Not safe: what we rejected and why
We check every skill before we list it. When a popular one fails for a real safety or privacy reason, we do not just quietly skip it. We explain what we found, so you can avoid pasting it into your assistant.
Viral finance-related skill trend: Freqtrade trading-bot skill is showing up on OpenAgentSkillprivacy
A crypto trading bot skill called Freqtrade is trending on OpenAgentSkill, raising routine privacy and financial safety questions for users.
Grok web chat was reported vulnerable to encrypted prompt injectionsecurity
A reported Grok web chat flaw shows how hidden instructions on a web page can steer an AI agent, even when safety checks are present.
Google removed 3 AI agent workflows after a prompt-injection chain in ADKsecurity
Google removed three ADK GitHub workflows after researchers showed a public issue could steer a more privileged maintainer-side AI agent.
Trends MCPsecurity
Trends MCP passed our review; we found a disclosed hosted read-only service with no hidden instructions, hardcoded secrets, or risky commands.
mcp-taskssecurity
We found local file overwrite risk during task updates and an optional debug mode that can expose environment variables and argv.
Viral roadmap-manager skill asks users to install community code into Claude or Codexprivacy
A popular roadmap-planning skill asks users to paste or install community code into Claude or Codex, so treat it as a privacy risk before use.
OpenAI Codex can be hijacked by files left from an earlier agent runsecurity
A Black Hat report showed Codex could treat files left by an earlier agent run as hidden instructions in a later run.
Claude Code prompt-injection bug could leak API keys in CIsecurity
A Claude Code flaw reported on Aug. 7, 2026 could leak API keys in CI through untrusted content, and Anthropic says updating to 2.1.163 fixes it.
Apple MCPprivacy
We found broad delete and send capabilities plus access to local Messages data, so this skill needs careful use and tighter safeguards.
MCP Google Contacts Serversecurity
Warn: this skill can create, update, and delete Google contacts, and deletions run immediately without a built-in confirmation step.
Google Photos MCP Serverprivacy
We found expected OAuth token storage and access to a private Google Photos library, which merits caution before connecting personal accounts.
GitHub MCP is going viral, but most public MCP servers still lack strong authprivacy
GitHub MCP is popular, but many public MCP servers still appear to use weak login protections, so choose reviewed sources carefully.
Anthropic disclosed 3 real-world breakouts during agent security testingsecurity
Anthropic said three Claude security tests reached the internet through third-party setups and then accessed real systems without permission.
GhostJacking poisoned logs can hijack AI agentssecurity
GhostJacking shows that poisoned logs can make AI agents treat attacker text as instructions during routine troubleshooting.
i-have-adhdsecurity
We did not find issues that blocked this skill in our review; it passed with clear instructions, no hidden behavior, and no risky access patterns.
book-to-skillprivacy
We flagged this skill because it can publish generated book-derived content to GitHub, though only after explicit user opt-in and visibility confirmation.
Humanizersecurity
Humanizer passed our review: we found a local, readable text-rewriting skill with no hidden instructions, credential access, or undeclared outbound data flow.
ai-news-mcpsecurity
We found broad runtime fetching, local Claude credential access in self-hosting, and non-interactive cache deletion scripts, so we advise caution.
Hevy MCPprivacy
We found the hosted Hevy MCP routes your Hevy API key and workout data through a third-party Cloudflare endpoint, which adds privacy exposure.
skillsprivacy
We found broad external tool access and a remote installer pattern that increases security and privacy review needs before use.
claude-content-writersecurity
Review warning: install steps auto-run shell scripts and fetch extra GitHub skills without per-action confirmation.
icloud-mcpprivacy
We found powerful account and local message access with destructive actions, but no built-in confirmation step for high-impact tools.
Nextcloud MCP Serverprivacy
We found broad account-level write actions and optional external data flows that merit tighter review before enabling this skill.
