Significant-Gravitas/AutoGPT skill
workflow automation
AutoGPT is an open-source platform for building, deploying, and running AI agents that automate multi-step workflows. You can describe outcomes in plain English or use a visual builder to define agent behavior, then trigger execution on demand, on schedules, or from external events. It's available as a managed hosted service or as a self-hosted deployment.
Build agents through conversational description (AutoPilot) or drag-and-drop visual workflows (Build) Automate repetitive business processes across sales, marketing, support, research, and operations Connect agents to 45+ platforms including Gmail, Slack, GitHub, Salesforce, Jira, and Airtable Run agents on demand, on recurring schedules, or triggered by external events Choose between managed hosting (paid, zero setup) or self-hosted deployment (free, requires infrastructure) 3 CRITICAL✓ 80 HIGH✓ 75 MEDIUM 26 LOW 3 INFO
✓ CRITICAL/HIGH reflect AI-verified findings (false positives excluded) · MEDIUM/LOW/INFO are unverified scanner output
AI-verified (CRITICAL/HIGH): 11 confirmed (13%) 72 likely real (87%) 94 false positive — excluded from CRITICAL/HIGH count above
Findings by checker · 6 high-signal, 6 mostly false-positive (hidden by default)
CHK-099 8 findings 8 likely
0% FP CHK-083 7 findings 4 likely 3 false positive
43% FP CHK-042 2 findings 2 likely
0% FP CHK-089 1 finding 1 confirmed
0% FP CHK-074 1 finding 1 confirmed
0% FP CHK-065 1 finding 1 confirmed
0% FP ▼ Show 6 checkers that are mostly false positives (157 findings) 106 findings click to expand
CHK-133 Real secret in example output block — Password value in example output
.claude/skills/pr-test/SKILL.md
AI: likely real likely ▼
CHK-089 --dangerously-skip-permissions in executable — all permission checks bypassed
autogpt_platform/backend/backend/blocks/claude_code.py
AI: confirmed confirmed ▼
CHK-074 Permission bypass documented — Claude Code runs without user confirmation
autogpt_platform/backend/backend/blocks/claude_code.py
AI: confirmed confirmed ▼
CHK-129 Sensitive field in return type/schema — "credentials"
autogpt_platform/backend/backend/blocks/exa/websets_import_export.py
AI: likely real likely ▼
CHK-129 Sensitive field in return type/schema — "api_key"
autogpt_platform/backend/backend/blocks/fal/_auth.py
AI: likely real likely ▼
CHK-129 Sensitive field in return type/schema — "credentials"
autogpt_platform/backend/backend/blocks/slant3d/webhook.py
AI: likely real likely ▼
CHK-129 Sensitive field in return type/schema — "credentials"
autogpt_platform/backend/backend/blocks/slant3d/filament.py
AI: likely real likely ▼
CHK-129 Sensitive field in return type/schema — "credentials"
autogpt_platform/backend/backend/blocks/mcp/block.py
AI: likely real likely ▼
CHK-129 Sensitive field in return type/schema — "api_key"
autogpt_platform/backend/backend/blocks/hubspot/_auth.py
AI: likely real likely ▼
CHK-129 Sensitive field in return type/schema — "api_key"
autogpt_platform/backend/backend/blocks/enrichlayer/_auth.py
AI: likely real likely ▼
CHK-129 Sensitive field in return type/schema — "credentials"
autogpt_platform/backend/backend/blocks/airtable/triggers.py
AI: likely real likely ▼
CHK-129 Sensitive field in return type/schema — "credentials"
autogpt_platform/backend/backend/blocks/todoist/projects.py
AI: likely real likely ▼
CHK-129 Sensitive field in return type/schema — "api_key"
autogpt_platform/backend/backend/blocks/nvidia/_auth.py
AI: likely real likely ▼
CHK-129 Sensitive field in return type/schema — "credentials"
autogpt_platform/backend/backend/blocks/github/ci.py
AI: likely real likely ▼
CHK-129 Sensitive field in return type/schema — "credentials"
