{"feedVersion":"1.0","generatedAt":"2026-07-20T16:30:55.823Z","description":"SkillAudit Threat Intelligence Feed — real-time security findings from AI skill scans","totalScansProcessed":1982,"recentThreats":{"count":20,"severityBreakdown":{"critical":19,"high":1,"medium":0,"low":0},"uniqueDomains":1,"items":[{"scanId":"39920aceadeb","source":"https://raw.githubusercontent.com/modelcontextprotocol/servers/main/src/sequentialthinking/README.md","domain":"raw.githubusercontent.com","ruleId":"CMD_INJECTION","severity":"critical","category":"code_execution","name":"Command injection","description":"Skill constructs shell commands from dynamic input using dangerous concatenation or template patterns — enables arbitrary command execution via ; | && `` $() injection","line":61,"detectedAt":"2026-07-20T11:03:50.723Z"},{"scanId":"39920aceadeb","source":"https://raw.githubusercontent.com/modelcontextprotocol/servers/main/src/sequentialthinking/README.md","domain":"raw.githubusercontent.com","ruleId":"INTENT_SECURITY_DISABLE_INTENT","severity":"critical","category":"intent_analysis","name":"Security disable intent","description":"Instruction asks to disable security measures","line":130,"detectedAt":"2026-07-20T11:03:50.723Z"},{"scanId":"aa47f0c3a83d","source":"https://raw.githubusercontent.com/modelcontextprotocol/servers/main/src/filesystem/README.md","domain":"raw.githubusercontent.com","ruleId":"CMD_INJECTION","severity":"critical","category":"code_execution","name":"Command injection","description":"Skill constructs shell commands from dynamic input using dangerous concatenation or template patterns — enables arbitrary command execution via ; | && `` $() injection","line":206,"detectedAt":"2026-07-20T11:03:50.614Z"},{"scanId":"aa47f0c3a83d","source":"https://raw.githubusercontent.com/modelcontextprotocol/servers/main/src/filesystem/README.md","domain":"raw.githubusercontent.com","ruleId":"THREAT_CHAIN_SYSTEM_COMPROMISE","severity":"critical","category":"persistence","name":"Threat Chain: SYSTEM_COMPROMISE","description":"Can modify system AND escalate privileges - full system compromise","line":39,"detectedAt":"2026-07-20T11:03:50.614Z"},{"scanId":"39920aceadeb","source":"https://raw.githubusercontent.com/modelcontextprotocol/servers/main/src/sequentialthinking/README.md","domain":"raw.githubusercontent.com","ruleId":"CMD_INJECTION","severity":"critical","category":"code_execution","name":"Command injection","description":"Skill constructs shell commands from dynamic input using dangerous concatenation or template patterns — enables arbitrary command execution via ; | && `` $() injection","line":29,"detectedAt":"2026-07-20T11:03:50.723Z"},{"scanId":"0e0d8f3a1daf","source":"https://raw.githubusercontent.com/modelcontextprotocol/servers/main/src/everything/AGENTS.md","domain":"raw.githubusercontent.com","ruleId":"CMD_INJECTION","severity":"critical","category":"code_execution","name":"Command injection","description":"Skill constructs shell commands from dynamic input using dangerous concatenation or template patterns — enables arbitrary command execution via ; | && `` $() injection","line":38,"detectedAt":"2026-07-20T11:03:50.659Z"},{"scanId":"aa47f0c3a83d","source":"https://raw.githubusercontent.com/modelcontextprotocol/servers/main/src/filesystem/README.md","domain":"raw.githubusercontent.com","ruleId":"CMD_INJECTION","severity":"critical","category":"code_execution","name":"Command injection","description":"Skill constructs shell commands from dynamic input using dangerous concatenation or template patterns — enables arbitrary command execution via ; | && `` $() injection","line":210,"detectedAt":"2026-07-20T11:03:50.614Z"},{"scanId":"aa47f0c3a83d","source":"https://raw.githubusercontent.com/modelcontextprotocol/servers/main/src/filesystem/README.md","domain":"raw.githubusercontent.com","ruleId":"CMD_INJECTION","severity":"critical","category":"code_execution","name":"Command injection","description":"Skill constructs shell commands from dynamic input using dangerous concatenation or template patterns — enables arbitrary command execution via ; | && `` $() injection","line":208,"detectedAt":"2026-07-20T11:03:50.614Z"},{"scanId":"aa47f0c3a83d","source":"https://raw.githubusercontent.com/modelcontextprotocol/servers/main/src/filesystem/README.md","domain":"raw.githubusercontent.com","ruleId":"CMD_INJECTION","severity":"critical","category":"code_execution","name":"Command