Threat Research
Skill Risk Index
Real security scans of the most popular AI agent skills.
Available for these agents| Skill | Stars | Findings | Risk |
|---|---|---|---|
| cann-review github/leoyeai This skill sends sensitive values to an external host and executes remote code during use. Automated analysis flagged 6 additional risk patterns. | 2.1k | 21 | Critical |
| figma-to-static github/leoyeai This skill reads local credential files and sends sensitive values to an external host. Automated analysis flagged 2 additional risk patterns. | 2.1k | 6 | Critical |
| openclaw-workflow github/leoyeai Automated analysis flagged 8 potential risk patterns. | 2.1k | 8 | Critical |
| proactive-amcp github/leoyeai This skill sends sensitive values to an external host and reads local credential files. Automated analysis flagged 9 additional risk patterns. | 2.1k | 32 | Critical |
| wtt-skill github/leoyeai This skill sends sensitive values to an external host and reads local credential files. Automated analysis flagged 7 additional risk patterns. | 2.1k | 13 | Critical |
| textme github/sickn33 This skill executes remote code during use and sends sensitive values to an external host. Automated analysis flagged 1 additional risk pattern. | 43.8k | 3 | High |
| boss-cli github/jackwener This skill sends sensitive values to an external host. Automated analysis flagged 1 additional risk pattern. | 842 | 3 | High |
| clawsend github/leoyeai Automated analysis flagged 4 potential risk patterns. | 2.1k | 4 | High |
| wemp-ops github/leoyeai This skill sends sensitive values to an external host. Automated analysis flagged 2 additional risk patterns. | 2.1k | 3 | High |
| gh-issues github/openclaw Automated analysis flagged 2 potential risk patterns. | 385.8k | 2 | Medium |
| skill-creator github/openclaw Automated analysis flagged 4 potential risk patterns. | 385.8k | 4 | Medium |
| sandbox-bench github/vercel Automated analysis flagged 3 potential risk patterns. | 141.7k | 3 | Medium |
| design github/nextlevelbuilder Automated analysis flagged 2 potential risk patterns. | 115.3k | 2 | Medium |
| mode-creator github/thedotmack This skill sends sensitive values to an external host. Automated analysis flagged 1 additional risk pattern. | 90.3k | 2 | Medium |
| paperclip github/paperclipai This skill sends sensitive values to an external host. Automated analysis flagged 1 additional risk pattern. | 76.4k | 2 | Medium |
| bmad-deep-recon github/bmad-code-org Automated analysis flagged 2 potential risk patterns. | 51.7k | 2 | Medium |
| macrocli github/hkuds This skill sends sensitive values to an external host. Automated analysis flagged 1 additional risk pattern. | 46.9k | 5 | Medium |
| qa-team github/posthog Automated analysis flagged 2 potential risk patterns. | 37.6k | 2 | Medium |
| markitdown github/k-dense-ai Automated analysis flagged 3 potential risk patterns. | 33.1k | 3 | Medium |
| scientific-slides github/k-dense-ai This skill sends sensitive values to an external host. Automated analysis flagged 1 additional risk pattern. | 33.1k | 2 | Medium |
| heroui-native github/heroui-inc This skill executes remote code during use. Automated analysis flagged 2 additional risk patterns. | 30.3k | 4 | Medium |
| deploy-to-vercel github/vercel-labs This skill sends sensitive values to an external host. | 29.9k | 2 | Medium |
| antigravity github/jackwener This skill contains obfuscated or hidden content. Automated analysis flagged 2 additional risk patterns. | 28k | 3 | Medium |
| baoyu-post-to-x github/jimliu Automated analysis flagged 3 potential risk patterns. | 24.8k | 3 | Medium |
| ce-optimize github/everyinc Automated analysis flagged 2 potential risk patterns. | 24.2k | 2 | Medium |
| ce-pov github/everyinc Automated analysis flagged 2 potential risk patterns. | 24.2k | 2 | Medium |
| archon github/coleam00 This skill executes remote code during use. Automated analysis flagged 1 additional risk pattern. | 23.1k | 2 | Medium |
| colleague-skill github/titanwings This skill sends sensitive values to an external host. | 20.8k | 2 | Medium |
| video-use github/browser-use This skill sends sensitive values to an external host. Automated analysis flagged 1 additional risk pattern. | 20.5k | 2 | Medium |
| Aphorisms github/danielmiessler Automated analysis flagged 4 potential risk patterns. | 17.9k | 4 | Medium |
| Art github/danielmiessler Automated analysis flagged 3 potential risk patterns. | 17.9k | 3 | Medium |
| BrightData github/danielmiessler This skill sends sensitive values to an external host. Automated analysis flagged 1 additional risk pattern. | 17.9k | 2 | Medium |
| vast-gpu github/wanshuiyin Automated analysis flagged 2 potential risk patterns. | 14.5k | 2 | Medium |
| openapi-to-mcp github/mcp-use Automated analysis flagged 3 potential risk patterns. | 10.5k | 3 | Medium |
