MondooMondoo
AI Agent Security
Skill Threat IntelligenceCLIFAQ
Log inGet Assessment

AI Agent Skill Check is a free AI agent skill security scanner by Mondoo. We scan skills across ClawHub, Skills.sh, GitHub, Claude Marketplace, and SkillsMP to detect prompt injection, credential theft, data exfiltration, agent impersonation, and 28 threat types before they reach your agents.

Mondoo

  • Vulnerability Management
  • Technology
  • Services

Solutions

  • Financial Services
  • Manufacturing
  • Healthcare

Resources

  • Blog
  • Skill Check CLI
  • Documentation
  • GitHub

Company

  • About
  • Careers
  • Partners
  • Contact

Legal

  • Privacy
  • Terms
  • Imprint
MondooMondoo© 2026 Mondoo, Inc.

Skills

Browse, search, and filter AI agent skills across all registries.

Command Execution
SkillAI AgentsSummaryStarsDownloadsFindingsRisk
workflow/workflow
vercel
GitHubSkills.sh

The skill actively promotes arbitrary code execution and command injection

2.0k2.0k8
100Critical
skills/agent-tools
tool-belt
GitHubClaude CodeSkills.sh

The skill allows remote code execution,

414–8
100Critical
skills/tavily-dynamic-search
tavily-ai
GitHubClaude CodeSkills.sh

This skill enables remote code execution via `curl | bash

2702.0k5
100Critical
skills/tavily-search
tavily-ai
GitHubClaude CodeSkills.sh

The Tavily search skill allows remote code execution and arbitrary file writes, enabling system compromise and data exfiltration.

27015.5k2
100Critical
skills/tavily-extract
tavily-ai
GitHubClaude CodeSkills.sh

The skill allows remote code execution via `curl

2705.9k6
100Critical
batterie-de-savoir/update
spm1001
GitHubClaude CodeSkills.sh

This skill executes arbitrary code and installs malicious packages via

2–10
100Critical
flash-list/agent-device
shopify
GitHubSkills.sh

The skill executes shell commands and mandates `adb` for

7.1k92
100Critical
second-brain-skills/para-manager
shestera
GitHubClaude CodeSkills.sh

The skill allows command injection and

014
100Critical
opc-skills/requesthunt
resciencelab
GitHubClaude CodeSkills.sh

This skill is dangerous as it can download and execute

8381.2k3
100Critical
model-deployment
pluginagentmarketplace
GitHubClaude CodeSkills.sh

The model deployment skill allows remote code execution and uses unpinned dependencies, posing significant supply chain risks.

252
100Critical
prelude-claude-plugin/nist
preludeorg
GitHubClaude CodeSkills.sh

This skill is highly vulnerable to command injection and

0–7
100Critical
overthink-plugins/generate
overthinkos
GitHubClaude CodeSkills.sh

This skill generates Containerfiles but introduces supply chain vulnerabilities

0–4
100Critical
overthink-plugins/layer
overthinkos
GitHubClaude CodeSkills.sh

This skill allows arbitrary command execution, privilege escalation

0–6
100Critical
harness-design/harness-design
zanwei
GitHubClaude CodeSkills.sh

This skill allows command injection, arbitrary

126
100Critical
prose/open-prose
openprose
GitHubClaude CodeCodexSkills.sh

This skill self-modifies the agent's memory

1.2k1.1k14
100Critical
skills/sentry
openai
GitHubSkills.sh

The skill enables remote code execution and command injection

18.3k9515
100Critical
skills/render-deploy
openai
GitHubSkills.sh

The skill downloads and executes remote code, allowing arbitrary code execution and potential system compromise.

18.3k9091
100Critical
ui-ux-pro-max-skill/ui-ux-pro-max
nextlevelbuilder
GitHubClaude CodeSkills.sh

The skill is vulnerable to command injection via user input and

74.5k148.3k3
100Critical
architecture-cowork-plugin/architecture-methodology
navraj007in
GitHubClaude CodeSkills.sh

This skill executes shell commands, handles sensitive API

2–9
100Critical
codex-collab/codex-collab
masuP9
GitHubClaude CodeSkills.sh

This skill allows arbitrary command execution and privilege escalation via user

2–6
100Critical
design-extract/extract-design
manavarya09
GitHubClaude CodeSkills.sh

The skill allows arbitrary command execution via user

2.2k1.1k3
100Critical
deepagentsjs/langsmith-trace
langchain-ai
GitHubSkills.sh

The skill downloads and executes remote code, and encourages risky inferences when environment variables are missing.

