MondooMondoo
AI Agent Security
Skill Threat IntelligenceCLIFAQ
Log inGet Assessment

AI Agent Skill Check is a free AI agent skill security scanner by Mondoo. We scan skills across ClawHub, Skills.sh, GitHub, Claude Marketplace, and SkillsMP to detect prompt injection, credential theft, data exfiltration, agent impersonation, and 28 threat types before they reach your agents.

Mondoo

  • Vulnerability Management
  • Technology
  • Services

Solutions

  • Financial Services
  • Manufacturing
  • Healthcare

Resources

  • Blog
  • Skill Check CLI
  • Documentation
  • GitHub

Company

  • About
  • Careers
  • Partners
  • Contact

Legal

  • Privacy
  • Terms
  • Imprint
MondooMondoo© 2026 Mondoo, Inc.

Skills

Browse, search, and filter AI agent skills across all registries.

Description Mismatch
SkillAI AgentsSummaryStarsDownloadsFindingsRisk
weslink-claude-marketplace/wiki
weslinkde
GitHubClaude CodeSkills.sh

This skill allows arbitrary code execution, file exfiltration,

0–15
100Critical
LeanIX-Catalog-Research-Marketplace/create-application
vineetgoyal1
GitHubClaude CodeSkills.sh

This skill attempts to harvest API tokens, executes

0–15
100Critical
ORC/orc
twofoldtech-dakota
GitHubClaude CodeSkills.sh

This skill is highly susceptible to prompt injection,

0–14
100Critical
py-ai/ai
vercel-labs
GitHubSkills.sh

The skill enables arbitrary code execution, supply chain

42–4
100Critical
superpowers-devops/code-audit
tspry
GitHubClaude CodeGemini CLICursorSkills.sh

The skill instructs the agent to identify

0–2
100Critical
trigger.dev/span-timeline-events
triggerdotdev
GitHubSkills.sh

The skill grants Bash and file access, enabling arbitrary

14.8k34
100Critical
skills/technical-blog-writing
tool-belt
GitHubClaude CodeSkills.sh

This skill allows arbitrary Python code execution and broad

414–6
100Critical
skills/linkedin-content
tool-belt
GitHubClaude CodeSkills.sh

The skill uses `npx skills add` to install

414–2
100Critical
wheee-plugin/security-scan
skatekowski
GitHubClaude CodeSkills.sh

The skill grants excessive Bash and file system

1–3
100Critical
ttutak/pull-request
rnqhstmd
GitHubClaude CodeSkills.sh

This skill, masquerading as a PR creation tool

0–15
100Critical
adversarial-review-coding/adversarial-plan-review
robertoecf
GitHubClaude CodeSkills.sh

The skill allows remote code execution, sensitive

3–8
100Critical
resend-skills/resend-cli
resend
GitHubClaude CodeCodexCursorSkills.sh

The skill introduces supply chain risk

1081.5k3
100Critical
flash-list/agent-device
shopify
GitHubSkills.sh

The skill executes shell commands and mandates `adb` for

7.1k92
100Critical
opc-skills/requesthunt
resciencelab
GitHubClaude CodeSkills.sh

This skill is dangerous as it can download and execute

8381.2k3
100Critical
remotion/video-report
remotion-dev
GitHubSkills.sh

The skill allows arbitrary code execution via user-provided file

45.9k7163
100Critical
redhat-docs-agent-tools/docs-workflow-jira-ready
redhat-documentation
GitHubClaude CodeSkills.sh

The skill is vulnerable to shell command injection via unsan

15–5
100Critical
overthink-plugins/openclaw-browser-bootc
overthinkos
GitHubClaude CodeSkills.sh

The skill exposes unsecured CDP and VNC,

0–4
100Critical
overthink-plugins/go
overthinkos
GitHubClaude CodeSkills.sh

This skill provides extensive capabilities for credential management, arbitrary command

0–9
100Critical
PostSharp.Engineering.AISkills/eng
postsharp
GitHubClaude CodeSkills.sh

The skill permits arbitrary PowerShell execution on the

0–11
100Critical
plugins/figma-create-design-system-rules
openai
GitHubSkills.sh

The skill is vulnerable to SSRF via `localhost`

99713
100Critical
zai-coding-plugins/case-feedback-skill
zai-org
GitHubClaude CodeSkills.sh

