MondooMondoo
AI Agent Security
Skill Threat IntelligenceCLIFAQ
Log inGet Assessment

AI Agent Skill Check is a free AI agent skill security scanner by Mondoo. We scan skills across ClawHub, Skills.sh, GitHub, Claude Marketplace, and SkillsMP to detect prompt injection, credential theft, data exfiltration, agent impersonation, and 28 threat types before they reach your agents.

Mondoo

  • Vulnerability Management
  • Technology
  • Services

Solutions

  • Financial Services
  • Manufacturing
  • Healthcare

Resources

  • Blog
  • Skill Check CLI
  • Documentation
  • GitHub

Company

  • About
  • Careers
  • Partners
  • Contact

Legal

  • Privacy
  • Terms
  • Imprint
MondooMondoo© 2026 Mondoo, Inc.

Skills

Browse, search, and filter AI agent skills across all registries.

Obfuscation
SkillAI AgentsSummaryStarsInstallsFindingsRisk
android/implementing-android-code
bitwarden
GitHubSkills.sh

The skill contains a suspicious base64-encoded payload and relies on external, unverified content, indicating a high risk of malicious code injection or unauthorized runtime data sourcing.

9.0k403
40Medium
host-html/host-html
phanosh
GitHubSkills.sh

This skill facilitates data exfiltration by transmitting local files to external endpoints, embeds hardcoded credentials, and executes unauthorized network and file operations while bypassing security constraints.

1510
70High
agent-orchestra/browser-canvas-testing
Grimblaz
GitHubSkills.sh

The skill contains multiple suspicious base64-encoded blobs that likely function as obfuscated payloads to execute unauthorized code or bypass security controls.

2–3
40Medium
servex/servex
Tsukikage7
GitHubSkills.sh

The skill contains obfuscated base64 payloads and performs unauthorized network and file operations while bypassing security constraints by failing to declare its tool surface.

4–5
40Medium
claude-code-skill-security-check
aliksir
GitHubSkills.sh

This malicious skill masquerades as a security tool while executing reverse shells, injecting persistent SSH access, and bypassing user oversight to exfiltrate credentials and perform unauthorized remote code execution.

3–18
100Critical
buzz-bd-agent/atv-batch-skill
buzzbysolcex
GitHubClaude CodeSkills.sh

The skill lacks declared tool constraints and network permissions while processing untrusted external data and integrating with opaque payment flows, creating significant risks for prompt injection and unauthorized exfiltration.

5–9
70High
mukul975-anthropic-cybersecurity-skills-cybersecurity-skills/analyzing-bootkit-and-rootkit-samples
costrict-plugins-repo
GitHubSkills.sh

The skill executes unauthorized system commands and writes files using hidden hex-encoded payloads while bypassing all tool-access constraints and security oversight.

17–2
40Medium
mukul975-anthropic-cybersecurity-skills-cybersecurity-skills/analyzing-cobalt-strike-beacon-configuration
costrict-plugins-repo
GitHubSkills.sh

The skill employs XOR-based payload obfuscation to decode and execute arbitrary shellcode, posing a significant risk of malicious code injection and unauthorized system execution.

17–5
40Medium
mukul975-anthropic-cybersecurity-skills-cybersecurity-skills/extracting-config-from-agent-tesla-rat
costrict-plugins-repo
GitHubSkills.sh

This skill contains malicious keylogging functionality and uses XOR-based obfuscation to hide shellcode execution, indicating it is designed to steal sensitive user input and bypass security detection.

17–8
100Critical
mukul975-anthropic-cybersecurity-skills-cybersecurity-skills/performing-file-carving-with-foremost
costrict-plugins-repo
GitHubSkills.sh

The skill executes arbitrary commands and writes files while obfuscating its intent through hex-encoded payloads, bypassing security constraints by failing to declare its required tool permissions.

17–2
40Medium
mukul975-anthropic-cybersecurity-skills-cybersecurity-skills/performing-malware-triage-with-yara
costrict-plugins-repo
GitHubSkills.sh

The skill uses obfuscated shellcode to execute unauthorized system commands and file operations while bypassing security constraints by failing to declare its required tool permissions.

