The skill facilitates unauthorized offensive security operations and introduces critical supply chain risks by allowing automated, high-privilege code modification based on potentially malicious, user-controlled inputs.
The skill includes instructions to execute offensive security tools (Metasploit, Burp Suite) and perform penetration testing, which exceeds the scope of 'security hardening' and 'defense-in-depth' controls.
Phase 4, Step 11: 'Execute comprehensive penetration testing... Use Burp Suite, Metasploit, and custom exploits.'
The skill mandates automated code modification ('Patched code with vulnerability fixes') based on the output of automated scanners. This creates a high risk of 'poisoned' remediation where an attacker influences the scanner output to force the agent to inject malicious code into the codebase.
Coordinate immediate remediation of critical vulnerabilities (CVSS 7+) in: $ARGUMENTS. Fix SQL injections... Apply security patches for CVEs.
Exploitation or pentest tool — offensive security tool invocation
Metasploit
The skill instructs the agent to spawn sub-agents with broad, high-privilege instructions (e.g., 'Perform comprehensive security assessment', 'Execute... custom exploits') using user-provided arguments. This allows an attacker to inject malicious commands into the sub-agent's execution context via the $ARGUMENTS variable.
Use Task tool with subagent_type="security-auditor" - Prompt: "Perform comprehensive security assessment on: $ARGUMENTS."
Skill body contains no code blocks or usage examples, making it harder for users to evaluate.
Skill does not specify a license field. Specifying a license helps users understand usage terms.
[](https://mondoo.com/ai-agent-security/skills/github/sickn33/antigravity-awesome-skills/security-scanning-security-hardening)<a href="https://mondoo.com/ai-agent-security/skills/github/sickn33/antigravity-awesome-skills/security-scanning-security-hardening"><img src="https://mondoo.com/ai-agent-security/api/badge/github/sickn33/antigravity-awesome-skills/security-scanning-security-hardening.svg" alt="Mondoo Skill Check" /></a>https://mondoo.com/ai-agent-security/api/badge/github/sickn33/antigravity-awesome-skills/security-scanning-security-hardening.svgSkills can read files, run commands, and access credentials. Mondoo helps organizations manage the security risks of AI agent skills across their entire fleet.