MondooMondoo
AI Agent Security
Skill Threat IntelligenceCLIFAQ
Log inGet Assessment

AI Agent Skill Check is a free AI agent skill security scanner by Mondoo. We scan skills across ClawHub, Skills.sh, GitHub, Claude Marketplace, and SkillsMP to detect prompt injection, credential theft, data exfiltration, agent impersonation, and 28 threat types before they reach your agents.

Mondoo

  • Vulnerability Management
  • Technology
  • Services

Solutions

  • Financial Services
  • Manufacturing
  • Healthcare

Resources

  • Blog
  • Skill Check CLI
  • Documentation
  • GitHub

Company

  • About
  • Careers
  • Partners
  • Contact

Legal

  • Privacy
  • Terms
  • Imprint
MondooMondoo© 2026 Mondoo, Inc.

Skills

Browse, search, and filter AI agent skills across all registries.

SkillAI AgentsSummaryStarsInstallsFindingsRisk
skills/find-skills
vercel-labs
GitHubSkills.sh

The skill forces non-interactive global installations of unpinned, untrusted packages, creating a critical security vulnerability that allows arbitrary code execution with system-wide privileges.

23.1k2.1M5
70High
skills/frontend-design
anthropics
GitHubSkills.sh

The skill lacks transparency due to the absence of code blocks or usage examples, preventing users from verifying its functionality and security posture.

153.0k568.1k1
15Low
agent-skills/vercel-react-best-practices
vercel-labs
GitHubSkills.sh

No security issues detected in vercel-labs/agent-skills/vercel-react-best-practices.

28.1k489.8k–
0None
agent-browser/agent-browser
vercel-labs
GitHubSkills.sh

This skill facilitates remote code execution via dynamic instruction fetching, exposes sensitive session data through an insecure proxy, and employs keyword stuffing to hijack agent control for unauthorized tasks.

36.5k467.0k8
70High
azure-skills/microsoft-foundry
microsoft
GitHubSkills.sh

The skill uses keyword stuffing for over-triggering, lacks defined tool constraints for sensitive operations, and references missing documentation, suggesting potential runtime execution from unverified external sources.

1.2k405.2k7
40Medium
agent-skills/web-design-guidelines
vercel-labs
GitHubSkills.sh

The skill facilitates remote prompt injection by fetching and executing authoritative instructions from an external URL, allowing attackers to hijack agent behavior while bypassing security review processes.

28.1k403.6k4
70High
azure-skills/azure-ai
microsoft
GitHubSkills.sh

The skill exhibits potential impersonation risks and relies on missing documentation files, causing silent workflow degradation and preventing transparent evaluation of its functionality.

1.2k402.6k7
40Medium
azure-skills/azure-deploy
microsoft
GitHubSkills.sh

The skill contains multiple broken documentation links to missing external files, creating an opaque execution environment that prevents proper security evaluation of its deployment workflows.

1.2k402.3k6
15Low
azure-skills/azure-diagnostics
microsoft
GitHubSkills.sh

The skill contains multiple broken documentation references, indicating incomplete packaging that may cause runtime failures or unexpected behavior when accessing external resources.

1.2k402.2k5
15Low
azure-skills/azure-prepare
microsoft
GitHubSkills.sh

The skill lacks defined tool constraints and relies on missing external documentation, creating an opaque execution environment that prevents proper security auditing and verification of its runtime behavior.

1.2k402.1k7
15Low
azure-skills/azure-storage
microsoft
GitHubSkills.sh

The skill contains multiple broken documentation links, indicating poor maintenance and potential runtime instability due to missing dependency references.

1.2k401.8k5
15Low
azure-skills/azure-validate
microsoft
GitHubSkills.sh

The skill lacks transparency and relies on missing external documentation, creating an opaque execution environment that prevents proper security verification of its runtime behavior.

1.2k401.5k4
15Low
azure-skills/entra-app-registration
microsoft
GitHubSkills.sh

The skill lacks transparency and contains multiple broken documentation references, leading to potential runtime failures or reliance on unverified external content.

1.2k401.4k6
15Low
azure-skills/appinsights-instrumentation
microsoft
GitHubSkills.sh

The skill lacks transparency and contains multiple broken documentation references, leading to silent runtime degradation and an inability for users to verify its intended functionality.

