MondooMondoo
AI Agent Security
Skill Threat IntelligenceCLIFAQ
Log inGet Assessment

AI Agent Skill Check is a free AI agent skill security scanner by Mondoo. We scan skills across ClawHub, Skills.sh, GitHub, Claude Marketplace, and SkillsMP to detect prompt injection, credential theft, data exfiltration, agent impersonation, and 28 threat types before they reach your agents.

Mondoo

  • Vulnerability Management
  • Technology
  • Services

Solutions

  • Financial Services
  • Manufacturing
  • Healthcare

Resources

  • Blog
  • Skill Check CLI
  • Documentation
  • GitHub

Company

  • About
  • Careers
  • Partners
  • Contact

Legal

  • Privacy
  • Terms
  • Imprint
MondooMondoo© 2026 Mondoo, Inc.

Skills

Browse, search, and filter AI agent skills across all registries.

Credential Theft
SkillAI AgentsSummaryStarsInstallsFindingsRisk
skills/wrangler
cloudflare
GitHubSkills.sh

The skill executes unpinned packages and performs unauthorized network and file operations while accessing sensitive environment variables without declaring necessary tool constraints or security permissions.

2.0k26.8k5
40Medium
mcp-use/mcp-apps-builder
mcp-use
GitHubSkills.sh

The skill executes unpinned packages and accesses sensitive environment variables without defined tool constraints, creating significant supply chain risks and potential for unauthorized data exfiltration.

10.1k15.4k10
40Medium
claude-code/mcp-integration
anthropics
GitHubSkills.sh

The skill violates naming conventions, lacks a license, and poses a significant security risk by accessing sensitive environment variables without justification.

135.0k11.5k3
40Medium
claude-code/plugin-structure
anthropics
GitHubSkills.sh

The skill violates naming conventions, lacks a license, and improperly accesses sensitive environment variables, posing a significant risk of credential exfiltration.

135.0k9.9k3
40Medium
mcp-use/mcp-builder
mcp-use
GitHubSkills.sh

The skill lacks defined tool constraints, executes unpinned packages, and accesses sensitive environment variables, creating significant supply chain and data exfiltration risks.

10.1k9.3k10
40Medium
mcp-use/chatgpt-app-builder
mcp-use
GitHubSkills.sh

This skill poses significant risks by executing unpinned packages, accessing sensitive environment variables, and performing unconstrained system operations while lacking transparency regarding its purpose and security controls.

10.1k9.1k11
40Medium
claude-plugins-official/mcp-integration
anthropics
GitHubSkills.sh

The skill poses a security risk by accessing sensitive environment variables, potentially exposing credentials and configuration data to unauthorized processes.

31.3k3.7k2
40Medium
claude-plugins-official/plugin-structure
anthropics
GitHubSkills.sh

The skill poses a security risk by accessing sensitive environment variables, potentially exposing critical system credentials and configuration data.

31.3k3.6k2
40Medium
skills/skill-scanner
getsentry
GitHubSkills.sh

The skill attempts to access sensitive credential files and perform unauthorized file writes while actively bypassing mandatory human oversight protocols.

8041.8k4
100Critical
agent-skills/first-flag
launchdarkly
GitHubSkills.sh

The skill exposes hardcoded credentials, executes unpinned packages, and performs unauthorized network and file operations without declaring necessary tool constraints, creating significant security and supply chain risks.

191.7k5
100Critical
agent-skills/aws-ami-builder
hashicorp
GitHubSkills.sh

The skill poses a security risk by attempting to access sensitive credential file paths, potentially leading to unauthorized exposure of AWS access keys and environment secrets.

6771.5k2
100Critical
antigravity-awesome-skills/gcp-cloud-run
sickn33
GitHubClaude CodeSkills.sh

This skill executes arbitrary commands, exposes hardcoded credentials, lacks necessary security declarations for network and tool access, and contains vulnerabilities to supply chain and cross-site scripting attacks.

41.2k1.2k10
100Critical
knowledge-work-plugins/zoom-cobrowse-sdk
anthropics
GitHubSkills.sh

The skill contains hardcoded credentials, lacks necessary tool and network constraints, uses insecure dependency management, and references missing documentation, creating significant security and supply chain risks.

22.2k1.1k11
100Critical
agent-skills/claimable-postgres
neondatabase
GitHubSkills.sh

The skill lacks defined tool constraints and network permissions while accessing sensitive environment variables, creating an unmonitored attack surface that risks unauthorized data exfiltration and system compromise.