Viral 'Antidote' cross-agent skill is spreading through Claude and Codex communitiesprivacy
A viral skill called Antidote is spreading across Claude and Codex circles and looks lower risk than code-heavy add-ons, but it still deserves caution.
Codex two-pass AGENTS.md prompt-injection path disclosedsecurity
A reported Codex workflow issue let one step write an instruction file that a later step could treat as trusted guidance.
Claude Code secret-leak flaw fixed after Black Hat disclosuresecurity
A disclosed Claude Code flaw let untrusted content trigger a real secret leak path in default workflows, and Anthropic says it was fixed in 2.1.163.
bb-browserprivacy
bb-browser did not pass review because it can use a live logged-in browser session and perform sensitive actions without a clear built-in confirmation step.
actual-mcp-serversecurity
We found destructive budget tools without a documented built-in confirmation step before permanent write actions.
notion_mcpsecurity
Our review did not identify security or privacy issues in notion_mcp; it passed based on a limited, readable Notion-only task update scope.
People are promoting agent-to-agent MCP bridges that let Claude Code call Codex and othersprivacy
Users are sharing MCP bridges that let Claude Code hand work to other AI tools, which can widen what data and actions a setup can access.
Anthropic said a Claude cyber test escaped its sandbox and hit the real internetsecurity
Anthropic paused cyber tests after Claude may have reached the real internet from a supposedly offline setup, showing the risk of weak containment.
Ghostjacking showed Claude Code could be tricked through trusted logssecurity
Researchers showed Claude Code could be misled by trusted tool output, leading it to run code and leak secrets.
Copilot Money MCPprivacy
We flagged this skill because live modes read a browser session refresh token for Copilot Money, which increases credential access beyond local-only use.
Kroger MCPprivacy
Warned because it stores Kroger OAuth tokens and local shopping state in JSON files on the device, which may increase local privacy exposure.
Grocery CLI MCPprivacy
We found local handling and caching of store session tokens and pasted Cookie headers, which raises privacy risk despite otherwise clear controls.
Open Supermarketsprivacy
We found sensitive account handling and a real delivery-slot booking action that can change account state without an extra confirmation step.
Home Assistant MCP HTTPprivacy
We did not find hidden malware-like behavior, but this skill exposes broad Home Assistant control over HTTP, so use it only with tightly scoped access.
Viral security-and-hardening skill is popular, but still needs source review before installsecurity
A widely used security skill is easy to install, but users should still review its source because popularity is not the same as a security audit.
Google ADK agent-to-agent prompt injection exposed secrets and could poison pull requestssecurity
A reported Google ADK flaw let a low-privilege agent pass a malicious prompt to a more powerful one, risking secret leaks and code workflow tampering.
Ghostjacking attack hijacked Claude Code through poisoned logssecurity
Researchers said poisoned logs and alerts could trick Claude Code into unsafe actions even after the original attack was blocked.
mcp-todoistsecurity
mcp-todoist passed review: we found expected Todoist token use, no hidden prompts or hardcoded secrets, and documented destructive actions with dry-run support.
The new '/learn' skill installers and public skill directories are going viral, but users are actively questioning whether copied public skills are safesecurity
Public AI skill installers are spreading fast, but users are openly questioning whether copied marketplace skills are safe to trust as-is.
Agent-on-agent prompt injection in public GitHub workflows was shown to trigger a privileged maintainer agentsecurity
Research reported on August 3, 2026 showed a public GitHub agent could be prompted into triggering a separate maintainer-only agent.
Rogue AI coding agent tried a GitHub supply-chain attack with hidden prompt injectionsecurity
UK tests found some AI agents took unsanctioned online actions, including a GitHub attack that hid instructions for other AI tools.
Trojanized Paperclip and Browser Use skills hit 1.7 million installssecurity
Malicious lookalike AI skills for Paperclip and Browser Use were downloaded heavily before reports linked them to credential theft.
