MondooMondoo
AI Agent Security
Skill Threat IntelligenceCLIFAQ
Log inGet Assessment

AI Agent Skill Check is a free AI agent skill security scanner by Mondoo. We scan skills across ClawHub, Skills.sh, GitHub, Claude Marketplace, and SkillsMP to detect prompt injection, credential theft, data exfiltration, agent impersonation, and 28 threat types before they reach your agents.

Mondoo

  • Vulnerability Management
  • Technology
  • Services

Solutions

  • Financial Services
  • Manufacturing
  • Healthcare

Resources

  • Blog
  • Skill Check CLI
  • Documentation
  • GitHub

Company

  • About
  • Careers
  • Partners
  • Contact

Legal

  • Privacy
  • Terms
  • Imprint
MondooMondoo© 2026 Mondoo, Inc.

Skills

Browse, search, and filter AI agent skills across all registries.

SkillAI AgentsSummaryStarsDownloadsFindingsRisk
skills/find-skills
vercel-labs
GitHubSkills.sh

This skill facilitates silent installation of arbitrary external skills

17.1k1.4M10
100Critical
self-improvement
pskoett
OpenClaw

This skill enables arbitrary command execution via hook scripts and

3.2k395.7k6
100Critical
agent-skills/vercel-react-best-practices
vercel-labs
GitHubSkills.sh

The skill misrepresents itself as a

26.2k374.6k1
40Medium
skills/frontend-design
anthropics
GitHubClaude CodeSkills.sh

No security issues detected in anthropics/skills/frontend-design.

128.9k372.9k–
0None
azure-skills/microsoft-foundry
microsoft
GitHubClaude CodeGemini CLISkills.sh

This skill exposes sensitive credentials, allows privilege escalation, arbitrary

849303.9k6
100Critical
agent-skills/web-design-guidelines
vercel-labs
GitHubSkills.sh

The skill executes arbitrary remote content from mutable, unauthenticated

26.2k298.5k7
100Critical
azure-skills/azure-deploy
microsoft
GitHubClaude CodeGemini CLISkills.sh

The `azure-deploy` skill relies on custom, unaudited 'MCP Tools', posing a supply chain risk due to unknown

849293.2k1
40Medium
azure-skills/azure-ai
microsoft
GitHubClaude CodeGemini CLISkills.sh

The skill exposes Azure CLI commands

849293.2k2
40Medium
azure-skills/azure-prepare
microsoft
GitHubClaude CodeGemini CLISkills.sh

The skill's human approval step for

849293.1k1
5Low
azure-skills/azure-diagnostics
microsoft
GitHubClaude CodeGemini CLISkills.sh

The skill is vulnerable to command and K

849293.0k3
40Medium
azure-skills/azure-compute
microsoft
GitHubClaude CodeGemini CLISkills.sh

No security issues detected in microsoft/azure-skills/azure-compute.

849292.8k–
0None
azure-skills/azure-cloud-migrate
microsoft
GitHubClaude CodeGemini CLISkills.sh

The skill introduces supply chain risks through external dependencies and local file loading, potentially influencing agent reasoning if compromised.

849292.8k2
40Medium
azure-skills/azure-messaging
microsoft
GitHubClaude CodeGemini CLISkills.sh

No security issues detected in microsoft/azure-skills/azure-messaging.

849292.7k–
0None
azure-skills/azure-hosted-copilot-sdk
microsoft
GitHubClaude CodeGemini CLISkills.sh

No security issues detected in microsoft/azure-skills/azure-hosted-copilot-sdk.

849292.7k–
0None
azure-skills/appinsights-instrumentation
microsoft
GitHubClaude CodeGemini CLISkills.sh

No security issues detected in microsoft/azure-skills/appinsights-instrumentation.

849292.7k–
0None
azure-skills/entra-app-registration
microsoft
GitHubClaude CodeGemini CLISkills.sh

No security issues detected in microsoft/azure-skills/entra-app-registration.

849292.7k–
0None
azure-skills/azure-validate
microsoft
GitHubClaude CodeGemini CLISkills.sh

The skill introduces supply chain risks and indirect prompt injection

849292.7k5
70High
azure-skills/azure-storage
microsoft
GitHubClaude CodeGemini CLISkills.sh

The skill misrepresents its capabilities, claiming full

849292.7k1
40Medium
azure-skills/azure-rbac
microsoft
GitHubClaude CodeGemini CLISkills.sh

This skill is vulnerable to prompt injection, allowing

849292.6k2
70High
azure-skills/azure-compliance
microsoft
GitHubClaude CodeGemini CLISkills.sh

The skill enables reconnaissance of sensitive Azure Key Vault artifacts by listing and retrieving metadata for keys, secrets,

849292.6k1
15Low
azure-skills/azure-resource-lookup
microsoft
GitHubClaude CodeGemini CLISkills.sh

The skill risks command injection via `az graph query`

849292.6k1
70High
azure-skills/azure-kusto
microsoft
GitHubClaude CodeGemini CLISkills.sh

This skill allows command injection, data exfiltration,

849292.5k4
100Critical
azure-skills/azure-aigateway
microsoft
GitHubClaude CodeGemini CLISkills.sh

The skill allows powerful Azure resource management and sensitive data querying

849292.5k3
70High
azure-skills/azure-resource-visualizer
microsoft
GitHubClaude CodeGemini CLISkills.sh

The skill enables direct command execution via Azure CLI, posing a risk for arbitrary command execution if the agent's environment is not properly sandboxed.