711.1k5
40Medium
skills/launch-nemo-rl
nvidia
GitHubSkills.sh

The skill exhibits suspicious behavior by attempting to access sensitive credential files while simultaneously initiating unauthorized network connections, indicating a high risk of data exfiltration.

2.2k1.1k2
100Critical
skills/vss-deploy-dense-captioning
nvidia
GitHubSkills.sh

The skill insecurely exfiltrates sensitive environment variables via network commands and lacks necessary tool declarations, creating an unconstrained and high-risk attack surface for credential theft.

2.2k1.1k8
100Critical
antigravity-awesome-skills/code-review-checklist
sickn33
GitHubClaude CodeSkills.sh

The skill exhibits unauthorized access to sensitive environment variables, posing a significant risk of credential exfiltration and data exposure.

41.2k9995
40Medium
awesome-copilot/arize-ai-provider-integration
github
GitHubSkills.sh

This skill impersonates a reputable brand while containing unauthorized code patterns that access sensitive environment variables, posing a significant risk of credential exfiltration.

35.3k9213
40Medium
awesome-copilot/arize-evaluator
github
GitHubSkills.sh

The skill accesses sensitive environment variables and executes arbitrary commands without declaring allowed tools, creating an unconstrained and high-risk attack surface for potential system compromise.

35.3k9173
40Medium
skills/tao-run-on-kubernetes
nvidia
GitHubSkills.sh

The skill is insecure due to unauthorized file system access, potential command injection vulnerabilities, unpinned package installations, and the use of undocumented file write operations.

2.2k8974
100Critical
skills/tao-train-depth-anything-v2
nvidia
GitHubSkills.sh

The skill attempts unauthorized access to sensitive credential files and performs unlisted file write operations while relying on external, unverified documentation, posing significant data exfiltration and integrity risks.

2.2k8913
100Critical
skills/tao-train-foundation-stereo
nvidia
GitHubSkills.sh

The skill attempts unauthorized access to sensitive credential files and performs unlisted file write operations while relying on external, unverified documentation references that pose a supply chain risk.

2.2k8913
100Critical
awesome-copilot/mcp-security-audit
github
GitHubSkills.sh

This skill is malicious, containing a reverse shell and unauthorized environment access, while also suffering from critical vulnerabilities including arbitrary file read, command injection, and unpinned dependency execution.

35.3k75611
100Critical
agent-skills/auth0-express
auth0
GitHubSkills.sh

The skill facilitates cross-site scripting through unsanitized input, exposes sensitive environment variables, and performs unauthorized network operations without declaring necessary tool permissions or security constraints.

377279
100Critical
antigravity-awesome-skills/ethical-hacking-methodology
sickn33
GitHubClaude CodeSkills.sh

This skill facilitates unauthorized access and system compromise by providing automated exploitation, credential brute-forcing, and persistence mechanisms while lacking necessary security constraints on its tool execution surface.

41.2k66911
100Critical
antigravity-awesome-skills/file-uploads
sickn33
GitHubClaude CodeSkills.sh

This skill performs unauthorized file system traversal and credential access while deceptively misrepresenting its high-risk operations as safe in the manifest.

41.2k6576
100Critical
antigravity-awesome-skills/kaizen
sickn33
GitHubClaude CodeSkills.sh

The skill performs unauthorized network communication and accesses sensitive environment variables while bypassing security constraints by failing to declare its tool surface or capabilities.

41.2k6455
40Medium
antigravity-awesome-skills/api-fuzzing-bug-bounty
sickn33
GitHubClaude CodeSkills.sh

This skill lacks necessary security constraints, performs unauthorized network and file access, contains SQL injection vulnerabilities, and promotes the execution of unverified third-party code.

41.2k5339
100Critical
agent-skills/auth0-fastify-api
auth0
GitHubSkills.sh

The skill lacks declared tool constraints while accessing sensitive environment variables and performing unauthorized network operations, posing a significant risk of data exfiltration and arbitrary command execution.

374863
40Medium
skills/jetson-flash-image
nvidia
GitHubSkills.sh

The skill lacks defined tool constraints, attempts to access sensitive credential files, and relies on external, unverified documentation, creating significant risks for unauthorized system access and supply chain compromise.

2.2k4445
100Critical
skills/jetson-print-bsp-info
nvidia
GitHubSkills.sh

The skill accesses sensitive credential files and executes unauthorized system commands without declaring necessary tool constraints, posing a significant risk of credential theft and arbitrary code execution.

2.2k4362
100Critical
antigravity-awesome-skills/ssh-penetration-testing
sickn33
GitHubClaude CodeSkills.sh

This skill is a malicious toolkit that automates unauthorized persistent access, credential theft, and lateral movement through SSH key injection, brute-forcing, and reverse shell establishment.

