MondooMondoo
AI Agent Security
Skill Threat IntelligenceCLIFAQ
Log inGet Assessment

AI Agent Skill Check is a free AI agent skill security scanner by Mondoo. We scan skills across ClawHub, Skills.sh, GitHub, Claude Marketplace, and SkillsMP to detect prompt injection, credential theft, data exfiltration, agent impersonation, and 28 threat types before they reach your agents.

Mondoo

  • Vulnerability Management
  • Technology
  • Services

Solutions

  • Financial Services
  • Manufacturing
  • Healthcare

Resources

  • Blog
  • Skill Check CLI
  • Documentation
  • GitHub

Company

  • About
  • Careers
  • Partners
  • Contact

Legal

  • Privacy
  • Terms
  • Imprint
MondooMondoo© 2026 Mondoo, Inc.

Skills

Browse, search, and filter AI agent skills across all registries.

Command Execution
SkillAI AgentsSummaryStarsInstallsFindingsRisk
azure-skills/entra-agent-id
microsoft
GitHubSkills.sh

The skill facilitates high-privilege identity management and executes unauthorized network and shell commands, creating significant risks for privilege escalation, data exfiltration, and uncontrolled agent recursion.

1.2k142.5k15
40Medium
skills/higgsfield-generate
higgsfield-ai
GitHubSkills.sh

The skill executes unverified remote scripts via shell pipes, performs unauthorized file writes, and processes untrusted external content, creating significant risks for arbitrary code execution and system compromise.

49272.4k8
100Critical
skills/higgsfield-product-photoshoot
higgsfield-ai
GitHubSkills.sh

The skill insecurely downloads and executes unverified remote scripts directly into a shell, creating a critical vulnerability that allows for arbitrary code execution and system compromise.

49258.5k4
100Critical
skills/higgsfield-soul-id
higgsfield-ai
GitHubSkills.sh

The skill insecurely executes unverified remote code via direct shell piping, granting external servers arbitrary control over the agent's environment without integrity checks or version pinning.

49257.8k5
100Critical
skills/higgsfield-marketplace-cards
higgsfield-ai
GitHubSkills.sh

The skill executes unverified remote code via shell piping and establishes unauthorized network connections, posing a critical risk of arbitrary command execution and data exfiltration.

49256.9k4
100Critical
skills/infsh-cli
halt-catch-fire
GitHubSkills.sh

This skill executes unverified remote code, performs unauthorized file exfiltration, and uses unpinned dependencies, posing a critical risk of arbitrary code execution and data theft.

57528.8k14
100Critical
hyperframes/media-use
heygen-com
GitHubSkills.sh

The skill executes unverified remote scripts via insecure shell piping and performs unauthorized network operations, creating a critical risk of arbitrary code execution and persistent system compromise.

32.3k24.2k6
100Critical
skills/tavily-search
tavily-ai
GitHubSkills.sh

The skill forces the execution of unverified remote scripts to install dependencies, creating a critical supply chain vulnerability that enables arbitrary code execution and potential credential harvesting.

37823.2k9
100Critical
skills/clerk-backend-api
clerk
GitHubSkills.sh

This skill executes unverified remote code, exposes sensitive API keys in logs, and provides an administrative bypass that renders its mandatory authorization controls ineffective.

5113.3k12
100Critical
skills/tavily-research
tavily-ai
GitHubSkills.sh

The skill mandates an insecure curl-to-bash installation pattern that executes unverified remote scripts with system privileges, creating a critical risk of arbitrary code execution.

37812.6k7
100Critical
skills/sandbox-sdk
cloudflare
GitHubSkills.sh

The skill executes arbitrary shell commands and promotes insecure supply chain practices by installing unverified, unpinned global dependencies while lacking proper documentation and licensing.

1.9k12.5k6
100Critical
skills/tavily-extract
tavily-ai
GitHubSkills.sh

The skill executes unverified, remote shell scripts via insecure piping, creating a critical supply chain vulnerability that allows for arbitrary code execution and system compromise.

3789.0k8
100Critical
skills/tavily-cli
tavily-ai
GitHubSkills.sh

The skill executes arbitrary code by piping unverified remote scripts directly into a shell, creating a critical vulnerability that allows for unauthorized system access and remote command execution.

3788.8k7
100Critical
awesome-copilot/aspire
github
GitHubSkills.sh

The skill facilitates supply chain attacks by executing unverified remote code and lacks necessary security declarations for its network access and tool usage, posing a critical risk.

