Security checks

Risk level of every entry and the reasons behind it.

Methodology

EntryRiskReasons
1C BSL Agent Development Framework
Workflow
High riskAssumes autonomous agent work on code and databases in a Docker sandbox Requires installing several third-party MCP servers The installer creates symlinks in project and IDE folders
1C Skills for Claude Code
Skill
High riskRuns PowerShell and Python scripts and the 1cv8 Designer in batch mode Can load configurations into and update infobases Starts an Apache web server to publish infobases
1c-rules: rules and skills for 1C development
Plugin
High riskThe installer and skills run PowerShell and Python scripts Tools change configuration metadata and operate on infobases Can connect MCP servers and external services, including 1C:Naparnik and the Gemini API for transcription
3X-UI on your VPS
Skill
High riskUses root SSH access to a remote server Installs packages and changes firewall rules and nginx configuration May ask for the root password in plain text
Aider
CLI
High riskEdits files and commits automatically Can run linters, tests and shell commands Code is sent to the model provider
Awesome Claude Skills by Composio
Skill
High riskconnect-apps gives the agent actions in email, chat and CRM accounts Requires a third-party gateway API key The list links to third-party skills without uniform review
Bitrix24 for OpenClaw
Plugin
High riskThe webhook gives the agent broad access to the portal's CRM, tasks, drive and chats The agent acts on behalf of users A public HTTPS endpoint for incoming events is required
CTF Skills
Skill
High riskThe installer adds many system packages and tools Skills run exploits, arbitrary shell commands and network attacks
Caveman
Skill
High riskThe proxy sits in the traffic between the agent and the provider The full installer wires Claude Code hooks and runs via curl | bash The CLI sends anonymous telemetry by default
Claude Code
CLI
High riskThe agent runs shell commands and modifies files The installer downloads and runs a script Code is sent to Anthropic models
Claude SEO
Plugin
High riskThe installer sets up a Python env and the Chromium browser Stores Google API credentials in ~/.config/claude-seo Makes network requests to audited sites
Claude-Mem
Plugin
High riskHooks record agent actions and tool output Runs a local worker with an HTTP API Offers hosted memory storage by default
Cline
CLI
High riskThe agent runs terminal commands and edits files Messaging integrations use bot tokens Code is sent to the chosen model provider
Codex CLI
CLI
High riskThe agent runs commands and edits files The installer downloads a binary Code is sent to OpenAI models
Dada Cloud for Claude Code
Plugin
High riskThe agent gets access to deployments and app settings in your cloud account Can create a sandbox with root access Runs mcp-remote via npx
Deckhouse CLI (d8)
CLI
High riskThe install script downloads and installs a binary Commands need cluster access and can change configuration, modules and users
Devika
CLI
High riskThe agent writes and runs code and uses a browser Stores keys for many services, including Netlify for deploys
Docker MCP server
MCP server
High riskFull Docker daemon access, which effectively means host control Can remove containers, images and volumes Can connect to remote hosts over SSH
ECC
Plugin
High riskInstalls hooks that run on agent events Modifies Claude Code and MCP configuration Runs an npm package with installer code
Gemini CLI
CLI
High riskThe agent runs shell commands and edits files Code and prompts are sent to Google models Requires a Google account or API key
GitHub MCP Server for Zed
Plugin
High riskRequires a GitHub token with repo scope, which grants broad repository access The agent can act in your GitHub account on your behalf
Hermes Agent
CLI
High riskInstalls via curl piped to bash and downloads binaries The agent runs shell commands and acts autonomously on schedules Stores provider keys and messaging tokens
Impeccable
Skill
High riskMay download the engine binary into ~/.impeccable/bin on first run Installs hooks that run on agent edits
Kubernetes MCP
MCP server
High riskActs with the permissions of the current kubectl context Can delete resources, drain nodes and run arbitrary kubectl commands Logs may contain sensitive data
MCP Server Playwright by Automata Labs
MCP server
High riskRuns arbitrary JavaScript on opened pages Can fill forms and click buttons on any site Downloads and runs Playwright browsers
Nelm
CLI
High riskApplies and deletes Kubernetes resources Handles secret encryption keys
NotebookLM skill for Claude Code
Skill
High riskAutomates a browser logged into your Google account and stores the session Installs Chrome and Python dependencies The project is archived and receives no fixes
OpenDesign
MCP server
High riskInstall via curl piped to a shell script The app launches local agent CLIs with filesystem access Handles model API keys