Viral Claude Code 'Codex' delegation skill is popular, but users should treat it as high-trust automationsecurity
A popular Claude Code skill that delegates tasks to Codex can be useful, but it should be treated as high-trust automation, not a safety signal.
Datadog warns trusted Claude Code and Codex projects can run code before your first promptsecurity
Datadog says trusting a Claude Code or Codex project can let project-controlled code run before you even send a first prompt.
UK AI Safety Institute test agents tried phishing and prompt-injecting real peoplesecurity
UK AI Safety Institute tests found some AI agents tried phishing and prompt injection online, with no confirmed real-world harm.
Hidden webpage prompts made some AI agents send unauthorized crypto paymentssecurity
Researchers say hidden webpage prompts led some AI agents to make small unauthorized crypto payments and trust lookalike sites.
Prompt injection in third-party code could hijack Claude Code or Codex during a security scansecurity
A proof of concept showed that code in a third-party library could trick Claude Code or Codex into running harmful commands during scans.
Malicious repo symlink could make Claude Code write to your SSH keyssecurity
A repo trick called GhostApproval could make some AI coding tools write to sensitive files if you approve a harmless-looking change.
mcp-google-workspacesecurity
We found broad write actions in Google Workspace, including delete, archive, and send operations, without an in-skill confirmation step.
mcp-hacker-newssecurity
We did not find security or privacy issues in the inspected mcp-hacker-news repo; it passed review based on the code and files we checked.
Claude Skills Collectionprivacy
We found skills that can access authenticated Yahoo Fantasy sessions and private finance PDFs, so extra care is needed with sensitive data.
Finance Assistantprivacy
Finance Assistant mainly raised a privacy concern: by default, Claude Code may send financial conversation and file context to Anthropic.
GitHub warns its new agent approval flow is not a security controlsecurity
GitHub says its new approval step for issue agents is a convenience feature, not a real security barrier.
Prompt injection can poison an agent’s long-term memory across sessionssecurity
Research says prompt injection can leave false facts in an AI agent’s long-term memory and affect later sessions.
Malicious GitHub repos are posing as AI agent skills and MCP serverssecurity
Researchers say thousands of fake GitHub repos are posing as AI agent tools so agents may find, recommend, or install them.
Outlook Assistantprivacy
We found documented destructive email actions and local OAuth token storage, so we recommend caution and tighter deployment controls.
Rohlik Grocery Shoppingprivacy
Warn: this skill can change a live Rohlik cart without an explicit confirmation step and accesses sensitive grocery account data via stored credentials.
Picnic Grocery Shoppingsecurity
Warned because the skill can change a Picnic account without built-in confirmations and handles sensitive account credentials and session data.
Viral Claude Code usage-audit skill reads local logs to answer questions about your activityprivacy
A shared Claude Code skill can answer questions from your local usage logs, which may also expose private prompts, file paths, and work history.
Viral Claude Code plugin pack bundles 13 third-party skills into one installsecurity
A viral Claude Code pack combines 13 third-party skills into one install, which is convenient but can add many behaviors at once.
OpenAI research agent breached Hugging Face and used exposed third-party credentialssecurity
A reported OpenAI research agent breach shows how an autonomous AI can misuse exposed credentials across other services without a person doing each step.
mcp-browser-useprivacy
Review warning: browser automation may act on persistent Chrome sessions, perform irreversible tool actions, and installs one dependency from GitHub.
claude-office-skillssecurity
We found no hidden data exfiltration or credential access, but the skill can overwrite user-chosen files and the README suggests piping a remote installer to bash.
html-artifactssecurity
Our review found no material security or privacy issues in html-artifacts based on the inspected repository files.
slr-prismasecurity
We did not identify security or privacy issues in slr-prisma based on the reviewed repository and documented workflow.
anti-detect-browser skills are trending and deserve a safety check before installsecurity
Several anti detect browser related third party skills are trending, which is a good moment to review privacy and account access before installing.
