{"feedVersion":"1.0","generatedAt":"2026-09-06T13:07:35.588Z","description":"SkillAudit Threat Intelligence Feed — real-time security findings from AI skill scans","totalScansProcessed":2647,"recentThreats":{"count":20,"severityBreakdown":{"critical":5,"high":8,"medium":7,"low":0},"uniqueDomains":1,"items":[{"scanId":"a3d68f815b91","source":"https://heyclau.de/entry/mcp/codacy-mcp-server","domain":"heyclau.de","ruleId":"THREAT_CHAIN_DATA_EXFILTRATION","severity":"critical","category":"data_theft","name":"Threat Chain: DATA_EXFILTRATION","description":"Can access credentials AND send network requests - potential for data theft","line":136,"detectedAt":"2026-09-05T04:23:32.084Z"},{"scanId":"a3d68f815b91","source":"https://heyclau.de/entry/mcp/codacy-mcp-server","domain":"heyclau.de","ruleId":"INTENT_MALWARE_INSTALL_INTENT","severity":"critical","category":"intent_analysis","name":"Malware install intent","description":"Instruction asks to install malicious software","line":162,"detectedAt":"2026-09-05T04:23:32.084Z"},{"scanId":"7e2fa3f10c94","source":"https://heyclau.de/entry/mcp/toolhive-mcp-platform","domain":"heyclau.de","ruleId":"A2A_AGENT_IMPERSONATION","severity":"critical","category":"agent_manipulation","name":"A2A agent impersonation / card spoofing","description":"Skill fabricates or overrides Agent Card metadata to impersonate another agent, claim false capabilities, or inject hidden instructions into the A2A discovery layer","line":138,"detectedAt":"2026-09-05T04:23:31.955Z"},{"scanId":"7e2fa3f10c94","source":"https://heyclau.de/entry/mcp/toolhive-mcp-platform","domain":"heyclau.de","ruleId":"CONTAINER_ESCAPE","severity":"critical","category":"privilege_escalation","name":"Container/sandbox escape attempt","description":"Skill attempts to escape container or sandbox isolation — accessing Docker socket, mounting host filesystem, or exploiting kernel interfaces","line":138,"detectedAt":"2026-09-05T04:23:31.955Z"},{"scanId":"a3d68f815b91","source":"https://heyclau.de/entry/mcp/codacy-mcp-server","domain":"heyclau.de","ruleId":"CMD_INJECTION","severity":"critical","category":"code_execution","name":"Command injection","description":"Skill constructs shell commands from dynamic input using dangerous concatenation or template patterns — enables arbitrary command execution via ; | && `` $() injection","line":103,"detectedAt":"2026-09-05T04:23:32.084Z"},{"scanId":"7e2fa3f10c94","source":"https://heyclau.de/entry/mcp/toolhive-mcp-platform","domain":"heyclau.de","ruleId":"SSRF_PATTERN","severity":"high","category":"network","name":"Server-Side Request Forgery (SSRF)","description":"Skill crafts requests to internal/cloud metadata endpoints or uses URL schemes to access internal services","line":157,"detectedAt":"2026-09-05T04:23:31.955Z"},{"scanId":"7e2fa3f10c94","source":"https://heyclau.de/entry/mcp/toolhive-mcp-platform","domain":"heyclau.de","ruleId":"TOOL_SHADOW","severity":"high","category":"agent_manipulation","name":"Tool shadowing / redefinition","description":"Skill attempts to redefine, override, or shadow other tools to intercept their data","line":138,"detectedAt":"2026-09-05T04:23:31.955Z"},{"scanId":"7e2fa3f10c94","source":"https://heyclau.de/entry/mcp/toolhive-mcp-platform","domain":"heyclau.de","ruleId":"TOOL_SHADOW","severity":"high","category":"agent_manipulation","name":"Tool shadowing / redefinition","description":"Skill attempts to redefine, override, or shadow other tools to intercept their data","line":130,"detectedAt":"2026-09-05T04:23:31.955Z"},{"scanId":"7e2fa3f10c94","source":"https://heyclau.de/entry/mcp/toolhive-mcp-platform","domain":"heyclau.de","ruleId":"SSRF_PATTERN","severity":"high","category":"network","name":"Server-Side Request Forgery (SSRF)","description":"Skill crafts requests to internal/cloud metadata endpoints or uses URL schemes to access internal services","line":141,"detectedAt":"2026-09-05T04:23:31.955Z"},{"scanId":"7e2fa3f10c94","source":"https://heyclau.de/entry/mcp/toolhive-mcp-platform","domain":"heyclau.de","ruleId":"SSRF_PATTERN","severity":"high","category":"network","name":"Server-Side Request Forgery (SSRF)","description":"Skill crafts requests to internal/cloud metadata endpoints or uses URL schemes to access internal services","line":78,"detectedAt":"2026-09-05T04:23:31.955Z"},{"scanId":"7e2fa3f10c94","source":"https://heyclau.de/entry/mcp/toolhive-mcp-platform","domain":"heyclau.de","ruleId":"TOOL_SHADOW","severity":"high","category":"agent_manipulation","name":"Tool shadowing / redefinition","description":"Skill attempts to redefine, override, or shadow other tools to intercept their data","line":122,"detectedAt":"2026-09-05T04:23:31.955Z"},{"scanId":"7e2fa3f10c94","source":"https://heyclau.de/entry/mcp/toolhive-mcp-platform","domain":"heyclau.de","ruleId":"TOOL_SHADOW","severity":"high","category":"agent_manipulation","name":"Tool shadowing / redefinition","description":"Skill attempts to redefine, override, or shadow other tools to intercept their data","line":126,"detectedAt":"2026-09-05T04:23:31.955Z"},{"scanId":"7e2fa3f10c94","source":"https://heyclau.de/entry/mcp/toolhive-mcp-platform","domain":"heyclau.de","ruleId":"TOOL_SHADOW","severity":"high","category":"agent_manipulation","name":"Tool shadowing / redefinition","description":"Skill attempts to redefine, override, or shadow other tools to intercept their data","line":129,"detectedAt":"2026-09-05T04:23:31.955Z"},{"scanId":"5ab695b70bf8","source":"https://heyclau.de/entry/mcp/figma-mcp-server","domain":"heyclau.de","ruleId":"NET_SUSPICIOUS","severity":"medium","category":"network","name":"Suspicious network activity","description":"Skill makes network requests to unusual destinations","line":112,"detectedAt":"2026-09-05T04:23:30.673Z"},{"scanId":"5ab695b70bf8","source":"https://heyclau.de/entry/mcp/figma-mcp-server","domain":"heyclau.de","ruleId":"NET_SUSPICIOUS","severity":"medium","category":"network","name":"Suspicious network activity","description":"Skill makes network requests to unusual destinations","line":108,"detectedAt":"2026-09-05T04:23:30.673Z"},{"scanId":"5ab695b70bf8","source":"https://heyclau.de/entry/mcp/figma-mcp-server","domain":"heyclau.de","ruleId":"NET_SUSPICIOUS","severity":"medium","category":"network","name":"Suspicious network activity","description":"Skill makes network requests to unusual destinations","line":104,"detectedAt":"2026-09-05T04:23:30.673Z"},{"scanId":"5ab695b70bf8","source":"https://heyclau.de/entry/mcp/figma-mcp-server","domain":"heyclau.de","ruleId":"NET_SUSPICIOUS","severity":"medium","category":"network","name":"Suspicious network activity","description":"Skill makes network requests to unusual