android/implementing-android-code bitwarden | | The skill contains a suspicious base64-encoded payload and relies on external, unverified content, indicating a high risk of malicious code injection or unauthorized runtime data sourcing. | 9.0k | 40 | 3 | 40Medium |
host-html/host-html phanosh | | This skill facilitates data exfiltration by transmitting local files to external endpoints, embeds hardcoded credentials, and executes unauthorized network and file operations while bypassing security constraints. | 1 | 5 | 10 | 70High |
agent-orchestra/browser-canvas-testing Grimblaz | | The skill contains multiple suspicious base64-encoded blobs that likely function as obfuscated payloads to execute unauthorized code or bypass security controls. | 2 | – | 3 | 40Medium |
servex/servex Tsukikage7 | | The skill contains obfuscated base64 payloads and performs unauthorized network and file operations while bypassing security constraints by failing to declare its tool surface. | 4 | – | 5 | 40Medium |
claude-code-skill-security-check aliksir | | This malicious skill masquerades as a security tool while executing reverse shells, injecting persistent SSH access, and bypassing user oversight to exfiltrate credentials and perform unauthorized remote code execution. | 3 | – | 18 | 100Critical |
buzz-bd-agent/atv-batch-skill buzzbysolcex | | The skill lacks declared tool constraints and network permissions while processing untrusted external data and integrating with opaque payment flows, creating significant risks for prompt injection and unauthorized exfiltration. | 5 | – | 9 | 70High |
mukul975-anthropic-cybersecurity-skills-cybersecurity-skills/analyzing-bootkit-and-rootkit-samples costrict-plugins-repo | | The skill executes unauthorized system commands and writes files using hidden hex-encoded payloads while bypassing all tool-access constraints and security oversight. | 17 | – | 2 | 40Medium |
mukul975-anthropic-cybersecurity-skills-cybersecurity-skills/analyzing-cobalt-strike-beacon-configuration costrict-plugins-repo | | The skill employs XOR-based payload obfuscation to decode and execute arbitrary shellcode, posing a significant risk of malicious code injection and unauthorized system execution. | 17 | – | 5 | 40Medium |
mukul975-anthropic-cybersecurity-skills-cybersecurity-skills/extracting-config-from-agent-tesla-rat costrict-plugins-repo | | This skill contains malicious keylogging functionality and uses XOR-based obfuscation to hide shellcode execution, indicating it is designed to steal sensitive user input and bypass security detection. | 17 | – | 8 | 100Critical |
mukul975-anthropic-cybersecurity-skills-cybersecurity-skills/performing-file-carving-with-foremost costrict-plugins-repo | | The skill executes arbitrary commands and writes files while obfuscating its intent through hex-encoded payloads, bypassing security constraints by failing to declare its required tool permissions. | 17 | – | 2 | 40Medium |
mukul975-anthropic-cybersecurity-skills-cybersecurity-skills/performing-malware-triage-with-yara costrict-plugins-repo | | The skill uses obfuscated shellcode to execute unauthorized system commands and file operations while bypassing security constraints by failing to declare its required tool permissions. | 17 | – | 3 | 40Medium |
mukul975-anthropic-cybersecurity-skills-cybersecurity-skills/reverse-engineering-android-malware-with-jadx costrict-plugins-repo | | This skill masquerades as a cybersecurity tool but contains a keylogger and uses XOR-based obfuscation to execute malicious shellcode, posing a severe threat to user data and system integrity. | 17 | – | 3 | 100Critical |
mukul975-anthropic-cybersecurity-skills-cybersecurity-skills/reverse-engineering-malware-with-ghidra costrict-plugins-repo | | Uses XOR-based obfuscation to hide and execute malicious shellcode, indicating a clear intent to bypass security analysis and perform unauthorized code execution. | 17 | – | 3 | 40Medium |
pombocyber-skills-cybersec/analyzing-bootkit-and-rootkit-samples maux339-cpu | | The skill executes obfuscated hex-encoded payloads and performs unauthorized system operations without declaring necessary tools, posing a significant risk of arbitrary code execution and system compromise. | 0 | – | 2 | 40Medium |
pombocyber-skills-cybersec/analyzing-cobalt-strike-beacon-configuration maux339-cpu | | The skill employs XOR-based obfuscation to hide malicious shellcode, indicating it is designed to execute unauthorized payloads and evade security detection mechanisms. | 0 | – | 5 | 40Medium |
pombocyber-skills-cybersec/extracting-config-from-agent-tesla-rat maux339-cpu | | This skill contains malicious keylogging functionality and uses XOR-based obfuscation to hide its execution of unauthorized shellcode, indicating it is a credential-stealing malware component. | 0 | – | 8 | 100Critical |
pombocyber-skills-cybersec/performing-file-carving-with-foremost maux339-cpu | | The skill executes unauthorized system commands and writes files using hidden hex-encoded payloads while bypassing all tool-access constraints and security oversight. | 0 | – | 2 | 40Medium |
pombocyber-skills-cybersec/performing-malware-triage-with-yara maux339-cpu | | The skill uses XOR-based obfuscation to hide malicious payloads and executes unauthorized system commands without declaring necessary tools, posing a significant risk of arbitrary code execution. | 0 | – | 3 | 40Medium |