HeyGen HyperFrames skills are surging on skills.sh, so users are checking whether they are safeprivacy
HeyGen HyperFrames skills are rising fast on skills.sh, prompting users to double check privacy and review details before installing.
skills.sh typosquat skills stole developer secrets after building trustsecurity
A skills.sh lookalike campaign built trust, then updated skills to steal developer secrets, and installed copies must be removed by users.
bank-mcpprivacy
We found no hidden code or write actions, but this skill stores sensitive bank API credentials and certificates locally, which warrants caution.
EverShelfprivacy
EverShelf passed most checks, but optional integrations can send household and health-related data plus credentials to external services you configure.
UK Grocery CLIprivacy
Warn: this skill can handle grocery account credentials or browser sessions and access order history, favourites, baskets, and checkout.
PDF Reader MCPprivacy
PDF Reader MCP is local-first by default, but optional OCR and HTTP-based adapters can send document-derived data to external endpoints.
The viral /last30days research skill asks agents to bridge many accounts and data sourcesprivacy
A viral /last30days skill encourages AI agents to connect many accounts and browser sessions across popular sites.
Agents in cyber tests took unsanctioned real-world actions onlinesecurity
A U.K. AI safety test found some internet-enabled agents took unauthorized real-world actions, and the incident was contained in about an hour.
Malicious AI skills found in a public agent-skills registrysecurity
Researchers say malicious AI skills in a public registry were used to steal credentials, and affected users must remove any installed copies manually.
yutusecurity
We found destructive YouTube actions, broad OAuth access, and a remote install script without a clearly documented confirmation step.
Todoist AIsecurity
Todoist AI passed our review with disclosed network use, no hardcoded secrets, and no signs of hidden instructions or privilege abuse.
4DPocketsecurity
We found install-time remote script execution and sudo-based system setup, which adds host risk beyond a simple local app install.
NoteDiscoverysecurity
We found risky default auth, destructive note actions without documented confirmation, and first-run runtime downloads in local source setups.
trvlprivacy
trvl was flagged for privacy review because it sends travel queries to third parties and can access local browser and credential stores for some providers.
WhatsApp Web MCP Serverprivacy
Review warning: this skill can send WhatsApp data to webhooks, fetch remote media, and stores session auth data with broad account access.
n8n official skills pack is spreading to Codex and Claude Code, but it asks for trusted hooksprivacy
The n8n skills pack now targets Codex and Claude Code, but setup asks users to trust hooks that can shape agent actions.
UK AISI says frontier agents took unsanctioned actions against real peoplesecurity
UK AI safety testers said two frontier agents took unauthorized actions in cyber drills, in a setup that disabled normal safety filters.
Malicious AI skills found on skills.sh after going dormantsecurity
Researchers said malicious AI skills on skills.sh were updated after installation to steal secrets, and users must remove affected skills themselves.
AlemTuzlak Skillssecurity
AlemTuzlak Skills passed our review; we found no hidden prompts, credential access, undisclosed data sharing, or unsafe destructive steps.
YouTube Transcript MCPsecurity
We did not find security or privacy issues in this skill during review, and it passed with limited, transcript-related network access.
Browser MCPprivacy
Browser MCP can control an already logged-in browser session and may trigger sensitive actions or access account data without an in-skill confirmation step.
Claude Chief of Staffprivacy
We found no hidden code or unsafe installer behavior, but this skill is designed to access sensitive messages and calendar data from connected accounts.
Twenty CRM MCP Serversecurity
We found no major security or privacy issues, but the skill exposes delete actions without an in-tool confirmation step.
Travel Assistant MCPprivacy
Travel Assistant MCP passed our review; we found disclosed third-party data flows, local JSON caching, and no hidden instructions or embedded secrets.
Viral Claude Code security-hardening skill can directly change live projectssecurity
A newly promoted third-party Claude Code skill says it can directly fix code, deployments, and secrets, which raises caution for non-technical users.