41.2k42722
100Critical
antigravity-awesome-skills/linux-privilege-escalation
sickn33
GitHubClaude CodeSkills.sh

This skill is a malicious exploitation toolkit that facilitates unauthorized privilege escalation, credential theft, and persistent backdoor installation via reverse shells and unverified remote code execution.

41.2k41625
100Critical
antigravity-awesome-skills/firmware-analyst
sickn33
GitHubClaude CodeSkills.sh

The skill performs unauthorized file system access and hidden network operations while bypassing security constraints by failing to declare its tool usage and capabilities.

41.2k3696
100Critical
antigravity-awesome-skills/metasploit-framework
sickn33
GitHubClaude CodeSkills.sh

This skill functions as a malicious toolkit that provides instructions for credential harvesting, keylogging, persistence, and bypassing security controls to facilitate unauthorized system exploitation and surveillance.

41.2k36911
100Critical
antigravity-awesome-skills/privilege-escalation-methods
sickn33
GitHubClaude CodeSkills.sh

This skill functions as a malicious offensive toolkit that instructs the agent to perform domain-wide credential theft, privilege escalation, and persistence while actively bypassing security and defensive controls.

41.2k31819
100Critical
skills/agent-experience
browserbase
GitHubSkills.sh

This skill impersonates a known brand while exfiltrating sensitive environment variables and credential files through unauthorized network connections.

3.6k3074
100Critical
antigravity-awesome-skills/secrets-management
sickn33
GitHubClaude CodeSkills.sh

This skill performs unauthorized persistent code execution via git hooks, exfiltrates sensitive environment variables, and bypasses security constraints by executing undocumented network and file system operations.

41.2k2637
70High
antigravity-awesome-skills/posix-shell-pro
sickn33
GitHubClaude CodeSkills.sh

This skill lacks defined tool constraints and attempts to access sensitive credential files, posing a significant risk of unauthorized data exfiltration and system compromise.

41.2k25511
100Critical
design.md/typed-service-contracts
google-labs-code
GitHubSkills.sh

The skill poses a significant security risk by attempting to access sensitive credential file paths, indicating potential unauthorized data exfiltration.

16.0k2512
100Critical
jira-skill/jira-communication
netresearch
GitHubSkills.sh

The skill requests excessive workspace-wide write permissions and insecurely mandates storing sensitive Jira credentials in predictable local files vulnerable to exfiltration by malicious processes.

642383
100Critical
antigravity-awesome-skills/linux-shell-scripting
sickn33
GitHubClaude CodeSkills.sh

This skill exhibits dangerous patterns including credential exposure, unauthorized system enumeration, and unconstrained command execution, creating significant risks for lateral movement, data exfiltration, and system compromise.

41.2k1919
100Critical
varlock-claude-skill/varlock
wrsmith108
GitHubSkills.sh

The skill executes unverified remote scripts via shell pipes and uses insecure exec directives to handle sensitive credentials, creating critical command injection and credential exfiltration vulnerabilities.

2518512
100Critical
prisma-next/prisma-next-migrations
prisma
GitHubSkills.sh

The skill performs unauthorized access to sensitive environment variables and executes unconstrained system commands without declaring necessary tool permissions, posing a significant risk of data exfiltration and system compromise.

3811823
40Medium
prisma-next/prisma-next-contract
prisma
GitHubSkills.sh

The skill uses keyword stuffing to hijack queries, accesses sensitive environment variables, and executes unconstrained system commands, posing a significant risk of data exfiltration and unauthorized system access.

3811784
40Medium
prisma-next/prisma-next-quickstart
prisma
GitHubSkills.sh

The skill lacks defined tool constraints and improperly accesses sensitive environment variables, posing a significant risk of unauthorized data exfiltration and arbitrary command execution.

3811754
40Medium
antigravity-awesome-skills/shodan-reconnaissance
sickn33
GitHubClaude CodeSkills.sh

This skill exposes hardcoded credentials and executes unconstrained network and system commands without declaring necessary permissions, creating significant risks for unauthorized data exfiltration and system compromise.

41.2k1417
40Medium
antigravity-awesome-skills/burp-suite-testing
sickn33
GitHubClaude CodeSkills.sh

This skill contains critical vulnerabilities, including unauthorized access to credential files, SQL injection patterns, and path traversal flaws, posing a severe risk of data exfiltration and system compromise.

41.2k1396
100Critical
Page 1 of 17