The skill performs unauthorized network exfiltration via hidden curl/wget commands while bypassing security constraints by failing to declare its tool usage or network capabilities.
npx skills add https://github.com/posthog/ai-pluginPipe to curl/wget for data exfiltration detected (seen 3 times in this file at lines 167, 174, 203)
curl -s 'http://localhost:8123/' --data
Skill does not specify a license field. Specifying a license helps users understand usage terms.
Skill description is empty or too short. A clear description helps users evaluate the skill's purpose.
[](https://mondoo.com/ai-agent-security/skills/github/posthog/ai-plugin/debugging-signals-pipeline)<a href="https://mondoo.com/ai-agent-security/skills/github/posthog/ai-plugin/debugging-signals-pipeline"><img src="https://mondoo.com/ai-agent-security/api/badge/github/posthog/ai-plugin/debugging-signals-pipeline.svg" alt="Mondoo Skill Check" /></a>https://mondoo.com/ai-agent-security/api/badge/github/posthog/ai-plugin/debugging-signals-pipeline.svgSkills can read files, run commands, and access credentials. Mondoo helps organizations manage the security risks of AI agent skills across their entire fleet.