azure-skills/entra-agent-id microsoft | | The skill facilitates high-privilege identity management and executes unauthorized network and shell commands, creating significant risks for privilege escalation, data exfiltration, and uncontrolled agent recursion. | 1.2k | 142.5k | 15 | 40Medium |
skills/claude-api anthropics | | This skill hijacks agent model selection, mandates insecure external documentation fetching, and contains hardcoded commands for data exfiltration, posing significant risks to agent integrity and user security. | 156.8k | 45.3k | 5 | 70High |
skills/expo-api-routes expo | | This skill facilitates SSRF and data exfiltration by allowing unvalidated user input in network requests, exposes sensitive environment variables, uses insecure CORS policies, and lacks necessary security capability declarations. | 2.1k | 33.9k | 13 | 100Critical |
web-access/web-access eze-is | | This skill poses a critical risk by enabling arbitrary JavaScript execution, session hijacking, and unauthorized local file exfiltration while lacking necessary security constraints or declared tool permissions. | 7.7k | 12.3k | 9 | 70High |
skills/security-review getsentry | | The skill performs unauthorized file writes and initiates unapproved outbound network connections, creating a significant risk of data exfiltration and system compromise. | 804 | 8.2k | 3 | 70High |
awesome-copilot/flowstudio-power-automate-mcp github | | This skill lacks necessary tool constraints and security declarations while facilitating data exfiltration via unauthorized network access and insecure credential handling practices. | 35.3k | 4.0k | 10 | 40Medium |
skills/turnstile-spin cloudflare | | The skill executes unpinned, unverified dependencies and performs unauthorized network requests while insecurely handling sensitive API tokens without declaring necessary tool constraints or security boundaries. | 1.9k | 3.0k | 8 | 40Medium |
workflow/workflow vercel | | The skill executes unpinned packages and performs unauthorized network operations, creating significant supply chain risks and potential data exfiltration vectors due to a lack of defined tool constraints. | 2.1k | 2.8k | 5 | 40Medium |
skills/cuopt-server-api-python nvidia | | The skill performs unauthorized network communication and executes arbitrary commands without declaring necessary tool permissions, creating an unconstrained surface for potential data exfiltration and system compromise. | 2.2k | 1.3k | 4 | 15Low |
knowledge-work-plugins/build-zoom-team-chat-app anthropics | | The skill is critically insecure, exhibiting SQL injection, SSRF vulnerabilities, unconstrained network access, and insecure secret handling while failing to pin dependencies or declare necessary security capabilities. | 22.2k | 1.1k | 17 | 100Critical |
knowledge-work-plugins/build-zoom-video-sdk-app anthropics | | The skill performs unauthorized network operations and executes commands without declaring required tools, while relying on missing documentation that obscures its runtime behavior and data handling practices. | 22.2k | 1.1k | 9 | 15Low |
knowledge-work-plugins/setup-zoom-websockets anthropics | | The skill executes unsafe dynamic code, performs unauthorized network requests, and lacks necessary documentation, creating significant risks for code injection and unconstrained data exfiltration. | 22.2k | 1.1k | 10 | 100Critical |
knowledge-work-plugins/zoom-apps-sdk anthropics | | The skill performs unauthorized network operations and executes commands without declaring required tools, while relying on missing documentation that suggests potential runtime dependency on external, unverified sources. | 22.2k | 1.1k | 9 | 15Low |
knowledge-work-plugins/zoom-cobrowse-sdk anthropics | | The skill contains hardcoded credentials, lacks necessary tool and network constraints, uses insecure dependency management, and references missing documentation, creating significant security and supply chain risks. | 22.2k | 1.1k | 11 | 100Critical |
knowledge-work-plugins/zoom-oauth anthropics | | The skill performs unauthorized network operations and executes commands without declaring required tools, while containing infinite loop patterns that pose a significant risk of resource exhaustion and data exfiltration. | 22.2k | 1.1k | 10 | 15Low |
