/firmware-analyst sickn33 | | The skill performs unauthorized file system access and hidden network operations while bypassing security constraints by failing to declare its tool usage and capabilities. | 41.2k | 369 | 6 | 100Critical |
antigravity-awesome-skills/metasploit-framework sickn33 | | This skill functions as a malicious toolkit that provides instructions for credential harvesting, keylogging, persistence, and bypassing security controls to facilitate unauthorized system exploitation and surveillance. | 41.2k | 369 | 11 | 100Critical |
antigravity-awesome-skills/privilege-escalation-methods sickn33 | | This skill functions as a malicious offensive toolkit that instructs the agent to perform domain-wide credential theft, privilege escalation, and persistence while actively bypassing security and defensive controls. | 41.2k | 318 | 19 | 100Critical |
skills/agent-experience browserbase | | This skill impersonates a known brand while exfiltrating sensitive environment variables and credential files through unauthorized network connections. | 3.6k | 307 | 4 | 100Critical |
antigravity-awesome-skills/secrets-management sickn33 | | This skill performs unauthorized persistent code execution via git hooks, exfiltrates sensitive environment variables, and bypasses security constraints by executing undocumented network and file system operations. | 41.2k | 263 | 7 | 70High |
antigravity-awesome-skills/posix-shell-pro sickn33 | | This skill lacks defined tool constraints and attempts to access sensitive credential files, posing a significant risk of unauthorized data exfiltration and system compromise. | 41.2k | 255 | 11 | 100Critical |
design.md/typed-service-contracts google-labs-code | | The skill poses a significant security risk by attempting to access sensitive credential file paths, indicating potential unauthorized data exfiltration. | 16.0k | 251 | 2 | 100Critical |
jira-skill/jira-communication netresearch | | The skill requests excessive workspace-wide write permissions and insecurely mandates storing sensitive Jira credentials in predictable local files vulnerable to exfiltration by malicious processes. | 64 | 238 | 3 | 100Critical |
antigravity-awesome-skills/linux-shell-scripting sickn33 | | This skill exhibits dangerous patterns including credential exposure, unauthorized system enumeration, and unconstrained command execution, creating significant risks for lateral movement, data exfiltration, and system compromise. | 41.2k | 191 | 9 | 100Critical |
varlock-claude-skill/varlock wrsmith108 | | The skill executes unverified remote scripts via shell pipes and uses insecure exec directives to handle sensitive credentials, creating critical command injection and credential exfiltration vulnerabilities. | 25 | 185 | 12 | 100Critical |
prisma-next/prisma-next-migrations prisma | | The skill performs unauthorized access to sensitive environment variables and executes unconstrained system commands without declaring necessary tool permissions, posing a significant risk of data exfiltration and system compromise. | 381 | 182 | 3 | 40Medium |
prisma-next/prisma-next-contract prisma | | The skill uses keyword stuffing to hijack queries, accesses sensitive environment variables, and executes unconstrained system commands, posing a significant risk of data exfiltration and unauthorized system access. | 381 | 178 | 4 | 40Medium |
prisma-next/prisma-next-quickstart prisma | | The skill lacks defined tool constraints and improperly accesses sensitive environment variables, posing a significant risk of unauthorized data exfiltration and arbitrary command execution. | 381 | 175 | 4 | 40Medium |
antigravity-awesome-skills/shodan-reconnaissance sickn33 | | This skill exposes hardcoded credentials and executes unconstrained network and system commands without declaring necessary permissions, creating significant risks for unauthorized data exfiltration and system compromise. | 41.2k | 141 | 7 | 40Medium |
antigravity-awesome-skills/burp-suite-testing sickn33 | | This skill contains critical vulnerabilities, including unauthorized access to credential files, SQL injection patterns, and path traversal flaws, posing a severe risk of data exfiltration and system compromise. | 41.2k | 139 | 6 | 100Critical |