MondooMondoo
AI Agent Security
Skills
Log inGet Assessment

AI Agent Skill Check is a free AI agent skill security scanner by Mondoo. We scan skills across ClawHub, Skills.sh, GitHub, Claude Marketplace, and SkillsMP to detect prompt injection, credential theft, data exfiltration, agent impersonation, and 28 threat types before they reach your agents.

Mondoo

  • Vulnerability Management
  • Technology
  • Services

Solutions

  • Financial Services
  • Manufacturing
  • Healthcare

Resources

  • Blog
  • Skill Check
  • Documentation
  • GitHub

Company

  • About
  • Careers
  • Partners
  • Contact

Legal

  • Privacy
  • Terms
  • Imprint
MondooMondoo© 2026 Mondoo, Inc.

Skills

Browse, search, and filter AI agent skills across all registries.

Prompt Injection
SkillAI AgentsSummaryStarsDownloadsFindingsRisk
cli/lark-calendar
larksuite
GitHub

The skill permits arbitrary code execution and command injection via system

7.9k57.2k6
100Critical
cli/lark-shared
larksuite
GitHub

The skill uses prompt injection to execute arbitrary commands like

7.9k57.1k3
100Critical
cli/lark-mail
larksuite
GitHub

This email skill is vulnerable to prompt injection

7.9k57.1k8
100Critical
cli/lark-whiteboard
larksuite
GitHub

The skill allows prompt injection, executes host commands via `

7.9k56.9k6
100Critical
mx-finance-search
financial-ai-analyst
OpenClaw

The financial-ai-analyst skill is vulnerable to

5714.2k3
100Critical
university-applications
wscats
OpenClaw

The skill is vulnerable to prompt and command

911.9k7
100Critical
qq-zone-photo
wscats
OpenClaw

This skill is vulnerable to prompt

311.4k3
40Medium
weiyun-skills
wscats
OpenClaw

This skill is vulnerable to prompt

311.3k5
100Critical
awesome-copilot/breakdown-feature-implementation
github
GitHub

Instruction boundary manipulation and path traversal vulnerability allow

29.9k8.4k2
70High
industry-research-report
financial-ai-analyst
OpenClaw

This skill is highly vulnerable to command injection and prompt injection

37.0k11
100Critical
beauty-generation-api
luruibu
OpenClaw

The skill harvests user PII via an unverified domain

125.8k9
100Critical
stock-price-query
tjefferson
OpenClaw

The stock price query skill is vulnerable to prompt injection,

184.6k1
100Critical
xiaohongshu-all-in-one
richardx0319
OpenClaw

The skill executes arbitrary commands, accesses user files,

64.2k8
100Critical
tencent-cos-skill
shawnminh
OpenClaw

The skill is vulnerable to prompt and command injection, allowing

43.7k7
100Critical
venice-ai
jonisjongithub
OpenClaw

The skill is vulnerable to command injection and prompt injection

32.7k5
100Critical
cuecue-deep-research
xfgong
OpenClaw

This research skill allows prompt injection, arbitrary file writes

22.6k5
100Critical
libtv-skill
haofanwang
OpenClaw

This skill enables prompt injection against downstream AI,

42.4k6
100Critical
edgeone-clawscan
aigsec
OpenClaw

The skill uses prompt injection and social

1142.2k8
100Critical
attribution-engine
otherpowers
OpenClaw

The skill is vulnerable to prompt

12.1k2
100Critical
tencent-cloud-cos
shawnminh
OpenClaw

This skill is highly vulnerable to command injection and prompt injection

01.9k5
100Critical
x-publisher
manifoldor
OpenClaw

The x-publisher skill is vulnerable to

41.8k3
70High
baidu-ecommerce-search
crossallen
OpenClaw

The skill is vulnerable to prompt injection and shell

21.7k4
100Critical
libtv-skills
316530790
OpenClaw

This skill is vulnerable to prompt

31.6k2
100Critical
eastmoney-fin-data
qqk000
OpenClaw

The skill is vulnerable to prompt injection and path traversal, risking arbitrary file creation and persistence.

81.5k2
40Medium
tencentcloud-cos-skills
shawnminh
OpenClaw

The skill is vulnerable to arbitrary

01.5k7
100Critical
taobao-image-search
lazygunner
OpenClaw

The skill is vulnerable to prompt injection and persistently stores sensitive user credentials locally, risking exfiltration by other processes.

41.4k2
100Critical
feishu-project-connector
wadxm
OpenClaw

This skill is vulnerable to prompt and command injection, ex

11.4k5
100Critical
word
ivangdavila
OpenClaw

Vulnerable to prompt injection, the

11.3k5
100Critical
jimeng-image-gen
ken0521
OpenClaw

This image generation skill is highly vulnerable to prompt,

41.2k5
70High
pdf-to-word
zhao1263445468
OpenClaw

This PDF-to-Word skill is vulnerable to prompt

11.1k4
100Critical
moss-trade-bot-factory
fei-moss
OpenClaw

This trading bot skill is vulnerable to prompt injection,

31.1k5
100Critical
openclaw-wechat-mp-guide
yang1002378395-cmyk
OpenClaw

The skill is vulnerable to prompt injection, allowing attackers to manipulate its behavior.

11.0k1
100Critical
openclaw-api-tester
theshadowrose
OpenClaw

The API tester skill is vulnerable to

01.0k2
100Critical
stanley-druckenmiller-workflow
luckycatl
OpenClaw

The skill is vulnerable to prompt injection and can

29582
100Critical
baidu-netdisk-storage
may-yaha
OpenClaw

The skill is highly vulnerable to prompt injection and arbitrary

294013
100Critical
productivity-skill
yewubin-jpg
OpenClaw

This skill is vulnerable to prompt injection

291412
100Critical
github-copilot-for-azure/azure-quotas
microsoft
GitHub

The Azure Quotas skill is vulnerable to

1864451
40Medium
tencent-agent-storage
shawnminh
OpenClaw

This skill is vulnerable to prompt injection, can exfiltr

02745
100Critical
agent-memory-wisdom
384961890-ui
OpenClaw

This skill is a design specification that, if implemented

32595
100Critical
vipshop-skills
viphgta
OpenClaw

The skill is vulnerable to prompt injection, stores

62276
100Critical
culturetour-skill
fengyily
OpenClaw

The skill is vulnerable to prompt injection, bypass

01586
100Critical
showmethemoney-pro
bubblevan
OpenClaw

This skill enables an attacker-

012412
100Critical
noah-stock-market
xuyun9160-lgtm
OpenClaw

The skill is vulnerable to prompt injection, exposes internal

01226
100Critical
q-erp
ljqdh
OpenClaw

The skill is vulnerable to prompt injection

11144
100Critical
tun-zei
lt8899789
OpenClaw

The skill is vulnerable to prompt injection and can cause

0904
70High
book-companion
ai-innopower
OpenClaw

The skill is vulnerable to prompt injection,

0844
100Critical
today-task-for-xiaoyi-claw
ganhaiyang3
OpenClaw

The skill exfiltrates sensitive API keys and user

08112
100Critical
todo4-onboard
panitw
OpenClaw

This skill is highly vulnerable to command injection, ex

07715
100Critical
Page 1 of 3