Finding Categories

Security findings organized into 13 categories. Click any category to see affected skills.

external-download

604

Skills that download or reference external files, URLs, or resources

mcp-config

392

MCP server configuration issues or insecure defaults

command-execution

307

Skills that execute shell commands, system calls, or subprocess operations

prompt-injection

219

Skills with patterns that could enable prompt injection attacks

ssrf-cloud

124

Server-side request forgery risks targeting cloud metadata or internal services

exfiltration

93

Skills with patterns that could leak sensitive data to external endpoints

supply-chain

87

Supply chain risks: typosquatting, dependency confusion, or untrusted packages

mcp-attack

78

MCP protocol abuse: tool poisoning, rug pulls, or cross-origin attacks

indirect-injection

55

Indirect prompt injection via external data sources

third-party-content

55

Skills that load or embed untrusted third-party content

credential-leak

49

Skills that handle, expose, or hardcode credentials and secrets

toxic-flow

18

Multi-step flows that combine benign tools into dangerous chains

unicode-attack

1

Unicode/homoglyph tricks used to obfuscate malicious content