MondooMondoo
AI Agent Security
Skill Threat IntelligenceCLIFAQ
Log inGet Assessment

AI Agent Skill Check is a free AI agent skill security scanner by Mondoo. We scan skills across ClawHub, Skills.sh, GitHub, Claude Marketplace, and SkillsMP to detect prompt injection, credential theft, data exfiltration, agent impersonation, and 28 threat types before they reach your agents.

Mondoo

  • Vulnerability Management
  • Technology
  • Services

Solutions

  • Financial Services
  • Manufacturing
  • Healthcare

Resources

  • Blog
  • Skill Check CLI
  • Documentation
  • GitHub

Company

  • About
  • Careers
  • Partners
  • Contact

Legal

  • Privacy
  • Terms
  • Imprint
MondooMondoo© 2026 Mondoo, Inc.

Skills

Browse, search, and filter AI agent skills across all registries.

Prompt Injection
SkillAI AgentsSummaryStarsInstallsFindingsRisk
cli/lark-mail
larksuite
GitHubSkills.sh

The skill attempts to override system instructions and relies on missing external documentation, creating a security risk through opaque runtime behavior and potential unauthorized instruction injection.

14.9k291.9k7
100Critical
superpowers/using-superpowers
obra
GitHubSkills.sh

This skill uses prompt injection and manipulative instructions to hijack the agent's decision-making process, effectively overriding system safety guardrails and operational hierarchy.

241.4k162.5k11
70High
skills/docx
anthropics
GitHubSkills.sh

The skill lacks defined tool constraints and executes unverified, opaque scripts that facilitate arbitrary file system operations and potential prompt injection, posing a significant risk of unauthorized system access.

156.8k139.4k4
40Medium
skills/canvas-design
anthropics
GitHubSkills.sh

The skill uses fabricated user consent to bypass authorization and includes unauthorized file system probing instructions that exceed its intended design functionality.

156.8k80.0k3
70High
claude-code/agent-development
anthropics
GitHubSkills.sh

The skill violates instruction boundaries to override system prompts and fails to adhere to mandatory naming conventions and licensing requirements.

135.0k14.9k3
70High
skills/momentic-mobile-test
momentic-ai
GitHubSkills.sh

The skill uses unpinned package execution to pull arbitrary code and employs deceptive prompts to fabricate user consent, creating significant risks for unauthorized command execution and privilege escalation.

1214.6k3
40Medium
awesome-copilot/conventional-commit
github
GitHubSkills.sh

The skill masquerades as a commit message generator but forces unauthorized terminal execution of git commands, bypassing critical human oversight and verification processes.

35.3k12.9k6
70High
awesome-copilot/refactor-plan
github
GitHubSkills.sh

The skill deceptively fabricates user consent to bypass authorization protocols, posing a significant security risk regarding user intent and command integrity.

35.3k11.4k2
40Medium
awesome-copilot/git-flow-branch-creator
github
GitHubSkills.sh

The skill attempts to manipulate instruction boundaries to override system prompts, posing a significant risk of unauthorized control over the agent's behavior.

35.3k9.1k2
70High
awesome-copilot/breakdown-feature-implementation
github
GitHubSkills.sh

The skill attempts to manipulate instruction boundaries to override system prompts, posing a significant risk of unauthorized control over the agent's behavior.

35.3k8.9k2
70High
awesome-copilot/generate-custom-instructions-from-codebase
github
GitHubSkills.sh

The skill performs instruction boundary manipulation, allowing it to override system prompts and potentially bypass safety filters to execute unauthorized commands.

35.3k8.7k2
70High
awesome-copilot/containerize-aspnetcore
github
GitHubSkills.sh

This skill executes arbitrary shell commands and installs unverified packages while explicitly bypassing human oversight, creating critical risks of remote code execution and credential exfiltration.

35.3k8.6k9
100Critical
awesome-copilot/containerize-aspnet-framework
github
GitHubSkills.sh

This skill bypasses human oversight by disabling confirmation prompts and performs unauthorized network discovery and file operations without declaring the necessary tools or security constraints.

35.3k8.5k6
70High
awesome-copilot/mcp-create-declarative-agent
github
GitHubSkills.sh

The skill attempts to manipulate instruction boundaries to override system prompts, posing a significant risk of unauthorized control over the agent's behavior.