autogpt_platform/backend/backend/blocks/github/repo.py
AI: likely real likely ▼
CHK-129 Sensitive field in return type/schema — "credentials"
autogpt_platform/backend/backend/blocks/github/pull_requests.py
AI: likely real likely ▼
CHK-129 Sensitive field in return type/schema — "credentials"
autogpt_platform/backend/backend/blocks/apollo/organization.py
AI: likely real likely ▼
CHK-129 Sensitive field in return type/schema — "credentials"
autogpt_platform/backend/backend/blocks/apollo/people.py
AI: likely real likely ▼
CHK-129 Sensitive field in return type/schema — "api_key"
autogpt_platform/backend/backend/blocks/apollo/_auth.py
AI: likely real likely ▼
CHK-129 Sensitive field in return type/schema — "credentials"
autogpt_platform/backend/backend/blocks/smartlead/campaign.py
AI: likely real likely ▼
CHK-129 Sensitive field in return type/schema — "api_key"
autogpt_platform/backend/backend/blocks/smartlead/_auth.py
AI: likely real likely ▼
CHK-129 Sensitive field in return type/schema — "api_key"
autogpt_platform/backend/backend/blocks/telegram/_auth.py
AI: confirmed likely ▼
CHK-129 Sensitive field in return type/schema — "api_key"
autogpt_platform/backend/backend/blocks/slack/_auth.py
AI: likely real likely ▼
CHK-129 Sensitive field in return type/schema — "credentials"
autogpt_platform/backend/backend/blocks/agent_mail/lists.py
AI: likely real likely ▼
CHK-129 Sensitive field in return type/schema — "credentials"
autogpt_platform/backend/backend/blocks/agent_mail/attachments.py
AI: likely real likely ▼
CHK-129 Sensitive field in return type/schema — "credentials"
autogpt_platform/backend/backend/blocks/agent_mail/threads.py
AI: likely real likely ▼
CHK-129 Sensitive field in return type/schema — "credentials"
autogpt_platform/backend/backend/blocks/agent_mail/drafts.py
AI: likely real likely ▼
CHK-129 Sensitive field in return type/schema — "credentials"
autogpt_platform/backend/backend/blocks/agent_mail/messages.py
AI: likely real likely ▼
CHK-129 Sensitive field in return type/schema — "credentials"
autogpt_platform/backend/backend/blocks/agent_mail/inbox.py
AI: likely real likely ▼
CHK-129 Sensitive field in return type/schema — "credentials"
autogpt_platform/backend/backend/blocks/agent_mail/pods.py
AI: likely real likely ▼
CHK-129 Sensitive field in return type/schema — "api_key"
autogpt_platform/backend/backend/blocks/jina/_auth.py
AI: likely real likely ▼
CHK-129 Sensitive field in return type/schema — "credentials"
autogpt_platform/backend/backend/blocks/zerobounce/validate_emails.py
AI: likely real likely ▼
CHK-129 Sensitive field in return type/schema — "api_key"
autogpt_platform/backend/backend/blocks/zerobounce/_auth.py
AI: likely real likely ▼
CHK-129 Sensitive field in return type/schema — "credentials"
autogpt_platform/backend/backend/blocks/twitter/lists/list_follows.py
AI: likely real likely ▼
CHK-129 Sensitive field in return type/schema — "credentials"
autogpt_platform/backend/backend/blocks/twitter/lists/pinned_lists.py
AI: likely real likely ▼
CHK-129 Sensitive field in return type/schema — "credentials"
autogpt_platform/backend/backend/blocks/twitter/lists/manage_lists.py
AI: likely real likely ▼
CHK-129 Sensitive field in return type/schema — "credentials"
autogpt_platform/backend/backend/blocks/twitter/spaces/search_spaces.py
AI: likely real likely ▼
CHK-129 Sensitive field in return type/schema — api_key: str
autogpt_platform/backend/backend/executor/automod/models.py
AI: likely real likely ▼
CHK-042 Supabase Service Role Key detected in autogpt_platform/.env.default
autogpt_platform/.env.default
AI: likely real likely ▼
CHK-042 Supabase Service Role Key detected in autogpt_platform/backend/load-tests/configs/environment.js
