The skill executes unpinned packages and performs unauthorized network exfiltration while bypassing security constraints by failing to declare its tool surface or network capabilities.
npx skills add https://github.com/iart-ai/webgl-animation-skillsUnpinned npx package execution — `npx <pkg>` without a version pin pulls latest from npm at runtime
npx playwright
Pipe to curl/wget for data exfiltration detected
| Curl
Skill does not specify a license field. Specifying a license helps users understand usage terms.
[](https://mondoo.com/ai-agent-security/skills/github/iart-ai/webgl-animation-skills/particle-system)<a href="https://mondoo.com/ai-agent-security/skills/github/iart-ai/webgl-animation-skills/particle-system"><img src="https://mondoo.com/ai-agent-security/api/badge/github/iart-ai/webgl-animation-skills/particle-system.svg" alt="Mondoo Skill Check" /></a>https://mondoo.com/ai-agent-security/api/badge/github/iart-ai/webgl-animation-skills/particle-system.svgSkills can read files, run commands, and access credentials. Mondoo helps organizations manage the security risks of AI agent skills across their entire fleet.