Submit
Anyone can add an entry. A submission is a GitHub issue, so the whole conversation — who asked, what was decided, when it went live — stays public and permanent.
What happens to it
- You open an issue with the link to the repository, or to the directory inside it.
- It is queued ahead of the backlog. Somebody asking beats a crawler finding.
- It is read in full — the instruction text, the code, the dependencies, the manifests.
- The findings are published on its page whatever they say, each one citing the file and line it was found on. A page that says do not install this is a page we publish.
- We keep watching. When the repository changes it is audited again, and the page shows every audit it has ever had.
Submit one
A skill
a SKILL.md and whatever it carriesAn MCP server
we read its exposed tools and classify each oneA tool
a product built on the models
a SKILL.md and whatever it carriesAn MCP server
we read its exposed tools and classify each oneA tool
a product built on the models
What we will not do
We do not remove a finding because the author asks. If a finding is wrong, say so on the issue with the reasoning and it is re-audited — that correction is public too. Nobody can pay for a grade, and the audit does not know who is listed anywhere else on this site.