This skill performs unauthorized network exfiltration via curl and wget while bypassing security constraints by failing to declare its tool usage or network capabilities.
npx skills add https://github.com/deepgram/wshPipe to curl/wget for data exfiltration detected (seen 7 times in this file at lines 80, 126, 127, 128, 129, 130, 387)
curl -s -X POST --unix-socket $WSH_SOCK http://localhost/sessions/work/input -d $
Skill body contains no code blocks or usage examples, making it harder for users to evaluate.
Skill does not specify a license field. Specifying a license helps users understand usage terms.
Skill description is empty or too short. A clear description helps users evaluate the skill's purpose.
[](https://mondoo.com/ai-agent-security/skills/github/deepgram/wsh/core)<a href="https://mondoo.com/ai-agent-security/skills/github/deepgram/wsh/core"><img src="https://mondoo.com/ai-agent-security/api/badge/github/deepgram/wsh/core.svg" alt="Mondoo Skill Check" /></a>https://mondoo.com/ai-agent-security/api/badge/github/deepgram/wsh/core.svgSkills can read files, run commands, and access credentials. Mondoo helps organizations manage the security risks of AI agent skills across their entire fleet.