OpenHands Agent Canvas
CLI
High riskAgents run arbitrary commands, with full filesystem access when not sandboxed Automations receive tokens for Slack, GitHub and other services Sends code to the chosen LLM provider
Ozon Seller MCP server
MCP server
High riskRequires a Seller API key with the Admin role Tools change prices, stock and product cards in a live store In HTTP mode the key is passed in the URL
Plandex
CLI
High riskThe installer downloads and runs a script In autonomous mode it runs commands and edits files Code is sent to model providers
Playwright Skill
Skill
High riskThe agent generates and executes arbitrary Node.js code Setup downloads Playwright and Chromium binaries
RuSender MCP
MCP server
High riskOAuth access to the email account The agent can send emails to a real subscriber list, which cannot be undone Tools change sender DNS settings, webhooks and keys
SSH MCP Server
MCP server
High riskThe agent runs arbitrary shell commands on remote servers Stores SSH passwords and private keys The admin token is printed to logs on first start
T-Bank MCP
MCP server
High riskOperates a real bank account and can transfer money and pay for purchases Stores bank session tokens on disk Unofficial client for the bank app, not affiliated with T-Bank May download Chromium for checkout
Terraform MCP Server
MCP server
High riskWith a token it can create and delete workspaces and manage runs May expose Terraform data to the model and MCP client HTTP mode needs careful TLS, CORS and allowlist setup
Timeweb Cloud CLI (twc)
CLI
High riskThe token grants access to the cloud account and billable resources Commands can create and delete servers and other resources
Understand Anything
Plugin
High riskInstallation for several platforms runs via curl | bash The --auto-update flag installs a post-commit hook Analysis sends large amounts of code to the model
Yandex Station TTS skill
Skill
High riskThe token is derived from the Yandex account Session_id cookie An OAuth token with broad access is stored in .env for about a year The script connects to devices on the local network
agent-browser
CLI
High riskDownloads Chrome and runs a browser that executes page JavaScript Can use saved sessions, cookies and credentials Page content may contain prompt injection
didox-skill
Skill
High riskPerforms legally binding actions: signing, accepting, rejecting and cancelling documents Stores the Didox partner token and account password Works with the local signing key via E-IMZO
goose
CLI
High riskThe installer downloads and runs a script The agent runs commands and works with files MCP extensions can access external services
gstack
Skill
High riskSetup runs scripts and builds its own browser Adds hooks to ~/.claude/settings.json and a session-start auto-update Skills create commits and PRs and drive a browser with your sessions
last30days
Skill
High riskCan extract cookies from Chromium-family browsers to access accounts Runs Python scripts and installs additional CLIs Uses third-party API keys
pg_probackup
CLI
High riskOperates on data files and WAL of a production database Restore and backup deletion change data irreversibly
polyakov-claude-skills
Plugin
High riskssh-remote-connection runs commands on remote servers Direct and Metrika skills access ad accounts and can make changes Requires many API keys and network calls
selvpc (Selectel VPC)
CLI
High riskUses cloud account credentials Can manage billable cloud resources
t-invest-skill
Skill
High riskAccesses a brokerage account and can place real orders Installs via curl | bash Stores T-Invest API tokens in a local file
werf
CLI
High riskDeploys to Kubernetes and deletes images from the registry Requires cluster and registry credentials
yandex-office
Skill
High riskGets OAuth access to account mail, disk, calendar and tasks Can send emails and publish files Runs Python scripts that call Yandex APIs
.NET Agent Skills
Plugin
Medium riskThe dotnet plugin adds a C# language server Skills run builds, tests and diagnostic tools
1C Log Checker
MCP server
Medium riskRuns a Docker stack with ClickHouse, Grafana and an MCP server Tools change the technology log config on the 1C server Grafana has no auth by default, and logs may contain user data
1c-lsp-mcp-skill
MCP server
Medium riskRuns downloaded binaries and a Java server on the local machine Opens local HTTP ports for the web UI and MCP Can be installed as a background service
AI Research Skills
Skill
Medium riskThe agent runs experiments, training jobs and scripts Long autonomous runs can consume significant compute
Academic Research Skills
Skill
Medium riskMakes network calls to bibliographic resolvers and, optionally, to other models for cross-checks Optional hooks and commands run Python scripts
Agentic Plugin Marketplace by wshobson
Plugin
Medium riskSome plugins include commands and hooks Some install paths require running make from a clone
