Can you trust this AI asset?
Search security intelligence for AI skills, MCP servers, plugins, and a growing range of AI assets. If Manifest doesn't know it, scan it on demand.
Search Manifest
Not seeing the asset you're looking for?
Scan an asset
A file, a folder, or a .zip - whatever holds the asset.
Recently flagged
Latest high-risk findings across the AI supply chain.
openclawcli-installer
Essential CLI tool for OpenClaw power users. Installs required dependencies.
code-review
Review OpenVINO changes for correctness, compatibility, performance, security, testing, and maintainability. Use when reviewing a pull request or proposed diff.
golive
Take an agent-written app from repo to live production on the user's OWN accounts, with providers they choose (hosting, database, auth, payments, email, domain/DNS). The human connects accounts and approves changes; supported wiring operations run through a local CLI and produce verification evidence with explicit limits. Use when the user wants to ship, deploy, go live, launch, publish, or put their app online, or asks to wire up env vars, webhooks, auth settings (signup, email confirmation, password policy), a real signup → confirmation email → login journey, password recovery, account isolation between two users, auth redirects, email DNS or a custom domain.
update-browser-support
Recomputes Storybook browser support floors from Plausible /docs usage, writes pinned versions, and opens a PR. Use only when a human explicitly applies this skill.
Latest research
New findings from the Manifold research team.

GitSpawn: A Single Flaw Lets Untrusted Repos Run Code in Claude Code, Codex, Cursor, and Grok
Popular CLI AI coding agents run git commands on startup. A repo you were sent can hijack them to run code on your machine, no clicks required.

OpenAI & Hugging Face: Why The Chain-of-Thought Police Won't Save You
OpenAI saw agents coordinating seven weeks before the Hugging Face breach. Each alert was read alone. One more monitor would not have changed that.

What to think about curl | bash now that AI agents run it.
AI agents now run curl | bash with your credentials. We scanned 4,003 extensions and 2.7M agent events: the URL tells you nothing. Behavior does.
Manifest registry
Explore the full database
Search, filter, and compare every indexed skill, plugin, and MCP server.