MondooMondoo
AI Agent Security
Skill Threat IntelligenceCLIFAQ
Log inGet Assessment

AI Agent Skill Check is a free AI agent skill security scanner by Mondoo. We scan skills across ClawHub, Skills.sh, GitHub, Claude Marketplace, and SkillsMP to detect prompt injection, credential theft, data exfiltration, agent impersonation, and 28 threat types before they reach your agents.

Mondoo

  • Vulnerability Management
  • Technology
  • Services

Solutions

  • Financial Services
  • Manufacturing
  • Healthcare

Resources

  • Blog
  • Skill Check CLI
  • Documentation
  • GitHub

Company

  • About
  • Careers
  • Partners
  • Contact

Legal

  • Privacy
  • Terms
  • Imprint
MondooMondoo© 2026 Mondoo, Inc.

Skills

Browse, search, and filter AI agent skills across all registries.

Credential Theft
SkillAI AgentsSummaryStarsDownloadsFindingsRisk
claude-nginx-hardening/nginx-hardening
trumb
GitHubClaude CodeSkills.sh

The skill accesses credential files, is vulnerable to SSRF

1–9
100Critical
redhat-docs-agent-tools/docs-workflow-jira-ready
redhat-documentation
GitHubClaude CodeSkills.sh

The skill is vulnerable to shell command injection via unsan

15–5
100Critical
ctf-skills/ctf-misc
ljagiello
GitHubSkills.sh

This CTF skill details numerous

1.9k2.9k16
100Critical
gh-aw-firewall/awf-skill
github
GitHubSkills.sh

This skill, despite claiming security, grants agents root

661017
100Critical
awesome-copilot/arize-ai-provider-integration
github
GitHubSkills.sh

The skill allows local file exfiltration and

32.2k7725
100Critical
clickhouse/review
clickhouse
GitHubSkills.sh

The skill permits arbitrary command execution, exfiltr

47.2k84
100Critical
skills/agentix-ceo
agentix-cloud
GitHubSkills.sh

The skill accesses sensitive environment variables,

0–14
100Critical
claude-ptt/whisper-setup
aaddrick
GitHubSkills.sh

The skill executes arbitrary code with root

2–6
100Critical
xcrawl-scrape
wykings
OpenClaw

This skill grants broad permissions, enabling system compromise, data

01.1k12
100Critical
news-summarizer
terrycarter1985
OpenClaw

The news summarizer accesses the `$OPENAI_API_KEY`, posing a risk if the agent's environment is compromised.

01042
100Critical
openclaw-omni-expert
thinkbugs
OpenClaw

This skill provides full remote control, handles credentials insecurely

09719
100Critical
heleni-maintenance
netanel-abergel
OpenClaw

The skill silently exfiltrates the

08717
100Critical
greenhelix-trading-bot-risk-service
mirni
OpenClaw

The skill deceptively claims not to execute

01043
100Critical
greenhelix-agent-interoperability-bridge
mirni
OpenClaw

The skill autonomously executes financial transactions across nine protocols without

014123
100Critical
github-bug-report
markma84
OpenClaw

The skill hardcodes a GitHub

0499
100Critical
kairoa-cli
luduoxin
OpenClaw

This skill facilitates remote code execution, extensive network reconnaissance,

07517
100Critical
database-migration-manager
llcsamih
OpenClaw

This database migration skill poses high risks due to extensive

0877
100Critical
roster
kleberbaum
OpenClaw

The skill has critical command injection vulnerabilities, allowing

08707
100Critical
surf
hughzhou-gif
OpenClaw

The skill allows arbitrary shell command execution, enabling supply chain

023912
100Critical
bria-ai
galbria
OpenClaw

The skill uses an unaudited external script, risking

41.7k4
100Critical
ai-skillhub
eeyan2025-art
OpenClaw

The skill is riddled with command injection vulnerabilities, exposing sensitive

018918
100Critical
acp-harness-delegation
chaoyang78
OpenClaw

The skill disables critical security controls, stores API

04114
100Critical
safe-evolver
confidentkai
OpenClaw

The skill autonomously modifies agent behavior, allowing arbitrary

112112
100Critical
minimax-token-plan-monitor
bbzhi177
OpenClaw

This skill stores plaintext credentials, executes arbitrary

014410
100Critical
run-test-plan
anderskev
OpenClaw

The skill executes arbitrary commands and exfiltrates data from

07815
100Critical
greenhelix-bot-arbitrage-framework
mirni
OpenClaw

This skill handles sensitive financial transactions and credentials, risking

0995
40Medium
tech-news-digest
dinstein
OpenClaw

The skill accesses sensitive environment variables and

238.0k4
40Medium