oathe / scan / reports

Audited agent skills and MCP servers

Every skill here was installed in an isolated sandbox and watched while it ran — file access, network calls, process activity. The score reflects what it did, not what its README claims. 2,986 skills audited so far.

Browse by verdict: malicious · dangerous · caution · safe · audit a new skill

Scores run 0–100. Every audit runs the skill in a sandbox and records what it actually does. How the audit works · What the verdicts mean