| Entry | Risk | Reasons |
|---|---|---|
| 1C BSL Agent Development Framework Workflow | High risk | Assumes autonomous agent work on code and databases in a Docker sandbox Requires installing several third-party MCP servers The installer creates symlinks in project and IDE folders |
| 1C Skills for Claude Code Skill | High risk | Runs PowerShell and Python scripts and the 1cv8 Designer in batch mode Can load configurations into and update infobases Starts an Apache web server to publish infobases |
| 1c-rules: rules and skills for 1C development Plugin | High risk | The installer and skills run PowerShell and Python scripts Tools change configuration metadata and operate on infobases Can connect MCP servers and external services, including 1C:Naparnik and the Gemini API for transcription |
| 3X-UI on your VPS Skill | High risk | Uses root SSH access to a remote server Installs packages and changes firewall rules and nginx configuration May ask for the root password in plain text |
| Aider CLI | High risk | Edits files and commits automatically Can run linters, tests and shell commands Code is sent to the model provider |
| Awesome Claude Skills by Composio Skill | High risk | connect-apps gives the agent actions in email, chat and CRM accounts Requires a third-party gateway API key The list links to third-party skills without uniform review |
| Bitrix24 for OpenClaw Plugin | High risk | The webhook gives the agent broad access to the portal's CRM, tasks, drive and chats The agent acts on behalf of users A public HTTPS endpoint for incoming events is required |
| CTF Skills Skill | High risk | The installer adds many system packages and tools Skills run exploits, arbitrary shell commands and network attacks |
| Caveman Skill | High risk | The proxy sits in the traffic between the agent and the provider The full installer wires Claude Code hooks and runs via curl | bash The CLI sends anonymous telemetry by default |
| Claude Code CLI | High risk | The agent runs shell commands and modifies files The installer downloads and runs a script Code is sent to Anthropic models |
| Claude SEO Plugin | High risk | The installer sets up a Python env and the Chromium browser Stores Google API credentials in ~/.config/claude-seo Makes network requests to audited sites |
| Claude-Mem Plugin | High risk | Hooks record agent actions and tool output Runs a local worker with an HTTP API Offers hosted memory storage by default |
| Cline CLI | High risk | The agent runs terminal commands and edits files Messaging integrations use bot tokens Code is sent to the chosen model provider |
| Codex CLI CLI | High risk | The agent runs commands and edits files The installer downloads a binary Code is sent to OpenAI models |
| Dada Cloud for Claude Code Plugin | High risk | The agent gets access to deployments and app settings in your cloud account Can create a sandbox with root access Runs mcp-remote via npx |
| Deckhouse CLI (d8) CLI | High risk | The install script downloads and installs a binary Commands need cluster access and can change configuration, modules and users |
| Devika CLI | High risk | The agent writes and runs code and uses a browser Stores keys for many services, including Netlify for deploys |
| Docker MCP server MCP server | High risk | Full Docker daemon access, which effectively means host control Can remove containers, images and volumes Can connect to remote hosts over SSH |
| ECC Plugin | High risk | Installs hooks that run on agent events Modifies Claude Code and MCP configuration Runs an npm package with installer code |
| Gemini CLI CLI | High risk | The agent runs shell commands and edits files Code and prompts are sent to Google models Requires a Google account or API key |
| GitHub MCP Server for Zed Plugin | High risk | Requires a GitHub token with repo scope, which grants broad repository access The agent can act in your GitHub account on your behalf |
| Hermes Agent CLI | High risk | Installs via curl piped to bash and downloads binaries The agent runs shell commands and acts autonomously on schedules Stores provider keys and messaging tokens |
| Impeccable Skill | High risk | May download the engine binary into ~/.impeccable/bin on first run Installs hooks that run on agent edits |
| Kubernetes MCP MCP server | High risk | Acts with the permissions of the current kubectl context Can delete resources, drain nodes and run arbitrary kubectl commands Logs may contain sensitive data |
| MCP Server Playwright by Automata Labs MCP server | High risk | Runs arbitrary JavaScript on opened pages Can fill forms and click buttons on any site Downloads and runs Playwright browsers |
| Nelm CLI | High risk | Applies and deletes Kubernetes resources Handles secret encryption keys |
| NotebookLM skill for Claude Code Skill | High risk | Automates a browser logged into your Google account and stores the session Installs Chrome and Python dependencies The project is archived and receives no fixes |
| OpenDesign MCP server | High risk | Install via curl piped to a shell script The app launches local agent CLIs with filesystem access Handles model API keys |
