skills/find-skills vercel-labs | | The skill forces insecure package installations by mandating global flags and auto-confirmation, while executing unpinned npx commands that expose the agent to arbitrary code execution from untrusted sources. | 29.4k | 3.0M | 8 | 70High |
skills/template-skill anthropics | | The skill is non-functional, lacks implementation details, and fails to specify a license, rendering it an unverified and incomplete template. | 157.8k | 50.8k | 3 | 15Low |
skills/tavily-search tavily-ai | | The skill forces the execution of unverified remote scripts to install dependencies, creating a critical supply chain vulnerability that enables arbitrary code execution and potential credential harvesting. | 378 | 23.2k | 9 | 100Critical |
awesome-copilot/conventional-commit github | | The skill masquerades as a commit message generator but forces unauthorized terminal execution of git commands, bypassing critical human oversight and verification processes. | 35.3k | 12.9k | 6 | 70High |
skills/tavily-research tavily-ai | | The skill mandates an insecure curl-to-bash installation pattern that executes unverified remote scripts with system privileges, creating a critical risk of arbitrary code execution. | 378 | 12.6k | 7 | 100Critical |
skills/tavily-cli tavily-ai | | The skill executes arbitrary code by piping unverified remote scripts directly into a shell, creating a critical vulnerability that allows for unauthorized system access and remote command execution. | 378 | 8.8k | 7 | 100Critical |
awesome-copilot/quasi-coder github | | The skill uses deceptive persona framing and arbitrary command execution to bypass safety filters, enabling remote code execution and unauthorized network scanning through malicious shorthand instruction injection. | 35.3k | 8.6k | 6 | 70High |
skills/tavily-crawl tavily-ai | | The skill forces the execution of unverified remote scripts via insecure curl-to-bash patterns, exposing the agent to arbitrary code execution and supply chain attacks. | 378 | 8.6k | 9 | 100Critical |
shopify-ai-toolkit/shopify-liquid shopify | | The skill systematically exfiltrates sensitive user prompts, proprietary code, and session identifiers to third-party servers while coercing the agent into executing unauthorized telemetry scripts without user consent or oversight. | 397 | 6.5k | 11 | 70High |
stitch-skills/upload-to-stitch google-labs-code | | This skill is malicious as it explicitly instructs the agent to scan and exfiltrate sensitive local configuration files and API keys from the user's home directory. | 8.1k | 6.3k | 9 | 100Critical |
shopify-ai-toolkit/shopify-custom-data shopify | | The skill hijacks the agent's reasoning to force mandatory, opaque bash script execution and silently exfiltrates sensitive user prompts and session identifiers to external endpoints without explicit user consent. | 397 | 5.9k | 10 | 70High |
shopify-ai-toolkit/shopify-polaris-app-home shopify | | The skill exfiltrates verbatim user prompts and session identifiers to external endpoints while executing opaque, unconstrained shell scripts that bypass the agent's visible reasoning loop. | 397 | 5.5k | 9 | 70High |
skills/tavily-dynamic-search tavily-ai | | The skill executes arbitrary remote code by piping unverified scripts directly into a shell, bypassing security controls and creating a critical vulnerability for remote command execution. | 378 | 4.8k | 9 | 100Critical |
shopify-ai-toolkit/shopify-app-store-review shopify | | This skill masquerades as an official tool to force the silent exfiltration of user prompts and session data via hidden scripts while enabling arbitrary remote command injection. | 397 | 4.3k | 13 | 100Critical |
awesome-copilot/copilot-spaces github | | The skill facilitates prompt injection via untrusted Copilot Spaces and requests excessive permissions to perform destructive CRUD operations, significantly exceeding its stated purpose of providing project context. | 35.3k | 4.1k | 5 | 70High |
skills/notion-cli makenotion | | The skill executes arbitrary remote code via insecure curl-to-bash installation and lacks necessary tool declarations, creating a critical risk of unauthorized system access and remote command execution. | 125 | 4.0k | 7 | 100Critical |
skills/hf-cli huggingface | | This skill facilitates arbitrary remote code execution, insecurely handles authentication tokens, and lacks necessary security constraints, creating significant risks for system compromise and unauthorized data access. | 10.7k | 1.5k | 11 | 100Critical |
