MondooMondoo
AI Agent Security
Skill Threat IntelligenceCLIFAQ
Log inGet Assessment

AI Agent Skill Check is a free AI agent skill security scanner by Mondoo. We scan skills across ClawHub, Skills.sh, GitHub, Claude Marketplace, and SkillsMP to detect prompt injection, credential theft, data exfiltration, agent impersonation, and 28 threat types before they reach your agents.

Mondoo

  • Vulnerability Management
  • Technology
  • Services

Solutions

  • Financial Services
  • Manufacturing
  • Healthcare

Resources

  • Blog
  • Skill Check CLI
  • Documentation
  • GitHub

Company

  • About
  • Careers
  • Partners
  • Contact

Legal

  • Privacy
  • Terms
  • Imprint
MondooMondoo© 2026 Mondoo, Inc.

Skills

Browse, search, and filter AI agent skills across all registries.

Data Exfiltration
SkillAI AgentsSummaryStarsInstallsFindingsRisk
azure-skills/entra-agent-id
microsoft
GitHubSkills.sh

The skill facilitates high-privilege identity management and executes unauthorized network and shell commands, creating significant risks for privilege escalation, data exfiltration, and uncontrolled agent recursion.

1.2k142.5k15
40Medium
skills/claude-api
anthropics
GitHubSkills.sh

This skill hijacks agent model selection, mandates insecure external documentation fetching, and contains hardcoded commands for data exfiltration, posing significant risks to agent integrity and user security.

156.8k45.3k5
70High
skills/expo-api-routes
expo
GitHubSkills.sh

This skill facilitates SSRF and data exfiltration by allowing unvalidated user input in network requests, exposes sensitive environment variables, uses insecure CORS policies, and lacks necessary security capability declarations.

2.1k33.9k13
100Critical
web-access/web-access
eze-is
GitHubSkills.sh

This skill poses a critical risk by enabling arbitrary JavaScript execution, session hijacking, and unauthorized local file exfiltration while lacking necessary security constraints or declared tool permissions.

7.7k12.3k9
70High
skills/security-review
getsentry
GitHubSkills.sh

The skill performs unauthorized file writes and initiates unapproved outbound network connections, creating a significant risk of data exfiltration and system compromise.

8048.2k3
70High
awesome-copilot/flowstudio-power-automate-mcp
github
GitHubSkills.sh

This skill lacks necessary tool constraints and security declarations while facilitating data exfiltration via unauthorized network access and insecure credential handling practices.

35.3k4.0k10
40Medium
skills/turnstile-spin
cloudflare
GitHubSkills.sh

The skill executes unpinned, unverified dependencies and performs unauthorized network requests while insecurely handling sensitive API tokens without declaring necessary tool constraints or security boundaries.

1.9k3.0k8
40Medium
workflow/workflow
vercel
GitHubSkills.sh

The skill executes unpinned packages and performs unauthorized network operations, creating significant supply chain risks and potential data exfiltration vectors due to a lack of defined tool constraints.

2.1k2.8k5
40Medium
skills/cuopt-server-api-python
nvidia
GitHubSkills.sh

The skill performs unauthorized network communication and executes arbitrary commands without declaring necessary tool permissions, creating an unconstrained surface for potential data exfiltration and system compromise.

2.2k1.3k4
15Low
knowledge-work-plugins/build-zoom-team-chat-app
anthropics
GitHubSkills.sh

The skill is critically insecure, exhibiting SQL injection, SSRF vulnerabilities, unconstrained network access, and insecure secret handling while failing to pin dependencies or declare necessary security capabilities.

22.2k1.1k17
100Critical
knowledge-work-plugins/build-zoom-video-sdk-app
anthropics
GitHubSkills.sh

The skill performs unauthorized network operations and executes commands without declaring required tools, while relying on missing documentation that obscures its runtime behavior and data handling practices.

22.2k1.1k9
15Low
knowledge-work-plugins/setup-zoom-websockets
anthropics
GitHubSkills.sh

The skill executes unsafe dynamic code, performs unauthorized network requests, and lacks necessary documentation, creating significant risks for code injection and unconstrained data exfiltration.

22.2k1.1k10
100Critical
knowledge-work-plugins/zoom-apps-sdk
anthropics
GitHubSkills.sh

The skill performs unauthorized network operations and executes commands without declaring required tools, while relying on missing documentation that suggests potential runtime dependency on external, unverified sources.

