skills/claude-api anthropics | | This skill performs unauthorized network exfiltration, mandates vendor lock-in by hijacking model selection, and hides its outbound communication capabilities by failing to declare required network permissions in the manifest. | 153.0k | 41.5k | 5 | 40Medium |
skills/expo-api-routes expo | | This skill facilitates SSRF and data exfiltration by allowing unvalidated user input in network requests, exposes sensitive environment variables, uses insecure CORS policies, and lacks necessary security capability declarations. | 2.1k | 33.9k | 13 | 100Critical |
web-access/web-access eze-is | | This skill poses a critical risk by enabling arbitrary JavaScript execution, session hijacking, and unauthorized local file exfiltration while lacking necessary security constraints or declared tool permissions. | 7.7k | 12.3k | 9 | 70High |
skills/security-review getsentry | | The skill performs unauthorized file writes and initiates unapproved outbound network connections, creating a significant risk of data exfiltration and system compromise. | 804 | 8.2k | 3 | 70High |
awesome-copilot/flowstudio-power-automate-mcp github | | This skill lacks necessary tool constraints and security declarations while facilitating data exfiltration via unauthorized network access and insecure credential handling practices. | 35.3k | 4.0k | 10 | 40Medium |
skills/turnstile-spin cloudflare | | The skill executes unpinned, unverified dependencies and performs unauthorized network requests while insecurely handling sensitive API tokens without declaring necessary tool constraints or security boundaries. | 1.9k | 3.0k | 8 | 40Medium |
workflow/workflow vercel | | The skill executes unpinned packages and performs unauthorized network operations, creating significant supply chain risks and potential data exfiltration vectors due to a lack of defined tool constraints. | 2.1k | 2.8k | 5 | 40Medium |
antigravity-awesome-skills/wordpress-penetration-testing sickn33 | | This skill functions as a malicious exploitation toolkit that instructs the agent to perform destructive SQL injections, exfiltrate credentials, and execute unauthorized reverse shells against target systems. | 41.2k | 775 | 21 | 100Critical |
agent-skills/anki-connect intellectronica | | The skill performs unauthorized network exfiltration and executes arbitrary commands while bypassing security constraints by failing to declare its required tools and capabilities. | 273 | 584 | 5 | 40Medium |
skills/use-runway-api runwayml | | The skill performs unauthorized file writes and network requests, uses unpinned dependencies, and includes malicious patterns for data exfiltration via shell commands. | 55 | 151 | 5 | 70High |
sentry-skills/security-review getsentry | | The skill performs unauthorized file writes and initiates unapproved outbound network connections, creating a significant risk of data exfiltration and system compromise. | 804 | 63 | 3 | 70High |
antigravity-awesome-skills/expo-api-routes sickn33 | | This skill poses a critical security risk by executing unpinned global dependencies and performing unauthorized network exfiltration of environment variables while lacking necessary tool-use constraints. | 41.2k | 48 | 8 | 100Critical |
antigravity-awesome-skills/claude-api sickn33 | | This skill impersonates a legitimate AI brand and contains malicious code that uses network utilities to exfiltrate sensitive data. | 41.2k | 40 | 3 | 40Medium |
awesome-supply-chain/supply-chain-automation kishorkukreja | | The skill exposes hardcoded credentials, lacks necessary tool and network constraints, and performs unauthorized outbound data transmissions, creating significant risks of credential theft and unmonitored system access. | 32 | 33 | 8 | 70High |
skills/indykite-authzen-kbac indykite | | The skill facilitates data exfiltration via shell commands, exposes sensitive credentials through insecure configuration practices, and lacks necessary security constraints for its network and file system operations. | 0 | 31 | 12 | 40Medium |
skills/indykite-ciq-create-node indykite | | The skill performs unauthorized network exfiltration via curl/wget and executes unconstrained system commands while masking its true functionality through missing documentation and suspicious hidden instructions. | 0 | 31 | 13 | 40Medium |
skills/indykite-ciq-add-property indykite | | The skill performs unauthorized network exfiltration via shell commands and lacks necessary tool declarations, while relying on missing external assets that create unpredictable and insecure runtime behavior. | 0 | 30 | 13 | 40Medium |
