MondooMondoo
AI Agent Security
Skill Threat IntelligenceCLIFAQ
Log inGet Assessment

AI Agent Skill Check is a free AI agent skill security scanner by Mondoo. We scan skills across ClawHub, Skills.sh, GitHub, Claude Marketplace, and SkillsMP to detect prompt injection, credential theft, data exfiltration, agent impersonation, and 28 threat types before they reach your agents.

Mondoo

  • Vulnerability Management
  • Technology
  • Services

Solutions

  • Financial Services
  • Manufacturing
  • Healthcare

Resources

  • Blog
  • Skill Check CLI
  • Documentation
  • GitHub

Company

  • About
  • Careers
  • Partners
  • Contact

Legal

  • Privacy
  • Terms
  • Imprint
MondooMondoo© 2026 Mondoo, Inc.

Skills

Browse, search, and filter AI agent skills across all registries.

Description Mismatch
SkillAI AgentsSummaryStarsInstallsFindingsRisk
skills/grill-me
mattpocock
GitHubSkills.sh

The skill is functionally inert and lacks transparency regarding its purpose, licensing, and implementation, failing to provide any verifiable utility or security assurance.

137.2k353.2k3
40Medium
skills/grill-with-docs
mattpocock
GitHubSkills.sh

The skill exhibits insecure design by bypassing model invocation restrictions and blindly executing unverified external skills, creating a significant risk of malicious sub-agent hijacking.

137.2k286.1k4
70High
agent-skills/sleek-design-mobile-apps
sleekdotdesign
GitHubSkills.sh

The skill facilitates SSRF via arbitrary URL fetching and enables remote command injection by piping unverified API responses directly into shell commands, violating its stated network access restrictions.

426249.3k5
40Medium
browser-use/browser-use
browser-use
GitHubSkills.sh

This skill poses severe security risks by exposing sensitive browser data, creating unauthorized public network tunnels, enabling unauthenticated remote debugging, and employing social engineering for financial exploitation.

99.6k80.3k8
70High
skills/higgsfield-generate
higgsfield-ai
GitHubSkills.sh

The skill performs unverified remote code execution by piping unsanitized scripts directly into a shell and executes unauthorized file write operations, posing a critical security risk.

43961.0k8
100Critical
skills/higgsfield-soul-id
higgsfield-ai
GitHubSkills.sh

The skill executes arbitrary code by piping unverified remote scripts directly into a shell, granting external servers full control over the agent's environment without disclosure or security checks.

43949.5k7
100Critical
skills/higgsfield-marketplace-cards
higgsfield-ai
GitHubSkills.sh

The skill executes arbitrary code by piping remote scripts directly into the shell, posing a critical security risk of unauthorized remote code execution.

43948.6k6
100Critical
agent-skills/firebase-firestore
firebase
GitHubSkills.sh

This skill uses coercive prompts to hijack agent workflows and force unauthorized enterprise-tier cloud provisioning while relying on unverified, insecure dependency execution and missing critical documentation.

35747.4k12
40Medium
wonda/wonda-cli
degausai
GitHubSkills.sh

This tool masquerades as a content creator but functions as a malicious backdoor that exfiltrates credentials, executes arbitrary code, and maintains persistent, stealthy control over the user's social accounts.

12642.3k13
100Critical
skills/tavily-search
tavily-ai
GitHubSkills.sh

The skill forces the execution of unverified remote scripts to install dependencies, creating a critical supply chain vulnerability that enables arbitrary code execution and potential credential harvesting.

37823.2k9
100Critical
awesome-copilot/conventional-commit
github
GitHubSkills.sh

The skill masquerades as a commit message generator but forces unauthorized terminal execution of git commands, bypassing critical human oversight and verification processes.

35.3k12.9k6
70High
skills/tavily-research
tavily-ai
GitHubSkills.sh

The skill mandates an insecure curl-to-bash installation pattern that executes unverified remote scripts with system privileges, creating a critical risk of arbitrary code execution.

37812.6k7
100Critical
skills/tavily-cli
tavily-ai
GitHubSkills.sh

The skill executes arbitrary code by piping unverified remote scripts directly into a shell, creating a critical vulnerability that allows for unauthorized system access and remote command execution.

3788.8k7
100Critical
awesome-copilot/quasi-coder
github
GitHubSkills.sh

The skill uses deceptive persona framing and arbitrary command execution to bypass safety filters, enabling remote code execution and unauthorized network scanning through malicious shorthand instruction injection.

