Every AI tool you ship
has a risk profile.
MCP servers, AI agents, IDE extensions, plugins, and skills — scored from declared trust, declared capabilities, and known dangerous combinations. The formula is published in full.
Catch of the Day
Entries currently scoring in the high or critical bands — the ones worth a closer read before a team installs them.
Cline
Cline is an autonomous coding agent that runs inside VS Code and takes the IDE far beyond autocomplete. Once approved, …
Kilo Code
Kilo Code is a multi-model AI coding assistant for VS Code that combines the agentic execution loop pioneered by Cline …
Roo Code
Roo Code is an open-source AI coding agent for VS Code, originally forked from Cline and now developed independently wi…
Blackbox AI
Blackbox AI is an AI code-search and chat extension that markets itself as an all-in-one developer assistant — autocomp…
Continue
Continue is an open-source IDE extension that brings autocomplete, chat, and inline edits to VS Code and JetBrains usin…
Sourcegraph Cody
Cody is Sourcegraph's AI coding assistant, distinguished from peers by tight integration with the Sourcegraph code-grap…
Recently Updated
The most recent additions and updates from the upstream registry and the hand-curated seeds.
Kilo Code
Kilo Code is a multi-model AI coding assistant for VS Code that combines the agentic execution loop pioneered by Cline …
Roo Code
Roo Code is an open-source AI coding agent for VS Code, originally forked from Cline and now developed independently wi…
Blackbox AI
Blackbox AI is an AI code-search and chat extension that markets itself as an all-in-one developer assistant — autocomp…
Continue
Continue is an open-source IDE extension that brings autocomplete, chat, and inline edits to VS Code and JetBrains usin…
Sourcegraph Cody
Cody is Sourcegraph's AI coding assistant, distinguished from peers by tight integration with the Sourcegraph code-grap…
Superpowers
Superpowers is a community-maintained Claude Code plugin that ships a curated library of skills — short, structured wor…
What's in the catalog
Five surfaces that AI now ships through. Every entry on every surface gets the same risk treatment.
MCP servers
Model Context Protocol servers that connect your AI agents to filesystems, databases, APIs, and tools — each one another door into the host.
AI tools
AI assistants and coding agents — desktop, CLI, and IDE-embedded. Containers whose real risk depends on what they're wired to.
IDE extensions
IDE extensions that bring AI into the editor. They read your code; some can also write, execute, and reach the network.
Plugins
Plugin bundles that extend an agent's skill set. Distributed by vendors and the community; risk varies by what each plugin can do.
Skills
Discrete agent workflows — brainstorming, debugging, TDD. Some are pure process; some touch files, run commands, or call out.
Every score is a pure function of trust level, declared high-risk capabilities, and matched dangerous combinations. No machine-learning model, no opaque heuristics — if a number on a page surprises you, you can trace it line by line.
Read the full methodology →