MondooMondoo
AI Agent Security
Skill Threat IntelligenceCLIFAQ
Log inGet Assessment

AI Agent Skill Check is a free AI agent skill security scanner by Mondoo. We scan skills across ClawHub, Skills.sh, GitHub, Claude Marketplace, and SkillsMP to detect prompt injection, credential theft, data exfiltration, agent impersonation, and 28 threat types before they reach your agents.

Mondoo

  • Vulnerability Management
  • Technology
  • Services

Solutions

  • Financial Services
  • Manufacturing
  • Healthcare

Resources

  • Blog
  • Skill Check CLI
  • Documentation
  • GitHub

Company

  • About
  • Careers
  • Partners
  • Contact

Legal

  • Privacy
  • Terms
  • Imprint
MondooMondoo© 2026 Mondoo, Inc.

Skills

Browse, search, and filter AI agent skills across all registries.

Credential Theft
SkillAI AgentsSummaryStarsInstallsFindingsRisk
skills/wrangler
cloudflare
GitHubSkills.sh

The skill executes unpinned packages and performs unauthorized network and file operations while accessing sensitive environment variables without declaring necessary tool constraints or security permissions.

1.9k24.0k5
40Medium
mcp-use/mcp-apps-builder
mcp-use
GitHubSkills.sh

The skill executes unpinned packages and accesses sensitive environment variables without defined tool constraints, creating significant supply chain risks and potential for unauthorized data exfiltration.

10.1k15.4k10
40Medium
claude-code/mcp-integration
anthropics
GitHubSkills.sh

The skill poses a security risk by accessing sensitive environment variables and fails to adhere to naming and licensing standards.

133.4k11.1k3
40Medium
claude-code/plugin-structure
anthropics
GitHubSkills.sh

The skill lacks a license, uses improper naming conventions, and poses a security risk by accessing sensitive environment variables without justification.

133.4k9.6k3
40Medium
mcp-use/mcp-builder
mcp-use
GitHubSkills.sh

The skill lacks defined tool constraints, executes unpinned packages, and accesses sensitive environment variables, creating significant supply chain and data exfiltration risks.

10.1k9.3k10
40Medium
mcp-use/chatgpt-app-builder
mcp-use
GitHubSkills.sh

This skill poses significant risks by executing unpinned packages, accessing sensitive environment variables, and performing unconstrained system operations while lacking transparency regarding its purpose and security controls.

10.1k9.1k11
40Medium
claude-plugins-official/mcp-integration
anthropics
GitHubSkills.sh

The skill poses a security risk by accessing sensitive environment variables, potentially exposing credentials and configuration data to unauthorized processes.

30.5k3.6k2
40Medium
claude-plugins-official/plugin-structure
anthropics
GitHubSkills.sh

The skill poses a security risk by accessing sensitive environment variables, potentially exposing critical system credentials and configuration data.

30.5k3.5k2
40Medium
skills/skill-scanner
getsentry
GitHubSkills.sh

The skill attempts to access sensitive credential files and perform unauthorized file writes while actively bypassing mandatory human oversight protocols.

8041.8k4
100Critical
agent-skills/aws-ami-builder
hashicorp
GitHubSkills.sh

The skill poses a security risk by attempting to access sensitive credential file paths, potentially leading to unauthorized exposure of AWS access keys and environment secrets.

6771.5k2
100Critical
antigravity-awesome-skills/gcp-cloud-run
sickn33
GitHubClaude CodeSkills.sh

This skill executes arbitrary commands, exposes hardcoded credentials, lacks necessary security declarations for network and tool access, and contains vulnerabilities to supply chain and cross-site scripting attacks.

41.2k1.2k10
100Critical
agent-skills/claimable-postgres
neondatabase
GitHubSkills.sh

The skill lacks defined tool constraints and network permissions while accessing sensitive environment variables, creating an unmonitored attack surface that risks unauthorized data exfiltration and system compromise.

711.1k5
40Medium
antigravity-awesome-skills/code-review-checklist
sickn33
GitHubClaude CodeSkills.sh

The skill exhibits unauthorized access to sensitive environment variables, posing a significant risk of credential exfiltration and data exposure.

41.2k9995
40Medium
knowledge-work-plugins/zoom-cobrowse-sdk
anthropics
GitHubSkills.sh

The skill exposes hardcoded credentials, lacks necessary security declarations for network and tool access, and provides insecure implementation instructions while failing to include critical documentation files.

21.4k98312
100Critical
awesome-copilot/arize-ai-provider-integration
github
GitHubSkills.sh

This skill impersonates a reputable brand while containing unauthorized code patterns that access sensitive environment variables, posing a significant risk of credential exfiltration.

