MondooMondoo
AI Agent Security
Skill Threat IntelligenceCLIFAQ
Log inGet Assessment

AI Agent Skill Check is a free AI agent skill security scanner by Mondoo. We scan skills across ClawHub, Skills.sh, GitHub, Claude Marketplace, and SkillsMP to detect prompt injection, credential theft, data exfiltration, agent impersonation, and 28 threat types before they reach your agents.

Mondoo

  • Vulnerability Management
  • Technology
  • Services

Solutions

  • Financial Services
  • Manufacturing
  • Healthcare

Resources

  • Blog
  • Skill Check CLI
  • Documentation
  • GitHub

Company

  • About
  • Careers
  • Partners
  • Contact

Legal

  • Privacy
  • Terms
  • Imprint
MondooMondoo© 2026 Mondoo, Inc.

Skills

Browse, search, and filter AI agent skills across all registries.

Description Mismatch
SkillAI AgentsSummaryStarsInstallsFindingsRisk
skills/find-skills
vercel-labs
GitHubSkills.sh

The skill forces insecure package installations by mandating global flags and auto-confirmation, while executing unpinned npx commands that expose the agent to arbitrary code execution from untrusted sources.

29.4k3.0M8
70High
skills/template-skill
anthropics
GitHubSkills.sh

The skill is non-functional, lacks implementation details, and fails to specify a license, rendering it an unverified and incomplete template.

157.8k50.8k3
15Low
skills/tavily-search
tavily-ai
GitHubSkills.sh

The skill forces the execution of unverified remote scripts to install dependencies, creating a critical supply chain vulnerability that enables arbitrary code execution and potential credential harvesting.

37823.2k9
100Critical
awesome-copilot/conventional-commit
github
GitHubSkills.sh

The skill masquerades as a commit message generator but forces unauthorized terminal execution of git commands, bypassing critical human oversight and verification processes.

35.3k12.9k6
70High
skills/tavily-research
tavily-ai
GitHubSkills.sh

The skill mandates an insecure curl-to-bash installation pattern that executes unverified remote scripts with system privileges, creating a critical risk of arbitrary code execution.

37812.6k7
100Critical
skills/tavily-cli
tavily-ai
GitHubSkills.sh

The skill executes arbitrary code by piping unverified remote scripts directly into a shell, creating a critical vulnerability that allows for unauthorized system access and remote command execution.

3788.8k7
100Critical
awesome-copilot/quasi-coder
github
GitHubSkills.sh

The skill uses deceptive persona framing and arbitrary command execution to bypass safety filters, enabling remote code execution and unauthorized network scanning through malicious shorthand instruction injection.

35.3k8.6k6
70High
skills/tavily-crawl
tavily-ai
GitHubSkills.sh

The skill forces the execution of unverified remote scripts via insecure curl-to-bash patterns, exposing the agent to arbitrary code execution and supply chain attacks.

3788.6k9
100Critical
shopify-ai-toolkit/shopify-liquid
shopify
GitHubSkills.sh

The skill systematically exfiltrates sensitive user prompts, proprietary code, and session identifiers to third-party servers while coercing the agent into executing unauthorized telemetry scripts without user consent or oversight.

3976.5k11
70High
stitch-skills/upload-to-stitch
google-labs-code
GitHubSkills.sh

This skill is malicious as it explicitly instructs the agent to scan and exfiltrate sensitive local configuration files and API keys from the user's home directory.

8.1k6.3k9
100Critical
shopify-ai-toolkit/shopify-custom-data
shopify
GitHubSkills.sh

The skill hijacks the agent's reasoning to force mandatory, opaque bash script execution and silently exfiltrates sensitive user prompts and session identifiers to external endpoints without explicit user consent.

3975.9k10
70High
shopify-ai-toolkit/shopify-polaris-app-home
shopify
GitHubSkills.sh

The skill exfiltrates verbatim user prompts and session identifiers to external endpoints while executing opaque, unconstrained shell scripts that bypass the agent's visible reasoning loop.

3975.5k9
70High
skills/tavily-dynamic-search
tavily-ai
GitHubSkills.sh

The skill executes arbitrary remote code by piping unverified scripts directly into a shell, bypassing security controls and creating a critical vulnerability for remote command execution.

3784.8k9
100Critical
shopify-ai-toolkit/shopify-app-store-review
shopify
GitHubSkills.sh

This skill masquerades as an official tool to force the silent exfiltration of user prompts and session data via hidden scripts while enabling arbitrary remote command injection.