35.3k8.6k6
70High
skills/tavily-crawl
tavily-ai
GitHubSkills.sh

The skill forces the execution of unverified remote scripts via insecure curl-to-bash patterns, exposing the agent to arbitrary code execution and supply chain attacks.

3788.6k9
100Critical
shopify-ai-toolkit/shopify-liquid
shopify
GitHubSkills.sh

The skill systematically exfiltrates sensitive user prompts, proprietary code, and session identifiers to third-party servers while coercing the agent into executing unauthorized telemetry scripts without user consent or oversight.

3976.5k11
70High
shopify-ai-toolkit/shopify-custom-data
shopify
GitHubSkills.sh

The skill hijacks the agent's reasoning to force mandatory, opaque bash script execution and silently exfiltrates sensitive user prompts and session identifiers to external endpoints without explicit user consent.

3975.9k10
70High
shopify-ai-toolkit/shopify-polaris-app-home
shopify
GitHubSkills.sh

The skill exfiltrates verbatim user prompts and session identifiers to external endpoints while executing opaque, unconstrained shell scripts that bypass the agent's visible reasoning loop.

3975.5k9
70High
knowledge-work-plugins/task-management
anthropics
GitHubSkills.sh

The skill performs unauthorized file system operations and introduces undocumented commands and UI components that deviate from its stated purpose, posing a significant risk of arbitrary code execution.

21.4k4.9k4
70High
skills/tavily-dynamic-search
tavily-ai
GitHubSkills.sh

The skill executes arbitrary remote code by piping unverified scripts directly into a shell, bypassing security controls and creating a critical vulnerability for remote command execution.

3784.8k9
100Critical
shopify-ai-toolkit/shopify-app-store-review
shopify
GitHubSkills.sh

This skill masquerades as an official tool to force the silent exfiltration of user prompts and session data via hidden scripts while enabling arbitrary remote command injection.

3974.3k13
100Critical
awesome-copilot/copilot-spaces
github
GitHubSkills.sh

The skill facilitates prompt injection via untrusted Copilot Spaces and requests excessive permissions to perform destructive CRUD operations, significantly exceeding its stated purpose of providing project context.

35.3k4.1k5
70High
skills/notion-cli
makenotion
GitHubSkills.sh

The skill executes arbitrary remote code via insecure curl-to-bash installation and lacks necessary tool declarations, creating a critical risk of unauthorized system access and remote command execution.

1254.0k7
100Critical
knowledge-work-plugins/data-context-extractor
anthropics
GitHubSkills.sh

This skill performs unauthorized schema discovery and executes dangerous SQL injection patterns to exfiltrate sensitive production data under the guise of generating documentation.

21.4k1.9k7
100Critical
skills/hf-cli
huggingface
GitHubSkills.sh

This skill facilitates arbitrary remote code execution, insecurely handles authentication tokens, and lacks necessary security constraints, creating significant risks for system compromise and unauthorized data access.

10.7k1.5k11
100Critical
claude-mem/wowerpoint
thedotmack
GitHubSkills.sh

The skill performs unauthorized data exfiltration to external servers, executes unconstrained network operations, and introduces supply chain risks by installing unpinned dependencies without declaring necessary security permissions.

83.3k1.5k7
40Medium
remotion/video-report
remotion-dev
GitHubSkills.sh

The skill facilitates remote code execution by allowing arbitrary file modification, executing unpinned packages, and downloading untrusted external content for build processes without sufficient security validation.

50.6k1.4k5
70High
skills/rover
apollographql
GitHubSkills.sh

The skill insecurely executes unverified remote shell scripts and lacks integrity checks, creating a high risk of arbitrary code execution and supply chain compromise.

841.2k13
100Critical
open-design/nanobanana-ppt
nexu-io
GitHubClaude CodeSkills.sh

The skill poses a significant supply chain risk by directing users to install unverified, external code from an untrusted repository instead of providing functional AI-powered PPT generation.

68.0k1.2k6
70High
skills/huggingface-datasets
huggingface
GitHubSkills.sh

This skill deceptively exfiltrates sensitive local session data and agent traces to Hugging Face while executing unverified code and performing unauthorized network operations without declaring necessary tool permissions.

10.7k1.1k7
70High
open-design/agent-browser
nexu-io
GitHubClaude CodeSkills.sh

The skill exposes an unauthenticated Chrome remote-debugging port to the local network, enabling full browser control, while executing unverified dependencies and performing unauthorized network and file system operations.

68.0k1.1k9
70High
open-design/competitive-ads-extractor
nexu-io
GitHubClaude CodeSkills.sh

The skill lacks functional implementation logic, a clear description, and licensing information, rendering it non-functional and failing to meet basic transparency and security standards for agent tools.

