MondooMondoo
AI Agent Security
Skills
Log inGet Assessment

AI Agent Skill Check is a free AI agent skill security scanner by Mondoo. We scan skills across ClawHub, Skills.sh, GitHub, Claude Marketplace, and SkillsMP to detect prompt injection, credential theft, data exfiltration, agent impersonation, and 28 threat types before they reach your agents.

Mondoo

  • Vulnerability Management
  • Technology
  • Services

Solutions

  • Financial Services
  • Manufacturing
  • Healthcare

Resources

  • Blog
  • Skill Check
  • Documentation
  • GitHub

Company

  • About
  • Careers
  • Partners
  • Contact

Legal

  • Privacy
  • Terms
  • Imprint
MondooMondoo© 2026 Mondoo, Inc.

Skills

Browse, search, and filter AI agent skills across all registries.

Command Execution
SkillAI AgentsSummaryStarsDownloadsFindingsRisk
ui-ux-pro-max-skill/ui-ux-pro-max
nextlevelbuilder
GitHubClaude CodeSkills.sh

The skill is vulnerable to command injection via user input and

66.7k119.6k3
100Critical
skills/agent-tools
tool-belt
GitHubClaude Code

The skill allows remote code execution, exfiltrates local files, and provides broad Twitter automation, significantly increasing attack surface and potential for abuse.

346116.3k5
100Critical
mck-ppt-design
likaku
OpenClaw

The skill enables arbitrary command execution via command

11.2k12
100Critical
openclaw-office-toolkit
axelhu
OpenClaw

The skill uses external binaries and handles files without robust input

01.2k4
100Critical
doubao-img
herry-zhu
OpenClaw

The skill executes arbitrary shell commands and JavaScript, systematically

199310
100Critical
opc-skills/requesthunt
resciencelab
GitHubClaude Code

This skill is dangerous as it can download and execute

7669123
100Critical
llm-memory-integration
xkzs2007
OpenClaw

Masquerades as an LLM memory tool

180822
100Critical
prose/open-prose
openprose
GitHubClaude CodeSkills.sh

This skill self-modifies the agent's memory

1.1k78014
100Critical
nano-banana-2-skill/nano-banana
kingbootoshi
GitHubClaude CodeSkills.sh

The skill executes arbitrary remote code from external sources

3323306
100Critical
greenhelix-agent-interoperability-bridge
mirni
OpenClaw

This skill autonomously executes financial transactions across multiple protocols without

08422
100Critical
baas
yakejiang
OpenClaw

This skill enables remote code execution, installs global packages

08217
100Critical
cfm-redis
ameylover
OpenClaw

The skill enables arbitrary command execution, prompt injection,

06716
100Critical
deepdive-osint
sinndarkblade
OpenClaw

The skill autonomously clones and executes unverified external code

03418
100Critical
rednote-contacts
batxent
OpenClaw

This skill allows remote code execution,

0346
100Critical
harness-design/harness-design
zanwei
GitHubClaude CodeSkills.sh

This skill allows command injection, arbitrary

116
100Critical
tweaktune/tweaktune-synthesizer
qooba
GitHubClaude Code

The skill allows arbitrary shell command execution

2–6
100Critical
prelude-claude-plugin/nist
preludeorg
GitHubClaude Code

This skill is highly vulnerable to command injection and

0–7
100Critical
custom-plugin-ai-engineer/model-deployment
pluginagentmarketplace
GitHubClaude Code

The model deployment skill allows remote code execution and uses unpinned dependencies, posing significant supply chain risks.

2–2
100Critical
overthink-plugins/layer
overthinkos
GitHubClaude Code

This skill allows arbitrary command execution, privilege escalation

0–6
100Critical
overthink-plugins/generate
overthinkos
GitHubClaude Code

This skill generates Containerfiles but introduces supply chain vulnerabilities

0–4
100Critical
codex-collab/codex-collab
masuP9
GitHubClaude CodeSkills.sh

This skill allows arbitrary command execution and privilege escalation via user

2–6
100Critical
architecture-cowork-plugin/architecture-methodology
navraj007in
GitHubClaude Code

This skill executes shell commands, handles sensitive API

2–9
100Critical
smalltv-ultra-skill/geekmagic-smalltv-ultra
yaniv-golan
GitHubClaude Code

This skill enables broad command execution, exposes WiFi credentials

1–8
100Critical
ilo/ilo
ilo-lang
GitHubClaude CodeSkills.sh

This skill enables arbitrary command execution, command injection

0–6
100Critical
oh-my-agent/oma-dev-workflow
first-fluke
GitHubClaude Code

The skill installs `mise` via `curl |

637–11
100Critical
agent-skills/developing-genkit-dart
firebase
GitHubSkills.sh

The skill enables remote code download and execution, allowing arbitrary code execution and potential compromise of the agent.

228–1
100Critical
claude-skill-collection/ios-polish
ElvinOuyang
GitHubClaude CodeSkills.sh

The skill executes shell commands and performs

1–5
100Critical
crabshell/verifying
ZipperBagCoffee
GitHubClaude Code

This skill allows arbitrary command execution and

1–15
100Critical
agent4ppt/revise-ppt
JinwangMok
GitHubClaude Code

This skill risks arbitrary file writes and remote

0–4
70High
swing-skills/swing-trace
TheStack-ai
GitHubClaude Code

This skill allows arbitrary shell command execution and file

32–6
100Critical
Capsule/task-orchestrator-hooks-builder
Angriff36
GitHubClaude Code

This skill generates and executes arbitrary bash scripts

0–6
100Critical
godfery-agent-council
godferylindsay
OpenClaw

The skill allows arbitrary command execution, persistent cron job scheduling

0–17
100Critical