Skip to content
ai-supply.store
DiscoverCategoriesLeaderboardsCommunityAgent APIFAQ
Sign inSign up free
Original research

The state of AI-capability security

Most registries never read the code they list. We extract and read the source of every capability, then grade it on a two-axis model: only malicious or tampered code lowers the score, while dangerous-by-capability traits (shell, network, injection strings, pickle) are surfaced as risk surface. Here is what reading 280 real capabilities shows — computed live from the current scans.

Verdicts across 280 scanned capabilities
Safe (no compromise signal)40% · 112/280
Review (a flagged finding to check)60% · 168/280
Quarantined (genuinely dangerous — hidden)0% · 0/280

Grades: 112 A · 162 B · 0 C · 6 D. 2 awaiting scan (source too large to fetch).

Capability surface (217 MCP servers / agents / tools)

What these code-executing capabilities can actually do, from static analysis of their source. This is the surface an agent grants when it installs one — and what an install-time policy should gate on.

Make network calls88% · 190/217
Read/write the filesystem90% · 196/217
Execute shell / subprocesses69% · 149/217
Access environment secrets87% · 189/217
Call external hosts (egress)100% · 216/217
Run install-lifecycle hooks12% · 27/217
Tool-description prompt-injection (poisoning)0% · 0/217
Datasets (13)
Carry a PII surface62% · 8/13
Prompts / templates (12)
Contain injection-shaped instructions42% · 5/12

Every verdict is reproducible on the listing Security tab, and agents can query it before installing: GET /api/v1/trust/{slug}.

How we grade →Browse grade-A capabilities →
ai-supply.store

Free, security-vetted AI capabilities — skills, MCPs, plugins, agents, datasets and more, each graded and freshness-tracked, and built for humans and agents alike.

api · v3.1status · all green
Contact
support@ai-supply.storesecurity@ai-supply.store
Catalog
  • Discover
  • Categories
  • Leaderboards
  • Benchmarks
  • Security
  • Scan a repo
Community
  • Community
  • FAQ
For agents
  • Quickstart (60s)
  • Authorize an agent
  • Agent API
  • OpenAPI spec
For builders
  • Publish
  • Dashboard
Account
  • Create account
  • Sign in
  • Settings
Legal
  • Terms
  • Publisher Agreement
  • Acceptable Use
  • Privacy