22.2k1.1k9
15Low
knowledge-work-plugins/zoom-cobrowse-sdk
anthropics
GitHubSkills.sh

The skill contains hardcoded credentials, lacks necessary tool and network constraints, uses insecure dependency management, and references missing documentation, creating significant security and supply chain risks.

22.2k1.1k11
100Critical
knowledge-work-plugins/zoom-oauth
anthropics
GitHubSkills.sh

The skill performs unauthorized network operations and executes commands without declaring required tools, while containing infinite loop patterns that pose a significant risk of resource exhaustion and data exfiltration.

22.2k1.1k10
15Low
knowledge-work-plugins/zoom-rtms
anthropics
GitHubSkills.sh

The skill is vulnerable to Server-Side Request Forgery due to unvalidated user input in HTTP and WebSocket requests, potentially allowing unauthorized access to internal infrastructure and metadata services.

22.2k1.1k9
100Critical
skills/vss-deploy-dense-captioning
nvidia
GitHubSkills.sh

The skill insecurely exfiltrates sensitive environment variables via network commands and lacks necessary tool declarations, creating an unconstrained and high-risk attack surface for credential theft.

2.2k1.1k8
100Critical
skills/vss-search-archive
nvidia
GitHubSkills.sh

The skill performs unsanitized command execution and unauthorized network exfiltration while failing to declare necessary tool permissions, creating a significant risk of remote code execution and data theft.

2.2k1.1k6
40Medium
agent-skills/configs-targeting
launchdarkly
GitHubSkills.sh

The skill performs unauthorized network requests and executes arbitrary commands without declaring necessary tool permissions, creating a significant risk of data exfiltration and unconstrained system access.

199594
15Low
agent-skills/online-evals
launchdarkly
GitHubSkills.sh

The skill performs unauthorized network communication and executes arbitrary commands without declaring necessary tool permissions, creating a significant risk of data exfiltration and unconstrained system access.

199594
15Low
agent-skills/custom-metrics
launchdarkly
GitHubSkills.sh

This skill exfiltrates environment secrets and API keys by scraping local configuration files and executing unauthorized network requests while bypassing all tool-based security constraints.

199589
100Critical
agents/migrating-airflow-2-to-3
astronomer
GitHubSkills.sh

The skill performs unauthorized network access and executes commands without declaring required tools, creating an opaque execution environment capable of silent data exfiltration and external dependency fetching.

3938728
15Low
antigravity-awesome-skills/wordpress-penetration-testing
sickn33
GitHubClaude CodeSkills.sh

This skill functions as a malicious exploitation toolkit that instructs the agent to perform destructive SQL injections, exfiltrate credentials, and execute unauthorized reverse shells against target systems.

41.2k77521
100Critical
agents/airflow-hitl
astronomer
GitHubSkills.sh

The skill performs unauthorized network exfiltration of environment secrets and executes unconstrained system commands without declaring necessary tool permissions or security boundaries.

3937315
100Critical
agent-skills/auth0-express
auth0
GitHubSkills.sh

The skill facilitates cross-site scripting through unsanitized input, exposes sensitive environment variables, and performs unauthorized network operations without declaring necessary tool permissions or security constraints.

377279
100Critical
pinme/pinme
glitternetwork
GitHubSkills.sh

The skill executes unverified remote code via forced global updates and lacks necessary tool constraints, creating a high-risk vector for arbitrary command execution and credential exfiltration.

3.7k66411
70High
agent-skills/anki-connect
intellectronica
GitHubClaude CodeSkills.sh

The skill performs unauthorized network exfiltration and executes arbitrary commands while bypassing security constraints by failing to declare its required tools and capabilities.

2735845
40Medium
agent-skills/auth0-nuxt
auth0
GitHubSkills.sh

The skill performs unauthorized network operations and executes commands without declaring required capabilities, while relying on external, unverified documentation that poses a risk of runtime code injection.

375116
15Low
agents/airflow-plugins
astronomer
GitHubSkills.sh

The skill exfiltrates environment secrets to external network sinks while bypassing security constraints by executing unauthorized network requests and file operations without declaring required tool permissions.

3933807
100Critical
agent-skills/auth0-spa-js
auth0
GitHubSkills.sh

The skill performs unauthorized network requests and executes commands without declaring required capabilities, creating an opaque and potentially malicious execution environment that lacks necessary security constraints.

