← Back to Home

Skills Directory

27 of 27 skills scanned for security vulnerabilities

GitHub CLI

85/100

Wrapper for GitHub CLI - delegates to official gh tool with secure OAuth.

Risk: low2/7/2026

Weather

85/100

Wrapper for weather API - simple HTTP requests to public weather service.

Risk: low2/7/2026

Weather API Skill

85/100

Well-implemented security practices with proper input validation, rate limiting, and credential handling; minor concerns around API endpoint trust and error handling.

Risk: low2/7/2026

1Password CLI

80/100

Wrapper for 1Password CLI - delegates security to the official 1Password command-line tool.

Risk: low2/7/2026

OpenAI Whisper

80/100

Wrapper for local Whisper CLI - offline speech-to-text with no API calls.

Risk: low2/7/2026

Apple Notes

75/100

Wrapper for memo CLI - delegates to macOS Notes app via AppleScript.

Risk: medium2/7/2026

Apple Reminders

75/100

Wrapper for remindctl CLI - delegates to macOS Reminders app via AppleScript.

Risk: medium2/7/2026

Coding Agent

75/100

Wrapper for AI coding assistants - delegates to external coding agents with full code access.

Risk: medium2/7/2026

Google Places

75/100

Wrapper for Google Places API CLI - requires API key for location data access.

Risk: medium2/7/2026

Local Places

72/100

Google Places API integration with proper error handling but has path injection vulnerability and lacks input validation on critical parameters.

Risk: medium2/7/2026

Skill Creator

72/100

Template generation script with path traversal vulnerabilities and insufficient validation of user-controlled file operations.

Risk: medium2/7/2026

OpenAI Image Gen

72/100

Legitimate OpenAI image generation script with proper API usage, but has path traversal risks and writes files to user-controlled locations without sufficient validation.

Risk: medium2/7/2026

Nano Banana Pro

72/100

Legitimate image generation tool with proper API key handling, but has path traversal vulnerabilities and unrestricted file system write access.

Risk: medium2/7/2026

X/Twitter

70/100

Wrapper for bird CLI - cookie-based Twitter automation with potential session hijacking risks.

Risk: medium2/7/2026

Google Workspace

70/100

Wrapper for Google Workspace CLI - requires OAuth tokens with broad API access.

Risk: medium2/7/2026

MCP Tool Porter

70/100

Wrapper for Model Context Protocol tools - connects to external MCP servers.

Risk: medium2/7/2026

Nano PDF

70/100

Wrapper for PDF editing CLI - processes PDF files with natural language.

Risk: medium2/7/2026

Summarize

70/100

Wrapper for video/audio summarization tools - downloads and transcribes media.

Risk: medium2/7/2026

Discord

70/100

Wrapper for Discord bot - requires bot token with potential for token leakage.

Risk: medium2/7/2026

Security Healthcheck

⚠️65/100

Wrapper for security audit commands - executes system-level security checks.

Risk: medium2/7/2026

Peekaboo

⚠️65/100

Wrapper for macOS UI automation - requires accessibility permissions and screen recording.

Risk: medium2/7/2026

WhatsApp CLI

⚠️65/100

Wrapper for WhatsApp CLI - requires WhatsApp session with message access.

Risk: medium2/7/2026

Model Usage

⚠️62/100

Script executes external commands and reads files with minimal input validation, presenting moderate security risks through command injection and path traversal vulnerabilities.

Risk: medium2/7/2026

Video Frames

⚠️45/100

Script has command injection vulnerabilities through unsanitized user inputs passed to ffmpeg and mkdir commands, allowing arbitrary command execution.

Risk: high2/7/2026

Android TikTok Automation

⚠️45/100

Android automation library with significant command injection vulnerabilities and unrestricted device control capabilities that could be exploited for malicious purposes.

Risk: high2/7/2026

API Integration Skill

🚨15/100

Critical security vulnerabilities including hardcoded credentials, SSRF, weak cryptography, injection vulnerabilities, and missing authentication controls.

Risk: critical2/7/2026

File Reader Skill

🚨5/100

This skill contains multiple critical vulnerabilities including command injection, path traversal, and arbitrary code execution that could lead to complete system compromise.

Risk: critical2/7/2026