skills/indykite-ciq-add-relationship-property indykite | | This skill exfiltrates data via unauthorized network commands, processes sensitive payment information, and lacks necessary tool declarations, indicating a high risk of malicious activity and insecure design. | 0 | 30 | 14 | 70High |
skills/indykite-ciq-create-node-with-link indykite | | The skill performs unauthorized network exfiltration via shell commands and lacks necessary tool declarations, while relying on missing external assets and suspicious hidden instructions to execute its workflow. | 0 | 30 | 13 | 40Medium |
skills/indykite-ciq-create-relationship indykite | | This skill exfiltrates data via unauthorized network commands, processes sensitive payment information, and lacks necessary security declarations, while relying on missing external assets to execute potentially malicious hidden instructions. | 0 | 30 | 14 | 70High |
skills/indykite-ciq-delete indykite | | The skill lacks declared tool permissions and executes unauthorized network requests to exfiltrate data while referencing missing files that may hide malicious runtime instructions. | 0 | 30 | 13 | 40Medium |
skills/indykite-ciq-read indykite | | The skill performs unauthorized network exfiltration and command execution while relying on external, unverified references that expose the agent to prompt injection and supply chain manipulation. | 0 | 30 | 14 | 40Medium |
claude-code-plugins-plus-skills/apollo-security-basics jeremylongshore | | The skill performs unauthorized shell execution and file operations while using dangerous command injection patterns to exfiltrate data via unapproved network requests. | 2.4k | 27 | 10 | 70High |
claude-code-plugins-plus-skills/clay-common-errors jeremylongshore | | The skill executes dynamic code via eval, performs unauthorized outbound network requests, and relies on unverified dependencies, creating significant risks for code injection and sensitive data exfiltration. | 2.4k | 26 | 7 | 100Critical |
claude-code-plugins-plus-skills/exa-debug-bundle jeremylongshore | | This skill performs unauthorized shell execution, file manipulation, and network exfiltration while attempting to bypass security manifests by fingerprinting the host environment and piping data to external servers. | 2.4k | 26 | 8 | 70High |
claude-code-plugins-plus-skills/clay-rate-limits jeremylongshore | | The skill lacks retry limits for rate-limited requests, creating a resource exhaustion vulnerability, and includes unrestricted outbound network access that could facilitate unauthorized data exfiltration. | 2.4k | 25 | 5 | 40Medium |
claude-code-plugins-plus-skills/juicebox-rate-limits jeremylongshore | | The skill uses insecure global variables for authentication and URL construction, enabling credential leakage and data exfiltration, while employing deceptive tagging to hijack agent activation. | 2.4k | 25 | 7 | 40Medium |
claude-code-plugins-plus-skills/juicebox-webhooks-events jeremylongshore | | The skill exposes a persistent, unvalidated webhook server that facilitates SSRF attacks and exfiltrates environment secrets to external network sinks, significantly exceeding its authorized tool permissions. | 2.4k | 25 | 13 | 100Critical |
claude-code-plugins-plus-skills/posthog-data-handling jeremylongshore | | This skill exposes high-privilege API keys, facilitates data exfiltration, and contains critical vulnerabilities including SQL injection and SSRF due to improper input sanitization and insecure network request handling. | 2.4k | 25 | 21 | 70High |
claude-code-plugins-plus-skills/instantly-upgrade-migration jeremylongshore | | This skill exfiltrates sensitive environment variables via unauthorized network requests and contains an infinite loop pattern that poses a significant risk of resource exhaustion and denial of service. | 2.4k | 24 | 6 | 100Critical |
claude-code-plugins-plus-skills/sentry-policy-guardrails jeremylongshore | | The skill insecurely handles sensitive credentials by exposing them in command arguments and exfiltrating them over the network, while also introducing command injection risks through unvalidated API responses. | 2.4k | 24 | 8 | 70High |
agent-skills/zeabur-template-backup zeabur | | The skill lacks necessary tool constraints, executes unverified shell commands via pipe-to-curl, and uses unpinned dependencies, creating significant risks for remote code execution and supply chain compromise. | 36 | 24 | 8 | 40Medium |
