The skill contains a suspicious base64-encoded payload and relies on external, unverified content, indicating a high risk of malicious code injection or unauthorized runtime data sourcing.
npx skills add https://github.com/bitwarden/androidLong base64-encoded blob detected (potential hidden payload)
app/src/main/kotlin/com/x8bit/bitwarden/data/tools/generator/repository/di/GeneratorRepositoryModule
SKILL.md links to "templates.md" but the file is not part of the skill package — the workflow silently degrades or the content is sourced elsewhere at runtime
[ViewModel template](templates.md#viewmodel-template-state-action-event-pattern)
Skill does not specify a license field. Specifying a license helps users understand usage terms.
[](https://mondoo.com/ai-agent-security/skills/github/bitwarden/android/implementing-android-code)<a href="https://mondoo.com/ai-agent-security/skills/github/bitwarden/android/implementing-android-code"><img src="https://mondoo.com/ai-agent-security/api/badge/github/bitwarden/android/implementing-android-code.svg" alt="Mondoo Skill Check" /></a>https://mondoo.com/ai-agent-security/api/badge/github/bitwarden/android/implementing-android-code.svgSkills can read files, run commands, and access credentials. Mondoo helps organizations manage the security risks of AI agent skills across their entire fleet.