Submit

Anyone can add an entry. A submission is a GitHub issue, so the whole conversation — who asked, what was decided, when it went live — stays public and permanent.

What happens to it

  1. You open an issue with the link to the repository, or to the directory inside it.
  2. It is queued ahead of the backlog. Somebody asking beats a crawler finding.
  3. It is read in full — the instruction text, the code, the dependencies, the manifests.
  4. The findings are published on its page whatever they say, each one citing the file and line it was found on. A page that says do not install this is a page we publish.
  5. We keep watching. When the repository changes it is audited again, and the page shows every audit it has ever had.

Submit one

A skill
a SKILL.md and whatever it carries
An MCP server
we read its exposed tools and classify each one
A tool
a product built on the models

What we will not do

We do not remove a finding because the author asks. If a finding is wrong, say so on the issue with the reasoning and it is re-audited — that correction is public too. Nobody can pay for a grade, and the audit does not know who is listed anywhere else on this site.