CodeThreat AICAAI Security HubUniverseRepo Risk
IndexTry CodeThreat
CodeThreat AICA

AI Composition Analysis. Open security intelligence for the AI component ecosystem.

Browse

AboutMCP ServersAgent Skills

Developers

API DocumentationCodeThreat AppSec

Standards

MITRE ATLASOWASP Agentic Top 10

Decreasing Agentic Security Inflation

By CodeThreat

AI Composition Analysis

Decreasing Agentic
Security Inflation

Open security intelligence for the AI component ecosystem. We index, scan, and publish risk profiles for MCP servers and Agent Skills so you can make informed decisions before adoption.

The Problem

AI agents rely on MCP servers and Agent Skills from public registries. Most of these components have no standardized security assessment — and many introduce real risk.

MCP Server Risks

Exposed tools can leak secrets, execute arbitrary code, or exfiltrate data. Registry metadata rarely includes security context.

There is no standard way to assess risk before adding an MCP server to your stack.

Agent Skill Risks

SKILL.md and tool definitions can contain prompt injection, data exfiltration, or unsafe syscalls. Skills are distributed across GitHub, SkillsMP, Tessl — with no central security view.

Duplicate skill names can confuse or deceive users about what they are actually running.

What We Do

We run a continuous pipeline: ingest from 10+ registries, run multi-phase security scans, and publish risk profiles with findings mapped to industry standards.

Ingest

Discover and index MCP servers and Agent Skills from official registries, GitHub, npm, and more.

Scan

Static analysis of tool definitions, remote scanning of live endpoints, behavioral analysis of source code. Skills are scanned with 58+ rules and AST dataflow analysis.

Publish

Risk scores, severity breakdowns, and findings mapped to MITRE ATLAS and OWASP Top 10 for Agentic Applications.

Standards We Map To

Findings are categorized and linked to established security frameworks so you can prioritize and remediate with industry context.

MITRE ATLASOWASP Top 10 for Agentic Applications 2026CycloneDX AI/ML-BOM

Why We Do This

Agentic security inflation means too much noise and too little actionable intelligence. AICA provides open, standardized vulnerability data for the AI component ecosystem — comparable to Sonatype OSS Index or Socket.dev, but for MCP servers and Agent Skills. So developers can see risk before they adopt.

Browse the IndexTry CodeThreat AppSec

CodeThreat AppSec

Scan your own AI components

Full SAST + SCA agentic security analysis for MCP servers and Skills.

Try CodeThreat