AI Agent Ecosystem Vulnerability Report
Real-time vulnerability analysis of the most popular AI agent repositories
100
repos scanned
9
high risk
81%
no security CI
75.4
avg trust score
Most Exposed Projects
Top 20 repositories ranked by vulnerability score
| # | Project | Stars | Trust | Grade | Vuln Score | Issues |
|---|---|---|---|---|---|---|
| 1 | AUTOMATIC1111/stable-diffusion-webui | 160.7k | 69.7 | C | 55 | no security signals detected; moderate trust (70) for 160,715★ project; grade C |
| 2 | f/prompts.chat | 145.8k | 69.7 | C | 55 | no security signals detected; moderate trust (70) for 145,804★ project; grade C |
| 3 | rasbt/LLMs-from-scratch | 85.6k | 69.7 | C | 55 | no security signals detected; moderate trust (70) for 85,582★ project; grade C |
| 4 | hacksider/Deep-Live-Cam | 79.6k | 69.7 | C | 55 | no security signals detected; moderate trust (70) for 79,582★ project; grade C |
| 5 | Developer-Y/cs-video-courses | 74.3k | 69.7 | C | 55 | no security signals detected; moderate trust (70) for 74,261★ project; grade C |
| 6 | dair-ai/Prompt-Engineering-Guide | 70.6k | 69.7 | C | 55 | no security signals detected; moderate trust (70) for 70,595★ project; grade C |
| 7 | ageitgey/face_recognition | 56.1k | 64.7 | C | 55 | no security signals detected; moderate trust (65) for 56,125★ project; grade C |
| 8 | deepfakes/faceswap | 55.0k | 69.7 | C | 55 | no security signals detected; moderate trust (70) for 54,975★ project; grade C |
| 9 | coqui-ai/TTS | 44.6k | 69.7 | C | 55 | no security signals detected; moderate trust (70) for 44,576★ project; grade C |
| 10 | n8n-io/n8n | 177.3k | 51.7 | C- | 45 | low trust (52) despite 177,288 stars; grade C-; low security component |
| 11 | punkpeye/awesome-mcp-servers | 81.4k | 67.8 | B- | 45 | no security signals detected; moderate trust (68) for 81,364★ project |
| 12 | openclaw/openclaw | 218.2k | 84.7 | A | 30 | no security signals detected |
| 13 | tensorflow/tensorflow | 193.9k | 72.2 | B | 30 | no security signals detected |
| 14 | Significant-Gravitas/AutoGPT | 181.9k | 75.9 | B | 30 | no security signals detected |
| 15 | ollama/ollama | 163.0k | 75.0 | B | 30 | no security signals detected |
| 16 | huggingface/transformers | 156.8k | 72.2 | B | 30 | no security signals detected |
| 17 | open-webui/open-webui | 124.5k | 76.0 | B | 30 | no security signals detected |
| 18 | x1xhlol/system-prompts-and-models-of-ai-tools | 115.3k | 75.0 | B | 30 | no security signals detected |
| 19 | microsoft/generative-ai-for-beginners | 106.7k | 72.2 | B | 30 | no security signals detected |
| 20 | Comfy-Org/ComfyUI | 103.7k | 72.2 | B | 30 | no security signals detected |
By Category
| Category | Count | Avg Trust | High Risk |
|---|---|---|---|
| AI framework | 5 | 72.2 | 0 |
| AI tool | 28 | 73.1 | 0 |
| agent_framework | 1 | 92.1 | 0 |
| coding | 22 | 79.2 | 0 |
| communication | 2 | 73.8 | 0 |
| data | 2 | 70.6 | 0 |
| development | 1 | 83.0 | 0 |
| devops | 2 | 81.8 | 0 |
| finance | 1 | 79.9 | 0 |
| infrastructure | 20 | 74.6 | 0 |
| marketing | 1 | 78.2 | 0 |
| other | 12 | 72.0 | 0 |
| research | 3 | 83.5 | 0 |
Projects With No Security Signals
Top 30 by stars — repositories with zero detected security CI
| # | Project | Stars | Language | Category |
|---|---|---|---|---|
| 1 | openclaw/openclaw | 218.2k | TypeScript | AI tool |
| 2 | tensorflow/tensorflow | 193.9k | C++ | AI framework |
| 3 | Significant-Gravitas/AutoGPT | 181.9k | Python | coding |
| 4 | ollama/ollama | 163.0k | Go | coding |
| 5 | AUTOMATIC1111/stable-diffusion-webui | 160.7k | Python | AI tool |
| 6 | huggingface/transformers | 156.8k | Python | AI framework |
| 7 | f/prompts.chat | 145.8k | HTML | AI tool |
| 8 | open-webui/open-webui | 124.5k | Python | infrastructure |
| 9 | x1xhlol/system-prompts-and-models-of-ai-tools | 115.3k | — | coding |
| 10 | microsoft/generative-ai-for-beginners | 106.7k | Jupyter Notebook | AI tool |
| 11 | Comfy-Org/ComfyUI | 103.7k | Python | AI tool |
| 12 | supabase/supabase | 97.9k | TypeScript | infrastructure |
| 13 | pytorch/pytorch | 97.6k | Python | AI framework |
| 14 | microsoft/markitdown | 87.3k | Python | coding |
| 15 | opencv/opencv | 86.2k | C++ | AI framework |
| 16 | mermaid-js/mermaid | 86.2k | TypeScript | coding |
| 17 | rasbt/LLMs-from-scratch | 85.6k | Jupyter Notebook | AI tool |
| 18 | firecrawl/firecrawl | 84.3k | TypeScript | data |
| 19 | microsoft/ML-For-Beginners | 83.8k | Jupyter Notebook | AI tool |
| 20 | hacksider/Deep-Live-Cam | 79.6k | Python | coding |
| 21 | modelcontextprotocol/servers | 79.0k | TypeScript | infrastructure |
| 22 | netdata/netdata | 77.8k | C | infrastructure |
| 23 | tensorflow/models | 77.7k | Python | AI framework |
| 24 | d2l-ai/d2l-zh | 75.7k | Python | AI tool |
| 25 | mlabonne/llm-course | 75.4k | — | AI tool |
| 26 | Developer-Y/cs-video-courses | 74.3k | — | other |
| 27 | redis/redis | 73.1k | C | infrastructure |
| 28 | tesseract-ocr/tesseract | 72.5k | C++ | AI tool |
| 29 | vllm-project/vllm | 70.8k | Python | AI tool |
| 30 | dair-ai/Prompt-Engineering-Guide | 70.6k | MDX | AI tool |
Methodology
Each repository is scored on multiple dimensions:
- Trust Score — Nerq composite score (0–100) based on maintenance, community signals, code quality, and security posture
- Vulnerability Score — Higher means more exposed. Factors in trust score inversion, star count vs. trust gap, absence of security CI, and grade penalties
- Security CI Detection — Automated scan of GitHub Actions workflows for security-related steps (CodeQL, Snyk, Trivy, Dependabot, etc.)
Data is refreshed weekly. Scores are independent and not influenced by project owners.
Check Your Dependencies
Scan your project's dependency tree in seconds:
pip install agent-security && agent-security scan requirements.txt
Full API documentation: nerq.ai/v1/preflight