35.3k8.7k10
100Critical
agent-skills/apify-actor-development
apify
GitHubSkills.sh

This skill executes unpinned, arbitrary code from the npm registry and performs unauthorized network and file operations without declaring necessary security constraints or tool permissions.

2.2k8.6k12
100Critical
awesome-copilot/containerize-aspnetcore
github
GitHubSkills.sh

This skill executes arbitrary shell commands and installs unverified packages while explicitly bypassing human oversight, creating critical risks of remote code execution and credential exfiltration.

35.3k8.6k9
100Critical
skills/tavily-crawl
tavily-ai
GitHubSkills.sh

The skill forces the execution of unverified remote scripts via insecure curl-to-bash patterns, exposing the agent to arbitrary code execution and supply chain attacks.

3788.6k9
100Critical
skills/tavily-map
tavily-ai
GitHubSkills.sh

The skill forces the installation of unverified third-party binaries and executes remote scripts directly in a shell without integrity checks, creating a critical risk of arbitrary code execution.

3788.3k8
100Critical
agent-skills/apify-actorization
apify
GitHubSkills.sh

The skill executes unverified remote code and performs unauthorized network and file operations without declaring necessary tool constraints, posing a critical risk of arbitrary command execution.

2.2k8.0k9
100Critical
skills/sandbox-agent
rivet-dev
GitHubSkills.sh

This malicious skill masquerades as an agent orchestrator to exfiltrate sensitive API keys, execute unverified remote code, and expose the host environment through insecure, unauthenticated network configurations.

178.0k15
100Critical
skills/tavily-dynamic-search
tavily-ai
GitHubSkills.sh

The skill executes arbitrary remote code by piping unverified scripts directly into a shell, bypassing security controls and creating a critical vulnerability for remote command execution.

3784.8k9
100Critical
skills/notion-cli
makenotion
GitHubSkills.sh

The skill executes arbitrary remote code via insecure curl-to-bash installation and lacks necessary tool declarations, creating a critical risk of unauthorized system access and remote command execution.

1254.0k7
100Critical
claude-plugins-official/writing-hookify-rules
anthropics
GitHubSkills.sh

The skill is malicious because it executes destructive shell or Java runtime commands, posing a critical risk to system integrity and security.

31.3k3.7k2
100Critical
resend-skills/resend-cli
resend
GitHubSkills.sh

This skill executes unverified remote code and performs unauthorized network operations while lacking necessary security constraints, creating significant risks for arbitrary command execution and large-scale spam abuse.

1343.4k11
100Critical
skills/agent-tools
halt-catch-fire
GitHubSkills.sh

This skill executes unverified remote code, exfiltrates local files without consent, and uses unpinned dependencies, creating a severe risk of arbitrary code execution and credential theft.

5502.7k15
100Critical
langsmith-skills/langsmith-trace
langchain-ai
GitHubSkills.sh

The skill executes unverified remote code via shell pipes and performs unauthorized network operations without declaring necessary tool permissions, creating a critical risk of arbitrary code execution.

1312.6k5
100Critical
langsmith-skills/langsmith-dataset
langchain-ai
GitHubSkills.sh

The skill executes unverified remote code via shell pipes, bypasses critical user confirmation prompts, and lacks necessary tool constraints, creating a high risk of arbitrary command execution and system compromise.

1312.5k8
100Critical
langsmith-skills/langsmith-evaluator
langchain-ai
GitHubSkills.sh

The skill executes unverified remote code via shell pipes and lacks necessary tool constraints, creating critical vulnerabilities for arbitrary code execution and unauthorized system access.

1312.5k6
100Critical
skills/apollo-mcp-server
apollographql
GitHubSkills.sh

The skill executes unverified remote code via insecure shell piping and uses unpinned package dependencies, creating critical vulnerabilities for arbitrary code execution and supply chain compromise.

902.0k8
100Critical
skills/sentry
openai
GitHubSkills.sh

This skill poses a critical security risk by executing arbitrary remote scripts, bypassing read-only constraints via unauthorized API calls, and performing unconstrained network and system operations without proper security declarations.

22.6k1.6k7
100Critical
pixijs-skills/pixijs-environments
pixijs
GitHubClaude CodeCursorSkills.sh

The skill performs unauthorized dynamic code execution and network access while using keyword stuffing to manipulate discovery, all while bypassing security constraints by failing to declare its tool surface.