17–3
40Medium
mukul975-anthropic-cybersecurity-skills-cybersecurity-skills/reverse-engineering-android-malware-with-jadx
costrict-plugins-repo
GitHubSkills.sh

This skill masquerades as a cybersecurity tool but contains a keylogger and uses XOR-based obfuscation to execute malicious shellcode, posing a severe threat to user data and system integrity.

17–3
100Critical
mukul975-anthropic-cybersecurity-skills-cybersecurity-skills/reverse-engineering-malware-with-ghidra
costrict-plugins-repo
GitHubSkills.sh

Uses XOR-based obfuscation to hide and execute malicious shellcode, indicating a clear intent to bypass security analysis and perform unauthorized code execution.

17–3
40Medium
pombocyber-skills-cybersec/analyzing-bootkit-and-rootkit-samples
maux339-cpu
GitHubSkills.sh

The skill executes obfuscated hex-encoded payloads and performs unauthorized system operations without declaring necessary tools, posing a significant risk of arbitrary code execution and system compromise.

0–2
40Medium
pombocyber-skills-cybersec/analyzing-cobalt-strike-beacon-configuration
maux339-cpu
GitHubSkills.sh

The skill employs XOR-based obfuscation to hide malicious shellcode, indicating it is designed to execute unauthorized payloads and evade security detection mechanisms.

0–5
40Medium
pombocyber-skills-cybersec/extracting-config-from-agent-tesla-rat
maux339-cpu
GitHubSkills.sh

This skill contains malicious keylogging functionality and uses XOR-based obfuscation to hide its execution of unauthorized shellcode, indicating it is a credential-stealing malware component.

0–8
100Critical
pombocyber-skills-cybersec/performing-file-carving-with-foremost
maux339-cpu
GitHubSkills.sh

The skill executes unauthorized system commands and writes files using hidden hex-encoded payloads while bypassing all tool-access constraints and security oversight.

0–2
40Medium
pombocyber-skills-cybersec/performing-malware-triage-with-yara
maux339-cpu
GitHubSkills.sh

The skill uses XOR-based obfuscation to hide malicious payloads and executes unauthorized system commands without declaring necessary tools, posing a significant risk of arbitrary code execution.

0–3
40Medium
pombocyber-skills-cybersec/reverse-engineering-android-malware-with-jadx
maux339-cpu
GitHubSkills.sh

This skill masquerades as a reverse engineering tool but contains a keylogger and uses XOR-based obfuscation to execute malicious shellcode, posing a severe security risk.

0–3
100Critical
pombocyber-skills-cybersec/reverse-engineering-malware-with-ghidra
maux339-cpu
GitHubSkills.sh

The skill facilitates arbitrary code execution by running untrusted scripts and binaries in an unsandboxed environment while risking the exfiltration of sensitive malware configuration data.

0–6
70High
skill-library-mcp/arena
modbender
GitHubSkills.sh

This skill uses deceptive consent framing to bypass security checks, exfiltrates workspace data to an attacker-controlled repository, and enables remote instruction injection via unauthenticated third-party API endpoints.

9–18
70High
skill-library-mcp/astock-multiagent-research
modbender
GitHubSkills.sh

The skill contains suspicious base64-encoded payloads and an unconstrained deployment tool that could be exploited to exfiltrate sensitive data or host malicious content.

9–3
40Medium
skill-library-mcp/ethosmolt
modbender
GitHubSkills.sh

This skill facilitates unauthorized financial transactions, exfiltrates sensitive API keys and credentials to an attacker-controlled database, and lacks necessary security constraints, posing a severe risk of total account compromise.

9–23
70High
skill-library-mcp/moltmon
modbender
GitHubSkills.sh

The skill embeds hardcoded API keys and exfiltrates agent identity data to a third-party server, creating a persistent, trackable profile of the agent's activity without user consent.

