by alexgreensh · MCP Server · ★ 63
That MCP server with 500 downloads. The Claude Code skill someone linked in Discord. The ClawHub extension your OpenClaw agent auto-installed. The npm package Cursor added to your lockfile. The Codex plugin you grabbed from GitHub. Did you vet any of them? Nobody does. The vetting step doesn't exist. 1,184 malicious skills found on ClawHub in one campaign. 36.8% of agent skills have security flaws. You find something useful, you install it. It runs with your credentials, your file access, your session context.
| Stars | 63 |
| Forks | 11 |
| Language | Python |
| Category | MCP Server |
| Quality Score | 59.704/100 |
| Last Updated | 2026-05-13 |
| Created | 2026-02-27 |
| Platforms | claude-code, mcp, python |
| Est. Tokens | ~80k |
Explore other popular mcp server tools:
repo-forensics is Automated Security scanner for GitHub repos, Agent Skills, Plugins, and MCP servers. 19 scanners. Zero dependencies. Keeps you and your agent safe.. It is categorized as a MCP Server with 63 GitHub stars.
repo-forensics is primarily written in Python. It covers topics such as agent-skill, claude-skills, forensics.
You can find installation instructions and usage details in the repo-forensics GitHub repository at github.com/alexgreensh/repo-forensics. The project has 63 stars and 11 forks, indicating an active community.