| OpenHands Agent Canvas CLI | High risk | Agents run arbitrary commands, with full filesystem access when not sandboxed Automations receive tokens for Slack, GitHub and other services Sends code to the chosen LLM provider |
| Ozon Seller MCP server MCP server | High risk | Requires a Seller API key with the Admin role Tools change prices, stock and product cards in a live store In HTTP mode the key is passed in the URL |
| Plandex CLI | High risk | The installer downloads and runs a script In autonomous mode it runs commands and edits files Code is sent to model providers |
| Playwright Skill Skill | High risk | The agent generates and executes arbitrary Node.js code Setup downloads Playwright and Chromium binaries |
| RuSender MCP MCP server | High risk | OAuth access to the email account The agent can send emails to a real subscriber list, which cannot be undone Tools change sender DNS settings, webhooks and keys |
| SSH MCP Server MCP server | High risk | The agent runs arbitrary shell commands on remote servers Stores SSH passwords and private keys The admin token is printed to logs on first start |
| T-Bank MCP MCP server | High risk | Operates a real bank account and can transfer money and pay for purchases Stores bank session tokens on disk Unofficial client for the bank app, not affiliated with T-Bank May download Chromium for checkout |
| Terraform MCP Server MCP server | High risk | With a token it can create and delete workspaces and manage runs May expose Terraform data to the model and MCP client HTTP mode needs careful TLS, CORS and allowlist setup |
| Timeweb Cloud CLI (twc) CLI | High risk | The token grants access to the cloud account and billable resources Commands can create and delete servers and other resources |
| Understand Anything Plugin | High risk | Installation for several platforms runs via curl | bash The --auto-update flag installs a post-commit hook Analysis sends large amounts of code to the model |
| Yandex Station TTS skill Skill | High risk | The token is derived from the Yandex account Session_id cookie An OAuth token with broad access is stored in .env for about a year The script connects to devices on the local network |
| agent-browser CLI | High risk | Downloads Chrome and runs a browser that executes page JavaScript Can use saved sessions, cookies and credentials Page content may contain prompt injection |
| didox-skill Skill | High risk | Performs legally binding actions: signing, accepting, rejecting and cancelling documents Stores the Didox partner token and account password Works with the local signing key via E-IMZO |
| goose CLI | High risk | The installer downloads and runs a script The agent runs commands and works with files MCP extensions can access external services |
| gstack Skill | High risk | Setup runs scripts and builds its own browser Adds hooks to ~/.claude/settings.json and a session-start auto-update Skills create commits and PRs and drive a browser with your sessions |
| last30days Skill | High risk | Can extract cookies from Chromium-family browsers to access accounts Runs Python scripts and installs additional CLIs Uses third-party API keys |
| pg_probackup CLI | High risk | Operates on data files and WAL of a production database Restore and backup deletion change data irreversibly |
| polyakov-claude-skills Plugin | High risk | ssh-remote-connection runs commands on remote servers Direct and Metrika skills access ad accounts and can make changes Requires many API keys and network calls |
| selvpc (Selectel VPC) CLI | High risk | Uses cloud account credentials Can manage billable cloud resources |
| t-invest-skill Skill | High risk | Accesses a brokerage account and can place real orders Installs via curl | bash Stores T-Invest API tokens in a local file |
| werf CLI | High risk | Deploys to Kubernetes and deletes images from the registry Requires cluster and registry credentials |
| yandex-office Skill | High risk | Gets OAuth access to account mail, disk, calendar and tasks Can send emails and publish files Runs Python scripts that call Yandex APIs |
| .NET Agent Skills Plugin | Medium risk | The dotnet plugin adds a C# language server Skills run builds, tests and diagnostic tools |
| 1C Log Checker MCP server | Medium risk | Runs a Docker stack with ClickHouse, Grafana and an MCP server Tools change the technology log config on the 1C server Grafana has no auth by default, and logs may contain user data |
| 1c-lsp-mcp-skill MCP server | Medium risk | Runs downloaded binaries and a Java server on the local machine Opens local HTTP ports for the web UI and MCP Can be installed as a background service |
| AI Research Skills Skill | Medium risk | The agent runs experiments, training jobs and scripts Long autonomous runs can consume significant compute |
| Academic Research Skills Skill | Medium risk | Makes network calls to bibliographic resolvers and, optionally, to other models for cross-checks Optional hooks and commands run Python scripts |
| Agentic Plugin Marketplace by wshobson Plugin | Medium risk | Some plugins include commands and hooks Some install paths require running make from a clone |
| Aide for VS Code Plugin | Medium risk | Sends code to an external model Batch mode changes many files at once |
