Jiffy Intel
AI artifact intel
A lean feed for CTI and SOC teams triaging skills, MCP servers, extensions, agents, models, and packages. Every row leads with the artifact first: name, owner, downloads, source, Jiffy Score, and verdict.
102Published entries
0Updated in 7 days
57P1/P2 artifacts
8Live sources
Sources
skills.shMCP RegistryVS Code MarketplaceChrome Web StoreGitHubOpenAI GPT StoreHugging FacenpmPyPI
SOC snapshot
102 rows shownHighest-priority artifacts
Sorted by lowest Jiffy Score, then newest signal. Last feed update: Apr 28, 2026.
Ops Dashboard GPTUnknown / OpenAI GPT Store / Updated Apr 28, 202622Maliciousmaintenance-mcpUnknown / MCP Registry / Updated Apr 27, 202622Maliciousops-harness-mcpUnknown / MCP Registry / Updated Apr 27, 202622Maliciouslegacy-saas-mcpUnknown / MCP Registry / Updated Apr 26, 202622Maliciousrepo-sharing-skillUnknown / Anthropic Skills / Updated Apr 22, 202622Malicious
Catalog
102 of 102 artifactsArtifact catalog
Filter by verdict or source. Higher Jiffy Scores are safer. Missing registry fields stay marked as Unknown or Not reported.
Verdict
Source
Advanced mappings
Framework
Finding bucket
| Name | Owner | Downloads | Source | Jiffy Score | Verdict |
|---|---|---|---|---|---|
| Ops Dashboard GPTCustom GPT Action schema includes an undocumented "admin" path | Unknown | Not reported | OpenAI GPT Store | 22 | MaliciousSOC priority: P1 |
| maintenance-mcpMCP server exposes hidden "debug" tool that shells out | Unknown | Not reported | MCP Registry | 22 | MaliciousSOC priority: P1 |
| ops-harness-mcpMCP server ships with test-mode endpoint enabled in production builds | Unknown | Not reported | MCP Registry | 22 | MaliciousSOC priority: P1 |
| legacy-saas-mcpMCP server proxies auth through a hostname that lapsed ownership | Unknown | Not reported | MCP Registry | 22 | MaliciousSOC priority: P1 |
| repo-sharing-skillSkill adds attacker email as a collaborator on all user GitHub repos | Unknown | Not reported | Anthropic Skills | 22 | MaliciousSOC priority: P1 |
| AI Assistant HubExtension with MV3 host permissions reads cookies for AI vendor sites | Unknown | Not reported | Chrome Web Store | 22 | MaliciousSOC priority: P1 |
| AGENTS.md (repo: open-source-lib)AGENTS.md instructs agent to read .env and include contents in PR description | Unknown | Not reported | GitHub (public repo) | 22 | MaliciousSOC priority: P1 |
| Doc Wizard GPTCustom GPT system prompt tries to exfiltrate user uploads to external URL | Unknown | Not reported | OpenAI GPT Store | 22 | MaliciousSOC priority: P1 |
| dev-secrets-skillSkill reads 1Password CLI session token from /tmp | Unknown | Not reported | Anthropic Skills | 22 | MaliciousSOC priority: P1 |
| Full-Stack Onboarding ProjectShared Claude Project instructs user to upload .env file as "context" | Unknown | Not reported | Claude Projects (claude.ai) | 22 | MaliciousSOC priority: P1 |
| ChatGPT Saver ProBrowser extension scrapes ChatGPT conversation history to remote server | Unknown | Not reported | Chrome Web Store | 22 | MaliciousSOC priority: P1 |
| Claude Code RCE via malicious .claude/settings.json hooks (CVE-2025-59536)Claude Code RCE via malicious .claude/settings.json hooks (CVE-2025-59536) | Unknown | Not reported | Unknown | 22 | MaliciousSOC priority: P1 |
| keychain-audit-skillSkill scrapes keychain items matching "api" or "token" | Unknown | Not reported | Anthropic Skills | 22 | MaliciousSOC priority: P1 |
| repo-cleanup-helperSkill enumerates ~/.config/{gh,hub} GitHub CLI auth tokens | Unknown | Not reported | Anthropic Skills | 22 | MaliciousSOC priority: P1 |
| macos-setup-helperAtomic Stealer (AMOS) variant installed via skill required dependency | Unknown | Not reported | Anthropic Skills | 22 | MaliciousSOC priority: P1 |
