| Pre-install decision |
|---|
| 82 · Manual review | 81 · Evidence missing | |
|---|
| Clear source, High execution risk, Claude | Clear source, High execution risk, Universal | Clear source, High execution risk, Claude |
|---|
| | High | |
|---|
| data exfiltration, human approval gap | prompt injection, tool poisoning, unexpected code execution | prompt injection, tool poisoning, identity privilege abuse |
|---|
| missing license, network without allowlist, no human approval | missing license, broad permissions, shell without guardrails | missing license, broad permissions, network without allowlist |
|---|
| Network, Command | Permission review, Network, Secrets, Command | Permission review, Network, Secrets, Command |
|---|
| 63% | | |
|---|
| Source & provenance |
|---|
| nextlevelbuilder/ui-ux-pro-max-skill/tree/main/.claude/skills/ui-ux-pro-max | neverinfamous/memory-journal-mcp | UseAI-pro/openclaw-skills-security |
|---|
| Design & Content | Knowledge & RAG | Productivity & Docs |
|---|
|
|---|
| Risk & permission signals |
|---|
| No explicit signals | needs credentials, network access | needs credentials |
|---|
| registry access, remote metadata pull, runtime dependencies may be required | repository clone, local runtime dependencies | local skill installation, workspace file updates |
|---|
| Install & compatibility |
|---|
| Claude, Codex, Cursor, Universal | Universal | Claude, Codex, Cursor, Windsurf |
|---|
| registry-install | script-backed | instruction-only |
|---|
|
|---|
| Community |
|---|
| | 13 | 48 |
|---|