1.2k401.3k6
15Low
azure-skills/azure-compliance
microsoft
GitHubSkills.sh

The skill lacks transparency and references multiple missing documentation files, creating an opaque execution environment where workflows may silently degrade or fetch external content from untrusted sources.

1.2k401.3k6
15Low
azure-skills/azure-rbac
microsoft
GitHubSkills.sh

The skill lacks transparency and verifiable code documentation, preventing users from assessing its security posture or confirming it performs only intended Azure role-based access control operations.

1.2k401.3k1
15Low
azure-skills/azure-resource-lookup
microsoft
GitHubSkills.sh

The skill exhibits a potential supply chain risk by referencing external documentation that is missing from the package, which could lead to unauthorized content injection or runtime execution errors.

1.2k401.3k1
15Low
azure-skills/azure-aigateway
microsoft
GitHubSkills.sh

The skill impersonates a brand, lacks declared tool constraints, performs unauthorized network access, and relies on missing external documentation, creating significant security and transparency risks.

1.2k401.2k8
40Medium
azure-skills/azure-kusto
microsoft
GitHubSkills.sh

No security issues detected in microsoft/azure-skills/azure-kusto.

1.2k401.1k–
0None
azure-skills/azure-resource-visualizer
microsoft
GitHubSkills.sh

The skill contains broken documentation links and missing assets, leading to silent runtime degradation and a lack of transparency regarding its operational dependencies.

1.2k401.1k4
15Low
azure-skills/azure-messaging
microsoft
GitHubSkills.sh

The skill lacks sufficient documentation and code examples, preventing users from verifying its functionality and assessing potential security risks.

1.2k390.9k1
15Low
skills/remotion-best-practices
remotion-dev
GitHubSkills.sh

The skill uses hidden text, executes unpinned packages, performs unauthorized network and file operations, and relies on missing external documentation, creating significant security and supply chain risks.

3.7k381.3k10
70High
azure-skills/azure-hosted-copilot-sdk
microsoft
GitHubSkills.sh

The skill contains broken documentation links to missing reference files, causing silent workflow degradation and preventing users from verifying security and configuration practices.

1.2k374.2k6
15Low
skills/grill-me
mattpocock
GitHubSkills.sh

The skill is functionally inert and lacks transparency regarding its purpose, licensing, and implementation, failing to provide any verifiable utility or security assurance.

137.2k353.2k3
40Medium
azure-skills/azure-compute
microsoft
GitHubSkills.sh

The skill documentation references multiple missing workflow files, indicating incomplete packaging that causes silent functional degradation during runtime.

1.2k345.0k5
15Low
azure-skills/azure-cloud-migrate
microsoft
GitHubSkills.sh

The skill lacks transparency and relies on multiple missing documentation files, creating an opaque execution environment where critical workflow logic is sourced from external, unverified locations at runtime.

1.2k335.0k6
15Low
skills/improve-codebase-architecture
mattpocock
GitHubSkills.sh

The skill lacks defined tool constraints, documentation, and transparency, creating an opaque execution environment that prevents proper security auditing and verification of its runtime behavior.

137.2k289.8k4
15Low
skills/grill-with-docs
mattpocock
GitHubSkills.sh

The skill exhibits insecure design by bypassing model invocation restrictions and blindly executing unverified external skills, creating a significant risk of malicious sub-agent hijacking.

137.2k286.1k4
70High
skills/skill-creator
anthropics
GitHubSkills.sh

The skill lacks defined tool constraints, allowing unrestricted execution of commands, file operations, and network access, which poses a significant security risk for arbitrary code execution.

153.0k278.4k2
15Low
skills/tdd
mattpocock
GitHubSkills.sh

The skill lacks essential documentation files and a specified license, leading to potential runtime errors and ambiguity regarding usage terms.

137.2k273.4k4
15Low
azure-skills/azure-quotas
microsoft
GitHubSkills.sh

The skill bypasses user confirmation, probes cloud metadata, and executes unconstrained operations while relying on external, non-packaged documentation, creating significant security and transparency risks.

1.2k271.7k5
40Medium
caveman/caveman
juliusbrussee
GitHubSkills.sh

The skill lacks a license and a descriptive purpose, but it does not exhibit any malicious behavior or security vulnerabilities.