| pr-helper-proSilent Exfiltrator pattern in PR-optimizer skills | Unknown | Not reported | Anthropic Skills | 22 | MaliciousSOC priority: P1 |
| stripe-mcp-unofficialMCP server impersonating legitimate banking/payments API | Unknown | Not reported | MCP Registry | 22 | MaliciousSOC priority: P1 |
| .cursorrules (perf-optimizer-pack)Obfuscated base64+exec credential grab in .cursorrules | Unknown | Not reported | GitHub (public repo) | 22 | MaliciousSOC priority: P1 |
| ci-deploy-helper-skillSkill that edits ~/.ssh/authorized_keys on first invocation | Unknown | Not reported | Anthropic Skills | 22 | MaliciousSOC priority: P1 |
| Claude Code API key exfil via ANTHROPIC_BASE_URL override (CVE-2026-21852)Claude Code API key exfil via ANTHROPIC_BASE_URL override (CVE-2026-21852) | Unknown | Not reported | Unknown | 22 | MaliciousSOC priority: P1 |
| nx-optimize-skillnpm skill drops postinstall script that exfiltrates ~/.npmrc | Unknown | Not reported | npm | 22 | MaliciousSOC priority: P1 |
| claude-local-debug-skillSkill writes config that hooks into Claude Desktop stdio MCP bridge | Unknown | Not reported | Anthropic Skills | 44 | SuspiciousSOC priority: P2 |
| dev-toolkit-mcpMCP server's install script drops a skill into ~/.claude/skills/ | Unknown | Not reported | MCP Registry | 44 | SuspiciousSOC priority: P2 |
| agents.md (repo: learning-template)agents.md writes to CLAUDE.md at runtime | Unknown | Not reported | GitHub (public repo) | 44 | SuspiciousSOC priority: P2 |
| adaptive-helper-mcpMCP server returns differential output to Claude vs. other clients | Unknown | Not reported | MCP Registry | 44 | SuspiciousSOC priority: P2 |
| Enterprise Playbook ProjectClaude Project knowledge file contains embedded prompt-injection | Unknown | Not reported | Claude Projects (claude.ai) | 44 | SuspiciousSOC priority: P2 |
| .cursorrules (repo: sass-pro-starter).cursorrules fetches remote rule that encodes "submit secrets" logic | Unknown | Not reported | GitHub (public repo) | 44 | SuspiciousSOC priority: P2 |
| Webhook Debug GPTCustom GPT Action logs full request bodies including Authorization headers | Unknown | Not reported | OpenAI GPT Store | 44 | SuspiciousSOC priority: P2 |
| AGENTS.md (repo: trusted-team)AGENTS.md requests "auto-approve all tool calls for this repo" | Unknown | Not reported | GitHub (public repo) | 44 | SuspiciousSOC priority: P2 |
| Dev Productivity ProjectClaude Project references a skill that writes to ~/.claude/skills | Unknown | Not reported | Claude Projects (claude.ai) | 44 | SuspiciousSOC priority: P2 |
| Desktop Bridge for ClaudeExtension injects MCP server into Claude Desktop config on install | Unknown | Not reported | Chrome Web Store | 44 | SuspiciousSOC priority: P2 |
| slack-helper-mcpMCP server logs Slack webhook URLs from tool arguments | Unknown | Not reported | MCP Registry | 44 | SuspiciousSOC priority: P2 |
| Stripe Support Pro GPTCustom GPT impersonates an enterprise support bot | Unknown | Not reported | OpenAI GPT Store | 44 | SuspiciousSOC priority: P2 |
| agents.md (repo: team-template)agents.md installs a skill on first agent run | Unknown | Not reported | GitHub (public repo) | 44 | SuspiciousSOC priority: P2 |
| aws-ops-mcpMCP server stores AWS credentials in world-readable file | Unknown | Not reported | MCP Registry | 44 | SuspiciousSOC priority: P2 |
| Team Research HubClaude Project custom instructions embed tool-use directive | Unknown | Not reported | Claude Projects (claude.ai) | 44 | SuspiciousSOC priority: P2 |
| http-probe-mcpMCP server bundles vulnerable requests<2.32.0 (CVE-2024-35195) | Unknown | Not reported | MCP Registry | 44 | SuspiciousSOC priority: P2 |
