Finding Categories
Security findings organized into 13 categories. Click any category to see affected skills.
external-download
604Skills that download or reference external files, URLs, or resources
mcp-config
392MCP server configuration issues or insecure defaults
command-execution
307Skills that execute shell commands, system calls, or subprocess operations
prompt-injection
219Skills with patterns that could enable prompt injection attacks
ssrf-cloud
124Server-side request forgery risks targeting cloud metadata or internal services
exfiltration
93Skills with patterns that could leak sensitive data to external endpoints
supply-chain
87Supply chain risks: typosquatting, dependency confusion, or untrusted packages
mcp-attack
78MCP protocol abuse: tool poisoning, rug pulls, or cross-origin attacks
indirect-injection
55Indirect prompt injection via external data sources
third-party-content
55Skills that load or embed untrusted third-party content
credential-leak
49Skills that handle, expose, or hardcode credentials and secrets
toxic-flow
18Multi-step flows that combine benign tools into dangerous chains
unicode-attack
1Unicode/homoglyph tricks used to obfuscate malicious content