oathe / scan / reports / malicious

Malicious agent skills and MCP servers

These skills did something clearly harmful when we ran them. Do not install them.

A malicious verdict means the sandbox caught the skill doing something no reasonable user would agree to — reading credentials it has no use for, shipping data to an anonymous endpoint, taking instructions from a remote server, or hiding what it was doing from the user. Nothing here is a guess about what the code could do. It is what the skill did.

Trust score 0–19 · 24 skills · Other verdicts: dangerous · caution · safe · audit a new skill

Scores run 0–100. Every audit runs the skill in a sandbox and records what it actually does. How the audit works · What the verdicts mean