knowledge-work-plugins/zoom-rtms anthropics | | The skill is vulnerable to Server-Side Request Forgery due to unvalidated user input in HTTP and WebSocket requests, potentially allowing unauthorized access to internal infrastructure and metadata services. | 22.2k | 1.1k | 9 | 100Critical |
skills/vss-deploy-dense-captioning nvidia | | The skill insecurely exfiltrates sensitive environment variables via network commands and lacks necessary tool declarations, creating an unconstrained and high-risk attack surface for credential theft. | 2.2k | 1.1k | 8 | 100Critical |
skills/vss-search-archive nvidia | | The skill performs unsanitized command execution and unauthorized network exfiltration while failing to declare necessary tool permissions, creating a significant risk of remote code execution and data theft. | 2.2k | 1.1k | 6 | 40Medium |
agent-skills/configs-targeting launchdarkly | | The skill performs unauthorized network requests and executes arbitrary commands without declaring necessary tool permissions, creating a significant risk of data exfiltration and unconstrained system access. | 19 | 959 | 4 | 15Low |
agent-skills/online-evals launchdarkly | | The skill performs unauthorized network communication and executes arbitrary commands without declaring necessary tool permissions, creating a significant risk of data exfiltration and unconstrained system access. | 19 | 959 | 4 | 15Low |
agent-skills/custom-metrics launchdarkly | | This skill exfiltrates environment secrets and API keys by scraping local configuration files and executing unauthorized network requests while bypassing all tool-based security constraints. | 19 | 958 | 9 | 100Critical |
agents/migrating-airflow-2-to-3 astronomer | | The skill performs unauthorized network access and executes commands without declaring required tools, creating an opaque execution environment capable of silent data exfiltration and external dependency fetching. | 393 | 872 | 8 | 15Low |
antigravity-awesome-skills/wordpress-penetration-testing sickn33 | | This skill functions as a malicious exploitation toolkit that instructs the agent to perform destructive SQL injections, exfiltrate credentials, and execute unauthorized reverse shells against target systems. | 41.2k | 775 | 21 | 100Critical |
agents/airflow-hitl astronomer | | The skill performs unauthorized network exfiltration of environment secrets and executes unconstrained system commands without declaring necessary tool permissions or security boundaries. | 393 | 731 | 5 | 100Critical |
agent-skills/auth0-express auth0 | | The skill facilitates cross-site scripting through unsanitized input, exposes sensitive environment variables, and performs unauthorized network operations without declaring necessary tool permissions or security constraints. | 37 | 727 | 9 | 100Critical |
pinme/pinme glitternetwork | | The skill executes unverified remote code via forced global updates and lacks necessary tool constraints, creating a high-risk vector for arbitrary command execution and credential exfiltration. | 3.7k | 664 | 11 | 70High |
agent-skills/anki-connect intellectronica | | The skill performs unauthorized network exfiltration and executes arbitrary commands while bypassing security constraints by failing to declare its required tools and capabilities. | 273 | 584 | 5 | 40Medium |
agent-skills/auth0-nuxt auth0 | | The skill performs unauthorized network operations and executes commands without declaring required capabilities, while relying on external, unverified documentation that poses a risk of runtime code injection. | 37 | 511 | 6 | 15Low |
agents/airflow-plugins astronomer | | The skill exfiltrates environment secrets to external network sinks while bypassing security constraints by executing unauthorized network requests and file operations without declaring required tool permissions. | 393 | 380 | 7 | 100Critical |
agent-skills/auth0-spa-js auth0 | | The skill performs unauthorized network requests and executes commands without declaring required capabilities, creating an opaque and potentially malicious execution environment that lacks necessary security constraints. | 37 | 353 | 6 | 15Low |
skills/use-runway-api runwayml | | The skill performs unauthorized file writes and network requests, uses unpinned dependencies, and includes malicious patterns for data exfiltration via shell commands. | 55 | 151 | 5 | 70High |
common-skills/scan-new-specs warpdotdev | | The skill executes unauthorized network requests and arbitrary commands to exfiltrate data while bypassing security constraints by failing to declare its required tools and capabilities. | 113 | 106 | 4 | 40Medium |