| Anthropic skills Skill | Medium risk | Document skills run scripts to process files |
| Awesome LLM Apps Skill | Medium risk | Skills ship executable scripts Apps in the repo require model API keys |
| Chef for Bitrix CLI | Medium risk | Runs builds and browser tests Stores a Bitrix login and password in .env.test for tests chef init hooks installs VCS hooks |
| Chestnyi Znak MCP server MCP server | Medium risk | Requires a JWT token for the company's labelling system account Network calls to an API with the company's product and document data |
| Claude-Codex Review Skill Skill | Medium risk | Runs PowerShell or Bash wait scripts A second agent gets read and write access to the project directory |
| Context7 MCP server | Medium risk | Sends library queries to an external service Uses an API key Documentation content is community-contributed and not fully vetted |
| DESIGN.md Plugin | Medium risk | Runs an npm package via npx Downloads example templates from the network |
| DaData MCP MCP server | Medium risk | Requires a DaData API key and secret key Paid calls spend account balance Personal data may be sent through the service |
| DataLikers MCP MCP server | Medium risk | Requires a paid API key Requests and results pass through an external service Tools return data about real social network users |
| Excalidraw Diagram Skill Skill | Medium risk | The renderer runs a Python script and Chromium |
| Garden Skills Skill | Medium risk | Skills run image generation and TTS scripts Generation needs external service API keys |
| GigaChat image generation MCP MCP server | Medium risk | Requires a GigaChat API key Runs a third-party Docker image |
| LinkFox Skills Skill | Medium risk | Skills run Python scripts and call a paid API Requires a LinkFox API key Some skills need Amazon, Shopee or 1688 store authorization and can create orders and ad campaigns |
| MAX Messenger MCP server MCP server | Medium risk | Requires a MAX bot token Tools send and delete messages and change chat members and admins |
| MCP BSL LS Bridge MCP server | Medium risk | Builds and runs a Docker container with a Java server The rename tool can modify code files across the project |
| MCP SQLite Server (npx) MCP server | Medium risk | Runs a local process via npx from an npm package The agent gets access to the database file contents |
| MCP server for 1C:Naparnik MCP server | Medium risk | Requires a 1C:Naparnik token Code sent for checks goes to an external API Runs a Docker container with an HTTP server |
| MPSTATS skills Skill | Medium risk | Requires an MPSTATS API token Runs bash scripts that make network calls |
| MaxStat MCP MCP server | Medium risk | Requires an API token, and requests spend paid credits Tools create webhook subscriptions that send data to an external URL |
| Obsidian skills Skill | Medium risk | Skills call external CLIs: Obsidian CLI and defuddle Defuddle fetches web pages |
| OpenAPI to CLI (ocli) CLI | Medium risk | Makes real HTTP requests to APIs, including POST, PUT and DELETE Stores tokens and credentials in profiles |
| PR-Agent CLI | Medium risk | Requires a git provider token and an LLM key PR code is sent to the chosen model Posts comments on PRs |
| Ponytail Plugin | Medium risk | Plugins install Node.js lifecycle hooks May add a statusLine entry to ~/.claude/settings.json |
| Prompt caching audit Skill | Medium risk | Runs local Python scripts for analysis |
| Reference MCP servers MCP server | Medium risk | Filesystem and Git read and modify files in allowed paths Fetch makes network requests to arbitrary URLs Servers are not intended for production |
| SPb Gorzdrav Skill | Medium risk | The agent makes network requests to a city API via curl |
| Scientific Agent Skills Skill | Medium risk | Skills run Python scripts and install packages via uv They call external APIs and scientific databases Some community skills are not exhaustively reviewed |
| Skill Conductor Skill | Medium risk | Runs Python scripts via uv Evals call LLMs and consume tokens |
| Skill Seekers CLI | Medium risk | Scrapes external sites and repositories Uses provider API keys for enhancement and uploads Writes skill files into several agents' directories |
| Superpowers Plugin | Medium risk | Registers a session-start hook Agents and subagents work autonomously for long periods and run commands in the project Loads a logo from the authors' site by default |
| Tabby CLI | Medium risk | Runs a server and downloads models Indexes company repositories and documentation |
| Trail of Bits skills Plugin | Medium risk | Skills run shell commands and external analyzers The second-opinion plugin sends code to external LLM CLIs |
| Travel Search RU Skill | Medium risk | Sends search criteria to a third-party server Runs a bundled Python script |
| UI UX Pro Max Skill | Medium risk | Installs a global npm package The skill runs local Python scripts |
| Vercel Agent Skills Skill | Medium risk | The deploy skill uploads project code to an external service Some skills include helper scripts |
| XBSL Skills for 1C:Element Skill | Medium risk | Runs Python scripts that create and modify project files Deployment uses an Element client secret Playwright checks may create records in the app |