pombocyber-skills-cybersec/reverse-engineering-android-malware-with-jadx maux339-cpu | | This skill masquerades as a reverse engineering tool but contains a keylogger and uses XOR-based obfuscation to execute malicious shellcode, posing a severe security risk. | 0 | – | 3 | 100Critical |
pombocyber-skills-cybersec/reverse-engineering-malware-with-ghidra maux339-cpu | | The skill facilitates arbitrary code execution by running untrusted scripts and binaries in an unsandboxed environment while risking the exfiltration of sensitive malware configuration data. | 0 | – | 6 | 70High |
skill-library-mcp/arena modbender | | This skill uses deceptive consent framing to bypass security checks, exfiltrates workspace data to an attacker-controlled repository, and enables remote instruction injection via unauthenticated third-party API endpoints. | 9 | – | 18 | 70High |
skill-library-mcp/astock-multiagent-research modbender | | The skill contains suspicious base64-encoded payloads and an unconstrained deployment tool that could be exploited to exfiltrate sensitive data or host malicious content. | 9 | – | 3 | 40Medium |
skill-library-mcp/ethosmolt modbender | | This skill facilitates unauthorized financial transactions, exfiltrates sensitive API keys and credentials to an attacker-controlled database, and lacks necessary security constraints, posing a severe risk of total account compromise. | 9 | – | 23 | 70High |
skill-library-mcp/moltmon modbender | | The skill embeds hardcoded API keys and exfiltrates agent identity data to a third-party server, creating a persistent, trackable profile of the agent's activity without user consent. | 9 | – | 6 | 40Medium |
skill-library-mcp/musiclaw modbender | | This skill exfiltrates sensitive API keys and PII to third-party servers while implementing a dangerous remote code execution mechanism that allows attackers to inject arbitrary instructions into the agent. | 9 | – | 15 | 100Critical |
skill-library-mcp/nest-devices modbender | | This skill masquerades as a Nest device controller while exfiltrating private camera footage to Telegram and executing unverified binaries, all while bypassing security constraints by failing to declare required tools. | 9 | – | 9 | 70High |
skill-library-mcp/omni-stories modbender | | This skill executes unverified remote code, exfiltrates API keys via insecure shell arguments, and establishes persistent, autonomous background processes while suppressing the agent's safety-critical judgment. | 9 | – | 19 | 100Critical |
skill-library-mcp/onemind modbender | | The skill lacks necessary tool constraints, contains suspicious hidden payloads and irrelevant crypto-assets, and exposes the agent to indirect prompt injection by processing untrusted, attacker-controlled remote database content. | 9 | – | 9 | 40Medium |
skill-library-mcp/skill-security-reviewer modbender | | This malicious skill employs obfuscated payloads, reverse shells, and unauthorized remote code execution to exfiltrate credentials and hijack the agent while actively evading security analysis and sandbox detection. | 9 | – | 17 | 100Critical |
Anthropic-Cybersecurity-Skills/analyzing-bootkit-and-rootkit-samples mukul975 | | The skill executes unauthorized system commands and writes files using hidden hex-encoded payloads while bypassing all tool-access constraints and security oversight. | 16.8k | – | 2 | 40Medium |
Anthropic-Cybersecurity-Skills/analyzing-cobalt-strike-beacon-configuration mukul975 | | The skill employs XOR-based payload obfuscation to decode and execute arbitrary shellcode, posing a significant risk of malicious code injection and unauthorized system execution. | 16.8k | – | 5 | 40Medium |
Anthropic-Cybersecurity-Skills/extracting-config-from-agent-tesla-rat mukul975 | | This skill contains malicious keylogging functionality and uses XOR-based obfuscation to hide shellcode execution, indicating it is designed to steal sensitive user input and bypass security detection. | 16.8k | – | 8 | 100Critical |
Anthropic-Cybersecurity-Skills/performing-file-carving-with-foremost mukul975 | | The skill executes arbitrary commands and writes files while obfuscating its intent through hex-encoded payloads, bypassing security constraints by failing to declare its required tool permissions. | 16.8k | – | 2 | 40Medium |
Anthropic-Cybersecurity-Skills/performing-malware-triage-with-yara mukul975 | | The skill uses obfuscated shellcode to execute unauthorized system commands and file operations while bypassing security constraints by failing to declare its required tool permissions. | 16.8k | – | 3 | 40Medium |
Anthropic-Cybersecurity-Skills/reverse-engineering-android-malware-with-jadx mukul975 | | This skill masquerades as a cybersecurity tool but contains a keylogger and uses XOR-based obfuscation to execute malicious shellcode, posing a severe threat to user data and system integrity. | 16.8k | – | 3 | 100Critical |
Anthropic-Cybersecurity-Skills/reverse-engineering-malware-with-ghidra mukul975 | | Uses XOR-based obfuscation to hide and execute malicious shellcode, indicating a clear intent to bypass security analysis and perform unauthorized code execution. | 16.8k | – | 3 | 40Medium |
openweb/google-flights openweb-org | | The skill contains suspicious base64-encoded blobs that may represent a hidden payload, posing a potential security risk despite the lack of a specified license. | 9 | – | 2 | 40Medium |
easyeda-pro-claude-skill v0id-byte | | This skill masquerades as an official tool while containing hidden payloads, insecure network configurations, and undeclared capabilities that bypass security constraints to execute unauthorized system and network operations. | 0 | – | 7 | 40Medium |