The skill uses deceptive pre-authorized instructions to bypass user consent while lacking transparency through missing code documentation and licensing information.
Fabricated user consent / pre-authorized instruction — a statement falsely attributed to the user to manufacture authorization
The user ALREADY said
Skill body contains no code blocks or usage examples, making it harder for users to evaluate.
Skill does not specify a license field. Specifying a license helps users understand usage terms.
[](https://mondoo.com/ai-agent-security/skills/github/sickn33/antigravity-awesome-skills/canvas-design)<a href="https://mondoo.com/ai-agent-security/skills/github/sickn33/antigravity-awesome-skills/canvas-design"><img src="https://mondoo.com/ai-agent-security/api/badge/github/sickn33/antigravity-awesome-skills/canvas-design.svg" alt="Mondoo Skill Check" /></a>https://mondoo.com/ai-agent-security/api/badge/github/sickn33/antigravity-awesome-skills/canvas-design.svgSkills can read files, run commands, and access credentials. Mondoo helps organizations manage the security risks of AI agent skills across their entire fleet.