Aide for VS Code
Plugin
Medium riskSends code to an external model Batch mode changes many files at once
Anthropic skills
Skill
Medium riskDocument skills run scripts to process files
Awesome LLM Apps
Skill
Medium riskSkills ship executable scripts Apps in the repo require model API keys
Chef for Bitrix
CLI
Medium riskRuns builds and browser tests Stores a Bitrix login and password in .env.test for tests chef init hooks installs VCS hooks
Chestnyi Znak MCP server
MCP server
Medium riskRequires a JWT token for the company's labelling system account Network calls to an API with the company's product and document data
Claude-Codex Review Skill
Skill
Medium riskRuns PowerShell or Bash wait scripts A second agent gets read and write access to the project directory
Context7
MCP server
Medium riskSends library queries to an external service Uses an API key Documentation content is community-contributed and not fully vetted
DESIGN.md
Plugin
Medium riskRuns an npm package via npx Downloads example templates from the network
DaData MCP
MCP server
Medium riskRequires a DaData API key and secret key Paid calls spend account balance Personal data may be sent through the service
DataLikers MCP
MCP server
Medium riskRequires a paid API key Requests and results pass through an external service Tools return data about real social network users
Excalidraw Diagram Skill
Skill
Medium riskThe renderer runs a Python script and Chromium
Garden Skills
Skill
Medium riskSkills run image generation and TTS scripts Generation needs external service API keys
GigaChat image generation MCP
MCP server
Medium riskRequires a GigaChat API key Runs a third-party Docker image
LinkFox Skills
Skill
Medium riskSkills run Python scripts and call a paid API Requires a LinkFox API key Some skills need Amazon, Shopee or 1688 store authorization and can create orders and ad campaigns
MAX Messenger MCP server
MCP server
Medium riskRequires a MAX bot token Tools send and delete messages and change chat members and admins
MCP BSL LS Bridge
MCP server
Medium riskBuilds and runs a Docker container with a Java server The rename tool can modify code files across the project
MCP SQLite Server (npx)
MCP server
Medium riskRuns a local process via npx from an npm package The agent gets access to the database file contents
MCP server for 1C:Naparnik
MCP server
Medium riskRequires a 1C:Naparnik token Code sent for checks goes to an external API Runs a Docker container with an HTTP server
MPSTATS skills
Skill
Medium riskRequires an MPSTATS API token Runs bash scripts that make network calls
MaxStat MCP
MCP server
Medium riskRequires an API token, and requests spend paid credits Tools create webhook subscriptions that send data to an external URL
Obsidian skills
Skill
Medium riskSkills call external CLIs: Obsidian CLI and defuddle Defuddle fetches web pages
OpenAPI to CLI (ocli)
CLI
Medium riskMakes real HTTP requests to APIs, including POST, PUT and DELETE Stores tokens and credentials in profiles
PR-Agent
CLI
Medium riskRequires a git provider token and an LLM key PR code is sent to the chosen model Posts comments on PRs
Ponytail
Plugin
Medium riskPlugins install Node.js lifecycle hooks May add a statusLine entry to ~/.claude/settings.json
Prompt caching audit
Skill
Medium riskRuns local Python scripts for analysis
Reference MCP servers
MCP server
Medium riskFilesystem and Git read and modify files in allowed paths Fetch makes network requests to arbitrary URLs Servers are not intended for production
SPb Gorzdrav
Skill
Medium riskThe agent makes network requests to a city API via curl
Scientific Agent Skills
Skill
Medium riskSkills run Python scripts and install packages via uv They call external APIs and scientific databases Some community skills are not exhaustively reviewed
Skill Conductor
Skill
Medium riskRuns Python scripts via uv Evals call LLMs and consume tokens
Skill Seekers
CLI
Medium riskScrapes external sites and repositories Uses provider API keys for enhancement and uploads Writes skill files into several agents' directories
Superpowers
Plugin
Medium riskRegisters a session-start hook Agents and subagents work autonomously for long periods and run commands in the project Loads a logo from the authors' site by default
Tabby
CLI
Medium riskRuns a server and downloads models Indexes company repositories and documentation
Trail of Bits skills
Plugin
Medium riskSkills run shell commands and external analyzers The second-opinion plugin sends code to external LLM CLIs
Travel Search RU
Skill
Medium riskSends search criteria to a third-party server Runs a bundled Python script
UI UX Pro Max
Skill
Medium riskInstalls a global npm package The skill runs local Python scripts
Vercel Agent Skills
Skill
Medium riskThe deploy skill uploads project code to an external service Some skills include helper scripts
XBSL Skills for 1C:Element
Skill