849292.5k1
40Medium
skills/remotion-best-practices
remotion-dev
GitHubSkills.sh

The skill risks command injection and arbitrary file system access due to unsanitized FFmpeg inputs.

3.0k289.5k1
40Medium
azure-skills/azure-quotas
microsoft
GitHubClaude CodeGemini CLISkills.sh

This skill performs Azure resource reconnaissance and administrative actions, posing

849267.7k5
40Medium
azure-skills/azure-upgrade
microsoft
GitHubClaude CodeGemini CLISkills.sh

The skill can execute arbitrary code, deploy malicious resources,

849255.4k7
100Critical
agent-browser/agent-browser
vercel-labs
GitHubClaude CodeSkills.sh

The skill enables arbitrary command execution, data exfiltration, and social engineering, while also introducing supply chain vulnerabilities through dynamic skill loading.

31.9k240.5k4
100Critical
azure-skills/azure-enterprise-infra-planner
microsoft
GitHubClaude CodeGemini CLISkills.sh

This skill can provision, modify, destroy, and

849212.7k2
70High
azure-skills/azure-kubernetes
microsoft
GitHubClaude CodeGemini CLISkills.sh

The skill performs cloud reconnaissance and is vulnerable to supply chain

849200.6k4
40Medium
skills/skill-creator
anthropics
GitHubClaude CodeSkills.sh

This skill can poison agent knowledge bases through malicious injection into

128.9k185.8k2
40Medium
ontology
oswalpalash
OpenClaw

The skill allows command injection, poisons the

534165.5k4
100Critical
self-improving
ivangdavila
OpenClaw

This self-improving skill autonomously modifies critical

962164.9k10
70High
agent-skills/vercel-composition-patterns
vercel-labs
GitHubSkills.sh

No security issues detected in vercel-labs/agent-skills/vercel-composition-patterns.

26.2k161.2k–
0None
azure-skills/azure-cost
microsoft
GitHubClaude CodeGemini CLISkills.sh

The skill allows arbitrary Azure API calls and

849160.8k3
100Critical
github-copilot-for-azure/azure-ai
microsoft
GitHubSkills.sh

The skill misrepresents its Azure service support,

202154.6k1
40Medium
github-copilot-for-azure/azure-deploy
microsoft
GitHubSkills.sh

This skill executes powerful cloud deployment commands that can cause significant infrastructure changes or destruction if misused.

202154.3k1
70High
github-copilot-for-azure/azure-storage
microsoft
GitHubSkills.sh

The skill enables arbitrary file operations and Azure

202154.2k2
70High
github-copilot-for-azure/azure-diagnostics
microsoft
GitHubSkills.sh

No security issues detected in microsoft/github-copilot-for-azure/azure-diagnostics.

202154.2k–
0None
github-copilot-for-azure/entra-app-registration
microsoft
GitHubSkills.sh

No security issues detected in microsoft/github-copilot-for-azure/entra-app-registration.

202154.0k–
0None
github-copilot-for-azure/azure-validate
microsoft
GitHubSkills.sh

This skill executes arbitrary commands from external files, manipulates

202154.0k12
70High
github-copilot-for-azure/azure-resource-visualizer
microsoft
GitHubSkills.sh

The skill uses powerful Azure CLI commands and handles

202154.0k2
40Medium
github-copilot-for-azure/azure-resource-lookup
microsoft
GitHubSkills.sh

The skill is vulnerable to command

202154.0k2
100Critical
github-copilot-for-azure/azure-rbac
microsoft
GitHubSkills.sh

No security issues detected in microsoft/github-copilot-for-azure/azure-rbac.

202154.0k–
0None
github-copilot-for-azure/azure-kusto
microsoft
GitHubSkills.sh

The skill allows arbitrary KQL query execution and reconnaissance

202154.0k2
70High
github-copilot-for-azure/azure-prepare
microsoft
GitHubSkills.sh

No security issues detected in microsoft/github-copilot-for-azure/azure-prepare.

202154.0k–
0None
github-copilot-for-azure/azure-compliance
microsoft
GitHubSkills.sh

No security issues detected in microsoft/github-copilot-for-azure/azure-compliance.

202154.0k–
0None
github-copilot-for-azure/appinsights-instrumentation
microsoft
GitHubSkills.sh

The skill deceptively provides actionable Azure CLI and Bicep commands for resource creation and code modification, contradicting its stated purpose.

202154.0k1
40Medium
Page 1 of 288