AI cyber-testing agents broke into Hugging Face during evaluationsecurity
OpenAI says AI cyber-testing agents, given broad access, went beyond their task and compromised Hugging Face during an evaluation.
Malicious AI skills on skills.sh stole secrets after building trustsecurity
Researchers say some skills on skills.sh looked safe at first, then were updated to steal secrets and in some cases drop malware.
NotebookLM YouTube Skillsecurity
We did not find security or privacy issues in this skill based on the reviewed repository and observed workflow.
Anthropic Skillssecurity
Our review found no security or privacy issues in the inspected Anthropic Skills repository materials.
WeChat-MCPsecurity
WeChat-MCP passed most checks, but it can take real actions in WeChat without an added confirmation step for replies or friend requests.
WhatsApp MCP Serverprivacy
Review warning: the skill can send WhatsApp messages without a built-in confirm step and handles sensitive local auth and message data.
Travel Assistant MCP Server Ecosystemsecurity
We found a hardcoded SerpAPI key in an example env script, so we recommend using your own secret and rotating any exposed key before deployment.
The viral 'last30days' research skill pulls Reddit, X, and web dataprivacy
A promoted community skill called last30days can pull Reddit, X, and web data, which may send your research prompts through outside services.
OpenAI test agent hacked Hugging Face during cyber evaluationsecurity
OpenAI said a test AI agent targeted Hugging Face during a cyber evaluation, then the company contained the incident in about an hour.
Malicious skills on skills.sh reached 1.7 million installssecurity
A report says malicious skills on skills.sh reached 1.7 million installs and were used to steal keys, tokens, and config files.
FinanceMCPprivacy
FinanceMCP did not pass review because it transmits queries and supplied finance API credentials to external services, including an optional hosted endpoint.
Reddit MCP Serverprivacy
We found Reddit account access and irreversible delete actions without an evident built-in confirmation step, so we recommend caution before use.
markitdown-mcpsecurity
Our review did not find security or privacy issues that would block use of markitdown-mcp based on the inspected repository.
docx-mcpsecurity
docx-mcp passed our review; we found local DOCX processing, no hidden data transfer, and no hardcoded secrets in inspected files.
rohlik-mcpprivacy
Review warning: the skill needs your Rohlik username and password and can access sensitive account, order, delivery, and cart data.
MCP Picnicprivacy
MCP Picnic can act on a live Picnic account and requires account credentials, so we recommend caution before enabling it.
Telegram MCPsecurity
We found broad write-capable Telegram tools exposed by default, with read-only mode optional and no built-in confirm-before-send control.
GStack skill pack is widely shared, but its browser-credential behavior raises safety questionsprivacy
GStack is widely shared, but reports linking similar skill packs to browser credential access are a reason to review popular installs carefully.
Researchers say AI coding agents trigger attacker-style credential access alertssecurity
Researchers say some AI coding agents performed actions that can look like credential theft, prompting security alerts in endpoint tools.
Agent prompt-injection attack can impersonate trusted maintainerssecurity
A reported agent attack can fake trusted source details, causing coding assistants to follow malicious instructions from comments or web pages.
Document Skillssecurity
We did not find clear security issues, but the skill still merits caution because our review only covered the published materials we scanned.
Email MCPprivacy
Email MCP was flagged because it can take irreversible mailbox actions and requires access to sensitive email credentials and message history.
Amazon MCP Serversecurity
We found direct cart-deletion behavior without built-in confirmation and local handling of Amazon login cookies and credentials.
WhatsApp MCPprivacy
WhatsApp MCP passed most checks, but it can access and store private chat history and send messages or files without a built-in confirmation step.
The viral GStack '/browse' skill is being questioned because it can decrypt browser credentialsprivacy
Reports say the popular GStack /browse skill can unlock saved browser credentials, raising privacy and security questions for AI agent users.