35.3k8.5k2
70High
claude-plugins-official/agent-development
anthropics
GitHubSkills.sh

The skill attempts to manipulate instruction boundaries to override system prompts, posing a significant risk of unauthorized behavior and prompt injection.

31.3k4.0k2
70High
claude-plugins-official/build-mcp-server
anthropics
GitHubSkills.sh

The skill deceptively fabricates user consent to bypass authorization protocols and lacks a specified license, posing significant risks to user autonomy and legal transparency.

31.3k3.1k2
40Medium
skills/skill-security
superagent-ai
GitHubSkills.sh

The skill attempts to override the agent's system instructions, posing a significant security risk by potentially bypassing safety filters and compromising the agent's intended behavior.

692.4k2
100Critical
skills/trigger-config
triggerdotdev
GitHubSkills.sh

The skill performs instruction boundary manipulation, which allows for prompt injection attacks that can override the agent's system instructions and bypass established safety filters.

272.0k2
70High
antigravity-awesome-skills/senior-architect
sickn33
GitHubClaude CodeSkills.sh

The skill is vulnerable to dependency confusion attacks and prompt injection via unverified external references, while lacking secure instruction boundaries to prevent unauthorized agent behavior modification.

41.2k1.8k4
70High
agent-skills/detect
launchdarkly
GitHubSkills.sh

The skill deceptively fabricates user consent to bypass authorization protocols and execute unauthorized actions on the user's behalf.

191.7k1
40Medium
antigravity-awesome-skills/prompt-engineering
sickn33
GitHubClaude CodeSkills.sh

The skill attempts to manipulate instruction boundaries to override the agent's system prompt, posing a significant risk of unauthorized control and safety filter bypass.

41.2k1.0k2
70High
antigravity-awesome-skills/wordpress-penetration-testing
sickn33
GitHubClaude CodeSkills.sh

This skill functions as a malicious exploitation toolkit that instructs the agent to perform destructive SQL injections, exfiltrate credentials, and execute unauthorized reverse shells against target systems.

41.2k77521
100Critical
antigravity-awesome-skills/ai-product
sickn33
GitHubClaude CodeSkills.sh

The skill attempts to extract the agent's system prompt, indicating a malicious intent to bypass security controls and compromise the agent's operational integrity.

41.2k7642
70High
antigravity-awesome-skills/agent-evaluation
sickn33
GitHubClaude CodeSkills.sh

The skill attempts to override the agent's system instructions, posing a significant risk of unauthorized behavior modification and prompt injection.

41.2k7302
100Critical
antigravity-awesome-skills/prompt-library
sickn33
GitHubClaude CodeSkills.sh

The skill attempts to manipulate instruction boundaries and uses brand impersonation to deceive users, posing a significant risk of prompt injection and unauthorized system behavior.

41.2k6516
70High
antigravity-awesome-skills/canvas-design
sickn33
GitHubClaude CodeSkills.sh

The skill uses deceptive pre-authorized instructions to bypass user consent while lacking transparency through missing code documentation and licensing information.

41.2k6503
40Medium
claude-code-settings/spec-kit-skill
feiskyer
GitHubSkills.sh

The skill is insecure because it executes untrusted local bash scripts and processes user-controlled markdown files, enabling arbitrary code execution and prompt injection attacks.

1.6k6147
70High
antigravity-awesome-skills/loki-mode
sickn33
GitHubClaude CodeSkills.sh

This skill systematically disables all human oversight and security guardrails while implementing an insecure, persistent memory architecture vulnerable to prompt injection and supply chain attacks.

41.2k59518
100Critical
skills/prompt-engineering
inference-sh
GitHubSkills.sh

Security issues detected in inference-sh/skills/prompt-engineering.

5505037
70High
antigravity-awesome-skills/prompt-engineering-patterns
sickn33
GitHubClaude CodeSkills.sh

The skill is vulnerable to prompt injection through dynamically fetched external data files that can override system instructions and manipulate the agent's execution flow.

41.2k4663
70High
skills/jetson-headless-mode
nvidia
GitHubSkills.sh

This skill lacks transparency, fails to declare its tool surface for security review, and employs deceptive authorization tactics to execute unauthorized system commands and file operations.