claude-code-plugins-plus-skills/sentry-rate-limits jeremylongshore | | The skill insecurely handles sensitive Sentry authentication tokens by passing them through unquoted environment variables into network commands, leading to potential credential exfiltration and command injection vulnerabilities. | 2.4k | 23 | 6 | 70High |
css-skills/css-hover-effects dabaibian | | This skill hides malicious content using CSS and performs unauthorized network exfiltration and command execution while bypassing security constraints by failing to declare its required tools. | 5 | 19 | 6 | 70High |
sentry-python/security-review getsentry | | The skill performs unauthorized file system modifications and initiates unapproved outbound network connections, creating a significant risk of data exfiltration and system compromise. | 2.2k | 19 | 3 | 70High |
ai-plugin/debugging-signals-pipeline posthog | | The skill performs unauthorized network exfiltration via hidden curl/wget commands while bypassing security constraints by failing to declare its tool usage or network capabilities. | 54 | 13 | 5 | 40Medium |
sandbox-sdk/sandbox-bridge cloudflare | | The skill performs unauthorized host enumeration and network exfiltration while bypassing security constraints by failing to declare its tool usage and network capabilities. | 1.0k | 11 | 5 | 40Medium |
clickhouse/keeper-stress-analysis clickhouse | | The skill performs unauthorized network connections and utilizes pipe-to-curl commands to exfiltrate data, posing a critical security risk despite the missing license. | 48.2k | 5 | 3 | 40Medium |
serpapi-claude-plugin/search serpapi | | The skill insecurely exposes API keys via shell commands, performs unauthorized HTTP exfiltration, and is vulnerable to prompt injection through attacker-controlled local JSON configuration files. | 12 | 5 | 10 | 100Critical |
clickhouse/close-flaky-issues clickhouse | | The skill uses fabricated user authorization to exfiltrate data via unauthorized network connections and pipe commands, posing a severe security risk to the host environment. | 48.2k | 4 | 4 | 40Medium |
openclaw/trello firecrawl | | The skill insecurely exposes sensitive Trello credentials via shell commands, facilitates command injection, and performs unauthorized network exfiltration while lacking necessary tool and capability declarations. | 3 | 4 | 7 | 100Critical |
claude-code-plugins-plus-skills/abridge-local-dev-loop jeremylongshore | | The skill uses insecure dynamic code execution and lacks validation for FHIR server endpoints, creating significant risks of code injection, unauthorized data exfiltration, and clinical database corruption. | 2.4k | 2 | 8 | 100Critical |
power-cat-skills/eval-generator-code-app microsoft | | The skill executes arbitrary code via dynamic evaluation and shell commands, performs unauthorized file system traversal, and initiates unmonitored network requests, creating a severe risk of remote code execution. | 21 | 2 | 15 | 100Critical |
pubchem-mcp-server/api-context cyanheads | | The skill executes arbitrary code via eval(), lacks necessary tool constraints, and performs unauthorized outbound network requests, creating significant risks for code injection and data exfiltration. | 9 | 1 | 10 | 100Critical |
wsh/core deepgram | | This skill performs unauthorized network exfiltration via curl and wget while bypassing security constraints by failing to declare its tool usage or network capabilities. | 5 | 1 | 6 | 40Medium |
warden-skills/vercel-deepsec getsentry | | The skill contains critical vulnerabilities including SQL injection, command execution, and SSRF, which enable unauthorized data exfiltration and internal network access, contradicting its stated purpose of secure code analysis. | 56 | 1 | 10 | 100Critical |
claude-code-plugins-plus-skills/algolia-debug-bundle jeremylongshore | | The skill performs unauthorized file writes, accesses sensitive environment variables, and uses network requests to exfiltrate data, violating security policies by bypassing restricted tool permissions. | 2.4k | 1 | 6 | 70High |
claude-code-plugins-plus-skills/bamboohr-upgrade-migration jeremylongshore | | The skill insecurely exposes the BAMBOOHR_API_KEY in process lists and exfiltrates sensitive credentials to an external network endpoint via unauthenticated shell commands. | 2.4k | 1 | 5 | 70High |