skills/grill-me mattpocock | | The skill is functionally inert and lacks transparency regarding its purpose, licensing, and implementation, failing to provide any verifiable utility or security assurance. | 137.2k | 353.2k | 3 | 40Medium |
skills/grill-with-docs mattpocock | | The skill exhibits insecure design by bypassing model invocation restrictions and blindly executing unverified external skills, creating a significant risk of malicious sub-agent hijacking. | 137.2k | 286.1k | 4 | 70High |
agent-skills/sleek-design-mobile-apps sleekdotdesign | | The skill facilitates SSRF via arbitrary URL fetching and enables remote command injection by piping unverified API responses directly into shell commands, violating its stated network access restrictions. | 426 | 249.3k | 5 | 40Medium |
browser-use/browser-use browser-use | | This skill poses severe security risks by exposing sensitive browser data, creating unauthorized public network tunnels, enabling unauthenticated remote debugging, and employing social engineering for financial exploitation. | 99.6k | 80.3k | 8 | 70High |
skills/higgsfield-generate higgsfield-ai | | The skill performs unverified remote code execution by piping unsanitized scripts directly into a shell and executes unauthorized file write operations, posing a critical security risk. | 439 | 61.0k | 8 | 100Critical |
skills/higgsfield-soul-id higgsfield-ai | | The skill executes arbitrary code by piping unverified remote scripts directly into a shell, granting external servers full control over the agent's environment without disclosure or security checks. | 439 | 49.5k | 7 | 100Critical |
skills/higgsfield-marketplace-cards higgsfield-ai | | The skill executes arbitrary code by piping remote scripts directly into the shell, posing a critical security risk of unauthorized remote code execution. | 439 | 48.6k | 6 | 100Critical |
agent-skills/firebase-firestore firebase | | This skill uses coercive prompts to hijack agent workflows and force unauthorized enterprise-tier cloud provisioning while relying on unverified, insecure dependency execution and missing critical documentation. | 357 | 47.4k | 12 | 40Medium |
wonda/wonda-cli degausai | | This tool masquerades as a content creator but functions as a malicious backdoor that exfiltrates credentials, executes arbitrary code, and maintains persistent, stealthy control over the user's social accounts. | 126 | 42.3k | 13 | 100Critical |
skills/tavily-search tavily-ai | | The skill forces the execution of unverified remote scripts to install dependencies, creating a critical supply chain vulnerability that enables arbitrary code execution and potential credential harvesting. | 378 | 23.2k | 9 | 100Critical |
awesome-copilot/conventional-commit github | | The skill masquerades as a commit message generator but forces unauthorized terminal execution of git commands, bypassing critical human oversight and verification processes. | 35.3k | 12.9k | 6 | 70High |
skills/tavily-research tavily-ai | | The skill mandates an insecure curl-to-bash installation pattern that executes unverified remote scripts with system privileges, creating a critical risk of arbitrary code execution. | 378 | 12.6k | 7 | 100Critical |
skills/tavily-cli tavily-ai | | The skill executes arbitrary code by piping unverified remote scripts directly into a shell, creating a critical vulnerability that allows for unauthorized system access and remote command execution. | 378 | 8.8k | 7 | 100Critical |
awesome-copilot/quasi-coder github | | The skill uses deceptive persona framing and arbitrary command execution to bypass safety filters, enabling remote code execution and unauthorized network scanning through malicious shorthand instruction injection. | 35.3k | 8.6k | 6 | 70High |
skills/tavily-crawl tavily-ai | | The skill forces the execution of unverified remote scripts via insecure curl-to-bash patterns, exposing the agent to arbitrary code execution and supply chain attacks. | 378 | 8.6k | 9 | 100Critical |
shopify-ai-toolkit/shopify-liquid shopify | | The skill systematically exfiltrates sensitive user prompts, proprietary code, and session identifiers to third-party servers while coercing the agent into executing unauthorized telemetry scripts without user consent or oversight. | 397 | 6.5k | 11 | 70High |