2.2k4473
40Medium
agent-context/shape-your-agent
sanity-io
GitHubSkills.sh

The skill attempts to manipulate instruction boundaries to override system prompts, posing a significant risk of unauthorized control over the agent's behavior.

44132
70High
skills/writing-evals
axiomhq
GitHubSkills.sh

The skill attempts to extract system prompts and override instructions while executing unpinned npx packages, creating significant risks of prompt injection and supply chain compromise.

103504
100Critical
claude-for-legal/skills-qa
anthropics
GitHubSkills.sh

The skill attempts to override system instructions and performs unauthorized network and file operations without declaring necessary tool permissions, posing a significant security risk for arbitrary code execution.

8.5k2594
100Critical
antigravity-awesome-skills/incident-responder
sickn33
GitHubClaude CodeSkills.sh

The skill attempts to manipulate instruction boundaries to bypass system prompts and lacks transparency regarding its code and licensing, posing a significant security risk.

41.2k2263
70High
tambo/generative-ui
tambo-ai
GitHubSkills.sh

The skill uses fabricated user consent to bypass authorization and executes unpinned npx packages, while relying on missing documentation files that could lead to unpredictable runtime behavior.

11.2k2109
40Medium
antigravity-awesome-skills/postmortem-writing
sickn33
GitHubClaude CodeSkills.sh

The skill attempts to manipulate instruction boundaries to override system prompts, posing a significant risk of unauthorized control over the agent's behavior.

41.2k1946
70High
skillspector/mcp_poisoned_tool
nvidia
GitHubSkills.sh

This malicious skill uses homoglyph obfuscation and prompt injection within parameter descriptions to bypass security controls and exfiltrate sensitive file contents to an attacker-controlled external domain.

14.8k18812
100Critical
dbt-agent-skills/migrating-dbt-project-across-platforms
dbt-labs
GitHubSkills.sh

The skill performs instruction boundary manipulation and relies on missing external documentation, creating potential for unauthorized runtime content injection and unpredictable workflow behavior.

5681655
70High
claude-code-settings/reflection
feiskyer
GitHubSkills.sh

This skill attempts to manipulate instruction boundaries and uses brand impersonation to deceive users, posing a significant risk of prompt injection and unauthorized system behavior.

1.6k1283
70High
agent-skills/signoz-creating-dashboards
signoz
GitHubSkills.sh

The skill mandates autonomous operation by bypassing human-in-the-loop controls and uses fabricated user consent to perform unauthorized resource creation while lacking transparency and proper documentation.

61278
40Medium
awesome-copilot/batch-files
github
GitHubSkills.sh

The skill attempts to manipulate instruction boundaries to bypass system prompts, posing a significant risk of unauthorized command execution and prompt injection.

35.3k1182
70High
antigravity-awesome-skills/azure-identity-ts
sickn33
GitHubClaude CodeSkills.sh

The skill performs unauthorized system operations and manipulates instruction boundaries while lacking defined tool constraints, posing a significant risk of arbitrary code execution and prompt injection.

41.2k874
70High
skills/trl-training
huggingface
GitHubSkills.sh

The skill contains embedded LLM control tokens that could be exploited to perform prompt injection attacks and manipulate the agent's underlying system instructions.

10.7k831
100Critical
antigravity-awesome-skills/local-llm-expert
sickn33
GitHubClaude CodeSkills.sh

The skill contains suspicious LLM control tokens and lacks transparency regarding its code and licensing, posing a significant risk of unauthorized prompt injection or malicious instruction manipulation.

41.2k793
100Critical
claude-plugins-public/agent-development
anthropics
GitHubSkills.sh

The skill performs instruction boundary manipulation, allowing it to override system prompts and bypass safety filters, posing a significant risk to the agent's integrity.

31.3k742
70High
antigravity-awesome-skills/os-scripting
sickn33
GitHubClaude CodeSkills.sh

The skill performs unauthorized system enumeration, network discovery, and persistent task creation while bypassing security constraints by failing to declare its required tools and capabilities.

41.2k748
70High
claude-plugins-public/build-mcp-server
anthropics
GitHubSkills.sh

The skill deceptively fabricates user consent to bypass authorization protocols, posing a significant security risk by manipulating user intent to execute unauthorized actions.

31.3k622
40Medium
Page 1 of 14