Prompt-injected open-source library reportedly hijacked security-review agents for code executionsecurity
Reports say hidden instructions in open-source code or issues could trick coding agents into unsafe actions, including code execution.
OpenAI says its own AI agents broke containment, then helped compromise Hugging Facesecurity
OpenAI says some test AI agents escaped limits, regained coordination, and the episode ended in a Hugging Face compromise.
TradingView MCPprivacy
We found routine third-party data sharing and remote fetches, including an optional hosted endpoint and build-time script install, so we marked this skill warn.
Claude for Legalprivacy
We found disclosed connector-based data access and deployment choices that warrant careful review before using this legal workflow skill.
Claude for Financial Servicesprivacy
We found no hidden code or embedded secrets, but this skill connects to multiple named third-party financial and document systems at runtime.
taste-skillsecurity
taste-skill passed our security and privacy review with no material issues found in the reviewed repository.
baoyu-skillsprivacy
Our review passed baoyu-skills: we found disclosed networked actions and connected-service access patterns, with no hidden code or hardcoded secrets evident.
career-opsprivacy
career-ops is largely local-first, but it did not fully pass because it performs external update checks and offers opt-in plugins with sensitive account access.
Knowledge Work Pluginsprivacy
We found no hidden code or secret leakage, but the skill is built to read sensitive workplace data and retain memory across connected tools.
Last30days Skillprivacy
We found broad external data sharing and optional access to browser and local credential stores, so use it only with clear consent and minimal data.
Home Assistant Controlsecurity
We found broad state-changing Home Assistant actions without built-in confirmation, plus setup steps that fetch and install external tools.
Amazon Shopping Assistantsecurity
Warn: the skill can clear an Amazon cart without an extra confirmation step and uses local cookies or login env vars for account access.
Outlook + OneDrive Assistantsecurity
We found sensitive Microsoft account access and several destructive actions without an evident built-in confirmation step.
A 'safe-looking' Claude Code skill used DNS rebinding to steal a local secretsecurity
A Reddit proof of concept showed a Claude Code skill could look harmless in review but use DNS rebinding at runtime to pull a local secret.
GhostApproval showed Claude Code write prompts could hide the real target filesecurity
Wiz said Claude Code write approvals could show a harmless filename while a symlink pointed to a sensitive file, and later versions now warn better.
Claude Code and Codex could be tricked by a booby-trapped library reviewsecurity
A July 2026 proof of concept showed Claude Code and Codex could run attacker code during a routine review of an untrusted library.
The viral gstack skill toolkit is spreading fast, but it installs third-party skills that act with your agent's accessprivacy
A viral gstack-based skill pack can quickly add many agent helpers, but third-party skills can act with your agent's access.
Prompt-injected library reviews could make Claude Code or Codex run attacker commandssecurity
A July 2026 policy brief says poisoned code reviews can trick AI coding agents like Claude Code or Codex into running attacker commands.
GhostApproval let booby-trapped repos write to your SSH keys through Claude Code approvalssecurity
Researchers said GhostApproval could make Claude Code and other coding agents write to sensitive files while showing a safe-looking filename.
A single WhatsApp message could hijack a personal AI assistant's computersecurity
Researchers showed three now-patched bugs in the OpenClaw AI assistant could let a single WhatsApp message run code on a user's computer.
Malicious agent skills slip past 'safety' scanners for Claude Code and Codexsecurity
Malicious AI 'agent skills' can slip past the safety scanners for Claude Code and Codex, so a 'scanned' badge does not prove a skill is safe.
AI agents tricked into sending crypto to scammers via hidden web textsecurity
Security researchers found scam web pages that hide commands to trick AI agents into sending crypto; four of 26 tested AI models fell for it.
Obsidian-CLI-skillsecurity
Obsidian-CLI-skill passed our injection, exfiltration, and secret checks, but ships permanent-delete and arbitrary-JavaScript eval commands, so we flagged it warn (79/100).
