Skip to content
ai-supply.store
ОбзорКатегорииРейтингиСообществоAgent APIFAQ
ВойтиБесплатная регистрация
Original research

The state of AI-capability security

Most registries never read the code they list. We extract and read the source of every capability, then grade it on a two-axis model: only malicious or tampered code lowers the score, while dangerous-by-capability traits (shell, network, injection strings, pickle) are surfaced as risk surface. Here is what reading 280 real capabilities shows — computed live from the current scans.

Verdicts across 280 scanned capabilities
Safe (no compromise signal)40% · 112/280
Review (a flagged finding to check)60% · 168/280
Quarantined (genuinely dangerous — hidden)0% · 0/280

Grades: 112 A · 162 B · 0 C · 6 D. 2 awaiting scan (source too large to fetch).

Capability surface (217 MCP servers / agents / tools)

What these code-executing capabilities can actually do, from static analysis of their source. This is the surface an agent grants when it installs one — and what an install-time policy should gate on.

Make network calls88% · 190/217
Read/write the filesystem90% · 196/217
Execute shell / subprocesses69% · 149/217
Access environment secrets87% · 189/217
Call external hosts (egress)100% · 216/217
Run install-lifecycle hooks12% · 27/217
Tool-description prompt-injection (poisoning)0% · 0/217
Datasets (13)
Carry a PII surface62% · 8/13
Prompts / templates (12)
Contain injection-shaped instructions42% · 5/12

Every verdict is reproducible on the listing Security tab, and agents can query it before installing: GET /api/v1/trust/{slug}.

How we grade →Browse grade-A capabilities →
ai-supply.store

Бесплатные AI-возможности с проверкой безопасности — skills, MCP, плагины, агенты, датасеты и другое. У каждой своя оценка безопасности и контроль актуальности, и всё создано как для людей, так и для агентов.

api · v3.1status · all green
Контакты
support@ai-supply.storesecurity@ai-supply.store
Каталог
  • Обзор
  • Категории
  • Рейтинги
  • Бенчмарки
  • Безопасность
  • Scan a repo
Сообщество
  • Сообщество
  • FAQ
Для агентов
  • Быстрый старт (60s)
  • Авторизовать агента
  • Agent API
  • Спецификация OpenAPI
Для разработчиков
  • Опубликовать
  • Панель управления
Аккаунт
  • Создать аккаунт
  • Войти
  • Настройки
Правовые документы
  • Условия использования
  • Соглашение издателя
  • Правила допустимого использования
  • Конфиденциальность