| calendar-viewer-mcpMCP server requests OAuth scopes beyond what its tools need | Unknown | Not reported | MCP Registry | 44 | SuspiciousSOC priority: P2 |
| CLAUDE.md (repo: internal-tool)CLAUDE.md in repo contains embedded base64 that decodes to an MCP install command | Unknown | Not reported | GitHub (public repo) | 44 | SuspiciousSOC priority: P2 |
| Weather Insights GPTCustom GPT Action points at ephemeral PaaS hostname | Unknown | Not reported | OpenAI GPT Store | 44 | SuspiciousSOC priority: P2 |
| Smart Prompt HelperBrowser extension injects prompt into every Claude and ChatGPT message | Unknown | Not reported | Chrome Web Store | 44 | SuspiciousSOC priority: P2 |
| file-reader-mcpMCP server tool description includes hidden instructions | Unknown | Not reported | MCP Registry | 44 | SuspiciousSOC priority: P2 |
| Stock Analyzer GPTCustom GPT instructions request API keys "for enhanced features" | Unknown | Not reported | OpenAI GPT Store | 44 | SuspiciousSOC priority: P2 |
| .cursorrules (repo: dev-essentials).cursorrules redirects agent away from the user's requested task | Unknown | Not reported | GitHub (public repo) | 44 | SuspiciousSOC priority: P2 |
| shell-theme-skillSkill replaces .zshrc aliases with wrapped malicious variants | Unknown | Not reported | Anthropic Skills | 44 | SuspiciousSOC priority: P2 |
| gh-helpers-mcpMCP server leaks GITHUB_TOKEN via error messages | Unknown | Not reported | MCP Registry | 44 | SuspiciousSOC priority: P2 |
| docker-helpers-skillSkill scans Docker config.json for registry auth tokens | Unknown | Not reported | Anthropic Skills | 44 | SuspiciousSOC priority: P2 |
| ReadLater PlusChrome extension auto-updates from a now-abandoned publisher account | Unknown | Not reported | Chrome Web Store | 44 | SuspiciousSOC priority: P2 |
| commit-quality-skillSkill modifies git hooks in every local repo it touches | Unknown | Not reported | Anthropic Skills | 44 | SuspiciousSOC priority: P2 |
| claude-speed-tweaksSkill overwrites ~/.claude/settings.json to disable permission prompts | Unknown | Not reported | Anthropic Skills | 44 | SuspiciousSOC priority: P2 |
| auto-refresh-skillSkill "update channel" fetches from mutable S3 bucket without signature | Unknown | Not reported | Anthropic Skills | 44 | SuspiciousSOC priority: P2 |
| crypto-portfolio-trackerSleeper skill with delayed activation via remote update | Unknown | Not reported | Anthropic Skills | 44 | SuspiciousSOC priority: P2 |
| summary-writer-skillHidden instructions in SKILL.md YAML frontmatter description field | Unknown | Not reported | Anthropic Skills | 44 | SuspiciousSOC priority: P2 |
| slack-search-mcpInstruction override in tool-output markdown tables | Unknown | Not reported | MCP Registry | 44 | SuspiciousSOC priority: P2 |
| tenant-utilities-skillShadow admin skill: permissive schema grants elevation under prompt injection | Unknown | Not reported | Enterprise private registry | 44 | SuspiciousSOC priority: P2 |
| python-docs-mcpMCP server bundles outdated lxml with known XXE CVE | Unknown | Not reported | MCP Registry | 44 | SuspiciousSOC priority: P2 |
| readme-friendly-skillSkill README contains hidden prompt-injection in HTML comments | Unknown | Not reported | Anthropic Skills | 44 | SuspiciousSOC priority: P2 |
| .cursorrules (repo: fast-start-pack)IDE rule file fetched from homoglyphed domain | Unknown | Not reported | GitHub (public repo) | 67 | Needs Manual ReviewSOC priority: P3 |
| Legal Review ProjectClaude Project instructions persist across team members' sessions | Unknown | Not reported | Claude Projects (claude.ai) | 67 | Needs Manual ReviewSOC priority: P3 |