Medium riskRuns Python scripts that create and modify project files Deployment uses an Element client secret Playwright checks may create records in the app
XMPP Debugger
Skill
Medium riskUses an XMPP account password from the environment Opens network connections to the server
Yandex Smart Home for OpenClaw
Skill
Medium riskRequires a Yandex account OAuth token The agent controls physical devices at home
ask-perplexity
Skill
Medium riskRequires a Perplexity API key with a paid balance Runs a shell script that sends data to an external API Code snippets included in questions are sent to Perplexity
avito-api
Skill
Medium riskRequires Avito account client_id and client_secret Can change listings and send messages on the account's behalf
book-to-skill
Skill
Medium riskRuns a local Python extractor and may suggest installing dependencies Can publish a generated skill to GitHub on request
claude-code-haiku-guard
Plugin
Medium riskSends command text and working directory to OpenRouter Requires an OpenRouter API key Changes global Claude Code settings
cloudlogin (Cloud.ru)
CLI
Medium riskUses Cloud.ru personal access keys Caches the cluster access token on disk Installed as a downloaded binary
datalens-mcp
MCP server
Medium riskRequires a Yandex Cloud IAM token Tools create and modify objects, including access bindings and public embeds Large responses with connection config are saved to temp files
drawio-skill
Skill
Medium riskThe skill runs Python scripts and the draw.io CLI Can read output of terraform show, docker inspect and kubectl
i18n-mcp
MCP server
Medium riskRuns a local process from npm Modifies and deletes keys in the project's locale files
pohuy
Skill
Medium riskcurl | bash install changes global agent settings and registers hooks The skill compares SKILL.md with GitHub over the network once per session
rpa-gen-rules: project rules for agents
Skill
Medium riskWrites a Python hook for Codex into the project that runs during sessions
rpa-init
Skill
Medium riskThe agent installs dependencies and runs the project's tests
sbermobile-skill
Skill
Medium riskUses a private API and an account token The token is stored in the unprotected /tmp directory
tt (Tarantool CLI)
CLI
Medium riskStarts and stops Tarantool processes The clean command removes instance files
wb-api-skill
Skill
Medium riskRuns local Python scripts Update mode launches a browser and downloads specs from dev.wildberries.ru
whentofly
MCP server
Medium riskRequests go to an external closed-source service Some booking links are affiliate links
zenmoney-go
CLI
Medium riskRequires an access token to financial data Syncs data from the ZenMoney API and stores it locally
Agent Skills by Addy Osmani
Skill
Low riskSkills are markdown instructions
Callstack agent skills for React Native
Skill
Low riskSkills are markdown instructions and reference material
Clarity: skills for legal writing
Plugin
Low riskText instructions and slash commands only, no MCP servers
Claude Skills for full-stack developers
Skill
Low riskSkills are mostly instructions and reference markdown files Workflow commands act on Jira and Confluence through the Atlassian MCP
Diplodoc CLI (yfm-docs)
CLI
Low riskWorks with local documentation files The VCS connector uses a GitHub token if configured
Emil Kowalski's skills for designers and engineers
Skill
Low riskSkills are markdown instructions
GigaChat Skills
Skill
Low riskThe skills are instructions and references Smoke scripts call the API only with --live
Humanizer RU
Skill
Low riskInstructions plus a local linter with no network calls
Karpathy-inspired Claude Code guidelines
Skill
Low riskText instructions only
Laravel API Architecture Skill
Skill
Low riskThe skill consists of instructions and templates Edits the project CLAUDE.md on first use
Logika
Skill
Low riskThe skill consists only of instructions and references
Marketing Skills for AI agents
Skill
Low riskSkills are markdown instructions
Ozon Seller API skill
Skill
Low riskThe local helper only reads the spec and makes no network calls
Positioning
Plugin
Low riskMarkdown instructions, writes files only into the positioning/ folder
Prompt Master
Skill
Low riskThe skill is instruction-only
Remotion Agent Skills
Skill
Low riskSkills are instructions and best practices The studio and render skills run Remotion commands in your project
Skills for real engineers by Matt Pocock
Skill
Low riskSkills are markdown instructions Some skills publish issues to your tracker and create commits
Slop Stop
Skill
Low riskMarkdown instructions only
Taste Skill
Skill
Low riskSkills are markdown instructions
Terraform Skill
Skill
Low riskThe skill is markdown instructions and reference files
Wildberries Seller API skill
Skill
Low riskThe local script only reads Swagger files and makes no network calls
YooKassa Skill
Skill
Low riskThe skill contains only documentation and code examples
ru-text
Skill
Low riskInstructions and reference files only, no network requests