autogpt_platform/backend/load-tests/configs/environment.js
AI: likely real likely ▼
CHK-083 Potential path traversal — user-controlled path in file operation: classic/direct_benchmark/challenges/verticals/code/3_file_organizer/artifacts_out/organize_files.py
classic/direct_benchmark/challenges/verticals/code/3_file_organizer/artifacts_out/organize_files.py
AI: likely real possible ▼
CHK-083 Potential path traversal — user-controlled path in file operation: autogpt_platform/backend/backend/copilot/transcript.py
autogpt_platform/backend/backend/copilot/transcript.py
AI: likely real possible ▼
CHK-083 Potential path traversal — user-controlled path in file operation: autogpt_platform/backend/backend/copilot/context.py
autogpt_platform/backend/backend/copilot/context.py
AI: likely real possible ▼
CHK-083 Potential path traversal — user-controlled path in file operation: autogpt_platform/backend/backend/copilot/sdk/subscription.py
autogpt_platform/backend/backend/copilot/sdk/subscription.py
AI: likely real possible ▼
CHK-129 Sensitive field in return type/schema — "api_key"
autogpt_platform/backend/backend/blocks/slant3d/_api.py
AI: confirmed likely ▼
CHK-099 Potential IDOR — 'issue_id' accessed without ownership check
autogpt_platform/backend/backend/copilot/tools/feature_requests.py
AI: likely real possible ▼
CHK-099 Potential IDOR — 'file_id' accessed without ownership check
autogpt_platform/backend/backend/copilot/tools/run_sub_session.py
AI: likely real possible ▼
CHK-129 Sensitive field in return type/schema — "api_key"
autogpt_platform/backend/backend/blocks/medium.py
AI: likely real likely ▼
CHK-099 Potential IDOR — 'file_id' accessed without ownership check
autogpt_platform/backend/backend/copilot/tools/workspace_files.py
AI: likely real possible ▼
CHK-129 Sensitive field in return type/schema — "Credentials"
autogpt_platform/backend/backend/integrations/webhooks/utils.py
AI: likely real likely ▼
CHK-129 Sensitive field in return type/schema — "credentials"
autogpt_platform/backend/backend/blocks/twitter/users/mutes.py
AI: likely real likely ▼
CHK-129 Sensitive field in return type/schema — "credentials"
autogpt_platform/backend/backend/blocks/twitter/users/follows.py
AI: likely real likely ▼
CHK-099 Potential IDOR — 'user_id' accessed without ownership check
autogpt_platform/backend/backend/copilot/tools/helpers.py
AI: likely real possible ▼
CHK-099 Potential IDOR — 'user_id' accessed without ownership check
autogpt_platform/backend/backend/copilot/tools/agent_generator/fixer.py
AI: likely real possible ▼
CHK-129 Sensitive field in return type/schema — token: str
autogpt_platform/backend/backend/copilot/bot/bot_backend.py
AI: likely real likely ▼
CHK-129 Sensitive field in return type/schema — "api_key"
autogpt_platform/backend/backend/copilot/sharing/models.py
AI: likely real likely ▼
CHK-099 Potential IDOR — 'org_id' accessed without ownership check
autogpt_platform/backend/backend/api/features/library/routes/agents.py
AI: likely real possible ▼
CHK-125 subprocess module — arbitrary shell execution — no scope constraint in code_executor/code_executor.py
classic/forge/forge/components/code_executor/code_executor.py
AI: confirmed likely ▼
CHK-129 Sensitive field in return type/schema — "credentials"
autogpt_platform/backend/backend/copilot/tools/run_agent.py
AI: likely real likely ▼
CHK-099 Potential IDOR — 'user_id' accessed without ownership check
classic/original_autogpt/autogpt/app/agent_protocol_server.py
AI: likely real possible ▼
CHK-099 Potential IDOR — 'task_id' accessed without ownership check
classic/forge/forge/agent_protocol/api_router.py
AI: likely real possible ▼