74.9k267.0k2
0None
azure-skills/azure-upgrade
microsoft
GitHubSkills.sh

The skill contains multiple broken documentation links to missing external files, creating an opaque execution environment where critical workflow logic is sourced from untrusted or undefined locations.

1.2k264.2k6
15Low
runcomfy-agent-skills/video-edit
agentspace-so
GitHubSkills.sh

The skill executes unpinned, unverified packages and performs arbitrary system operations without declaring required tools, creating significant risks for supply chain attacks and unauthorized system access.

22263.2k4
40Medium
runcomfy-agent-skills/image-to-video
agentspace-so
GitHubSkills.sh

The skill executes unpinned, unverified packages and performs arbitrary system operations without declaring necessary tool constraints, creating a significant risk of supply chain compromise and unauthorized system access.

22262.7k4
40Medium
runcomfy-agent-skills/flux-kontext
agentspace-so
GitHubSkills.sh

The skill executes unpinned, unverified npx packages at runtime, creating a significant supply chain risk by allowing arbitrary code execution from potentially malicious or compromised external dependencies.

22262.3k3
40Medium
runcomfy-agent-skills/happyhorse-1-0
agentspace-so
GitHubSkills.sh

The skill executes unpinned, unverified dependencies and performs arbitrary system operations without declaring required tools, creating a high risk of supply chain compromise and unauthorized system access.

22261.8k4
40Medium
runcomfy-agent-skills/gpt-image-edit
agentspace-so
GitHubSkills.sh

The skill executes unpinned, unverified packages via npx at runtime, creating a significant supply chain risk by allowing arbitrary code execution from potentially compromised or malicious external dependencies.

22261.7k3
40Medium
runcomfy-agent-skills/seedance-v2
agentspace-so
GitHubSkills.sh

The skill executes unpinned, unverified packages via npx, creating a significant supply chain risk by allowing arbitrary, potentially malicious code to run in the agent's environment.

22261.7k3
40Medium
runcomfy-agent-skills/wan-2-7
agentspace-so
GitHubSkills.sh

The skill executes unpinned, unverified packages via npx, creating a significant supply chain risk by allowing arbitrary, potentially malicious code to run without integrity checks or version constraints.

22261.7k3
40Medium
skills/to-prd
mattpocock
GitHubSkills.sh

The skill forces the execution of an undefined, external setup command, creating a significant security risk by allowing arbitrary, potentially malicious environment configuration from an untrusted source.

137.2k254.6k4
70High
skills/agentspace
agentspace-so
GitHubSkills.sh

The skill facilitates unauthorized local file exfiltration and grants excessive file-editing permissions while relying on unverified, unpinned dependencies that expose the workspace to significant remote compromise risks.

10254.4k6
40Medium
cli/lark-doc
larksuite
GitHubSkills.sh

The skill contains multiple broken documentation references that cause silent workflow degradation and fails to specify a license, indicating poor maintenance and lack of transparency.

14.4k252.7k6
15Low
cli/lark-base
larksuite
GitHubSkills.sh

The skill lacks transparency due to missing documentation files and an unspecified license, creating potential reliability issues and ambiguity regarding usage terms.

14.4k251.9k7
15Low
cli/lark-im
larksuite
GitHubSkills.sh

The skill lacks documentation for its core functions and introduces security risks by processing potentially malicious external content without adequate validation or defined usage terms.

14.4k251.7k7
40Medium
cli/lark-shared
larksuite
GitHubSkills.sh

The skill lacks defined tool constraints, allowing unrestricted execution of commands, file operations, and network access, which poses a significant security risk for unauthorized system interaction.

14.4k251.2k2
15Low
agent-skills/sleek-design-mobile-apps
sleekdotdesign
GitHubSkills.sh

The skill facilitates SSRF via arbitrary URL fetching and enables remote command injection by piping unverified API responses directly into shell commands, violating its stated network access restrictions.

426249.3k5
40Medium
skills/to-issues
mattpocock
GitHubSkills.sh

The skill executes an undefined, arbitrary command that risks unauthorized code execution and environment poisoning, while lacking transparency through missing documentation and licensing.

137.2k243.8k3
40Medium
Page 1 of 1079