oathe / scan / reports
Audited agent skills and MCP servers
Every skill here was installed in an isolated sandbox and watched while it ran — file access, network calls, process activity. The score reflects what it did, not what its README claims. 2,986 skills audited so far.
Browse by verdict: malicious · dangerous · caution · safe · audit a new skill
Scores run 0–100. Every audit runs the skill in a sandbox and records what it actually does. How the audit works · What the verdicts mean