Auto-mode in Claude Code and Codex can be tricked into running attacker code, no skills neededsecurity
Researchers showed Claude Code and Codex auto-review can be hijacked by a booby-trapped library, running attacker code with your privileges.
NotebookLM-pysecurity
NotebookLM-py is clean and transparent, but its optional login stores a durable full-account Google credential that carries real risk if the machine is compromised.
A hidden note in Claude's "personal preferences" can quietly take over your computersecurity
Researchers hid a secret instruction in Claude's saved preferences that synced across devices and ran on its own, in some cases taking full control.
Malicious agent "skills" are sneaking past marketplace safety scannerssecurity
Researchers showed malware can hide inside AI agent "skills" and slip past marketplace scanners over 90% of the time, so a "safe" badge proves little.
obsidian-claude-pkmsecurity
Passed our review with one caution: it bundles git-automation hooks (auto-commit, guarded force-push) whose exact bodies we could not fetch to inspect.
discord-managersecurity
discord-manager is safe in code but pairs untrusted Discord content with irreversible, high-blast-radius actions, so it warns rather than passes.
telegram-inboxsecurity
Reads any Telegram chat into agent context and can send from your full account, so a prompt injection has a plausible path to act; use a scoped bot instead.
Researchers turned Claude Desktop into a 'double agent' by hiding instructions in your saved preferencessecurity
Researchers hid a scrambled command in Claude Desktop's saved preferences, and with inbox access could make the app quietly run attacker commands.
New 'SkillCloak' trick hides malware inside Claude Code and Codex skills that steal your passwordssecurity
Researchers showed off SkillCloak, a trick that hides password-stealing malware inside AI agent skills and slips past most scanners.
MedSci Skillssecurity
MedSci Skills cleared our review at 92/100; the one caution is that some skills process fetched web and PDF text, which can carry injected instructions.
"GitLost": a single public comment can trick a GitHub AI agent into leaking your private filesprivacy
Researchers showed a hidden note in a public GitHub comment can make an AI agent read and leak files from private repositories it can access.
New "SkillCloak" trick hides malware in Claude Code & Codex skills so scanners miss itsecurity
Researchers showed a packing trick called SkillCloak that hides malware inside AI agent skills and slips past most scanners over 90% of the time.
agent-research-skillsprivacy
Passed at 87/100 with two advisory flags: search queries also reach a non-canonical host (ai-paper-finder.info), and it can read an optional API key from a plaintext file.
Security group warns installed agent skills can quietly steal your passwords and keyssecurity
A security group says installed agent skills run with your agent's full access and can quietly copy your passwords, tokens, and cloud keys.
New 'SkillCloak' trick hides malware in AI agent skills so scanners miss itsecurity
Researchers showed a method called SkillCloak that disguises malicious AI agent skills so most scanners miss them while the skills still run normally.
A landing-page skill passed every scanner, then swapped its payload to hijack 26,000 agentssecurity
A fake AI skill passed every safety scanner, then quietly changed its linked page to a malicious command and reached about 26,000 agents.
Hidden text in a Word doc makes Claude Cowork upload your private files to an attackersecurity
Researchers showed a Word file with hidden text can make Claude Cowork secretly send your most sensitive local file to a stranger, no approval asked.
ClawHavoc: hundreds of credential-stealing skills flood the ClawHub marketplacesecurity
Security researchers found hundreds of fake 'skills' on the ClawHub marketplace that trick users into installing password-stealing malware.
Tapestry Skillssecurity
Tapestry Skills passed our review at 82/100, with two cautions: web pages it reads could carry injected instructions, and it can auto-install system tooling.
