MondooMondoo
AI Agent Security
Skill Threat IntelligenceCLIFAQ
Log inGet Assessment

AI Agent Skill Check is a free AI agent skill security scanner by Mondoo. We scan skills across ClawHub, Skills.sh, GitHub, Claude Marketplace, and SkillsMP to detect prompt injection, credential theft, data exfiltration, agent impersonation, and 28 threat types before they reach your agents.

Mondoo

  • Vulnerability Management
  • Technology
  • Services

Solutions

  • Financial Services
  • Manufacturing
  • Healthcare

Resources

  • Blog
  • Skill Check CLI
  • Documentation
  • GitHub

Company

  • About
  • Careers
  • Partners
  • Contact

Legal

  • Privacy
  • Terms
  • Imprint
MondooMondoo© 2026 Mondoo, Inc.

Skills

Browse, search, and filter AI agent skills across all registries.

Data Exfiltration
SkillAI AgentsSummaryStarsInstallsFindingsRisk
skills/claude-api
anthropics
GitHubSkills.sh

This skill performs unauthorized network exfiltration, mandates vendor lock-in by hijacking model selection, and hides its outbound communication capabilities by failing to declare required network permissions in the manifest.

153.0k41.5k5
40Medium
skills/expo-api-routes
expo
GitHubSkills.sh

This skill facilitates SSRF and data exfiltration by allowing unvalidated user input in network requests, exposes sensitive environment variables, uses insecure CORS policies, and lacks necessary security capability declarations.

2.1k33.9k13
100Critical
web-access/web-access
eze-is
GitHubSkills.sh

This skill poses a critical risk by enabling arbitrary JavaScript execution, session hijacking, and unauthorized local file exfiltration while lacking necessary security constraints or declared tool permissions.

7.7k12.3k9
70High
skills/security-review
getsentry
GitHubSkills.sh

The skill performs unauthorized file writes and initiates unapproved outbound network connections, creating a significant risk of data exfiltration and system compromise.

8048.2k3
70High
awesome-copilot/flowstudio-power-automate-mcp
github
GitHubSkills.sh

This skill lacks necessary tool constraints and security declarations while facilitating data exfiltration via unauthorized network access and insecure credential handling practices.

35.3k4.0k10
40Medium
skills/turnstile-spin
cloudflare
GitHubSkills.sh

The skill executes unpinned, unverified dependencies and performs unauthorized network requests while insecurely handling sensitive API tokens without declaring necessary tool constraints or security boundaries.

1.9k3.0k8
40Medium
workflow/workflow
vercel
GitHubSkills.sh

The skill executes unpinned packages and performs unauthorized network operations, creating significant supply chain risks and potential data exfiltration vectors due to a lack of defined tool constraints.

2.1k2.8k5
40Medium
antigravity-awesome-skills/wordpress-penetration-testing
sickn33
GitHubClaude CodeSkills.sh

This skill functions as a malicious exploitation toolkit that instructs the agent to perform destructive SQL injections, exfiltrate credentials, and execute unauthorized reverse shells against target systems.

41.2k77521
100Critical
agent-skills/anki-connect
intellectronica
GitHubClaude CodeSkills.sh

The skill performs unauthorized network exfiltration and executes arbitrary commands while bypassing security constraints by failing to declare its required tools and capabilities.

2735845
40Medium
skills/use-runway-api
runwayml
GitHubSkills.sh

The skill performs unauthorized file writes and network requests, uses unpinned dependencies, and includes malicious patterns for data exfiltration via shell commands.

551515
70High
sentry-skills/security-review
getsentry
GitHubSkills.sh

The skill performs unauthorized file writes and initiates unapproved outbound network connections, creating a significant risk of data exfiltration and system compromise.

804633
70High
antigravity-awesome-skills/expo-api-routes
sickn33
GitHubClaude CodeSkills.sh

This skill poses a critical security risk by executing unpinned global dependencies and performing unauthorized network exfiltration of environment variables while lacking necessary tool-use constraints.

41.2k488
100Critical
antigravity-awesome-skills/claude-api
sickn33
GitHubClaude CodeSkills.sh

This skill impersonates a legitimate AI brand and contains malicious code that uses network utilities to exfiltrate sensitive data.

41.2k403
40Medium
awesome-supply-chain/supply-chain-automation
kishorkukreja
GitHubClaude CodeSkills.sh

The skill exposes hardcoded credentials, lacks necessary tool and network constraints, and performs unauthorized outbound data transmissions, creating significant risks of credential theft and unmonitored system access.

