The skill poses a significant security risk by attempting to access sensitive credential file paths, indicating potential unauthorized data exfiltration.
npx skills add https://github.com/google-labs-code/design.mdAccess to known credential file paths detected
/etc/passwd
Skill does not specify a license field. Specifying a license helps users understand usage terms.
[](https://mondoo.com/ai-agent-security/skills/github/google-labs-code/design.md/typed-service-contracts)<a href="https://mondoo.com/ai-agent-security/skills/github/google-labs-code/design.md/typed-service-contracts"><img src="https://mondoo.com/ai-agent-security/api/badge/github/google-labs-code/design.md/typed-service-contracts.svg" alt="Mondoo Skill Check" /></a>https://mondoo.com/ai-agent-security/api/badge/github/google-labs-code/design.md/typed-service-contracts.svgSkills can read files, run commands, and access credentials. Mondoo helps organizations manage the security risks of AI agent skills across their entire fleet.