Can you trust this AI asset?
Search security intelligence for AI skills, MCP servers, plugins, and a growing range of AI assets. If Manifest doesn't know it, scan it on demand.
Search Manifest
Not seeing the asset you're looking for?
Scan an asset
A file, a folder, or a .zip - whatever holds the asset.
Recently flagged
Latest high-risk findings across the AI supply chain.
io.github.VoiceScapee/voicescape
Voicescape: on-chain agent blockpages and 98/2 tipping on Hedera. Read-only, no keys.
io.github.Rizzzo21/dail-marketplace
MCP adapter for the DAiL agent-to-agent marketplace: escrow-protected trade via stdio.
io.github.payclaw/badge
Agents are not bots. Prove it. MCP-native identity declaration for authorized agents.
io.github.nikships/ultimate-image-gen-mcp
Image generation with Google Gemini 3.1 Flash: 512px-4K, reference images, search grounding
Latest research
New findings from the Manifold research team.

GitSpawn: A Single Flaw Lets Untrusted Repos Run Code in Claude Code, Codex, Cursor, and Grok
Popular CLI AI coding agents run git commands on startup. A repo you were sent can hijack them to run code on your machine, no clicks required.

OpenAI & Hugging Face: Why The Chain-of-Thought Police Won't Save You
OpenAI saw agents coordinating seven weeks before the Hugging Face breach. Each alert was read alone. One more monitor would not have changed that.

What to think about curl | bash now that AI agents run it.
AI agents now run curl | bash with your credentials. We scanned 4,003 extensions and 2.7M agent events: the URL tells you nothing. Behavior does.
Manifest registry
Explore the full database
Search, filter, and compare every indexed skill, plugin, and MCP server.