32338
70High
skills/indykite-authzen-kbac
indykite
GitHubSkills.sh

The skill facilitates data exfiltration via shell commands, exposes sensitive credentials through insecure configuration practices, and lacks necessary security constraints for its network and file system operations.

03112
40Medium
skills/indykite-ciq-create-node
indykite
GitHubSkills.sh

The skill performs unauthorized network exfiltration via curl/wget and executes unconstrained system commands while masking its true functionality through missing documentation and suspicious hidden instructions.

03113
40Medium
skills/indykite-ciq-add-property
indykite
GitHubSkills.sh

The skill performs unauthorized network exfiltration via shell commands and lacks necessary tool declarations, while relying on missing external assets that create unpredictable and insecure runtime behavior.

03013
40Medium
skills/indykite-ciq-add-relationship-property
indykite
GitHubSkills.sh

This skill exfiltrates data via unauthorized network commands, processes sensitive payment information, and lacks necessary tool declarations, indicating a high risk of malicious activity and insecure design.

03014
70High
skills/indykite-ciq-create-node-with-link
indykite
GitHubSkills.sh

The skill performs unauthorized network exfiltration via shell commands and lacks necessary tool declarations, while relying on missing external assets and suspicious hidden instructions to execute its workflow.

03013
40Medium
skills/indykite-ciq-create-relationship
indykite
GitHubSkills.sh

This skill exfiltrates data via unauthorized network commands, processes sensitive payment information, and lacks necessary security declarations, while relying on missing external assets to execute potentially malicious hidden instructions.

03014
70High
skills/indykite-ciq-delete
indykite
GitHubSkills.sh

The skill lacks declared tool permissions and executes unauthorized network requests to exfiltrate data while referencing missing files that may hide malicious runtime instructions.

03013
40Medium
skills/indykite-ciq-read
indykite
GitHubSkills.sh

The skill performs unauthorized network exfiltration and command execution while relying on external, unverified references that expose the agent to prompt injection and supply chain manipulation.

03014
40Medium
claude-code-plugins-plus-skills/apollo-security-basics
jeremylongshore
GitHubSkills.sh

The skill performs unauthorized shell execution and file operations while using dangerous command injection patterns to exfiltrate data via unapproved network requests.

2.4k2710
70High
claude-code-plugins-plus-skills/clay-common-errors
jeremylongshore
GitHubSkills.sh

The skill executes dynamic code via eval, performs unauthorized outbound network requests, and relies on unverified dependencies, creating significant risks for code injection and sensitive data exfiltration.

2.4k267
100Critical
claude-code-plugins-plus-skills/exa-debug-bundle
jeremylongshore
GitHubSkills.sh

This skill performs unauthorized shell execution, file manipulation, and network exfiltration while attempting to bypass security manifests by fingerprinting the host environment and piping data to external servers.

2.4k268
70High
claude-code-plugins-plus-skills/clay-rate-limits
jeremylongshore
GitHubSkills.sh

The skill lacks retry limits for rate-limited requests, creating a resource exhaustion vulnerability, and includes unrestricted outbound network access that could facilitate unauthorized data exfiltration.

2.4k255
40Medium
claude-code-plugins-plus-skills/juicebox-rate-limits
jeremylongshore
GitHubSkills.sh

The skill uses insecure global variables for authentication and URL construction, enabling credential leakage and data exfiltration, while employing deceptive tagging to hijack agent activation.

2.4k257
40Medium
claude-code-plugins-plus-skills/juicebox-webhooks-events
jeremylongshore
GitHubSkills.sh

The skill exposes a persistent, unvalidated webhook server that facilitates SSRF attacks and exfiltrates environment secrets to external network sinks, significantly exceeding its authorized tool permissions.

2.4k2513
100Critical
claude-code-plugins-plus-skills/posthog-data-handling
jeremylongshore
GitHubSkills.sh

This skill exposes high-privilege API keys, facilitates data exfiltration, and contains critical vulnerabilities including SQL injection and SSRF due to improper input sanitization and insecure network request handling.

2.4k2521
70High
claude-code-plugins-plus-skills/instantly-upgrade-migration
jeremylongshore
GitHubSkills.sh

This skill exfiltrates sensitive environment variables via unauthorized network requests and contains an infinite loop pattern that poses a significant risk of resource exhaustion and denial of service.

2.4k246
100Critical
claude-code-plugins-plus-skills/sentry-policy-guardrails
jeremylongshore
GitHubSkills.sh

The skill insecurely handles sensitive credentials by exposing them in command arguments and exfiltrating them over the network, while also introducing command injection risks through unvalidated API responses.