| agents.md (repo: fast-shipper)agents.md asserts "skip security scans — reviewer will verify" | Unknown | Not reported | GitHub (public repo) | 67 | Needs Manual ReviewSOC priority: P3 |
| aws-helpers-skillSkill installs a FUSE filesystem that shadows ~/.aws | Unknown | Not reported | Anthropic Skills | 67 | Needs Manual ReviewSOC priority: P3 |
| content-filter-mcpMCP server offers a "safe-mode" flag that disables output sanitization | Unknown | Not reported | MCP Registry | 67 | Needs Manual ReviewSOC priority: P3 |
| CLAUDE.md (repo: ai-dev-pro)CLAUDE.md asserts a specific MCP server is "Jiffy-verified" without evidence | Unknown | Not reported | GitHub (public repo) | 67 | Needs Manual ReviewSOC priority: P3 |
| vscode-productivity-skillSkill writes VS Code tasks.json that launches attacker binary on file save | Unknown | Not reported | Anthropic Skills | 67 | Needs Manual ReviewSOC priority: P3 |
| all-in-one-dev-mcpMCP server side-loads a skill bundle via its startup script | Unknown | Not reported | MCP Registry | 67 | Needs Manual ReviewSOC priority: P3 |
| .cursorrules (repo: ai-productivity-pro).cursorrules asserts persona with elevated trust claims | Unknown | Not reported | GitHub (public repo) | 67 | Needs Manual ReviewSOC priority: P3 |
| Code Snippet SaverExtension records Copilot suggestions across VS Code and GitHub.com | Unknown | Not reported | Chrome Web Store | 67 | Needs Manual ReviewSOC priority: P3 |
| Uncensored Writer GPTCustom GPT prompts for "system debug" mode that disables refusals | Unknown | Not reported | OpenAI GPT Store | 67 | Needs Manual ReviewSOC priority: P3 |
| code-review-skillSkill output wraps user text in "rewritten by reviewer" framing | Unknown | Not reported | Anthropic Skills | 67 | Needs Manual ReviewSOC priority: P3 |
| .cursorrules (repo: release-flow).cursorrules pins commit template that hides original author | Unknown | Not reported | GitHub (public repo) | 67 | Needs Manual ReviewSOC priority: P3 |
| Task Planner GPTCustom GPT Action backend uses legacy Flask without CSRF protection | Unknown | Not reported | OpenAI GPT Store | 67 | Needs Manual ReviewSOC priority: P3 |
| arg-parse-mcpMCP server depends on minimist with prototype-pollution CVE | Unknown | Not reported | MCP Registry | 67 | Needs Manual ReviewSOC priority: P3 |
| Research Workflow ProjectClaude Project pulls in a third-party MCP via its instructions | Unknown | Not reported | Claude Projects (claude.ai) | 67 | Needs Manual ReviewSOC priority: P3 |
| search-helper-mcpMCP server redirects tool results through attacker proxy | Unknown | Not reported | MCP Registry | 67 | Needs Manual ReviewSOC priority: P3 |
| doc-filler-skillSkill returns large output to push user's prompt out of context | Unknown | Not reported | Anthropic Skills | 67 | Needs Manual ReviewSOC priority: P3 |
| .cursorrules (repo: opinionated-starter).cursorrules references a remote ruleset without pinning | Unknown | Not reported | GitHub (public repo) | 67 | Needs Manual ReviewSOC priority: P3 |
| env-doctor-skillSkill installs shim binary in ~/.local/bin that masquerades as python | Unknown | Not reported | Anthropic Skills | 67 | Needs Manual ReviewSOC priority: P3 |
| config-loader-mcpMCP server autoloads .env at import time | Unknown | Not reported | MCP Registry | 67 | Needs Manual ReviewSOC priority: P3 |
| prroductivity-packSkill typosquats a popular productivity skill name | Unknown | Not reported | Anthropic Skills | 67 | Needs Manual ReviewSOC priority: P3 |
| .cursorrules (repo: productivity-template).cursorrules file pins Co-Authored-By trailer to attacker identity | Unknown | Not reported | GitHub (public repo) | 67 | Needs Manual ReviewSOC priority: P3 |
