| Pre-install decision |
|---|
| 81 · Evidence missing | | 81 · Manual review |
|---|
| Clear source, High execution risk, Universal | Clear source, High execution risk, Claude | Clear source, High execution risk, Universal |
|---|
| High | | High |
|---|
| prompt injection, tool poisoning, unexpected code execution | data exfiltration, human approval gap | unexpected code execution, data exfiltration, memory context poisoning |
|---|
| missing license, broad permissions, shell without guardrails | missing license, network without allowlist, no human approval | missing license, broad permissions, shell without guardrails |
|---|
| Permission review, Network, Secrets, Command | Network, Command | Permission review, Network, Command |
|---|
| | 63% | 67% |
|---|
| Source & provenance |
|---|
| neverinfamous/memory-journal-mcp | nextlevelbuilder/ui-ux-pro-max-skill/tree/main/.claude/skills/ui-ux-pro-max | project-nomos/nomos |
|---|
| Knowledge & RAG | Design & Content | Knowledge & RAG |
|---|
|
|---|
| Risk & permission signals |
|---|
| needs credentials, network access | No explicit signals | No explicit signals |
|---|
| repository clone, local runtime dependencies | registry access, remote metadata pull, runtime dependencies may be required | repository clone, local runtime dependencies |
|---|
| Install & compatibility |
|---|
| Universal | Claude, Codex, Cursor, Universal | Universal |
|---|
| script-backed | registry-install | script-backed |
|---|
|
|---|
| Community |
|---|
| 13 | | 10 |
|---|