| XMPP Debugger Skill | Medium risk | Uses an XMPP account password from the environment Opens network connections to the server |
| Yandex Smart Home for OpenClaw Skill | Medium risk | Requires a Yandex account OAuth token The agent controls physical devices at home |
| ask-perplexity Skill | Medium risk | Requires a Perplexity API key with a paid balance Runs a shell script that sends data to an external API Code snippets included in questions are sent to Perplexity |
| avito-api Skill | Medium risk | Requires Avito account client_id and client_secret Can change listings and send messages on the account's behalf |
| book-to-skill Skill | Medium risk | Runs a local Python extractor and may suggest installing dependencies Can publish a generated skill to GitHub on request |
| claude-code-haiku-guard Plugin | Medium risk | Sends command text and working directory to OpenRouter Requires an OpenRouter API key Changes global Claude Code settings |
| cloudlogin (Cloud.ru) CLI | Medium risk | Uses Cloud.ru personal access keys Caches the cluster access token on disk Installed as a downloaded binary |
| datalens-mcp MCP server | Medium risk | Requires a Yandex Cloud IAM token Tools create and modify objects, including access bindings and public embeds Large responses with connection config are saved to temp files |
| drawio-skill Skill | Medium risk | The skill runs Python scripts and the draw.io CLI Can read output of terraform show, docker inspect and kubectl |
| i18n-mcp MCP server | Medium risk | Runs a local process from npm Modifies and deletes keys in the project's locale files |
| pohuy Skill | Medium risk | curl | bash install changes global agent settings and registers hooks The skill compares SKILL.md with GitHub over the network once per session |
| rpa-gen-rules: project rules for agents Skill | Medium risk | Writes a Python hook for Codex into the project that runs during sessions |
| rpa-init Skill | Medium risk | The agent installs dependencies and runs the project's tests |
| sbermobile-skill Skill | Medium risk | Uses a private API and an account token The token is stored in the unprotected /tmp directory |
| tt (Tarantool CLI) CLI | Medium risk | Starts and stops Tarantool processes The clean command removes instance files |
| wb-api-skill Skill | Medium risk | Runs local Python scripts Update mode launches a browser and downloads specs from dev.wildberries.ru |
| whentofly MCP server | Medium risk | Requests go to an external closed-source service Some booking links are affiliate links |
| zenmoney-go CLI | Medium risk | Requires an access token to financial data Syncs data from the ZenMoney API and stores it locally |
| Agent Skills by Addy Osmani Skill | Low risk | Skills are markdown instructions |
| Callstack agent skills for React Native Skill | Low risk | Skills are markdown instructions and reference material |
| Clarity: skills for legal writing Plugin | Low risk | Text instructions and slash commands only, no MCP servers |
| Claude Skills for full-stack developers Skill | Low risk | Skills are mostly instructions and reference markdown files Workflow commands act on Jira and Confluence through the Atlassian MCP |
| Diplodoc CLI (yfm-docs) CLI | Low risk | Works with local documentation files The VCS connector uses a GitHub token if configured |
| Emil Kowalski's skills for designers and engineers Skill | Low risk | Skills are markdown instructions |
| GigaChat Skills Skill | Low risk | The skills are instructions and references Smoke scripts call the API only with --live |
| Humanizer RU Skill | Low risk | Instructions plus a local linter with no network calls |
| Karpathy-inspired Claude Code guidelines Skill | Low risk | Text instructions only |
| Laravel API Architecture Skill Skill | Low risk | The skill consists of instructions and templates Edits the project CLAUDE.md on first use |
| Logika Skill | Low risk | The skill consists only of instructions and references |
| Marketing Skills for AI agents Skill | Low risk | Skills are markdown instructions |
| Ozon Seller API skill Skill | Low risk | The local helper only reads the spec and makes no network calls |
| Positioning Plugin | Low risk | Markdown instructions, writes files only into the positioning/ folder |
| Prompt Master Skill | Low risk | The skill is instruction-only |
| Remotion Agent Skills Skill | Low risk | Skills are instructions and best practices The studio and render skills run Remotion commands in your project |
| Skills for real engineers by Matt Pocock Skill | Low risk | Skills are markdown instructions Some skills publish issues to your tracker and create commits |
| Slop Stop Skill | Low risk | Markdown instructions only |
| Taste Skill Skill | Low risk | Skills are markdown instructions |
| Terraform Skill Skill | Low risk | The skill is markdown instructions and reference files |
| Wildberries Seller API skill Skill | Low risk | The local script only reads Swagger files and makes no network calls |
| YooKassa Skill Skill | Low risk | The skill contains only documentation and code examples |
| ru-text Skill | Low risk | Instructions and reference files only, no network requests |