The skill contains suspicious base64-encoded blobs that may represent a hidden payload, posing a potential security risk despite the lack of a specified license.
npx skills add https://github.com/openweb-org/openwebLong base64-encoded blob detected (potential hidden payload) (seen 2 times in this file at lines 40, 46)
CBwQAhopEgoyMDI2LTA0LTMwagwIAhIIL20vMGZ2eWdyDQgDEgkvbS8wMl8yODYaKRIKMjAyNi0wNS0wNGoNCAMSCS9tLzAyXzI4NnIMCAISCC9tLzBmdnlnQAFIAXABggELCP
Skill does not specify a license field. Specifying a license helps users understand usage terms.
[](https://mondoo.com/ai-agent-security/skills/github/openweb-org/openweb/google-flights)<a href="https://mondoo.com/ai-agent-security/skills/github/openweb-org/openweb/google-flights"><img src="https://mondoo.com/ai-agent-security/api/badge/github/openweb-org/openweb/google-flights.svg" alt="Mondoo Skill Check" /></a>https://mondoo.com/ai-agent-security/api/badge/github/openweb-org/openweb/google-flights.svgSkills can read files, run commands, and access credentials. Mondoo helps organizations manage the security risks of AI agent skills across their entire fleet.