Install payload
Install payload is broadly covered in current results.
100% (12/12)
5 trusted · 72 review in this set — compare to see which signals differ.
Trust signals across 40 of 77 results
4 trust signals differ in this sample: Review status, Package trust, Source provenance, Submitter
Signals differ on Review status, Package trust, Source provenance — add entries to compare before you install.
Rollout signal scan
Biggest gaps: metadata review, package integrity. 0 entries have 2+ required gaps.
Install payload
Install payload is broadly covered in current results.
100% (12/12)
Most at-risk entries in this view
Backend Architect Agent - Agents
Missing required: Safety notes
Snyk Agent Scan
No required rollout gaps
MCP Tool Search Scaling Capability Pack Skill
No required rollout gaps
Snyk MCP Server for Claude
No required rollout gaps
/security-audit - Security Scanner Command for Claude Code
No required rollout gaps
Adoption queue
18/77 visible results are in hold tier and need mitigation before adoption.
1 blockers: Metadata review
70/100
Request metadata review from maintainers or internal owners.
skills/cli-data-viz-quickstart · trust trusted · confidence 83%
1 blockers: Metadata review
70/100
Request metadata review from maintainers or internal owners.
skills/codex-plugin-creator-capability-pack · trust trusted · confidence 83%
1 blockers: Metadata review
70/100
Request metadata review from maintainers or internal owners.
skills/image-ocr-table-extraction · trust trusted · confidence 83%
1 blockers: Metadata review
70/100
Request metadata review from maintainers or internal owners.
mcp/socket-mcp-server · trust trusted · confidence 83%
1 blockers: Metadata review
70/100
Request metadata review from maintainers or internal owners.
skills/windsurf-collaborative-development · trust trusted · confidence 83%
No required blockers for this preset.
64/100
Collect package checksum or signed artifact information.
mcp/contrastapi-mcp-server · trust review · confidence 83%
1 blockers: Metadata review
50/100
Request metadata review from maintainers or internal owners.
Collect package checksum or signed artifact information.
commands/catalog-collision-scan · trust review · confidence 67%
1 blockers: Metadata review
50/100
Request metadata review from maintainers or internal owners.
Collect package checksum or signed artifact information.
commands/security · trust review · confidence 67%
Decision confidence
18/77 results are low-confidence and need review before adoption.
Confident candidate for staged adoption.
74/100
skills/cli-data-viz-quickstart · trust trusted
Confident candidate for staged adoption.
74/100
skills/codex-plugin-creator-capability-pack · trust trusted
Confident candidate for staged adoption.
74/100
skills/image-ocr-table-extraction · trust trusted
Confident candidate for staged adoption.
74/100
mcp/socket-mcp-server · trust trusted
Confident candidate for staged adoption.
74/100
skills/windsurf-collaborative-development · trust trusted
Address Package integrity before broader rollout.
68/100
mcp/contrastapi-mcp-server · trust review
Address Metadata review, Package integrity before broader rollout.
54/100
commands/catalog-collision-scan · trust review
Address Metadata review, Package integrity before broader rollout.
54/100
commands/security · trust review
Freshness distribution
Median age 279 days; 3 fresh of 12 scanned. Re-verify the oldest entries.
Theme distribution
119 distinct themes with no dominant one. Most common: security, mcp, python.
119 distinct themes across 24 scanned
Security scanner from Snyk for discovering local AI agent components, including MCP servers and Agent Skills, and checking them for prompt injection, tool poisoning, tool shadowing, toxic flows, malware payloads, credential handling, and hardcoded secrets.
Expert MCP tool search scaling capability pack for designing, reviewing, and rolling out MCP tool search scaling with source-backed checklists, production rules, and privacy-safe output contracts.
Official Snyk Studio MCP Server for connecting Claude Code, Codex CLI, Cursor, Gemini CLI, and other local MCP clients to Snyk Code, Open Source, IaC, container, SBOM, AI-BOM, package-health, authentication, and secure-at-inception workflows.
Deploy 100 specialized sub-agents for comprehensive enterprise-grade security, performance, and optimization audit of production codebase
Scans for potential sensitive data exposure and alerts immediately.
Automated security vulnerability scanning that integrates with development workflow to detect and prevent security issues before deployment.
Expert backend architect specializing in scalable system design, microservices, API development, and infrastructure planning
Master collaborative AI-assisted development with Windsurf IDE's Cascade AI, multi-file context awareness, and Flow patterns for team workflows.