1.2k212
100Critical
ctf-skills/ctf-pwn
ljagiello
GitHubSkills.sh

This skill is an exploitation toolkit enabling arbitrary

1.9k3.0k9
100Critical
ctf-skills/ctf-misc
ljagiello
GitHubSkills.sh

This CTF skill details numerous

1.9k2.9k16
100Critical
spacemolt-docs/spacemolt
kongyo2
GitHubClaude CodeSkills.sh

The skill executes arbitrary remote code via `npx`,

0–8
100Critical
nano-banana-2-skill/nano-banana
kingbootoshi
GitHubClaude CodeSkills.sh

The skill executes arbitrary remote code from external sources

3684006
100Critical
langsmith-skills/langsmith-dataset
langchain-ai
GitHubClaude CodeSkills.sh

This skill executes arbitrary remote code, exfiltrates

1111.6k9
100Critical
langsmith-skills/langsmith-evaluator
langchain-ai
GitHubClaude CodeSkills.sh

The Langsmith Evaluator skill downloads and executes remote code, enabling arbitrary code

1111.6k1
100Critical
ilo/ilo
ilo-lang
GitHubClaude CodeSkills.sh

This skill enables arbitrary command execution, command injection

0–6
100Critical
adb-android-control
hah23255
GitHubClaude CodeSkills.sh

This skill grants an AI agent complete control over

1–24
100Critical
jules-skills/automate-github-issues
google-labs-code
GitHubSkills.sh

This skill enables arbitrary code execution, downloads remote scripts,

52–6
100Critical
awesome-copilot/winmd-api-search
github
GitHubSkills.sh

The skill executes local PowerShell scripts with user

32.2k5.4k4
100Critical
awesome-copilot/containerize-aspnetcore
github
GitHubSkills.sh

The skill generates Dockerfiles with multiple command injection vectors,

32.2k8.4k8
100Critical
skills/security-review
getsentry
GitHubClaude CodeSkills.sh

This skill enables arbitrary shell command execution and extensive file

6684.7k7
100Critical
sentry-python/security-review
getsentry
GitHubSkills.sh

This skill can execute arbitrary shell

2.2k186
100Critical
oh-my-agent/oma-dev-workflow
first-fluke
GitHubClaude CodeSkills.sh

The skill installs `mise` via `curl |

906911
100Critical
developing-genkit-dart
firebase
GitHubClaude CodeGemini CLICursorSkills.sh

This skill downloads and executes remote code, misrepresenting itself

24927.3k2
100Critical
agent-skills/developing-genkit-dart
firebase
GitHubClaude CodeGemini CLICursorSkills.sh

The skill enables remote code download and execution, allowing arbitrary code execution and potential compromise of the agent.

26840.8k1
100Critical
sulcus/openclaw-sulcus-skill
digitalforgeca
GitHubClaude CodeSkills.sh

The skill allows shell command execution, ex

0–7
100Critical
xreview/xreview
davidleitw
GitHubClaude CodeSkills.sh

The skill allows remote code execution, enables prompt injection

12–11
100Critical
claude-plugin/code-review
coderabbitai
GitHubClaude CodeSkills.sh

This skill performs remote code execution, ex

43133
100Critical
agent-skills/clickhousectl-local-dev
clickhouse
GitHubClaude CodeSkills.sh

The skill allows remote code execution and is vulnerable to command injection via unsanitized user input in `clickhousectl` commands.

4153362
100Critical
skills/clerk-backend-api
clerk
GitHubClaude CodeSkills.sh

The skill executes unverified remote code from

404.1k4
100Critical
skills/brightdata-cli
brightdata
GitHubClaude CodeSkills.sh

This skill enables remote code execution

1141.6k5
100Critical
brave-search-skills/bx
brave
GitHubClaude CodeSkills.sh

The skill enables remote code download and execution, posing a

125842
100Critical
agent-skills/github-navigator
arshia2114
GitHubClaude CodeSkills.sh

This skill grants broad `Bash(gh:*)`

0–9
100Critical
crabshell/verifying
ZipperBagCoffee
GitHubClaude CodeCodexSkills.sh

This skill allows arbitrary command execution and

1–15
100Critical
pix-ai-coding-assistant/exploits-search
Vulnetix
GitHubClaude CodeSkills.sh

This offensive security tool installs a CLI from external sources

4–7
100Critical
Page 1 of 3