destinations","line":100,"detectedAt":"2026-09-05T04:23:30.673Z"},{"scanId":"5ab695b70bf8","source":"https://heyclau.de/entry/mcp/figma-mcp-server","domain":"heyclau.de","ruleId":"NET_SUSPICIOUS","severity":"medium","category":"network","name":"Suspicious network activity","description":"Skill makes network requests to unusual destinations","line":51,"detectedAt":"2026-09-05T04:23:30.673Z"},{"scanId":"5ab695b70bf8","source":"https://heyclau.de/entry/mcp/figma-mcp-server","domain":"heyclau.de","ruleId":"NET_SUSPICIOUS","severity":"medium","category":"network","name":"Suspicious network activity","description":"Skill makes network requests to unusual destinations","line":59,"detectedAt":"2026-09-05T04:23:30.673Z"},{"scanId":"5ab695b70bf8","source":"https://heyclau.de/entry/mcp/figma-mcp-server","domain":"heyclau.de","ruleId":"NET_SUSPICIOUS","severity":"medium","category":"network","name":"Suspicious network activity","description":"Skill makes network requests to unusual destinations","line":47,"detectedAt":"2026-09-05T04:23:30.673Z"}]},"flaggedDomains":{"count":10,"items":[{"domain":"heyclau.de","riskLevel":"high","riskScore":30,"url":"https://heyclau.de/entry/mcp/codacy-mcp-server","flaggedAt":"2026-09-05T04:23:32.090Z"},{"domain":"heyclau.de","riskLevel":"critical","riskScore":96,"url":"https://heyclau.de/entry/mcp/toolhive-mcp-platform","flaggedAt":"2026-09-05T04:23:31.959Z"},{"domain":"heyclau.de","riskLevel":"critical","riskScore":171,"url":"https://heyclau.de/entry/mcp/figma-mcp-server","flaggedAt":"2026-09-05T04:23:30.677Z"},{"domain":"github.com","riskLevel":"critical","riskScore":92,"url":"https://github.com/anthropics/anthropic-cookbook","flaggedAt":"2026-09-05T03:01:12.828Z"},{"domain":"github.com","riskLevel":"critical","riskScore":92,"url":"https://github.com/modelcontextprotocol/servers","flaggedAt":"2026-09-05T03:01:08.026Z"},{"domain":"github.com","riskLevel":"critical","riskScore":92,"url":"https://github.com/modelcontextprotocol/servers","flaggedAt":"2026-09-05T03:01:03.690Z"},{"domain":"github.com","riskLevel":"critical","riskScore":99,"url":"https://github.com/obra/superpowers","flaggedAt":"2026-08-29T20:33:07.053Z"},{"domain":"github.com","riskLevel":"critical","riskScore":82,"url":"https://github.com/anthropics/courses","flaggedAt":"2026-08-29T20:33:03.777Z"},{"domain":"github.com","riskLevel":"critical","riskScore":82,"url":"https://github.com/anthropics/anthropic-cookbook","flaggedAt":"2026-08-29T20:30:28.957Z"},{"domain":"github.com","riskLevel":"critical","riskScore":82,"url":"https://github.com/anthropics/anthropic-cookbook","flaggedAt":"2026-08-29T20:27:56.900Z"}]},"trendingRules":{"count":10,"description":"Most frequently triggered detection rules across all scans","items":[{"ruleId":"CMD_INJECTION","hitCount":3089},{"ruleId":"SSRF_ADVANCED","hitCount":942},{"ruleId":"CROSS_TOOL_ACCESS","hitCount":408},{"ruleId":"A2A_CROSS_AGENT_INJECT","hitCount":313},{"ruleId":"A2A_DATA_LEAK","hitCount":308},{"ruleId":"CRYPTO_THEFT","hitCount":288},{"ruleId":"THREAT_CHAIN_SYSTEM_COMPROMISE","hitCount":250},{"ruleId":"A2A_TASK_HIJACK","hitCount":222},{"ruleId":"REVERSE_SHELL","hitCount":214},{"ruleId":"SHELL_EXEC","hitCount":214}]},"subscribe":{"polling":"GET /feed?severity=high&limit=50 — poll for updates","since":"GET /feed/since?ts=<unix_ms> — get threats after a timestamp","webhook":"POST /scan/url with callback parameter for per-scan notifications"}}