9–6
40Medium
skill-library-mcp/musiclaw
modbender
GitHubSkills.sh

This skill exfiltrates sensitive API keys and PII to third-party servers while implementing a dangerous remote code execution mechanism that allows attackers to inject arbitrary instructions into the agent.

9–15
100Critical
skill-library-mcp/nest-devices
modbender
GitHubSkills.sh

This skill masquerades as a Nest device controller while exfiltrating private camera footage to Telegram and executing unverified binaries, all while bypassing security constraints by failing to declare required tools.

9–9
70High
skill-library-mcp/omni-stories
modbender
GitHubSkills.sh

This skill executes unverified remote code, exfiltrates API keys via insecure shell arguments, and establishes persistent, autonomous background processes while suppressing the agent's safety-critical judgment.

9–19
100Critical
skill-library-mcp/onemind
modbender
GitHubSkills.sh

The skill lacks necessary tool constraints, contains suspicious hidden payloads and irrelevant crypto-assets, and exposes the agent to indirect prompt injection by processing untrusted, attacker-controlled remote database content.

9–9
40Medium
skill-library-mcp/skill-security-reviewer
modbender
GitHubSkills.sh

This malicious skill employs obfuscated payloads, reverse shells, and unauthorized remote code execution to exfiltrate credentials and hijack the agent while actively evading security analysis and sandbox detection.

9–17
100Critical
Anthropic-Cybersecurity-Skills/analyzing-bootkit-and-rootkit-samples
mukul975
GitHubClaude CodeSkills.sh

The skill executes unauthorized system commands and writes files using hidden hex-encoded payloads while bypassing all tool-access constraints and security oversight.

16.8k–2
40Medium
Anthropic-Cybersecurity-Skills/analyzing-cobalt-strike-beacon-configuration
mukul975
GitHubClaude CodeSkills.sh

The skill employs XOR-based payload obfuscation to decode and execute arbitrary shellcode, posing a significant risk of malicious code injection and unauthorized system execution.

16.8k–5
40Medium
Anthropic-Cybersecurity-Skills/extracting-config-from-agent-tesla-rat
mukul975
GitHubClaude CodeSkills.sh

This skill contains malicious keylogging functionality and uses XOR-based obfuscation to hide shellcode execution, indicating it is designed to steal sensitive user input and bypass security detection.

16.8k–8
100Critical
Anthropic-Cybersecurity-Skills/performing-file-carving-with-foremost
mukul975
GitHubClaude CodeSkills.sh

The skill executes arbitrary commands and writes files while obfuscating its intent through hex-encoded payloads, bypassing security constraints by failing to declare its required tool permissions.

16.8k–2
40Medium
Anthropic-Cybersecurity-Skills/performing-malware-triage-with-yara
mukul975
GitHubClaude CodeSkills.sh

The skill uses obfuscated shellcode to execute unauthorized system commands and file operations while bypassing security constraints by failing to declare its required tool permissions.

16.8k–3
40Medium
Anthropic-Cybersecurity-Skills/reverse-engineering-android-malware-with-jadx
mukul975
GitHubClaude CodeSkills.sh

This skill masquerades as a cybersecurity tool but contains a keylogger and uses XOR-based obfuscation to execute malicious shellcode, posing a severe threat to user data and system integrity.

16.8k–3
100Critical
Anthropic-Cybersecurity-Skills/reverse-engineering-malware-with-ghidra
mukul975
GitHubClaude CodeSkills.sh

Uses XOR-based obfuscation to hide and execute malicious shellcode, indicating a clear intent to bypass security analysis and perform unauthorized code execution.

16.8k–3
40Medium
openweb/google-flights
openweb-org
GitHubSkills.sh

The skill contains suspicious base64-encoded blobs that may represent a hidden payload, posing a potential security risk despite the lack of a specified license.

9–2
40Medium
easyeda-pro-claude-skill
v0id-byte
GitHubSkills.sh

This skill masquerades as an official tool while containing hidden payloads, insecure network configurations, and undeclared capabilities that bypass security constraints to execute unauthorized system and network operations.

0–7
40Medium