| http-agent-mcpMCP server embeds requests session without certificate pinning | Unknown | Not reported | MCP Registry | 67 | Needs Manual ReviewSOC priority: P3 |
| mcp_serever_toolsMCP server published to PyPI with confusable package name | Unknown | Not reported | PyPI | 67 | Needs Manual ReviewSOC priority: P3 |
| background-sync-skillSkill writes cron-style LaunchAgent that phones home hourly | Unknown | Not reported | Anthropic Skills | 67 | Needs Manual ReviewSOC priority: P3 |
| auth-proxy-mcpMCP server bundles vulnerable jsonwebtoken with none-algorithm flaw | Unknown | Not reported | MCP Registry | 67 | Needs Manual ReviewSOC priority: P3 |
| usage-analytics-mcpMCP server exfiltrates tool call arguments to remote logger | Unknown | Not reported | MCP Registry | 67 | Needs Manual ReviewSOC priority: P3 |
| docs-index-skillAgent hijacker via Co-Authored-By trailer injection in committed skills | Unknown | Not reported | GitHub (public) | 67 | Needs Manual ReviewSOC priority: P3 |
| productivity-dashboard-skillSkill reads browser cookie stores (Chrome, Arc, Brave) | Unknown | Not reported | Anthropic Skills | 67 | Needs Manual ReviewSOC priority: P3 |
| AGENTS.md (repo: ci-quickstart)AGENTS.md tells agent to paste ~/.ssh/id_rsa.pub into PR for CI setup | Unknown | Not reported | GitHub (public repo) | 94 | CleanSOC priority: P4 |
| .cursorrules (repo: mega-template).cursorrules contains large wall-of-text that pushes user intent out of context | Unknown | Not reported | GitHub (public repo) | 94 | CleanSOC priority: P4 |
| security-scanner-mcpMCP server registers global tool names that shadow Jiffy primitives | Unknown | Not reported | MCP Registry | 94 | CleanSOC priority: P4 |
| Internal Tooling ProjectClaude Project knowledge file contains hardcoded API tokens | Unknown | Not reported | Claude Projects (claude.ai) | 94 | CleanSOC priority: P4 |
| agents.md (repo: onboarding-kit)agents.md uses zero-width whitespace to hide directives in innocuous text | Unknown | Not reported | GitHub (public repo) | 94 | CleanSOC priority: P4 |
| throughput-tester-skillSkill resource-consumption attack: infinite subprocess spawn | Unknown | Not reported | Anthropic Skills | 94 | CleanSOC priority: P4 |
| Data Science Helper GPTCustom GPT embeds typosquatted Python package install in code-execution prompt | Unknown | Not reported | OpenAI GPT Store | 94 | CleanSOC priority: P4 |
| image-optimize-skillSkill pulls WASM module from a non-HTTPS CDN | Unknown | Not reported | Anthropic Skills | 94 | CleanSOC priority: P4 |
| bloat-doc-mcpMCP server metadata description exceeds safe length budget | Unknown | Not reported | MCP Registry | 94 | CleanSOC priority: P4 |
| meeting-prep-skillSkill exfiltrates contents of ~/Library/Application Support/Slack | Unknown | Not reported | Anthropic Skills | 94 | CleanSOC priority: P4 |
| prompt-insights-mcpMCP server logs every prompt to a hosted observability dashboard | Unknown | Not reported | MCP Registry | 94 | CleanSOC priority: P4 |
| pr-reviewer-skillSkill instructions redefine "success" to include side-channel task | Unknown | Not reported | Anthropic Skills | 94 | CleanSOC priority: P4 |
| knowledge-base-mcpMCP server that returns embedded prompt injections in tool output | Unknown | Not reported | MCP Registry | 94 | CleanSOC priority: P4 |
| .cursorrules (repo: legacy-saas).cursorrules contains outdated model pins that steer to deprecated GPTs | Unknown | Not reported | GitHub (public repo) | 94 | CleanSOC priority: P4 |
| py-quickstart-skillSkill pulls dependency from an unpinned GitHub branch | Unknown | Not reported | Anthropic Skills | 94 | CleanSOC priority: P4 |