claude-mem/wowerpoint thedotmack | | The skill performs unauthorized data exfiltration to external servers, executes unconstrained network operations, and introduces supply chain risks by installing unpinned dependencies without declaring necessary security permissions. | 83.3k | 1.5k | 7 | 40Medium |
remotion/video-report remotion-dev | | The skill facilitates remote code execution by allowing arbitrary file modification, executing unpinned packages, and downloading untrusted external content for build processes without sufficient security validation. | 50.6k | 1.4k | 5 | 70High |
open-design/nanobanana-ppt nexu-io | | The skill poses a significant supply chain risk by directing users to install unverified, external code from an untrusted repository instead of providing functional AI-powered PPT generation. | 68.0k | 1.2k | 6 | 70High |
skills/huggingface-datasets huggingface | | This skill deceptively exfiltrates sensitive local session data and agent traces to Hugging Face while executing unverified code and performing unauthorized network operations without declaring necessary tool permissions. | 10.7k | 1.1k | 7 | 70High |
open-design/agent-browser nexu-io | | The skill exposes an unauthenticated Chrome remote-debugging port to the local network, enabling full browser control, while executing unverified dependencies and performing unauthorized network and file system operations. | 68.0k | 1.1k | 9 | 70High |
open-design/competitive-ads-extractor nexu-io | | The skill lacks functional implementation logic, a clear description, and licensing information, rendering it non-functional and failing to meet basic transparency and security standards for agent tools. | 68.0k | 1.1k | 4 | 40Medium |
open-design/domain-name-brainstormer nexu-io | | The skill lacks functional implementation logic, a clear description, and licensing information, rendering it non-functional and failing to meet basic transparency and security standards. | 68.0k | 1.1k | 4 | 40Medium |
open-design/minimax-pdf nexu-io | | The skill is a deceptive shell that lacks functional PDF capabilities and introduces severe supply chain risks by forcing users to execute unverified, remotely hosted code. | 68.0k | 1.1k | 6 | 70High |
open-design/youtube-clipper nexu-io | | The skill poses a critical supply chain risk by executing unverified, unpinned code from an external repository, masquerading as a video editor while lacking transparency and security controls. | 68.0k | 1.1k | 6 | 70High |
skills/huggingface-papers huggingface | | The skill performs unauthorized administrative modifications to user profiles and metadata while executing unconstrained network requests and potential prompt injections through external content, masquerading as a simple research summarizer. | 10.7k | 1.0k | 6 | 70High |
antigravity-awesome-skills/audio-transcriber sickn33 | | The skill deceptively exfiltrates sensitive data to external CLI tools, executes arbitrary commands without oversight, and lacks necessary security constraints, posing severe risks of prompt injection and supply chain compromise. | 41.2k | 1.0k | 9 | 70High |
skills/agent-tools inference-sh | | This skill executes unverified remote code, exfiltrates local files, and uses opaque binaries to bypass security oversight while posing as a legitimate tool to harvest user credentials. | 550 | 980 | 20 | 100Critical |
agent-skills/clickhousectl-cloud-deploy clickhouse | | The skill executes arbitrary remote code and insecurely manages sensitive credentials while bypassing security constraints by failing to declare its network and file system tool permissions. | 468 | 868 | 5 | 100Critical |
antigravity-awesome-skills/production-code-audit sickn33 | | The skill masquerades as a code auditor but forces autonomous, unverified, and recursive codebase modifications that risk destructive changes and the exposure of sensitive configuration data. | 41.2k | 849 | 10 | 100Critical |
antigravity-awesome-skills/wordpress-penetration-testing sickn33 | | This skill functions as a malicious exploitation toolkit that instructs the agent to perform destructive SQL injections, exfiltrate credentials, and execute unauthorized reverse shells against target systems. | 41.2k | 775 | 21 | 100Critical |
