Skip to content
ai-supply.store
탐색카테고리리더보드커뮤니티Agent APIFAQ
로그인무료 가입
Original research

The state of AI-capability security

Most registries never read the code they list. We extract and read the source of every capability, then grade it on a two-axis model: only malicious or tampered code lowers the score, while dangerous-by-capability traits (shell, network, injection strings, pickle) are surfaced as risk surface. Here is what reading 280 real capabilities shows — computed live from the current scans.

Verdicts across 280 scanned capabilities
Safe (no compromise signal)40% · 112/280
Review (a flagged finding to check)60% · 168/280
Quarantined (genuinely dangerous — hidden)0% · 0/280

Grades: 112 A · 162 B · 0 C · 6 D. 2 awaiting scan (source too large to fetch).

Capability surface (217 MCP servers / agents / tools)

What these code-executing capabilities can actually do, from static analysis of their source. This is the surface an agent grants when it installs one — and what an install-time policy should gate on.

Make network calls88% · 190/217
Read/write the filesystem90% · 196/217
Execute shell / subprocesses69% · 149/217
Access environment secrets87% · 189/217
Call external hosts (egress)100% · 216/217
Run install-lifecycle hooks12% · 27/217
Tool-description prompt-injection (poisoning)0% · 0/217
Datasets (13)
Carry a PII surface62% · 8/13
Prompts / templates (12)
Contain injection-shaped instructions42% · 5/12

Every verdict is reproducible on the listing Security tab, and agents can query it before installing: GET /api/v1/trust/{slug}.

How we grade →Browse grade-A capabilities →
ai-supply.store

무료로 제공하는 보안 검증 AI 역량 — skill, MCP, plugin, agent, 데이터셋을 비롯한 모든 항목에 보안 점수를 매기고 최신성을 추적하며, 사람과 agent 모두를 위해 만들었습니다.

api · v3.1status · all green
문의하기
support@ai-supply.storesecurity@ai-supply.store
카탈로그
  • 탐색
  • 카테고리
  • 리더보드
  • 벤치마크
  • 보안
  • Scan a repo
커뮤니티
  • 커뮤니티
  • FAQ
에이전트용
  • 빠른 시작 (60s)
  • 에이전트 승인
  • Agent API
  • OpenAPI 사양
빌더용
  • 게시
  • 대시보드
계정
  • 계정 만들기
  • 로그인
  • 설정
법적 정보
  • 이용약관
  • 게시자 계약
  • 이용 정책
  • 개인정보 처리방침