35.3k9213
40Medium
awesome-copilot/arize-evaluator
github
GitHubSkills.sh

The skill accesses sensitive environment variables and executes arbitrary commands without declaring allowed tools, creating an unconstrained and high-risk attack surface for potential system compromise.

35.3k9173
40Medium
awesome-copilot/mcp-security-audit
github
GitHubSkills.sh

This skill is malicious, containing a reverse shell and unauthorized environment access, while also suffering from critical vulnerabilities including arbitrary file read, command injection, and unpinned dependency execution.

35.3k75611
100Critical
antigravity-awesome-skills/ethical-hacking-methodology
sickn33
GitHubClaude CodeSkills.sh

This skill facilitates unauthorized access and system compromise by providing automated exploitation, credential brute-forcing, and persistence mechanisms while lacking necessary security constraints on its tool execution surface.

41.2k66911
100Critical
agent-skills/auth0-express
auth0
GitHubSkills.sh

The skill exposes sensitive environment variables and performs unauthorized network and file operations without declaring necessary tool permissions or providing required documentation.

316666
40Medium
antigravity-awesome-skills/file-uploads
sickn33
GitHubClaude CodeSkills.sh

This skill performs unauthorized file system traversal and credential access while deceptively misrepresenting its high-risk operations as safe in the manifest.

41.2k6576
100Critical
antigravity-awesome-skills/kaizen
sickn33
GitHubClaude CodeSkills.sh

The skill performs unauthorized network communication and accesses sensitive environment variables while bypassing security constraints by failing to declare its tool surface or capabilities.

41.2k6455
40Medium
antigravity-awesome-skills/api-fuzzing-bug-bounty
sickn33
GitHubClaude CodeSkills.sh

This skill lacks necessary security constraints, performs unauthorized network and file access, contains SQL injection vulnerabilities, and promotes the execution of unverified third-party code.

41.2k5339
100Critical
antigravity-awesome-skills/ssh-penetration-testing
sickn33
GitHubClaude CodeSkills.sh

This skill is a malicious toolkit that automates unauthorized persistent access, credential theft, and lateral movement through SSH key injection, brute-forcing, and reverse shell establishment.

41.2k42722
100Critical
agent-skills/auth0-fastify-api
auth0
GitHubSkills.sh

The skill lacks declared tool constraints while accessing sensitive environment variables and performing unauthorized network operations, posing a significant risk of data exfiltration and arbitrary command execution.

314253
40Medium
antigravity-awesome-skills/linux-privilege-escalation
sickn33
GitHubClaude CodeSkills.sh

This skill is a malicious exploitation toolkit that facilitates unauthorized privilege escalation, credential theft, and persistent backdoor installation via reverse shells and unverified remote code execution.

41.2k41625
100Critical
antigravity-awesome-skills/firmware-analyst
sickn33
GitHubClaude CodeSkills.sh

The skill performs unauthorized file system access and hidden network operations while bypassing security constraints by failing to declare its tool usage and capabilities.

41.2k3696
100Critical
antigravity-awesome-skills/metasploit-framework
sickn33
GitHubClaude CodeSkills.sh

This skill functions as a malicious toolkit that provides instructions for credential harvesting, keylogging, persistence, and bypassing security controls to facilitate unauthorized system exploitation and surveillance.

41.2k36911
100Critical
antigravity-awesome-skills/privilege-escalation-methods
sickn33
GitHubClaude CodeSkills.sh

This skill functions as a malicious offensive toolkit that instructs the agent to perform domain-wide credential theft, privilege escalation, and persistence while actively bypassing security and defensive controls.

41.2k31819
100Critical
skills/agent-experience
browserbase
GitHubSkills.sh

This skill impersonates a known brand while exfiltrating sensitive environment variables and credential files through unauthorized network connections.

3.6k3074
100Critical
antigravity-awesome-skills/secrets-management
sickn33
GitHubClaude CodeSkills.sh

This skill performs unauthorized persistent code execution via git hooks, exfiltrates sensitive environment variables, and bypasses security constraints by executing undocumented network and file system operations.

41.2k2637
70High
antigravity-awesome-skills/posix-shell-pro
sickn33
GitHubClaude CodeSkills.sh

This skill lacks defined tool constraints and attempts to access sensitive credential files, posing a significant risk of unauthorized data exfiltration and system compromise.

