The skill uses fabricated user authorization to exfiltrate data via unauthorized network connections and pipe commands, posing a severe security risk to the host environment.
npx skills add https://github.com/clickhouse/clickhousePipe to curl/wget for data exfiltration detected
curl -sS 'https://play.clickhouse.com/?user=play' --data
Fabricated user consent / pre-authorized instruction — a statement falsely attributed to the user to manufacture authorization
The user already authoriz
Skill does not specify a license field. Specifying a license helps users understand usage terms.
[](https://mondoo.com/ai-agent-security/skills/github/clickhouse/clickhouse/close-flaky-issues)<a href="https://mondoo.com/ai-agent-security/skills/github/clickhouse/clickhouse/close-flaky-issues"><img src="https://mondoo.com/ai-agent-security/api/badge/github/clickhouse/clickhouse/close-flaky-issues.svg" alt="Mondoo Skill Check" /></a>https://mondoo.com/ai-agent-security/api/badge/github/clickhouse/clickhouse/close-flaky-issues.svgSkills can read files, run commands, and access credentials. Mondoo helps organizations manage the security risks of AI agent skills across their entire fleet.