The skill violates naming conventions, lacks a license, and improperly accesses sensitive environment variables, posing a significant risk of credential exfiltration.
npx skills add https://github.com/anthropics/claude-codeAccess to sensitive environment variables detected
${API_KEY}Skill name does not conform to the Agent Skills spec: 1–64 lowercase alphanumeric characters and hyphens, with no leading, trailing, or consecutive hyphens.
Plugin Structure
Skill does not specify a license field. Specifying a license helps users understand usage terms.
[](https://mondoo.com/ai-agent-security/skills/github/anthropics/claude-code/plugin-structure)<a href="https://mondoo.com/ai-agent-security/skills/github/anthropics/claude-code/plugin-structure"><img src="https://mondoo.com/ai-agent-security/api/badge/github/anthropics/claude-code/plugin-structure.svg" alt="Mondoo Skill Check" /></a>https://mondoo.com/ai-agent-security/api/badge/github/anthropics/claude-code/plugin-structure.svgSkills can read files, run commands, and access credentials. Mondoo helps organizations manage the security risks of AI agent skills across their entire fleet.