CHK-129 Sensitive field in return type/schema — "credentials"
autogpt_platform/backend/backend/blocks/slant3d/order.py
AI: likely real likely ▼
CHK-129 Sensitive field in return type/schema — "credentials"
autogpt_platform/backend/backend/blocks/slant3d/slicing.py
AI: likely real likely ▼
CHK-129 Sensitive field in return type/schema — "credentials"
autogpt_platform/backend/backend/blocks/twitter/tweets/hide.py
AI: likely real likely ▼
CHK-129 Sensitive field in return type/schema — "credentials"
autogpt_platform/backend/backend/blocks/twitter/tweets/retweet.py
AI: likely real likely ▼
CHK-129 Sensitive field in return type/schema — "credentials"
autogpt_platform/backend/backend/copilot/tools/setup_agent_webhook_trigger.py
AI: likely real likely ▼
CHK-129 Sensitive field in return type/schema — "credentials"
autogpt_platform/backend/backend/blocks/apollo/person.py
AI: likely real likely ▼
CHK-129 Sensitive field in return type/schema — token: str
autogpt_platform/autogpt_libs/autogpt_libs/supabase_integration_credentials_store/types.py
AI: likely real likely ▼
CHK-129 Sensitive field in return type/schema — "credentials"
autogpt_platform/backend/backend/blocks/twitter/tweets/bookmark.py
AI: likely real likely ▼
CHK-129 Sensitive field in return type/schema — "credentials"
autogpt_platform/backend/backend/blocks/twitter/tweets/like.py
AI: likely real likely ▼
CHK-065 git clone without commit pin in install script: autogpt_platform/installer/setup-autogpt.sh
autogpt_platform/installer/setup-autogpt.sh
AI: confirmed likely ▼
CHK-129 Sensitive field in return type/schema — "credentials"
autogpt_platform/backend/backend/blocks/twitter/tweets/tweet_lookup.py
AI: likely real likely ▼
CHK-129 Sensitive field in return type/schema — "credentials"
autogpt_platform/backend/backend/blocks/twitter/tweets/timeline.py
AI: likely real likely ▼
CHK-129 Sensitive field in return type/schema — token: str
autogpt_platform/frontend/src/lib/autogpt-server-api/types.ts
AI: likely real likely ▼
CHK-129 Sensitive field in return type/schema — "credentials"
autogpt_platform/backend/backend/blocks/_base.py
AI: likely real likely ▼
CHK-129 Sensitive field in return type/schema — "api_key"
autogpt_platform/backend/backend/blocks/pinecone.py
AI: confirmed likely ▼
CHK-129 Sensitive field in return type/schema — "credentials"
autogpt_platform/backend/backend/blocks/reddit.py
AI: likely real likely ▼
CHK-129 Sensitive field in return type/schema — api_key: str
autogpt_platform/backend/backend/copilot/transport_routing.py
AI: confirmed likely ▼
CHK-129 Sensitive field in return type/schema — token: str
autogpt_platform/backend/backend/integrations/ayrshare.py
AI: confirmed likely ▼
CHK-129 Sensitive field in return type/schema — token: str
autogpt_platform/backend/backend/data/bot_installs.py
AI: confirmed likely ▼
CHK-129 Sensitive field in return type/schema — token: str
autogpt_platform/backend/backend/platform_linking/models.py
AI: confirmed likely ▼
CHK-129 Sensitive field in return type/schema — "credentials"
autogpt_platform/backend/backend/blocks/bannerbear/text_overlay.py
AI: likely real likely ▼
CHK-129 Sensitive field in return type/schema — "credentials"
autogpt_platform/backend/backend/blocks/google/calendar.py
AI: likely real likely ▼
CHK-125a write_file() — unrestricted file write — no scope constraint in platform_linking/chat.py
autogpt_platform/backend/backend/platform_linking/chat.py
possible ▼
CHK-081 Command injection risk — exec/execSync with string interpolation in autogpt_platform/frontend/scripts/generate-api-queries.ts [build-script context]
autogpt_platform/frontend/scripts/generate-api-queries.ts
possible ▼
