Registry Security Reports

Aguara Watch scans every public AI agent skill registry continuously. These reports summarize the security posture of each registry, how we scan them, and what we find.

ClawHub Security Report

Security analysis of 9,983 AI agent skills on ClawHub, the registry where 341 malicious skills were found.

9,983 skills Avg score: 97/100

mcp.so Security Report

Security analysis of 9,145 MCP servers on mcp.so, a metadata-focused discovery platform with lower scan depth.

9,145 skills Avg score: 99/100

PulseMCP Security Report

Security analysis of 8,621 MCP servers listed on PulseMCP, with GitHub README scanning for code-level findings.

8,621 skills Avg score: 100/100

Skills.sh Security Report

Security analysis of 4,219 AI agent skills on Skills.sh, the community marketplace with full implementation details.

4,219 skills Avg score: 97/100

LobeHub Security Report

Security analysis of 545 AI agent plugins on LobeHub, the smallest monitored registry with focused plugin content.

545 skills Avg score: 100/100