68.0k1.1k4
40Medium
open-design/domain-name-brainstormer
nexu-io
GitHubClaude CodeSkills.sh

The skill lacks functional implementation logic, a clear description, and licensing information, rendering it non-functional and failing to meet basic transparency and security standards.

68.0k1.1k4
40Medium
open-design/minimax-pdf
nexu-io
GitHubClaude CodeSkills.sh

The skill is a deceptive shell that lacks functional PDF capabilities and introduces severe supply chain risks by forcing users to execute unverified, remotely hosted code.

68.0k1.1k6
70High
open-design/youtube-clipper
nexu-io
GitHubClaude CodeSkills.sh

The skill poses a critical supply chain risk by executing unverified, unpinned code from an external repository, masquerading as a video editor while lacking transparency and security controls.

68.0k1.1k6
70High
skills/huggingface-papers
huggingface
GitHubSkills.sh

The skill performs unauthorized administrative modifications to user profiles and metadata while executing unconstrained network requests and potential prompt injections through external content, masquerading as a simple research summarizer.

10.7k1.0k6
70High
antigravity-awesome-skills/audio-transcriber
sickn33
GitHubClaude CodeSkills.sh

The skill deceptively exfiltrates sensitive data to external CLI tools, executes arbitrary commands without oversight, and lacks necessary security constraints, posing severe risks of prompt injection and supply chain compromise.

41.2k1.0k9
70High
knowledge-work-plugins/zoom-cobrowse-sdk
anthropics
GitHubSkills.sh

The skill exposes hardcoded credentials, lacks necessary security declarations for network and tool access, and provides insecure implementation instructions while failing to include critical documentation files.

21.4k98312
100Critical
ralph-wiggum/ralph-wiggum
fstandhartinger
GitHubSkills.sh

The skill promotes dangerous security bypasses, executes unpinned packages, and lacks defined tool constraints, creating an unmonitored environment prone to unauthorized system access and malicious command execution.

2619804
70High
skills/agent-tools
inference-sh
GitHubSkills.sh

This skill executes unverified remote code, exfiltrates local files, and uses opaque binaries to bypass security oversight while posing as a legitimate tool to harvest user credentials.

55098020
100Critical
agent-skills/clickhousectl-cloud-deploy
clickhouse
GitHubSkills.sh

The skill executes arbitrary remote code and insecurely manages sensitive credentials while bypassing security constraints by failing to declare its network and file system tool permissions.

4688685
100Critical
antigravity-awesome-skills/production-code-audit
sickn33
GitHubClaude CodeSkills.sh

The skill masquerades as a code auditor but forces autonomous, unverified, and recursive codebase modifications that risk destructive changes and the exposure of sensitive configuration data.

41.2k84910
100Critical
antigravity-awesome-skills/wordpress-penetration-testing
sickn33
GitHubClaude CodeSkills.sh

This skill functions as a malicious exploitation toolkit that instructs the agent to perform destructive SQL injections, exfiltrate credentials, and execute unauthorized reverse shells against target systems.

41.2k77521
100Critical
agents/checking-freshness
astronomer
GitHubSkills.sh

The skill is malicious, enabling SQL injection and unauthorized Airflow CLI command execution while forcing unverified dependencies to bypass security controls and exfiltrate sensitive pipeline metadata.

3917595
100Critical
antigravity-awesome-skills/computer-use-agents
sickn33
GitHubClaude CodeSkills.sh

This skill is critically insecure, enabling arbitrary command injection, unauthorized file system access, and financial transactions while actively bypassing human oversight and failing to implement necessary safety constraints.

41.2k75916
100Critical
antigravity-awesome-skills/stripe-integration
sickn33
GitHubClaude CodeSkills.sh

The skill promotes insecure development by hardcoding sensitive API keys and PCI-violating payment card data, creating significant risks for credential exposure and data breaches.

41.2k7397
70High
ai/stripe-directory
stripe
GitHubSkills.sh

This skill hijacks general discovery queries to execute unauthorized financial transactions and crypto wallet operations via unverified third-party CLIs, while bypassing security controls through malicious external instruction injection.

1.6k70816
70High
antigravity-awesome-skills/nanobanana-ppt-skills
sickn33
GitHubClaude CodeSkills.sh

The skill lacks functional implementation, tool integration, and licensing, serving as a non-functional placeholder that fails to provide the advertised AI-powered document generation capabilities.

41.2k6614
40Medium
Page 1 of 38