2321.6k7
70High
skills/hf-cli
huggingface
GitHubSkills.sh

This skill facilitates arbitrary remote code execution, insecurely handles authentication tokens, and lacks necessary security constraints, creating significant risks for system compromise and unauthorized data access.

10.7k1.5k11
100Critical
skills/render-deploy
openai
GitHubSkills.sh

This skill facilitates remote code execution, mandates insecure credential handling, and uses deceptive social engineering to trick users into granting escalated permissions and executing unverified, external malicious payloads.

22.6k1.5k16
100Critical
knowledge-work-plugins/nextflow-development
anthropics
GitHubSkills.sh

The skill performs unauthorized remote code execution and network access while lacking declared tool constraints and essential documentation, posing a significant security risk through opaque, unverified runtime behavior.

22.2k1.4k9
100Critical
skills/rover
apollographql
GitHubSkills.sh

The skill executes unverified remote scripts directly into a shell and encourages insecure handling of API keys, creating significant risks for arbitrary code execution and credential exposure.

901.3k12
100Critical
antigravity-awesome-skills/gcp-cloud-run
sickn33
GitHubClaude CodeSkills.sh

This skill executes arbitrary commands, exposes hardcoded credentials, lacks necessary security declarations for network and tool access, and contains vulnerabilities to supply chain and cross-site scripting attacks.

41.2k1.2k10
100Critical
skills/vss-deploy-profile
nvidia
GitHubSkills.sh

The skill bypasses human-in-the-loop controls for infrastructure changes, insecurely handles sensitive API keys, and executes unconstrained network and system operations without declaring required tool permissions.

2.2k1.1k11
70High
agent-skills/clickhousectl-local-dev
clickhouse
GitHubSkills.sh

The skill performs unauthorized remote code execution and network access while bypassing security constraints by failing to declare its tool surface and capabilities.

4681.0k3
100Critical
skills/hsb-test
nvidia
GitHubSkills.sh

This skill executes unauthorized shell commands and systematically bypasses mandatory user confirmation protocols to perform potentially destructive actions without human oversight.

2.2k9954
100Critical
skills/hsb-app
nvidia
GitHubSkills.sh

This skill executes dangerous, unverified bash scripts via SSH while actively bypassing mandatory user confirmation, creating a high risk of command injection and unauthorized system manipulation.

2.2k9906
100Critical
skills/agent-tools
inference-sh
GitHubSkills.sh

This skill executes unverified remote code, exfiltrates local files, and uses opaque binaries to bypass security oversight while posing as a legitimate tool to harvest user credentials.

55098020
100Critical
agent-skills/clickhousectl-cloud-deploy
clickhouse
GitHubSkills.sh

The skill executes arbitrary remote code and insecurely manages sensitive credentials while bypassing security constraints by failing to declare its network and file system tool permissions.

4688685
100Critical
antigravity-awesome-skills/wordpress-penetration-testing
sickn33
GitHubClaude CodeSkills.sh

This skill functions as a malicious exploitation toolkit that instructs the agent to perform destructive SQL injections, exfiltrate credentials, and execute unauthorized reverse shells against target systems.

41.2k77521
100Critical
awesome-copilot/mcp-security-audit
github
GitHubSkills.sh

This skill is malicious, containing a reverse shell and unauthorized environment access, while also suffering from critical vulnerabilities including arbitrary file read, command injection, and unpinned dependency execution.

35.3k75611
100Critical
skills/nemoclaw-user-get-started
nvidia
GitHubSkills.sh

This skill executes unverified remote code, disables critical authentication mechanisms, leaks sensitive dashboard tokens, and performs unauthorized network and system operations without declaring necessary security constraints.

1.3k70410
100Critical
agents/cosmos-dbt-fusion
astronomer
GitHubSkills.sh

The skill executes arbitrary remote code from an external URL and performs unauthorized network and file operations without declaring necessary tool permissions, posing a critical remote execution risk.

3936956
100Critical
jules-skills/automate-github-issues
google-labs-code
GitHubSkills.sh

The skill facilitates remote code execution and prompt injection via untrusted GitHub issues while exposing sensitive API keys and bypassing security constraints through undeclared tool and network access.

726408
100Critical
skills/infsh-cli
inference-sh
GitHubSkills.sh

This skill masquerades as an AI app runner to perform unauthorized remote code execution, arbitrary file exfiltration, and credential harvesting via unpinned dependencies and opaque third-party CLI tools.

55063419
100Critical
Page 1 of 22