| Kami github/tw93 Automated analysis flagged 2 potential risk patterns. | 10.5k | 2 | Medium |
| browser-automation github/civitai This skill sends sensitive values to an external host. Automated analysis flagged 1 additional risk pattern. | 7.2k | 2 | Medium |
| cloudflare github/civitai This skill sends sensitive values to an external host. Automated analysis flagged 1 additional risk pattern. | 7.2k | 2 | Medium |
| building-register-search github/nomadamas This skill contains prompt-injection style instructions. Automated analysis flagged 1 additional risk pattern. | 7.1k | 2 | Medium |
| webnovel-write github/lingfengqaq Automated analysis flagged 3 potential risk patterns. | 6.4k | 3 | Medium |
| bb-browser github/epiral This skill sends sensitive values to an external host. Automated analysis flagged 3 additional risk patterns. | 6k | 4 | Medium |
| n8n-self-hosting github/czlonkowski This skill sends sensitive values to an external host. Automated analysis flagged 1 additional risk pattern. | 6k | 2 | Medium |
| films-search github/netease-youdao This skill sends sensitive values to an external host. Automated analysis flagged 2 additional risk patterns. | 5.9k | 4 | Medium |
| music-search github/netease-youdao This skill sends sensitive values to an external host. Automated analysis flagged 3 additional risk patterns. | 5.9k | 4 | Medium |
| story github/worldwonderer This skill sends sensitive values to an external host. Automated analysis flagged 1 additional risk pattern. | 5.4k | 2 | Medium |
| amazon-alexa-qa github/browser-act This skill sends sensitive values to an external host. Automated analysis flagged 1 additional risk pattern. | 5.3k | 2 | Medium |
| google-maps-contact-extract github/browser-act Automated analysis flagged 4 potential risk patterns. | 5.3k | 4 | Medium |
| indeed-job-search github/browser-act This skill sends sensitive values to an external host. | 5.3k | 2 | Medium |
| linkedin-jobs-search github/browser-act This skill sends sensitive values to an external host. Automated analysis flagged 2 additional risk patterns. | 5.3k | 3 | Medium |
| webcrawler-deep-crawl github/browser-act This skill sends sensitive values to an external host. Automated analysis flagged 1 additional risk pattern. | 5.3k | 3 | Medium |
| facebook-groups-scrape-posts github/browser-act This skill sends sensitive values to an external host. Automated analysis flagged 1 additional risk pattern. | 5.3k | 2 | Medium |
| x-dm-auto-chat github/browser-act This skill sends sensitive values to an external host. Automated analysis flagged 3 additional risk patterns. | 5.3k | 6 | Medium |
| macos-spm-app-packaging github/dimillian Automated analysis flagged 2 potential risk patterns. | 3.9k | 2 | Medium |
| ops-monitor github/davepoon This skill sends sensitive values to an external host. Automated analysis flagged 1 additional risk pattern. | 3.3k | 2 | Medium |
| ops-package github/davepoon This skill sends sensitive values to an external host. | 3.3k | 7 | Medium |
| ops-yolo github/davepoon This skill sends sensitive values to an external host. Automated analysis flagged 2 additional risk patterns. | 3.3k | 3 | Medium |
| google-workspace github/mitsuhiko This skill sends sensitive values to an external host. Automated analysis flagged 1 additional risk pattern. | 2.8k | 2 | Medium |
| browser github/stellarlinkco Automated analysis flagged 4 potential risk patterns. | 2.7k | 4 | Medium |
| comet-classic-039-verify github/rpamis Automated analysis flagged 2 potential risk patterns. | 2.7k | 2 | Medium |
| pair-trade-screener github/tradermonty This skill sends sensitive values to an external host. | 2.6k | 2 | Medium |
| agents-pay github/aws This skill sends sensitive values to an external host. Automated analysis flagged 3 additional risk patterns. | 2.3k | 5 | Medium |
| aws-transform github/aws Automated analysis flagged 2 potential risk patterns. | 2.3k | 2 | Medium |
| ai-drama-prompt-factory github/leoyeai Automated analysis flagged 2 potential risk patterns. | 2.1k | 2 | Medium |
| ai-flight github/leoyeai This skill sends sensitive values to an external host. Automated analysis flagged 2 additional risk patterns. | 2.1k | 4 | Medium |
| ai-md github/leoyeai Automated analysis flagged 2 potential risk patterns. | 2.1k | 2 | Medium |
| airfly github/leoyeai This skill sends sensitive values to an external host. Automated analysis flagged 1 additional risk pattern. | 2.1k | 3 | Medium |
| airticket github/leoyeai This skill sends sensitive values to an external host. Automated analysis flagged 1 additional risk pattern. | 2.1k | 3 | Medium |
| awp github/leoyeai This skill sends sensitive values to an external host. | 2.1k | 5 | Medium |
| bankr-2 github/leoyeai This skill sends sensitive values to an external host. Automated analysis flagged 1 additional risk pattern. | 2.1k | 2 | Medium |
