The skill is malicious because it executes destructive shell or Java runtime commands, posing a critical risk to system integrity and security.
npx skills add https://github.com/anthropics/claude-plugins-officialDestructive shell or Java runtime command execution detected
rm -rf /
Skill does not specify a license field. Specifying a license helps users understand usage terms.
[](https://mondoo.com/ai-agent-security/skills/github/anthropics/claude-plugins-official/writing-hookify-rules)<a href="https://mondoo.com/ai-agent-security/skills/github/anthropics/claude-plugins-official/writing-hookify-rules"><img src="https://mondoo.com/ai-agent-security/api/badge/github/anthropics/claude-plugins-official/writing-hookify-rules.svg" alt="Mondoo Skill Check" /></a>https://mondoo.com/ai-agent-security/api/badge/github/anthropics/claude-plugins-official/writing-hookify-rules.svgSkills can read files, run commands, and access credentials. Mondoo helps organizations manage the security risks of AI agent skills across their entire fleet.