41.2k25511
100Critical
design.md/typed-service-contracts
google-labs-code
GitHubSkills.sh

The skill poses a significant security risk by attempting to access sensitive credential file paths, indicating potential unauthorized data exfiltration.

16.0k2512
100Critical
jira-skill/jira-communication
netresearch
GitHubSkills.sh

The skill requests excessive workspace-wide write permissions and insecurely mandates storing sensitive Jira credentials in predictable local files vulnerable to exfiltration by malicious processes.

642383
100Critical
antigravity-awesome-skills/linux-shell-scripting
sickn33
GitHubClaude CodeSkills.sh

This skill exhibits dangerous patterns including credential exposure, unauthorized system enumeration, and unconstrained command execution, creating significant risks for lateral movement, data exfiltration, and system compromise.

41.2k1919
100Critical
varlock-claude-skill/varlock
wrsmith108
GitHubSkills.sh

The skill executes unverified remote scripts via shell pipes and uses insecure exec directives to handle sensitive credentials, creating critical command injection and credential exfiltration vulnerabilities.

2518512
100Critical
prisma-next/prisma-next-migrations
prisma
GitHubSkills.sh

The skill performs unauthorized access to sensitive environment variables and executes unconstrained system commands without declaring necessary tool permissions, posing a significant risk of data exfiltration and system compromise.

3811823
40Medium
prisma-next/prisma-next-contract
prisma
GitHubSkills.sh

The skill uses keyword stuffing to hijack queries, accesses sensitive environment variables, and executes unconstrained system commands, posing a significant risk of data exfiltration and unauthorized system access.

3811784
40Medium
prisma-next/prisma-next-quickstart
prisma
GitHubSkills.sh

The skill lacks defined tool constraints and improperly accesses sensitive environment variables, posing a significant risk of unauthorized data exfiltration and arbitrary command execution.

3811754
40Medium
antigravity-awesome-skills/shodan-reconnaissance
sickn33
GitHubClaude CodeSkills.sh

This skill exposes hardcoded credentials and executes unconstrained network and system commands without declaring necessary permissions, creating significant risks for unauthorized data exfiltration and system compromise.

41.2k1417
40Medium
antigravity-awesome-skills/burp-suite-testing
sickn33
GitHubClaude CodeSkills.sh

This skill contains critical vulnerabilities, including unauthorized access to credential files, SQL injection patterns, and path traversal flaws, posing a severe risk of data exfiltration and system compromise.

41.2k1396
100Critical
antigravity-awesome-skills/xss-html-injection
sickn33
GitHubClaude CodeSkills.sh

This skill functions as a malicious attack toolkit, providing ready-to-deploy phishing, keylogging, and exfiltration payloads while bypassing security controls and operating without declared tool constraints.

41.2k13117
100Critical
taches-cc-resources/create-mcp-servers
glittercowboy
GitHubSkills.sh

This skill lacks defined tool constraints, performs unauthorized persistence, and exposes sensitive credentials by instructing users to store API keys in insecure shell configuration files.

1.9k1297
70High
antigravity-awesome-skills/sqlmap-database-pentesting
sickn33
GitHubClaude CodeSkills.sh

This skill facilitates malicious activity by enabling automated mass-exploitation, SSRF, and OS-level command execution under the guise of database penetration testing.

41.2k12413
100Critical
antigravity-awesome-skills/devops-deploy
sickn33
GitHubClaude CodeSkills.sh

The skill lacks defined security constraints, performs unauthorized network and environment access, and uses insecure dependency management, creating significant risks for supply chain and data exfiltration attacks.

41.2k1207
40Medium
awesome-agent-skills/vscode-sftp-config
libukai
GitHubClaude CodeSkills.sh

The skill performs unauthorized file system access and network operations while bypassing security constraints by failing to declare its tool surface and network capabilities.

4.7k835
100Critical
antigravity-awesome-skills/file-path-traversal
sickn33
GitHubClaude CodeSkills.sh

This skill facilitates unauthorized access to sensitive system credentials and provides actionable instructions for exploitation while bypassing security constraints by executing undeclared network and file system operations.

41.2k8210
100Critical
claude-plugins/security-scanner
hiroro-work
GitHubSkills.sh

This skill masquerades as a security scanner but executes remote code, establishes reverse shells, and exfiltrates sensitive credentials from the host environment.

457511
100Critical
antigravity-awesome-skills/odoo-rpc-api
sickn33
GitHubClaude CodeSkills.sh

The skill contains hardcoded credentials and performs unauthorized network operations without declaring necessary tool permissions, creating significant risks for credential exposure and uncontrolled system access.

41.2k725
100Critical
Page 1 of 16