Turn CSV, JSON, or Excel data into publication-ready charts with Python: load it with pandas and render bar, line, scatter, and statistical plots in matplotlib (with seaborn styling), then export high-DPI PNG or SVG.
Pull text out of images, scans, and PDFs with the Tesseract OCR engine and OpenCV preprocessing. Run OCR in 100+ languages, read per-word confidence and page orientation (OSD), binarize and deskew for accuracy, and reconstruct tables into CSV or JSON.
Security analysis and vulnerability scanning for dependencies
49 remote MCP security tools for CVE/KEV/CWE/EPSS lookup, composite CVSS+EPSS+KEV+PoC risk scoring, CVSS v3.x vector parsing, domain/IP/IOC enrichment, dependency and web intelligence checks, MITRE ATLAS AI/ML attacks, and MITRE D3FEND defenses. Anonymous tier available; Pro tier uses an API key.
Lightweight open-source serving framework for building custom AI model inference APIs by defining a LitAPI with setup and predict methods, with batching, streaming, multi-GPU autoscaling, OpenAI-compatible endpoints, and support for compound, multimodal, RAG, and agent pipelines.
Framework-agnostic agent memory lifecycle skill and Rust-native CLI for explicit recall, evidence-backed memory, forgetting, audit, consolidation, DOX/Revolve sync, and local SQLite/FTS storage.
Source-backed rules for reviewing AI-generated regular expressions before merge, covering catastrophic backtracking and ReDoS risk, input bounds, anchor and escaping correctness, validation versus parsing, safe engines, and privacy-safe test evidence.
Source-backed rules for reviewing AI-generated database access code for SQL injection before merge, covering parameterized queries, identifier handling, ORM safety, dynamic query construction, least-privilege access, and privacy-safe test evidence.
Open-source Python multi-agent framework for building agent societies, role-playing agents, stateful ChatAgent workflows, RAG agents, synthetic data generation, MCP-enabled use cases, and research-scale agent experiments.
Fullstack MCP framework for building MCP servers, MCP Apps, MCP agents, and MCP clients with TypeScript and Python SDKs, scaffolding, inspector tooling, hosted deployment, observability, OAuth, notifications, sampling, and agent integrations.
Apache-2.0 security scanner from NVIDIA for AI agent skills, with static pattern checks, optional LLM semantic analysis, MCP least-privilege and tool poisoning analyzers, OSV.dev vulnerability lookups, risk scoring, and terminal, JSON, Markdown, and SARIF reports.
Slash command runbook for scanning HeyClaude catalog collisions by slug, title, repo URL, and docs URL before opening a content-only PR—using audit-content patterns and GitHub code search.
Connect Claude to Semgrep — scan code for security vulnerabilities, run custom rules, inspect the AST, and pull AppSec Platform findings — with the official Semgrep Model Context Protocol server.
BoolsAI hosted MCP server with no authentication required for tech stack scanning via boolsai_scan and boolsai_scan_paths tools on boolsai.ai/mcp.
Official Pinecone Developer MCP server that connects Claude and other MCP clients to Pinecone projects and documentation for index management, record upserts, semantic search, cascading multi-index search, reranking, and documentation lookup over integrated-inference indexes.
PortSwigger's Burp Suite MCP Server extension connects Burp Suite to MCP clients through an SSE server or packaged stdio proxy for request, Repeater, Intruder, history, scanner, Collaborator, and configuration workflows.
Go-based enterprise-information gathering MCP server for authorized security research, exposing local SSE tools for company search, ICP records, apps, Weibo, WeChat public accounts, mini programs, recruiting data, copyright records, suppliers, investments, branches, and paginated data-source queries.
Source-backed agent for reviewing AI workflow submissions before publication with data-flow mapping, privacy metadata, governance evidence, MCP/tool authority checks, retention disclosure, and compliance escalation gates.
PreToolUse hook that reviews proposed writes to MCP configuration files and blocks inline credential values, credential-bearing URLs, and broad filesystem roots before they are saved.
Connect Claude to PlanetScale's official hosted MCP server for organizations, databases, branches, schemas, Insights, documentation search, and scoped SQL query workflows.
PreToolUse hook that scans proposed writes to prompt, agent, rule, markdown, and context files for common prompt-injection phrases before the content is saved into an AI-readable surface.
Source-backed agent for reviewing rendered frontend changes with screenshots, visual comparison evidence, viewport layout checks, keyboard/focus paths, accessibility scans, CLS risk, and privacy-safe QA artifacts.