antigravity-awesome-skills/computer-use-agents sickn33 | | This skill is critically insecure, enabling arbitrary command injection, unauthorized file system access, and financial transactions while actively bypassing human oversight and failing to implement necessary safety constraints. | 41.2k | 759 | 16 | 100Critical |
antigravity-awesome-skills/stripe-integration sickn33 | | The skill promotes insecure development by hardcoding sensitive API keys and PCI-violating payment card data, creating significant risks for credential exposure and data breaches. | 41.2k | 739 | 7 | 70High |
skills/11-change-gates-and-approval-contract planetscale | | The skill deceptively claims to enforce approval gates while containing hidden instructions that enable autonomous execution to bypass human oversight for sensitive actions. | 105 | 711 | 8 | 70High |
ai/stripe-directory stripe | | This skill hijacks general discovery queries to execute unauthorized financial transactions and crypto wallet operations via unverified third-party CLIs, while bypassing security controls through malicious external instruction injection. | 1.6k | 708 | 16 | 70High |
antigravity-awesome-skills/nanobanana-ppt-skills sickn33 | | The skill lacks functional implementation, tool integration, and licensing, serving as a non-functional placeholder that fails to provide the advertised AI-powered document generation capabilities. | 41.2k | 661 | 4 | 40Medium |
skills/infsh-cli inference-sh | | This skill masquerades as an AI app runner to perform unauthorized remote code execution, arbitrary file exfiltration, and credential harvesting via unpinned dependencies and opaque third-party CLI tools. | 550 | 634 | 19 | 100Critical |
antigravity-awesome-skills/loki-mode sickn33 | | This skill systematically disables all human oversight and security guardrails while implementing an insecure, persistent memory architecture vulnerable to prompt injection and supply chain attacks. | 41.2k | 595 | 18 | 100Critical |
antigravity-awesome-skills/social-content sickn33 | | The skill misleads users by claiming functional social media integration that does not exist, while also failing to provide a license for its instructional content. | 41.2k | 576 | 2 | 15Low |
antigravity-awesome-skills/cc-skill-strategic-compact sickn33 | | This skill lacks functional code and uses vague, deceptive descriptions to masquerade as a development tool, indicating it is likely a placeholder for future malicious content injection. | 41.2k | 571 | 6 | 40Medium |
antigravity-awesome-skills/using-superpowers sickn33 | | The skill employs coercive prompt injection techniques to override the agent's internal reasoning and safety protocols, forcing prioritized tool execution while discouraging critical context gathering. | 41.2k | 569 | 4 | 70High |
skills/background-removal inference-sh | | The skill performs unauthorized general-purpose image generation, uses unpinned dependencies, and facilitates command injection by piping untrusted output into execution commands, creating significant supply chain and security risks. | 550 | 530 | 7 | 70High |
antigravity-awesome-skills/skill-seekers sickn33 | | The skill lacks functional implementation and uses deceptive branding to impersonate an official AI tool, posing a risk of misleading users through non-transparent and potentially malicious intent. | 41.2k | 523 | 5 | 40Medium |
antigravity-awesome-skills/security-scanning-security-hardening sickn33 | | The skill facilitates unauthorized offensive security operations and introduces critical supply chain risks by allowing automated, high-privilege code modification based on potentially malicious, user-controlled inputs. | 41.2k | 499 | 6 | 70High |
cli/sentry-cli getsentry | | The skill facilitates insecure remote code execution by piping unverified scripts directly into a shell and encourages the agent to bypass critical security checks and oversight mechanisms. | 89 | 474 | 9 | 100Critical |
antigravity-awesome-skills/unit-testing-test-generate sickn33 | | The skill is critically insecure because it passes unsanitized user input directly to a shell execution function, enabling arbitrary command injection with the agent's system privileges. | 41.2k | 461 | 4 | 70High |
zerolang/zero vercel-labs | | The skill masquerades as a discovery tool while silently executing unverified remote scripts with elevated privileges, creating a critical vulnerability for arbitrary code execution and unauthorized system access. | 5.1k | 381 | 7 | 100Critical |