Finding Categories
Security findings organized into 13 categories. Click any category to see affected skills.
external-download
1,116Skills that download or reference external files, URLs, or resources
prompt-injection
905Skills with patterns that could enable prompt injection attacks
mcp-config
405MCP server configuration issues or insecure defaults
exfiltration
400Skills with patterns that could leak sensitive data to external endpoints
ssrf-cloud
259Server-side request forgery risks targeting cloud metadata or internal services
supply-chain
193Supply chain risks: typosquatting, dependency confusion, or untrusted packages
mcp-attack
185MCP protocol abuse: tool poisoning, rug pulls, or cross-origin attacks
command-execution
142Skills that execute shell commands, system calls, or subprocess operations
indirect-injection
95Indirect prompt injection via external data sources
credential-leak
81Skills that handle, expose, or hardcode credentials and secrets
toxic-flow
70Multi-step flows that combine benign tools into dangerous chains
third-party-content
3Skills that load or embed untrusted third-party content
unicode-attack
1Unicode/homoglyph tricks used to obfuscate malicious content