MondooMondoo
AI Agent Security
Skills
Log inGet Assessment

AI Agent Skill Check is a free AI agent skill security scanner by Mondoo. We scan skills across ClawHub, Skills.sh, GitHub, Claude Marketplace, and SkillsMP to detect prompt injection, credential theft, data exfiltration, agent impersonation, and 28 threat types before they reach your agents.

Mondoo

  • Vulnerability Management
  • Technology
  • Services

Solutions

  • Financial Services
  • Manufacturing
  • Healthcare

Resources

  • Blog
  • Skill Check
  • Documentation
  • GitHub

Company

  • About
  • Careers
  • Partners
  • Contact

Legal

  • Privacy
  • Terms
  • Imprint
MondooMondoo© 2026 Mondoo, Inc.

Skills

Browse, search, and filter AI agent skills across all registries.

Credential Theft
SkillAI AgentsSummaryStarsDownloadsFindingsRisk
tech-news-digest
dinstein
OpenClaw

The skill accesses sensitive environment variables and

238.0k4
40Medium
bria-ai
galbria
OpenClaw

The skill uses an unaudited external script, risking

41.7k4
100Critical
xcrawl-scrape
wykings
OpenClaw

This skill grants broad permissions, enabling system compromise, data

01.1k12
100Critical
awesome-copilot/arize-ai-provider-integration
github
GitHub

The skill handles sensitive API keys and environment variables

29.9k5805
100Critical
ai-skillhub
eeyan2025-art
OpenClaw

This skill allows arbitrary command injection

016318
100Critical
greenhelix-trading-bot-risk-service
mirni
OpenClaw

The skill deceptively claims not to execute

01043
100Critical
greenhelix-bot-arbitrage-framework
mirni
OpenClaw

This skill handles sensitive financial transactions and credentials, risking

0995
40Medium
github-bug-report
markma84
OpenClaw

The skill hardcodes a GitHub

0499
100Critical
acp-harness-delegation
chaoyang78
OpenClaw

The skill disables critical security controls, stores API

04114
100Critical
claude-ptt/whisper-setup
aaddrick
GitHubSkills.sh

The skill executes arbitrary code with root

2–6
100Critical