The skill lacks defined tool constraints, performs aggressive unauthorized network scanning, and utilizes insecure command execution patterns that bypass system-level security boundaries.
npx skills add https://github.com/astronomer/agentsInstruction boundary manipulation detected
### System
The `af instance discover local --scan` command performs a deep scan of ports 1024-65535, which is aggressive and could trigger security alerts or interfere with other services on the host.
af instance discover local --scan # Deep scan all ports 1024-65535
SKILL.md links to "api-reference.md" but the file is not part of the skill package — the workflow silently degrades or the content is sourced elsewhere at runtime
[api-reference.md](api-reference.md)
Skill does not specify a license field. Specifying a license helps users understand usage terms.
[](https://mondoo.com/ai-agent-security/skills/github/astronomer/agents/airflow)<a href="https://mondoo.com/ai-agent-security/skills/github/astronomer/agents/airflow"><img src="https://mondoo.com/ai-agent-security/api/badge/github/astronomer/agents/airflow.svg" alt="Mondoo Skill Check" /></a>https://mondoo.com/ai-agent-security/api/badge/github/astronomer/agents/airflow.svgSkills can read files, run commands, and access credentials. Mondoo helps organizations manage the security risks of AI agent skills across their entire fleet.