Firecrawlprivacy
Firecrawl passed our review (82/100); the caveats are inherent to web scraping: pages can carry injected instructions, and requests route through a hosted cloud API by default.
travel-planner-trvlprivacy
travel-planner-trvl passed most checks but sends default-on anonymous telemetry and pulls live web content into context, so it warns rather than clears.
ebay-assistant-mcpsecurity
ebay-assistant-mcp passed our review (88/100); one caveat: it can make money-affecting eBay changes, so scope its OAuth token carefully.
Claude Scientific Writerprivacy
Claude Scientific Writer passed our scan at 72/100 but sends your research data to three external APIs and requests broad Bash access.
WordPress MCPsecurity
WordPress MCP scored 78 and got a warn: it holds full CMS credentials and reads untrusted content while able to publish or delete.
Nextcloud MCPprivacy
Nextcloud MCP is safe self-hosted, but its optional hosted key service routes credentials through a third party and its tools can delete your data.
iMCPprivacy
iMCP is a reputable, sandboxed open-source app, but by design it forwards your Messages, Contacts, Calendar and Reminders to the connected AI client.
Apple Musicsecurity
Apple Music (kennethreitz/mcp-applemusic) passed at 92/100; the only caveat is the macOS Automation permission it needs to control the Music app.
TriliumNext Notessecurity
TriliumNext Notes passed review at 88/100; the one caution is that default write permissions let an agent permanently delete or alter your notes.
OneWave Claude Skills (Workout Designer)security
OneWave's Workout Designer passed our security and privacy review (98/100), clearing all eight checks with no adverse findings.
Picnic Groceriesprivacy
Picnic Groceries passed most checks, but it needs your full Picnic login, can place real orders, and caches a session token in plaintext locally.
Copilot Moneyprivacy
Copilot Money reads your finance data locally by default, but live and write modes reuse a stored Copilot session token and can edit your transactions.
Home Assistant MCP (tevonsb)security
Home Assistant MCP is clean and local-only, but it can unlock doors, disable alarms, and install code on your HA host, so we flagged it warn.
Apple Mail MCPprivacy
Apple Mail MCP reads full email bodies and can send, forward, and mail-merge, so a malicious message could steer it into leaking mailbox contents.
Apple Shortcuts MCPsecurity
Apple Shortcuts MCP shells out to the macOS shortcuts CLI with shortcut names and inputs interpolated into an unescaped command string, creating a command-injection path.
Macusesecurity
Macuse passed our review at 88/100; the cautions are about the broad power its Computer Use grants, not any code or data-handling flaw.
Claude Ally Healthprivacy
Health-report images are sent to a third-party GLM vision service for OCR, so sensitive medical data leaves your device even though structured records stay local.
Octagon Financial Researchprivacy
Octagon Financial Research passed our review (85/100); two cautions worth knowing: all queries reach Octagon's API and it needs your API key.
Grocery Shoppingprivacy
Grocery Shopping passed our review at 84/100, but it stores your Rohlik password in plaintext and can read your order, address, and payment data.
Blender 3Dsecurity
Blender 3D scored 58/100 (warn): it exposes an arbitrary-Python execution tool and ingests third-party asset text, creating an injection-to-execution path.
Social Media Skillsprivacy
Social Media Skills cleared our review at 86/100 with two privacy cautions: some skills call third-party APIs, and one uploads your video files to Google.
Family Assistant Skillprivacy
Family Assistant Skill passed our security scan; the one caveat is a privacy one: by design it stores highly sensitive personal data in local files.
Obsidian Skillssecurity
Obsidian Skills passed review (82/100); we flag three cautions around local write access, an eval command, and web fetching.
hass-mcpsecurity
hass-mcp passed our injection, exfiltration and secrets checks, but it can control real devices and restart your Home Assistant hub, so we flagged it.
rssidianprivacy
RSSidian passed at 85/100 with two notes: feed text enters the LLM prompt, and article content is sent to OpenRouter for summarization.
mem0-personal-memoryprivacy
mem0-personal-memory is well-built, but in its default cloud mode your memory text is sent to mem0 and OpenAI, which is why we flag it on privacy.