injection","description":"Skill constructs shell commands from dynamic input using dangerous concatenation or template patterns — enables arbitrary command execution via ; | && `` $() injection","line":207,"detectedAt":"2026-07-20T11:03:50.614Z"},{"scanId":"aa47f0c3a83d","source":"https://raw.githubusercontent.com/modelcontextprotocol/servers/main/src/filesystem/README.md","domain":"raw.githubusercontent.com","ruleId":"CMD_INJECTION","severity":"critical","category":"code_execution","name":"Command injection","description":"Skill constructs shell commands from dynamic input using dangerous concatenation or template patterns — enables arbitrary command execution via ; | && `` $() injection","line":205,"detectedAt":"2026-07-20T11:03:50.614Z"},{"scanId":"aa47f0c3a83d","source":"https://raw.githubusercontent.com/modelcontextprotocol/servers/main/src/filesystem/README.md","domain":"raw.githubusercontent.com","ruleId":"CMD_INJECTION","severity":"critical","category":"code_execution","name":"Command injection","description":"Skill constructs shell commands from dynamic input using dangerous concatenation or template patterns — enables arbitrary command execution via ; | && `` $() injection","line":190,"detectedAt":"2026-07-20T11:03:50.614Z"},{"scanId":"aa47f0c3a83d","source":"https://raw.githubusercontent.com/modelcontextprotocol/servers/main/src/filesystem/README.md","domain":"raw.githubusercontent.com","ruleId":"CMD_INJECTION","severity":"critical","category":"code_execution","name":"Command injection","description":"Skill constructs shell commands from dynamic input using dangerous concatenation or template patterns — enables arbitrary command execution via ; | && `` $() injection","line":51,"detectedAt":"2026-07-20T11:03:50.614Z"},{"scanId":"b47852113eab","source":"https://raw.githubusercontent.com/modelcontextprotocol/servers/main/src/time/README.md","domain":"raw.githubusercontent.com","ruleId":"CMD_INJECTION","severity":"critical","category":"code_execution","name":"Command injection","description":"Skill constructs shell commands from dynamic input using dangerous concatenation or template patterns — enables arbitrary command execution via ; | && `` $() injection","line":178,"detectedAt":"2026-07-20T11:03:50.524Z"},{"scanId":"7b623eb4c84a","source":"https://raw.githubusercontent.com/modelcontextprotocol/servers/main/src/memory/README.md","domain":"raw.githubusercontent.com","ruleId":"CMD_INJECTION","severity":"critical","category":"code_execution","name":"Command injection","description":"Skill constructs shell commands from dynamic input using dangerous concatenation or template patterns — enables arbitrary command execution via ; | && `` $() injection","line":136,"detectedAt":"2026-07-20T11:03:50.422Z"},{"scanId":"7b623eb4c84a","source":"https://raw.githubusercontent.com/modelcontextprotocol/servers/main/src/memory/README.md","domain":"raw.githubusercontent.com","ruleId":"CMD_INJECTION","severity":"critical","category":"code_execution","name":"Command injection","description":"Skill constructs shell commands from dynamic input using dangerous concatenation or template patterns — enables arbitrary command execution via ; | && `` $() injection","line":134,"detectedAt":"2026-07-20T11:03:50.422Z"},{"scanId":"42d439f9a004","source":"https://raw.githubusercontent.com/modelcontextprotocol/servers/main/src/git/README.md","domain":"raw.githubusercontent.com","ruleId":"CMD_INJECTION","severity":"critical","category":"code_execution","name":"Command injection","description":"Skill constructs shell commands from dynamic input using dangerous concatenation or template patterns — enables arbitrary command execution via ; | && `` $() injection","line":256,"detectedAt":"2026-07-20T11:03:50.320Z"},{"scanId":"3f226bd92dc6","source":"https://raw.githubusercontent.com/modelcontextprotocol/servers/main/src/filesystem/index.ts","domain":"raw.githubusercontent.com","ruleId":"THREAT_CHAIN_SYSTEM_COMPROMISE","severity":"critical","category":"persistence","name":"Threat Chain: SYSTEM_COMPROMISE","description":"Can modify system AND escalate privileges - full system