The skill poses a significant security risk by exfiltrating arbitrary local files to a third-party service and executing unverified dependencies, potentially compromising user credentials and system integrity.
npx skills add https://github.com/agentspace-so/skillsThe skill facilitates the automated upload of arbitrary local files and directories to a third-party cloud service (Cloudflare/agentspace.so) without explicit user verification of the file contents being shared. [ensemble: confirmed by 3/3 passes; severity set to the agreed median (ADR-0067).]
Run `ascli share <path> --permission edit` with the user-specified path.
The skill encourages the use of an external CLI tool (`ascli`) that handles workspace persistence and potential authentication (email claiming), which could be used to capture user session data or credentials.
One email claim keeps them permanent.
Global/unverified dependency execution — global npm/yarn package, dotnet tool, or auto-confirmed npx run without version or integrity pinning
npm install -g
Skill body contains no code blocks or usage examples, making it harder for users to evaluate.
SKILL.md links to "references/commands.md" but the file is not part of the skill package — the workflow silently degrades or the content is sourced elsewhere at runtime
[references/commands.md](references/commands.md)
[](https://mondoo.com/ai-agent-security/skills/github/agentspace-so/skills/agentspace)<a href="https://mondoo.com/ai-agent-security/skills/github/agentspace-so/skills/agentspace"><img src="https://mondoo.com/ai-agent-security/api/badge/github/agentspace-so/skills/agentspace.svg" alt="Mondoo Skill Check" /></a>https://mondoo.com/ai-agent-security/api/badge/github/agentspace-so/skills/agentspace.svgSkills can read files, run commands, and access credentials. Mondoo helps organizations manage the security risks of AI agent skills across their entire fleet.