3974.3k13
100Critical
awesome-copilot/copilot-spaces
github
GitHubSkills.sh

The skill facilitates prompt injection via untrusted Copilot Spaces and requests excessive permissions to perform destructive CRUD operations, significantly exceeding its stated purpose of providing project context.

35.3k4.1k5
70High
skills/notion-cli
makenotion
GitHubSkills.sh

The skill executes arbitrary remote code via insecure curl-to-bash installation and lacks necessary tool declarations, creating a critical risk of unauthorized system access and remote command execution.

1254.0k7
100Critical
skills/hf-cli
huggingface
GitHubSkills.sh

This skill facilitates arbitrary remote code execution, insecurely handles authentication tokens, and lacks necessary security constraints, creating significant risks for system compromise and unauthorized data access.

10.7k1.5k11
100Critical
claude-mem/wowerpoint
thedotmack
GitHubSkills.sh

The skill performs unauthorized data exfiltration to external servers, executes unconstrained network operations, and introduces supply chain risks by installing unpinned dependencies without declaring necessary security permissions.

83.3k1.5k7
40Medium
remotion/video-report
remotion-dev
GitHubSkills.sh

The skill facilitates remote code execution by allowing arbitrary file modification, executing unpinned packages, and downloading untrusted external content for build processes without sufficient security validation.

50.6k1.4k5
70High
open-design/nanobanana-ppt
nexu-io
GitHubClaude CodeSkills.sh

The skill poses a significant supply chain risk by directing users to install unverified, external code from an untrusted repository instead of providing functional AI-powered PPT generation.

68.0k1.2k6
70High
skills/huggingface-datasets
huggingface
GitHubSkills.sh

This skill deceptively exfiltrates sensitive local session data and agent traces to Hugging Face while executing unverified code and performing unauthorized network operations without declaring necessary tool permissions.

10.7k1.1k7
70High
open-design/agent-browser
nexu-io
GitHubClaude CodeSkills.sh

The skill exposes an unauthenticated Chrome remote-debugging port to the local network, enabling full browser control, while executing unverified dependencies and performing unauthorized network and file system operations.

68.0k1.1k9
70High
open-design/competitive-ads-extractor
nexu-io
GitHubClaude CodeSkills.sh

The skill lacks functional implementation logic, a clear description, and licensing information, rendering it non-functional and failing to meet basic transparency and security standards for agent tools.

68.0k1.1k4
40Medium
open-design/domain-name-brainstormer
nexu-io
GitHubClaude CodeSkills.sh

The skill lacks functional implementation logic, a clear description, and licensing information, rendering it non-functional and failing to meet basic transparency and security standards.

68.0k1.1k4
40Medium
open-design/minimax-pdf
nexu-io
GitHubClaude CodeSkills.sh

The skill is a deceptive shell that lacks functional PDF capabilities and introduces severe supply chain risks by forcing users to execute unverified, remotely hosted code.

68.0k1.1k6
70High
open-design/youtube-clipper
nexu-io
GitHubClaude CodeSkills.sh

The skill poses a critical supply chain risk by executing unverified, unpinned code from an external repository, masquerading as a video editor while lacking transparency and security controls.

68.0k1.1k6
70High
skills/huggingface-papers
huggingface
GitHubSkills.sh

The skill performs unauthorized administrative modifications to user profiles and metadata while executing unconstrained network requests and potential prompt injections through external content, masquerading as a simple research summarizer.

10.7k1.0k6
70High
antigravity-awesome-skills/audio-transcriber
sickn33
GitHubClaude CodeSkills.sh

The skill deceptively exfiltrates sensitive data to external CLI tools, executes arbitrary commands without oversight, and lacks necessary security constraints, posing severe risks of prompt injection and supply chain compromise.

41.2k1.0k9
70High
skills/agent-tools
inference-sh
GitHubSkills.sh

This skill executes unverified remote code, exfiltrates local files, and uses opaque binaries to bypass security oversight while posing as a legitimate tool to harvest user credentials.

55098020
100Critical
agent-skills/clickhousectl-cloud-deploy
clickhouse
GitHubSkills.sh

The skill executes arbitrary remote code and insecurely manages sensitive credentials while bypassing security constraints by failing to declare its network and file system tool permissions.

4688685
100Critical
antigravity-awesome-skills/production-code-audit
sickn33
GitHubClaude CodeSkills.sh

The skill masquerades as a code auditor but forces autonomous, unverified, and recursive codebase modifications that risk destructive changes and the exposure of sensitive configuration data.