compromise","line":51,"detectedAt":"2026-07-20T11:03:45.761Z"},{"scanId":"3f226bd92dc6","source":"https://raw.githubusercontent.com/modelcontextprotocol/servers/main/src/filesystem/index.ts","domain":"raw.githubusercontent.com","ruleId":"CMD_INJECTION","severity":"critical","category":"code_execution","name":"Command injection","description":"Skill constructs shell commands from dynamic input using dangerous concatenation or template patterns — enables arbitrary command execution via ; | && `` $() injection","line":767,"detectedAt":"2026-07-20T11:03:45.761Z"},{"scanId":"3f226bd92dc6","source":"https://raw.githubusercontent.com/modelcontextprotocol/servers/main/src/filesystem/index.ts","domain":"raw.githubusercontent.com","ruleId":"CMD_INJECTION","severity":"critical","category":"code_execution","name":"Command injection","description":"Skill constructs shell commands from dynamic input using dangerous concatenation or template patterns — enables arbitrary command execution via ; | && `` $() injection","line":533,"detectedAt":"2026-07-20T11:03:45.761Z"},{"scanId":"3f226bd92dc6","source":"https://raw.githubusercontent.com/modelcontextprotocol/servers/main/src/filesystem/index.ts","domain":"raw.githubusercontent.com","ruleId":"ENV_RECON","severity":"high","category":"reconnaissance","name":"Environment fingerprinting / reconnaissance","description":"Skill probes the host system to gather information about the environment — common precursor to targeted attacks","line":32,"detectedAt":"2026-07-20T11:03:45.761Z"}]},"flaggedDomains":{"count":10,"items":[{"domain":"raw.githubusercontent.com","riskLevel":"high","riskScore":30,"url":"https://raw.githubusercontent.com/modelcontextprotocol/servers/main/src/sequentialthinking/README.md","flaggedAt":"2026-07-20T11:03:50.724Z"},{"domain":"raw.githubusercontent.com","riskLevel":"moderate","riskScore":10,"url":"https://raw.githubusercontent.com/modelcontextprotocol/servers/main/src/everything/AGENTS.md","flaggedAt":"2026-07-20T11:03:50.660Z"},{"domain":"raw.githubusercontent.com","riskLevel":"critical","riskScore":80,"url":"https://raw.githubusercontent.com/modelcontextprotocol/servers/main/src/filesystem/README.md","flaggedAt":"2026-07-20T11:03:50.619Z"},{"domain":"raw.githubusercontent.com","riskLevel":"moderate","riskScore":10,"url":"https://raw.githubusercontent.com/modelcontextprotocol/servers/main/src/time/README.md","flaggedAt":"2026-07-20T11:03:50.525Z"},{"domain":"raw.githubusercontent.com","riskLevel":"moderate","riskScore":20,"url":"https://raw.githubusercontent.com/modelcontextprotocol/servers/main/src/memory/README.md","flaggedAt":"2026-07-20T11:03:50.423Z"},{"domain":"raw.githubusercontent.com","riskLevel":"moderate","riskScore":10,"url":"https://raw.githubusercontent.com/modelcontextprotocol/servers/main/src/git/README.md","flaggedAt":"2026-07-20T11:03:50.320Z"},{"domain":"raw.githubusercontent.com","riskLevel":"high","riskScore":47,"url":"https://raw.githubusercontent.com/modelcontextprotocol/servers/main/src/filesystem/index.ts","flaggedAt":"2026-07-20T11:03:45.764Z"},{"domain":"raw.githubusercontent.com","riskLevel":"moderate","riskScore":10,"url":"https://raw.githubusercontent.com/DietrichGebert/ponytail/main/skills/ponytail/SKILL.md","flaggedAt":"2026-07-19T23:29:23.469Z"},{"domain":"raw.githubusercontent.com","riskLevel":"moderate","riskScore":10,"url":"https://raw.githubusercontent.com/DietrichGebert/ponytail/main/skills/ponytail-review/SKILL.md","flaggedAt":"2026-07-19T23:29:23.457Z"},{"domain":"raw.githubusercontent.com","riskLevel":"moderate","riskScore":10,"url":"https://raw.githubusercontent.com/DietrichGebert/ponytail/main/skills/ponytail-help/SKILL.md","flaggedAt":"2026-07-19T23:29:23.450Z"}]},"trendingRules":{"count":10,"description":"Most frequently triggered detection rules across all scans","items":[{"ruleId":"CMD_INJECTION","hitCount":2159},{"ruleId":"SSRF_ADVANCED","hitCount":697},{"ruleId":"CROSS_TOOL_ACCESS","hitCount":268},{"ruleId":"A2A_DATA_LEAK","hitCount":224},{"ruleId":"A2A_CROSS_AGENT_INJECT","hitCount":217},{"ruleId":"CRYPTO_THEFT","hitCount":201},{"ruleId":"A2A_TASK_HIJACK","hitCount":196},{"ruleId":"THREAT_CHAIN_SYSTEM_COMPROMISE","hitCount":181},{"ruleId":"SHELL_EXEC","hitCount":158},{"ruleId":"PRIVILEGE_ESC","hitCount":142}]},"subscribe":{"polling":"GET /feed?severity=high&limit=50 — poll for updates","since":"GET /feed/since?ts=<unix_ms> — get threats after a timestamp","webhook":"POST /scan/url with callback parameter for per-scan notifications"}}