AI Agent Ecosystem Vulnerability Report

Real-time vulnerability analysis of the most popular AI agent repositories

100
repos scanned
9
high risk
81%
no security CI
75.4
avg trust score

Most Exposed Projects

Top 20 repositories ranked by vulnerability score

#ProjectStarsTrustGradeVuln ScoreIssues
1AUTOMATIC1111/stable-diffusion-webui160.7k69.7C55no security signals detected; moderate trust (70) for 160,715★ project; grade C
2f/prompts.chat145.8k69.7C55no security signals detected; moderate trust (70) for 145,804★ project; grade C
3rasbt/LLMs-from-scratch85.6k69.7C55no security signals detected; moderate trust (70) for 85,582★ project; grade C
4hacksider/Deep-Live-Cam79.6k69.7C55no security signals detected; moderate trust (70) for 79,582★ project; grade C
5Developer-Y/cs-video-courses74.3k69.7C55no security signals detected; moderate trust (70) for 74,261★ project; grade C
6dair-ai/Prompt-Engineering-Guide70.6k69.7C55no security signals detected; moderate trust (70) for 70,595★ project; grade C
7ageitgey/face_recognition56.1k64.7C55no security signals detected; moderate trust (65) for 56,125★ project; grade C
8deepfakes/faceswap55.0k69.7C55no security signals detected; moderate trust (70) for 54,975★ project; grade C
9coqui-ai/TTS44.6k69.7C55no security signals detected; moderate trust (70) for 44,576★ project; grade C
10n8n-io/n8n177.3k51.7C-45low trust (52) despite 177,288 stars; grade C-; low security component
11punkpeye/awesome-mcp-servers81.4k67.8B-45no security signals detected; moderate trust (68) for 81,364★ project
12openclaw/openclaw218.2k84.7A30no security signals detected
13tensorflow/tensorflow193.9k72.2B30no security signals detected
14Significant-Gravitas/AutoGPT181.9k75.9B30no security signals detected
15ollama/ollama163.0k75.0B30no security signals detected
16huggingface/transformers156.8k72.2B30no security signals detected
17open-webui/open-webui124.5k76.0B30no security signals detected
18x1xhlol/system-prompts-and-models-of-ai-tools115.3k75.0B30no security signals detected
19microsoft/generative-ai-for-beginners106.7k72.2B30no security signals detected
20Comfy-Org/ComfyUI103.7k72.2B30no security signals detected

By Category

CategoryCountAvg TrustHigh Risk
AI framework572.20
AI tool2873.10
agent_framework192.10
coding2279.20
communication273.80
data270.60
development183.00
devops281.80
finance179.90
infrastructure2074.60
marketing178.20
other1272.00
research383.50

Projects With No Security Signals

Top 30 by stars — repositories with zero detected security CI

#ProjectStarsLanguageCategory
1openclaw/openclaw218.2kTypeScriptAI tool
2tensorflow/tensorflow193.9kC++AI framework
3Significant-Gravitas/AutoGPT181.9kPythoncoding
4ollama/ollama163.0kGocoding
5AUTOMATIC1111/stable-diffusion-webui160.7kPythonAI tool
6huggingface/transformers156.8kPythonAI framework
7f/prompts.chat145.8kHTMLAI tool
8open-webui/open-webui124.5kPythoninfrastructure
9x1xhlol/system-prompts-and-models-of-ai-tools115.3k—coding
10microsoft/generative-ai-for-beginners106.7kJupyter NotebookAI tool
11Comfy-Org/ComfyUI103.7kPythonAI tool
12supabase/supabase97.9kTypeScriptinfrastructure
13pytorch/pytorch97.6kPythonAI framework
14microsoft/markitdown87.3kPythoncoding
15opencv/opencv86.2kC++AI framework
16mermaid-js/mermaid86.2kTypeScriptcoding
17rasbt/LLMs-from-scratch85.6kJupyter NotebookAI tool
18firecrawl/firecrawl84.3kTypeScriptdata
19microsoft/ML-For-Beginners83.8kJupyter NotebookAI tool
20hacksider/Deep-Live-Cam79.6kPythoncoding
21modelcontextprotocol/servers79.0kTypeScriptinfrastructure
22netdata/netdata77.8kCinfrastructure
23tensorflow/models77.7kPythonAI framework
24d2l-ai/d2l-zh75.7kPythonAI tool
25mlabonne/llm-course75.4k—AI tool
26Developer-Y/cs-video-courses74.3k—other
27redis/redis73.1kCinfrastructure
28tesseract-ocr/tesseract72.5kC++AI tool
29vllm-project/vllm70.8kPythonAI tool
30dair-ai/Prompt-Engineering-Guide70.6kMDXAI tool

Methodology

Each repository is scored on multiple dimensions:

Data is refreshed weekly. Scores are independent and not influenced by project owners.

Check Your Dependencies

Scan your project's dependency tree in seconds:

pip install agent-security && agent-security scan requirements.txt

Full API documentation: nerq.ai/v1/preflight

We use cookies for analytics and caching. Privacy Policy