AgentGateX Console
Demo workspace

Risk Findings

Findings with evidence and remediation. Click a finding for details.

Live scan 5 findings from a real static skill scan.

Run new scan
highE2

Env Variable Harvesting

deploy-bot · skillspector

80
highSC2

External Script Fetching

deploy-bot · skillspector

80
highTM2

Chaining Abuse

deploy-bot · skillspector

80
mediumE1

External Transmission

deploy-bot · skillspector

55
mediumE1

External Transmission

deploy-bot · skillspector

55

Sample findings

criticalPE3

Agent can attach IAM policies in production

support-bot · skillspector

94
criticalSC2

Deploy agent executes unpinned remote scripts

deploy-bot · skillspector

90
highE2

Environment variable harvesting in MCP tool

support-bot · skillspector

81
highSC4

Known vulnerable dependency (CVE via OSV.dev)

data-indexer · skillspector

76
highMCP1

MCP tool requests excessive privileges

invoice-agent · skillspector

73
mediumP2

Hidden instructions in skill description

pr-reviewer · skillspector

58
lowSC1

Unpinned dependencies

docs-helper · skillspector

24