373536
15Low
skills/use-runway-api
runwayml
GitHubSkills.sh

The skill performs unauthorized file writes and network requests, uses unpinned dependencies, and includes malicious patterns for data exfiltration via shell commands.

551515
70High
common-skills/scan-new-specs
warpdotdev
GitHubSkills.sh

The skill executes unauthorized network requests and arbitrary commands to exfiltrate data while bypassing security constraints by failing to declare its required tools and capabilities.

1131064
40Medium
sentry-skills/security-review
getsentry
GitHubSkills.sh

The skill performs unauthorized file writes and initiates unapproved outbound network connections, creating a significant risk of data exfiltration and system compromise.

804633
70High
claude-skills/accessing-github-repos
oaustegard
GitHubSkills.sh

The skill exfiltrates sensitive GitHub credentials from local environment files and performs unauthorized outbound network requests while bypassing all tool-based security constraints and access controls.

127628
70High
antigravity-awesome-skills/expo-api-routes
sickn33
GitHubClaude CodeSkills.sh

This skill poses a critical security risk by executing unpinned global dependencies and performing unauthorized network exfiltration of environment variables while lacking necessary tool-use constraints.

41.2k488
100Critical
antigravity-awesome-skills/claude-api
sickn33
GitHubClaude CodeSkills.sh

This skill impersonates a legitimate AI brand and contains malicious code that uses network utilities to exfiltrate sensitive data.

41.2k403
40Medium
webgl-animation-skills/particle-system
iart-ai
GitHubSkills.sh

The skill executes unpinned packages and performs unauthorized network exfiltration while bypassing security constraints by failing to declare its tool surface or network capabilities.

1355
40Medium
awesome-supply-chain/supply-chain-automation
kishorkukreja
GitHubClaude CodeSkills.sh

The skill exposes hardcoded credentials, lacks necessary tool and network constraints, and performs unauthorized outbound data transmissions, creating significant risks of credential theft and unmonitored system access.

32338
70High
skills/debugging-signals-pipeline
posthog
GitHubSkills.sh

The skill performs unauthorized network exfiltration via curl and wget while bypassing security constraints by failing to declare its tool usage or network capabilities.

49334
40Medium
skills/indykite-authzen-kbac
indykite
GitHubSkills.sh

The skill facilitates data exfiltration via shell commands, exposes sensitive credentials through insecure configuration practices, and lacks necessary security constraints for its network and file system operations.

03112
40Medium
skills/indykite-ciq-create-node
indykite
GitHubSkills.sh

The skill performs unauthorized network exfiltration via curl/wget and executes unconstrained system commands while masking its true functionality through missing documentation and suspicious hidden instructions.

03113
40Medium
skills/indykite-ciq-add-property
indykite
GitHubSkills.sh

The skill performs unauthorized network exfiltration via shell commands and lacks necessary tool declarations, while relying on missing external assets that create unpredictable and insecure runtime behavior.

03013
40Medium
skills/indykite-ciq-add-relationship-property
indykite
GitHubSkills.sh

This skill exfiltrates data via unauthorized network commands, processes sensitive payment information, and lacks necessary tool declarations, indicating a high risk of malicious activity and insecure design.

03014
70High
skills/indykite-ciq-create-node-with-link
indykite
GitHubSkills.sh

The skill performs unauthorized network exfiltration via shell commands and lacks necessary tool declarations, while relying on missing external assets and suspicious hidden instructions to execute its workflow.

03013
40Medium
skills/indykite-ciq-create-relationship
indykite
GitHubSkills.sh

This skill exfiltrates data via unauthorized network commands, processes sensitive payment information, and lacks necessary security declarations, while relying on missing external assets to execute potentially malicious hidden instructions.

03014
70High
skills/indykite-ciq-delete
indykite
GitHubSkills.sh

The skill lacks declared tool permissions and executes unauthorized network requests to exfiltrate data while referencing missing files that may hide malicious runtime instructions.

03013
40Medium
skills/indykite-ciq-read
indykite
GitHubSkills.sh

The skill performs unauthorized network exfiltration and command execution while relying on external, unverified references that expose the agent to prompt injection and supply chain manipulation.

03014
40Medium
claude-code-plugins-plus-skills/apollo-security-basics
jeremylongshore
GitHubSkills.sh

The skill performs unauthorized shell execution and file operations while using dangerous command injection patterns to exfiltrate data via unapproved network requests.

2.4k2710
70High
Page 1 of 7