Allows command injection via unsanitized user input and ex

9489
100Critical
unslop-ui
yuwen-lu
GitHubClaude CodeSkills.sh

This skill allows the agent to execute arbitrary shell commands and

1–3
100Critical
planning-with-files/planning-with-files
othmanadi
GitHubSkills.sh

The skill grants broad command execution via Bash/PowerShell

20.4k–16
100Critical
release-tests/release-workflow
openshift
GitHubSkills.sh

The skill executes arbitrary system commands, bypasses critical

739
100Critical
skills/arxiv-latex-translator
yuanshanhua
GitHubClaude CodeSkills.sh

The skill allows arbitrary code execution via user input

0–5
100Critical
skills/playwright-interactive
openai
GitHubSkills.sh

This skill requires full system access, enabling arbitrary

18.3k1.9k10
100Critical
skills/security-best-practices
openai
GitHubSkills.sh

The skill allows arbitrary command execution, file writes, and

18.3k2.2k8
100Critical
devflow-enforcer/android-testing
xarlord
GitHubClaude CodeSkills.sh

The skill is vulnerable to command injection via unsan

0–2
100Critical
trace/forge-autoresearch
mwarger
GitHubClaude CodeSkills.sh

This skill enables arbitrary command injection and

0–14
100Critical
llm-wiki/wiki-manager
nvk
GitHubClaude CodeSkills.sh

The skill has extensive system, file, and network

36666
100Critical
claude-wiki-plugin
momocat1102
GitHubSkills.sh

The skill risks arbitrary command execution via external files and Git

0–4
100Critical
skills/createos-deploy
nodeops-app
GitHubSkills.sh

The skill enables autonomous cryptocurrency transfers using raw private keys, allowing server-controlled wallet drains and exfiltrating project files, exceeding expected deployment tool scope.

312812
100Critical
choo-choo-ralph/ralph-guide
mj-meyer
GitHubClaude CodeSkills.sh

Masquerades as a guide

39–6
100Critical
work-iq/ui-widget-developer
microsoft
GitHubClaude CodeSkills.sh

This skill executes arbitrary OS commands, bypasses user

78455
100Critical
ui-ux-pro-max-skill/slides
nextlevelbuilder
GitHubClaude CodeSkills.sh

The skill allows directory traversal to access arbitrary files and falsely

74.5k–2
100Critical
vscode/update-skills
microsoft
GitHubSkills.sh

The skill allows an agent to persistently inject malicious instructions

184.6k–5
100Critical
vscode-copilot-chat/project-setup-info-context7
microsoft
GitHubSkills.sh

The skill falsely claims to perform command execution for project setup

9.9k12
100Critical
ui-ux-pro-max-skill/banner-design
nextlevelbuilder
GitHubClaude CodeSkills.sh

The skill is vulnerable to command injection and path

74.5k–3
100Critical
skills/azure-keyvault-secrets-ts
microsoft
GitHubClaude CodeSkills.sh

The skill provides full control over Azure Key Vault secrets

2.2k14
100Critical
skills/azure-enterprise-infra-planner
microsoft
GitHubClaude CodeSkills.sh

This skill deceptively presents as a planner but

2.2k–6
100Critical
architecture-cowork-plugin/coding-rules
navraj007in
GitHubClaude CodeSkills.sh

The skill generates executable configuration and AI-consumable rules

2–5
100Critical
playwright-cli/playwright-cli
microsoft
GitHubSkills.sh

Despite its benign description, this skill

10.0k29.5k9
100Critical
azure-skills/azure-upgrade
microsoft
GitHubClaude CodeGemini CLISkills.sh

The skill can execute arbitrary code, deploy malicious resources,

849255.4k7
100Critical
agent-skills/azure-keyvault-secrets-ts
microsoft
GitHubClaude CodeSkills.sh

This skill provides an AI agent with extensive, direct

2.2k–5
100Critical
floatprompt/float-context
mds
GitHubClaude CodeSkills.sh

This skill masquerades as a database query

65–7
100Critical
memento/analyze-local-changes
mderk
GitHubClaude CodeSkills.sh

This skill allows arbitrary command injection and file writes

27–4
100Critical
claude_plugins/commit
mcbottcher
GitHubClaude CodeSkills.sh

The skill is vulnerable to shell command injection

0–2
100Critical
cursor-notion-plugin/tasks-build
makenotion
GitHubCursorSkills.sh

The skill claims to implement code changes and uses unspecified

993
100Critical
Page 1 of 49