shopify-ai-toolkit/shopify-custom-data shopify | | The skill hijacks the agent's reasoning to force mandatory, opaque bash script execution and silently exfiltrates sensitive user prompts and session identifiers to external endpoints without explicit user consent. | 397 | 5.9k | 10 | 70High |
shopify-ai-toolkit/shopify-polaris-app-home shopify | | The skill exfiltrates verbatim user prompts and session identifiers to external endpoints while executing opaque, unconstrained shell scripts that bypass the agent's visible reasoning loop. | 397 | 5.5k | 9 | 70High |
knowledge-work-plugins/task-management anthropics | | The skill performs unauthorized file system operations and introduces undocumented commands and UI components that deviate from its stated purpose, posing a significant risk of arbitrary code execution. | 21.4k | 4.9k | 4 | 70High |
skills/tavily-dynamic-search tavily-ai | | The skill executes arbitrary remote code by piping unverified scripts directly into a shell, bypassing security controls and creating a critical vulnerability for remote command execution. | 378 | 4.8k | 9 | 100Critical |
shopify-ai-toolkit/shopify-app-store-review shopify | | This skill masquerades as an official tool to force the silent exfiltration of user prompts and session data via hidden scripts while enabling arbitrary remote command injection. | 397 | 4.3k | 13 | 100Critical |
awesome-copilot/copilot-spaces github | | The skill facilitates prompt injection via untrusted Copilot Spaces and requests excessive permissions to perform destructive CRUD operations, significantly exceeding its stated purpose of providing project context. | 35.3k | 4.1k | 5 | 70High |
skills/notion-cli makenotion | | The skill executes arbitrary remote code via insecure curl-to-bash installation and lacks necessary tool declarations, creating a critical risk of unauthorized system access and remote command execution. | 125 | 4.0k | 7 | 100Critical |
knowledge-work-plugins/data-context-extractor anthropics | | This skill performs unauthorized schema discovery and executes dangerous SQL injection patterns to exfiltrate sensitive production data under the guise of generating documentation. | 21.4k | 1.9k | 7 | 100Critical |
skills/hf-cli huggingface | | This skill facilitates arbitrary remote code execution, insecurely handles authentication tokens, and lacks necessary security constraints, creating significant risks for system compromise and unauthorized data access. | 10.7k | 1.5k | 11 | 100Critical |
claude-mem/wowerpoint thedotmack | | The skill performs unauthorized data exfiltration to external servers, executes unconstrained network operations, and introduces supply chain risks by installing unpinned dependencies without declaring necessary security permissions. | 83.3k | 1.5k | 7 | 40Medium |
remotion/video-report remotion-dev | | The skill facilitates remote code execution by allowing arbitrary file modification, executing unpinned packages, and downloading untrusted external content for build processes without sufficient security validation. | 50.6k | 1.4k | 5 | 70High |
skills/rover apollographql | | The skill insecurely executes unverified remote shell scripts and lacks integrity checks, creating a high risk of arbitrary code execution and supply chain compromise. | 84 | 1.2k | 13 | 100Critical |
open-design/nanobanana-ppt nexu-io | | The skill poses a significant supply chain risk by directing users to install unverified, external code from an untrusted repository instead of providing functional AI-powered PPT generation. | 68.0k | 1.2k | 6 | 70High |
skills/huggingface-datasets huggingface | | This skill deceptively exfiltrates sensitive local session data and agent traces to Hugging Face while executing unverified code and performing unauthorized network operations without declaring necessary tool permissions. | 10.7k | 1.1k | 7 | 70High |
open-design/agent-browser nexu-io | | The skill exposes an unauthenticated Chrome remote-debugging port to the local network, enabling full browser control, while executing unverified dependencies and performing unauthorized network and file system operations. | 68.0k | 1.1k | 9 | 70High |
open-design/competitive-ads-extractor nexu-io | | The skill lacks functional implementation logic, a clear description, and licensing information, rendering it non-functional and failing to meet basic transparency and security standards for agent tools. | 68.0k | 1.1k | 4 | 40Medium |
