The skill executes arbitrary commands and writes files while obfuscating its intent through hex-encoded payloads, bypassing security constraints by failing to declare its required tool permissions.
npx skills add https://github.com/costrict-plugins-repo/mukul975-anthropic-cybersecurity-skills-cybersecurity-skillsHex-encoded payload detected
\x53\x51\x4c\x69\x74\x65\x20\x66\x6f\x72\x6d\x61\x74
[](https://mondoo.com/ai-agent-security/skills/github/costrict-plugins-repo/mukul975-anthropic-cybersecurity-skills-cybersecurity-skills/performing-file-carving-with-foremost)<a href="https://mondoo.com/ai-agent-security/skills/github/costrict-plugins-repo/mukul975-anthropic-cybersecurity-skills-cybersecurity-skills/performing-file-carving-with-foremost"><img src="https://mondoo.com/ai-agent-security/api/badge/github/costrict-plugins-repo/mukul975-anthropic-cybersecurity-skills-cybersecurity-skills/performing-file-carving-with-foremost.svg" alt="Mondoo Skill Check" /></a>https://mondoo.com/ai-agent-security/api/badge/github/costrict-plugins-repo/mukul975-anthropic-cybersecurity-skills-cybersecurity-skills/performing-file-carving-with-foremost.svgSkills can read files, run commands, and access credentials. Mondoo helps organizations manage the security risks of AI agent skills across their entire fleet.