sentry-skills/security-review getsentry | | The skill performs unauthorized file writes and initiates unapproved outbound network connections, creating a significant risk of data exfiltration and system compromise. | 804 | 63 | 3 | 70High |
claude-skills/accessing-github-repos oaustegard | | The skill exfiltrates sensitive GitHub credentials from local environment files and performs unauthorized outbound network requests while bypassing all tool-based security constraints and access controls. | 127 | 62 | 8 | 70High |
antigravity-awesome-skills/expo-api-routes sickn33 | | This skill poses a critical security risk by executing unpinned global dependencies and performing unauthorized network exfiltration of environment variables while lacking necessary tool-use constraints. | 41.2k | 48 | 8 | 100Critical |
antigravity-awesome-skills/claude-api sickn33 | | This skill impersonates a legitimate AI brand and contains malicious code that uses network utilities to exfiltrate sensitive data. | 41.2k | 40 | 3 | 40Medium |
webgl-animation-skills/particle-system iart-ai | | The skill executes unpinned packages and performs unauthorized network exfiltration while bypassing security constraints by failing to declare its tool surface or network capabilities. | 1 | 35 | 5 | 40Medium |
awesome-supply-chain/supply-chain-automation kishorkukreja | | The skill exposes hardcoded credentials, lacks necessary tool and network constraints, and performs unauthorized outbound data transmissions, creating significant risks of credential theft and unmonitored system access. | 32 | 33 | 8 | 70High |
skills/debugging-signals-pipeline posthog | | The skill performs unauthorized network exfiltration via curl and wget while bypassing security constraints by failing to declare its tool usage or network capabilities. | 49 | 33 | 4 | 40Medium |
skills/indykite-authzen-kbac indykite | | The skill facilitates data exfiltration via shell commands, exposes sensitive credentials through insecure configuration practices, and lacks necessary security constraints for its network and file system operations. | 0 | 31 | 12 | 40Medium |
skills/indykite-ciq-create-node indykite | | The skill performs unauthorized network exfiltration via curl/wget and executes unconstrained system commands while masking its true functionality through missing documentation and suspicious hidden instructions. | 0 | 31 | 13 | 40Medium |
skills/indykite-ciq-add-property indykite | | The skill performs unauthorized network exfiltration via shell commands and lacks necessary tool declarations, while relying on missing external assets that create unpredictable and insecure runtime behavior. | 0 | 30 | 13 | 40Medium |
skills/indykite-ciq-add-relationship-property indykite | | This skill exfiltrates data via unauthorized network commands, processes sensitive payment information, and lacks necessary tool declarations, indicating a high risk of malicious activity and insecure design. | 0 | 30 | 14 | 70High |
skills/indykite-ciq-create-node-with-link indykite | | The skill performs unauthorized network exfiltration via shell commands and lacks necessary tool declarations, while relying on missing external assets and suspicious hidden instructions to execute its workflow. | 0 | 30 | 13 | 40Medium |
skills/indykite-ciq-create-relationship indykite | | This skill exfiltrates data via unauthorized network commands, processes sensitive payment information, and lacks necessary security declarations, while relying on missing external assets to execute potentially malicious hidden instructions. | 0 | 30 | 14 | 70High |
skills/indykite-ciq-delete indykite | | The skill lacks declared tool permissions and executes unauthorized network requests to exfiltrate data while referencing missing files that may hide malicious runtime instructions. | 0 | 30 | 13 | 40Medium |
skills/indykite-ciq-read indykite | | The skill performs unauthorized network exfiltration and command execution while relying on external, unverified references that expose the agent to prompt injection and supply chain manipulation. | 0 | 30 | 14 | 40Medium |
claude-code-plugins-plus-skills/apollo-security-basics jeremylongshore | | The skill performs unauthorized shell execution and file operations while using dangerous command injection patterns to exfiltrate data via unapproved network requests. | 2.4k | 27 | 10 | 70High |