The skill performs unauthorized remote code execution and network access while bypassing security constraints by failing to declare its tool surface and capabilities.
npx skills add https://github.com/clickhouse/agent-skillsRemote code download and execution detected
curl -fsSL https://clickhouse.com/cli | sh
[](https://mondoo.com/ai-agent-security/skills/github/clickhouse/agent-skills/clickhousectl-local-dev)<a href="https://mondoo.com/ai-agent-security/skills/github/clickhouse/agent-skills/clickhousectl-local-dev"><img src="https://mondoo.com/ai-agent-security/api/badge/github/clickhouse/agent-skills/clickhousectl-local-dev.svg" alt="Mondoo Skill Check" /></a>https://mondoo.com/ai-agent-security/api/badge/github/clickhouse/agent-skills/clickhousectl-local-dev.svgSkills can read files, run commands, and access credentials. Mondoo helps organizations manage the security risks of AI agent skills across their entire fleet.