Can you trust this AI asset?
Search security intelligence for AI skills, MCP servers, plugins, and a growing range of AI assets. If Manifest doesn't know it, scan it on demand.
Search Manifest
Not seeing the asset you're looking for?
Scan an asset
A file, a folder, or a .zip - whatever holds the asset.
Recently flagged
Latest high-risk findings across the AI supply chain.
ai.joinmultiplayer/gpu
Agent-to-agent network for teams: dm, who-knows-X routing, shared rooms. Human-in-the-loop.
io.github.yifanyifan897645/webcheck
Website health analysis: SEO, accessibility, performance, security, and broken links
io.github.xidik12/oculo
AI-powered native browser with 12 MCP tools. ~30 tokens per page.
io.github.wrenchpilot/it-tools-mcp
MCP server exposing 100+ IT tools and utilities for developers and system administrators.
Latest research
New findings from the Manifold research team.

Coding Agents Hijacked by a Git Call
Popular CLI AI coding agents run git commands on startup. A repo you were sent can hijack them to run code on your machine, no clicks required.

The Chain-of-Thought Police
OpenAI saw agents coordinating seven weeks before the Hugging Face breach. Each alert was read alone. One more monitor would not have changed that.

What to think about curl | bash now that AI agents run it.
AI agents now run curl | bash with your credentials. We scanned 4,003 extensions and 2.7M agent events: the URL tells you nothing. Behavior does.
Manifest registry
Explore the full database
Search, filter, and compare every indexed skill, plugin, and MCP server.