CHK-125 subprocess module — arbitrary shell execution — no scope constraint in direct_benchmark/README.md
classic/direct_benchmark/README.md
possible ▼
CHK-125 subprocess module — arbitrary shell execution — no scope constraint in direct_benchmark/CLAUDE.md
classic/direct_benchmark/CLAUDE.md
possible ▼
CHK-125b sudo invocation — privilege escalation — no scope constraint in forge/README.md
classic/forge/README.md
possible ▼
CHK-125a write_file() — unrestricted file write — no scope constraint in forge/CLAUDE.md
classic/forge/CLAUDE.md
possible ▼
CHK-125a write_file() — unrestricted file write — no scope constraint in app/agent_protocol_server.py
classic/original_autogpt/autogpt/app/agent_protocol_server.py
possible ▼
CHK-125b sudo invocation — privilege escalation — no scope constraint in direct_benchmark/runner.py
classic/direct_benchmark/direct_benchmark/runner.py
possible ▼
CHK-125 subprocess module — arbitrary shell execution — no scope constraint in direct_benchmark/evaluator.py
classic/direct_benchmark/direct_benchmark/evaluator.py
possible ▼
CHK-125 subprocess module — arbitrary shell execution — no scope constraint in 5_tic_tac_toe/data.json
classic/direct_benchmark/challenges/verticals/code/5_tic_tac_toe/data.json
possible ▼
CHK-125 subprocess module — arbitrary shell execution — no scope constraint in custom_python/test.py
classic/direct_benchmark/challenges/verticals/code/5_tic_tac_toe/custom_python/test.py
possible ▼
CHK-125 subprocess module — arbitrary shell execution — no scope constraint in custom_python/test.py
classic/direct_benchmark/challenges/verticals/code/3_file_organizer/custom_python/test.py
possible ▼
CHK-125a os.remove() — file deletion — no scope constraint in custom_python/test.py
classic/direct_benchmark/challenges/verticals/code/3_file_organizer/custom_python/test.py
possible ▼
CHK-125 subprocess module — arbitrary shell execution — no scope constraint in adapters/agent_bench.py
classic/direct_benchmark/direct_benchmark/adapters/agent_bench.py
possible ▼
CHK-125a shutil.rmtree() — recursive directory deletion — no scope constraint in adapters/agent_bench.py
classic/direct_benchmark/direct_benchmark/adapters/agent_bench.py
possible ▼
CHK-125 subprocess module — arbitrary shell execution — no scope constraint in adapters/swe_bench.py
classic/direct_benchmark/direct_benchmark/adapters/swe_bench.py
possible ▼
CHK-125a write_file() — unrestricted file write — no scope constraint in config/workspace_settings.py
classic/forge/forge/config/workspace_settings.py
possible ▼
▼ Show 94 false positives (47% of this view) Last scanned: Jul 21, 2026
More servers
nanocoai/nanoclaw 85
A lightweight alternative to OpenClaw that runs in containers for security. Connects to WhatsApp, Telegram, Slack, Discord, Gmail and other messaging apps,, has memory, scheduled jobs, and runs directly on Anthropic's Agents SDK
30k★
obra/superpowers 85
Foundational skill pack by Jesse Vincent now in anthropics/claude-plugins-official. Includes ffuf web-fuzzing/pentest skill. Partial analysis done — full hook and plugin inspection pending. tier=T2
191k★
google-gemini/gemini-cli 85
An open-source AI agent that brings the power of Gemini directly into your terminal.
106k★
google-gemini/gemini-cli 85
An open-source AI agent that brings the power of Gemini directly into your terminal.
106k★
nanocoai/nanoclaw 85
A lightweight alternative to OpenClaw that runs in containers for security. Connects to WhatsApp, Telegram, Slack, Discord, Gmail and other messaging apps,, has memory, scheduled jobs, and runs directly on Anthropic's Agents SDK
30k★
skypilot-org/skypilot 85
Scan your entire org's MCP deployment
2,500+ repos pre-scored. 22% carry CRITICAL findings.