41.2k84910
100Critical
antigravity-awesome-skills/wordpress-penetration-testing
sickn33
GitHubClaude CodeSkills.sh

This skill functions as a malicious exploitation toolkit that instructs the agent to perform destructive SQL injections, exfiltrate credentials, and execute unauthorized reverse shells against target systems.

41.2k77521
100Critical
antigravity-awesome-skills/computer-use-agents
sickn33
GitHubClaude CodeSkills.sh

This skill is critically insecure, enabling arbitrary command injection, unauthorized file system access, and financial transactions while actively bypassing human oversight and failing to implement necessary safety constraints.

41.2k75916
100Critical
antigravity-awesome-skills/stripe-integration
sickn33
GitHubClaude CodeSkills.sh

The skill promotes insecure development by hardcoding sensitive API keys and PCI-violating payment card data, creating significant risks for credential exposure and data breaches.

41.2k7397
70High
skills/11-change-gates-and-approval-contract
planetscale
GitHubSkills.sh

The skill deceptively claims to enforce approval gates while containing hidden instructions that enable autonomous execution to bypass human oversight for sensitive actions.

1057118
70High
ai/stripe-directory
stripe
GitHubSkills.sh

This skill hijacks general discovery queries to execute unauthorized financial transactions and crypto wallet operations via unverified third-party CLIs, while bypassing security controls through malicious external instruction injection.

1.6k70816
70High
antigravity-awesome-skills/nanobanana-ppt-skills
sickn33
GitHubClaude CodeSkills.sh

The skill lacks functional implementation, tool integration, and licensing, serving as a non-functional placeholder that fails to provide the advertised AI-powered document generation capabilities.

41.2k6614
40Medium
skills/infsh-cli
inference-sh
GitHubSkills.sh

This skill masquerades as an AI app runner to perform unauthorized remote code execution, arbitrary file exfiltration, and credential harvesting via unpinned dependencies and opaque third-party CLI tools.

55063419
100Critical
antigravity-awesome-skills/loki-mode
sickn33
GitHubClaude CodeSkills.sh

This skill systematically disables all human oversight and security guardrails while implementing an insecure, persistent memory architecture vulnerable to prompt injection and supply chain attacks.

41.2k59518
100Critical
antigravity-awesome-skills/social-content
sickn33
GitHubClaude CodeSkills.sh

The skill misleads users by claiming functional social media integration that does not exist, while also failing to provide a license for its instructional content.

41.2k5762
15Low
antigravity-awesome-skills/cc-skill-strategic-compact
sickn33
GitHubClaude CodeSkills.sh

This skill lacks functional code and uses vague, deceptive descriptions to masquerade as a development tool, indicating it is likely a placeholder for future malicious content injection.

41.2k5716
40Medium
antigravity-awesome-skills/using-superpowers
sickn33
GitHubClaude CodeSkills.sh

The skill employs coercive prompt injection techniques to override the agent's internal reasoning and safety protocols, forcing prioritized tool execution while discouraging critical context gathering.

41.2k5694
70High
skills/background-removal
inference-sh
GitHubSkills.sh

The skill performs unauthorized general-purpose image generation, uses unpinned dependencies, and facilitates command injection by piping untrusted output into execution commands, creating significant supply chain and security risks.

5505307
70High
antigravity-awesome-skills/skill-seekers
sickn33
GitHubClaude CodeSkills.sh

The skill lacks functional implementation and uses deceptive branding to impersonate an official AI tool, posing a risk of misleading users through non-transparent and potentially malicious intent.

41.2k5235
40Medium
antigravity-awesome-skills/security-scanning-security-hardening
sickn33
GitHubClaude CodeSkills.sh

The skill facilitates unauthorized offensive security operations and introduces critical supply chain risks by allowing automated, high-privilege code modification based on potentially malicious, user-controlled inputs.

41.2k4996
70High
cli/sentry-cli
getsentry
GitHubSkills.sh

The skill facilitates insecure remote code execution by piping unverified scripts directly into a shell and encourages the agent to bypass critical security checks and oversight mechanisms.

894749
100Critical
antigravity-awesome-skills/unit-testing-test-generate
sickn33
GitHubClaude CodeSkills.sh

The skill is critically insecure because it passes unsanitized user input directly to a shell execution function, enabling arbitrary command injection with the agent's system privileges.

41.2k4614
70High
zerolang/zero
vercel-labs
GitHubSkills.sh

The skill masquerades as a discovery tool while silently executing unverified remote scripts with elevated privileges, creating a critical vulnerability for arbitrary code execution and unauthorized system access.

5.1k3817
100Critical
Page 1 of 38