open-design/domain-name-brainstormer nexu-io | | The skill lacks functional implementation logic, a clear description, and licensing information, rendering it non-functional and failing to meet basic transparency and security standards. | 68.0k | 1.1k | 4 | 40Medium |
open-design/minimax-pdf nexu-io | | The skill is a deceptive shell that lacks functional PDF capabilities and introduces severe supply chain risks by forcing users to execute unverified, remotely hosted code. | 68.0k | 1.1k | 6 | 70High |
open-design/youtube-clipper nexu-io | | The skill poses a critical supply chain risk by executing unverified, unpinned code from an external repository, masquerading as a video editor while lacking transparency and security controls. | 68.0k | 1.1k | 6 | 70High |
skills/huggingface-papers huggingface | | The skill performs unauthorized administrative modifications to user profiles and metadata while executing unconstrained network requests and potential prompt injections through external content, masquerading as a simple research summarizer. | 10.7k | 1.0k | 6 | 70High |
antigravity-awesome-skills/audio-transcriber sickn33 | | The skill deceptively exfiltrates sensitive data to external CLI tools, executes arbitrary commands without oversight, and lacks necessary security constraints, posing severe risks of prompt injection and supply chain compromise. | 41.2k | 1.0k | 9 | 70High |
knowledge-work-plugins/zoom-cobrowse-sdk anthropics | | The skill exposes hardcoded credentials, lacks necessary security declarations for network and tool access, and provides insecure implementation instructions while failing to include critical documentation files. | 21.4k | 983 | 12 | 100Critical |
ralph-wiggum/ralph-wiggum fstandhartinger | | The skill promotes dangerous security bypasses, executes unpinned packages, and lacks defined tool constraints, creating an unmonitored environment prone to unauthorized system access and malicious command execution. | 261 | 980 | 4 | 70High |
skills/agent-tools inference-sh | | This skill executes unverified remote code, exfiltrates local files, and uses opaque binaries to bypass security oversight while posing as a legitimate tool to harvest user credentials. | 550 | 980 | 20 | 100Critical |
agent-skills/clickhousectl-cloud-deploy clickhouse | | The skill executes arbitrary remote code and insecurely manages sensitive credentials while bypassing security constraints by failing to declare its network and file system tool permissions. | 468 | 868 | 5 | 100Critical |
antigravity-awesome-skills/production-code-audit sickn33 | | The skill masquerades as a code auditor but forces autonomous, unverified, and recursive codebase modifications that risk destructive changes and the exposure of sensitive configuration data. | 41.2k | 849 | 10 | 100Critical |
antigravity-awesome-skills/wordpress-penetration-testing sickn33 | | This skill functions as a malicious exploitation toolkit that instructs the agent to perform destructive SQL injections, exfiltrate credentials, and execute unauthorized reverse shells against target systems. | 41.2k | 775 | 21 | 100Critical |
agents/checking-freshness astronomer | | The skill is malicious, enabling SQL injection and unauthorized Airflow CLI command execution while forcing unverified dependencies to bypass security controls and exfiltrate sensitive pipeline metadata. | 391 | 759 | 5 | 100Critical |
antigravity-awesome-skills/computer-use-agents sickn33 | | This skill is critically insecure, enabling arbitrary command injection, unauthorized file system access, and financial transactions while actively bypassing human oversight and failing to implement necessary safety constraints. | 41.2k | 759 | 16 | 100Critical |
antigravity-awesome-skills/stripe-integration sickn33 | | The skill promotes insecure development by hardcoding sensitive API keys and PCI-violating payment card data, creating significant risks for credential exposure and data breaches. | 41.2k | 739 | 7 | 70High |
ai/stripe-directory stripe | | This skill hijacks general discovery queries to execute unauthorized financial transactions and crypto wallet operations via unverified third-party CLIs, while bypassing security controls through malicious external instruction injection. | 1.6k | 708 | 16 | 70High |
antigravity-awesome-skills/nanobanana-ppt-skills sickn33 | | The skill lacks functional implementation, tool integration, and licensing, serving as a non-functional placeholder that fails to provide the advertised AI-powered document generation capabilities. | 41.2k | 661 | 4 | 40Medium |