SkillRisk
Scans AI agent skill configurations for supply chain attacks, SSRF vulnerabilities, and prompt injection threats.
≈ 1visits/mo
Emerging · estimate, read 2026-09-19
- For
- Developers using AI agents like Claude, Cursor, and Windsurf who need to secure their agent skills
- Price
- Price not read
- Activity
- Quietnothing dated on the site
- Company
- founding year not on record
- Runs as
- No-code
- scan skill files for malicious hooks and supply chain attacks
- detect MCP server vulnerabilities like SSRF and command injection
- identify hardcoded credentials and data exfiltration patterns
- #1
Brave
Browser that blocks ads and trackers, encrypts connections with built-in VPN, and includes private search.
1.4MActiveFrom $3/mo - #2
Synology Inc.
Provides network-attached storage, surveillance, and data protection systems for businesses and homes.
255kActive—2000 - #3
Lumo by Proton
Conversational AI assistant that encrypts all messages and does not retain conversation history.
3.4MActive— - #7
Darktrace
Detects novel threats across networks, email, cloud, and endpoints using behavioral analysis.
68.5knot read—2013 - #8
Canary Mail
Email client with AI-assisted composition, thread summarization, and encryption for managing multiple accounts across devices.
32.5kActiveFrom $36/yr - #13
Scamwise
Analyzes suspicious messages, emails, links, and images to detect scam signals and provide verdicts.
130kActive—
What is SkillRisk?
Scans AI agent skill configurations for supply chain attacks, SSRF vulnerabilities, and prompt injection threats.
Who is SkillRisk for?
Developers using AI agents like Claude, Cursor, and Windsurf who need to secure their agent skills
Do people use SkillRisk?
Emerging: ≈ 1 visits a month · estimate, 2026-09.
Is SkillRisk still maintained?
Quiet.
What are alternatives to SkillRisk?
In Security, by use: Brave, Synology Inc., Lumo by Proton, Darktrace, Canary Mail, Scamwise.
How we read a tool
No votes, no reviews, no vendor claims. Every week a crawler reads each tool's own site and a few public registries, and the words on the card are bands over what it read.
- Use: visits to the site (estimated), installs from npm and PyPI, presence in Chrome's usage report.
- Activity: the newest release on GitHub, npm or PyPI; the newest dated page on the site; open roles on a public jobs board.
- Price: the vendor's own pricing page, read with the date. A figure is printed only when it is on that page.
- The line and the use cases are written by us from the homepage, one row at a time, and refused when they repeat the vendor's marketing.
How AI assistants read each site — the reading vendors ask us about — is on each tool's own visibility page.