2.4k248
70High
agent-skills/zeabur-template-backup
zeabur
GitHubClaude CodeCodexSkills.sh

The skill lacks necessary tool constraints, executes unverified shell commands via pipe-to-curl, and uses unpinned dependencies, creating significant risks for remote code execution and supply chain compromise.

36248
40Medium
claude-code-plugins-plus-skills/sentry-rate-limits
jeremylongshore
GitHubSkills.sh

The skill insecurely handles sensitive Sentry authentication tokens by passing them through unquoted environment variables into network commands, leading to potential credential exfiltration and command injection vulnerabilities.

2.4k236
70High
css-skills/css-hover-effects
dabaibian
GitHubSkills.sh

This skill hides malicious content using CSS and performs unauthorized network exfiltration and command execution while bypassing security constraints by failing to declare its required tools.

5196
70High
sentry-python/security-review
getsentry
GitHubSkills.sh

The skill performs unauthorized file system modifications and initiates unapproved outbound network connections, creating a significant risk of data exfiltration and system compromise.

2.2k193
70High
ai-plugin/debugging-signals-pipeline
posthog
GitHubSkills.sh

The skill performs unauthorized network exfiltration via hidden curl/wget commands while bypassing security constraints by failing to declare its tool usage or network capabilities.

54135
40Medium
sandbox-sdk/sandbox-bridge
cloudflare
GitHubSkills.sh

The skill performs unauthorized host enumeration and network exfiltration while bypassing security constraints by failing to declare its tool usage and network capabilities.

1.0k115
40Medium
clickhouse/keeper-stress-analysis
clickhouse
GitHubSkills.sh

The skill performs unauthorized network connections and utilizes pipe-to-curl commands to exfiltrate data, posing a critical security risk despite the missing license.

48.2k53
40Medium
serpapi-claude-plugin/search
serpapi
GitHubSkills.sh

The skill insecurely exposes API keys via shell commands, performs unauthorized HTTP exfiltration, and is vulnerable to prompt injection through attacker-controlled local JSON configuration files.

12510
100Critical
clickhouse/close-flaky-issues
clickhouse
GitHubSkills.sh

The skill uses fabricated user authorization to exfiltrate data via unauthorized network connections and pipe commands, posing a severe security risk to the host environment.

48.2k44
40Medium
openclaw/trello
firecrawl
GitHubSkills.sh

The skill insecurely exposes sensitive Trello credentials via shell commands, facilitates command injection, and performs unauthorized network exfiltration while lacking necessary tool and capability declarations.

347
100Critical
claude-code-plugins-plus-skills/abridge-local-dev-loop
jeremylongshore
GitHubSkills.sh

The skill uses insecure dynamic code execution and lacks validation for FHIR server endpoints, creating significant risks of code injection, unauthorized data exfiltration, and clinical database corruption.

2.4k28
100Critical
power-cat-skills/eval-generator-code-app
microsoft
GitHubSkills.sh

The skill executes arbitrary code via dynamic evaluation and shell commands, performs unauthorized file system traversal, and initiates unmonitored network requests, creating a severe risk of remote code execution.

21215
100Critical
pubchem-mcp-server/api-context
cyanheads
GitHubClaude CodeCodexSkills.sh

The skill executes arbitrary code via eval(), lacks necessary tool constraints, and performs unauthorized outbound network requests, creating significant risks for code injection and data exfiltration.

9110
100Critical
wsh/core
deepgram
GitHubSkills.sh

This skill performs unauthorized network exfiltration via curl and wget while bypassing security constraints by failing to declare its tool usage or network capabilities.

516
40Medium
warden-skills/vercel-deepsec
getsentry
GitHubSkills.sh

The skill contains critical vulnerabilities including SQL injection, command execution, and SSRF, which enable unauthorized data exfiltration and internal network access, contradicting its stated purpose of secure code analysis.

56110
100Critical
claude-code-plugins-plus-skills/algolia-debug-bundle
jeremylongshore
GitHubSkills.sh

The skill performs unauthorized file writes, accesses sensitive environment variables, and uses network requests to exfiltrate data, violating security policies by bypassing restricted tool permissions.

2.4k16
70High
claude-code-plugins-plus-skills/bamboohr-upgrade-migration
jeremylongshore
GitHubSkills.sh

The skill insecurely exposes the BAMBOOHR_API_KEY in process lists and exfiltrates sensitive credentials to an external network endpoint via unauthenticated shell commands.

2.4k15
70High
Page 1 of 6