| chanjing-one-click-video-creation github/leoyeai This skill sends sensitive values to an external host. | 2.1k | 2 | Medium |
| cl-lp-rebalancer github/leoyeai This skill sends sensitive values to an external host. | 2.1k | 2 | Medium |
| claw-future github/leoyeai Automated analysis flagged 2 potential risk patterns. | 2.1k | 2 | Medium |
| claw-social github/leoyeai This skill sends sensitive values to an external host. | 2.1k | 4 | Medium |
| clawbuddy-buddy github/leoyeai This skill sends sensitive values to an external host. Automated analysis flagged 2 additional risk patterns. | 2.1k | 3 | Medium |
| codex-cli-task github/leoyeai This skill sends sensitive values to an external host. Automated analysis flagged 1 additional risk pattern. | 2.1k | 2 | Medium |
| codex-code-task github/leoyeai This skill sends sensitive values to an external host. Automated analysis flagged 1 additional risk pattern. | 2.1k | 2 | Medium |
| conduxt github/leoyeai Automated analysis flagged 4 potential risk patterns. | 2.1k | 4 | Medium |
| context-restore github/leoyeai This skill sends sensitive values to an external host. | 2.1k | 2 | Medium |
| crab github/leoyeai This skill sends sensitive values to an external host. Automated analysis flagged 1 additional risk pattern. | 2.1k | 2 | Medium |
| crypto-executor github/leoyeai This skill sends sensitive values to an external host. Automated analysis flagged 1 additional risk pattern. | 2.1k | 2 | Medium |
| cs-playwright-pro github/leoyeai Automated analysis flagged 2 potential risk patterns. | 2.1k | 2 | Medium |
| ctrip-flight github/leoyeai This skill sends sensitive values to an external host. Automated analysis flagged 2 additional risk patterns. | 2.1k | 4 | Medium |
| defipoly github/leoyeai Automated analysis flagged 4 potential risk patterns. | 2.1k | 4 | Medium |
| dinstein-tech-news-digest github/leoyeai This skill sends sensitive values to an external host. Automated analysis flagged 2 additional risk patterns. | 2.1k | 5 | Medium |
| edgeone-website-skeleton github/leoyeai Automated analysis flagged 3 potential risk patterns. | 2.1k | 3 | Medium |
| emblemai-agentwallet github/leoyeai Automated analysis flagged 3 potential risk patterns. | 2.1k | 3 | Medium |
| fbt-flight github/leoyeai This skill sends sensitive values to an external host. Automated analysis flagged 2 additional risk patterns. | 2.1k | 4 | Medium |
| fbt-hotel github/leoyeai Automated analysis flagged 3 potential risk patterns. | 2.1k | 3 | Medium |
| flightai github/leoyeai This skill sends sensitive values to an external host. Automated analysis flagged 1 additional risk pattern. | 2.1k | 3 | Medium |
| funai-skill github/leoyeai This skill sends sensitive values to an external host. Automated analysis flagged 2 additional risk patterns. | 2.1k | 3 | Medium |
| google-bigquery github/leoyeai This skill sends sensitive values to an external host. Automated analysis flagged 1 additional risk pattern. | 2.1k | 2 | Medium |
| google-classroom github/leoyeai This skill sends sensitive values to an external host. Automated analysis flagged 1 additional risk pattern. | 2.1k | 2 | Medium |
| health-score-pro github/leoyeai This skill sends sensitive values to an external host. | 2.1k | 2 | Medium |
| hsa-test3 github/leoyeai This skill sends sensitive values to an external host. Automated analysis flagged 2 additional risk patterns. | 2.1k | 3 | Medium |
| hsa-test4 github/leoyeai Automated analysis flagged 4 potential risk patterns. | 2.1k | 4 | Medium |
| i-am github/leoyeai Automated analysis flagged 3 potential risk patterns. | 2.1k | 3 | Medium |
| ifind-data github/leoyeai This skill sends sensitive values to an external host. Automated analysis flagged 3 additional risk patterns. | 2.1k | 4 | Medium |
| imap-smtp-email github/leoyeai Automated analysis flagged 3 potential risk patterns. | 2.1k | 3 | Medium |
| katbot-trading github/leoyeai This skill sends sensitive values to an external host. Automated analysis flagged 1 additional risk pattern. | 2.1k | 3 | Medium |
| last30days github/leoyeai Automated analysis flagged 2 potential risk patterns. | 2.1k | 2 | Medium |
| medeo-video github/leoyeai This skill sends sensitive values to an external host. | 2.1k | 3 | Medium |
Showing 100 of 20427 skills - scroll for more.
No skills match your filters.
Assessed by the Anomity Skill Intelligence engine. Findings indicate risk patterns, not confirmed exploitation. Maintainers can request a review or rescan. Machine-readable feed: feed.json - free with attribution, see the data terms. Plain-HTML listing of every skill: full skill directory.
Show you check your skills
Scanning your agent skills with Anomity? Add the badge to your README.
Skills are only half the picture
Scan-time vetting catches risky skills before install. Anomity governs what agents actually do at runtime: full visibility and enforcement across every AI agent and MCP. Book a 30-minute demo.




