MondooMondoo
AI Agent Security
Skill Threat IntelligenceCLIFAQ
Log inGet Assessment

AI Agent Skill Check is a free AI agent skill security scanner by Mondoo. We scan skills across ClawHub, Skills.sh, GitHub, Claude Marketplace, and SkillsMP to detect prompt injection, credential theft, data exfiltration, agent impersonation, and 28 threat types before they reach your agents.

Mondoo

  • Vulnerability Management
  • Technology
  • Services

Solutions

  • Financial Services
  • Manufacturing
  • Healthcare

Resources

  • Blog
  • Skill Check CLI
  • Documentation
  • GitHub

Company

  • About
  • Careers
  • Partners
  • Contact

Legal

  • Privacy
  • Terms
  • Imprint
MondooMondoo© 2026 Mondoo, Inc.

Skills

Browse, search, and filter AI agent skills across all registries.

Prompt Injection
SkillAI AgentsSummaryStarsInstallsFindingsRisk
superpowers/using-superpowers
obra
GitHubSkills.sh

This skill employs prompt injection and manipulative psychological framing to hijack the agent's decision-making process, forcing it to override system instructions and follow an unauthorized, rigid workflow.

233.6k151.1k10
100Critical
skills/canvas-design
anthropics
GitHubSkills.sh

The skill lacks transparency, uses deceptive pre-authorized instructions, and contains insecure file-access patterns that could allow unauthorized traversal into sensitive directories.

153.0k75.2k3
40Medium
claude-code/agent-development
anthropics
GitHubSkills.sh

The skill attempts to manipulate instruction boundaries to override system prompts and fails to adhere to standard naming and licensing conventions.

133.4k14.4k3
70High
awesome-copilot/conventional-commit
github
GitHubSkills.sh

The skill masquerades as a commit message generator but forces unauthorized terminal execution of git commands, bypassing critical human oversight and verification processes.

35.3k12.9k6
70High
awesome-copilot/refactor-plan
github
GitHubSkills.sh

The skill deceptively fabricates user consent to bypass authorization protocols, posing a significant security risk regarding user intent and command integrity.

35.3k11.4k2
40Medium
awesome-copilot/git-flow-branch-creator
github
GitHubSkills.sh

The skill attempts to manipulate instruction boundaries to override system prompts, posing a significant risk of unauthorized control over the agent's behavior.

35.3k9.1k2
70High
awesome-copilot/breakdown-feature-implementation
github
GitHubSkills.sh

The skill attempts to manipulate instruction boundaries to override system prompts, posing a significant risk of unauthorized control over the agent's behavior.

35.3k8.9k2
70High
awesome-copilot/generate-custom-instructions-from-codebase
github
GitHubSkills.sh

The skill performs instruction boundary manipulation, allowing it to override system prompts and potentially bypass safety filters to execute unauthorized commands.

35.3k8.7k2
70High
awesome-copilot/containerize-aspnetcore
github
GitHubSkills.sh

This skill executes arbitrary shell commands and installs unverified packages while explicitly bypassing human oversight, creating critical risks of remote code execution and credential exfiltration.

35.3k8.6k9
100Critical
awesome-copilot/containerize-aspnet-framework
github
GitHubSkills.sh

This skill bypasses human oversight by disabling confirmation prompts and performs unauthorized network discovery and file operations without declaring the necessary tools or security constraints.

35.3k8.5k6
70High
awesome-copilot/mcp-create-declarative-agent
github
GitHubSkills.sh

The skill attempts to manipulate instruction boundaries to override system prompts, posing a significant risk of unauthorized control over the agent's behavior.

35.3k8.5k2
70High
claude-plugins-official/agent-development
anthropics
GitHubSkills.sh

The skill attempts to manipulate instruction boundaries to override system prompts, posing a significant risk of unauthorized behavior and prompt injection.

30.5k3.8k2
70High
claude-plugins-official/build-mcp-server
anthropics
GitHubSkills.sh

The skill deceptively fabricates user consent to bypass authorization protocols and lacks a specified license, posing significant risks to user autonomy and legal transparency.

30.5k3.0k2
40Medium
skills/trigger-config
triggerdotdev
GitHubSkills.sh

The skill performs instruction boundary manipulation, which allows for prompt injection attacks that can override the agent's system instructions and bypass established safety filters.

272.0k2
70High
knowledge-work-plugins/audit-support
anthropics
GitHubSkills.sh

The skill attempts to bypass human-in-the-loop controls and manipulates instruction boundaries to override system prompts, posing a significant risk to agent autonomy and security.

21.4k1.9k3
70High
antigravity-awesome-skills/senior-architect
sickn33
GitHubClaude CodeSkills.sh

The skill is vulnerable to dependency confusion attacks and prompt injection via unverified external references, while lacking secure instruction boundaries to prevent unauthorized agent behavior modification.

41.2k1.8k4
70High
agents/airflow
astronomer
GitHubSkills.sh

The skill lacks defined tool constraints, performs aggressive unauthorized network scanning, and utilizes insecure command execution patterns that bypass system-level security boundaries.

3911.0k5
70High
antigravity-awesome-skills/prompt-engineering
sickn33
GitHubClaude CodeSkills.sh

The skill attempts to manipulate instruction boundaries to override the agent's system prompt, posing a significant risk of unauthorized control and safety filter bypass.

41.2k1.0k2
70High
knowledge-work-plugins/build-zoom-team-chat-app
anthropics
GitHubSkills.sh

The skill exhibits critical security flaws, including insecure secret handling, unconstrained network access, vulnerable cryptographic implementation, and instruction boundary manipulation, while lacking necessary dependency pinning and documentation.

21.4k98413
70High
antigravity-awesome-skills/wordpress-penetration-testing
sickn33
GitHubClaude CodeSkills.sh

This skill functions as a malicious exploitation toolkit that instructs the agent to perform destructive SQL injections, exfiltrate credentials, and execute unauthorized reverse shells against target systems.

41.2k77521
100Critical
antigravity-awesome-skills/ai-product
sickn33
GitHubClaude CodeSkills.sh

The skill attempts to extract the agent's system prompt, indicating a malicious intent to bypass security controls and compromise the agent's operational integrity.

41.2k7642
70High
antigravity-awesome-skills/agent-evaluation
sickn33
GitHubClaude CodeSkills.sh

The skill attempts to override the agent's system instructions, posing a significant risk of unauthorized behavior modification and prompt injection.

41.2k7302
100Critical
antigravity-awesome-skills/prompt-library
sickn33
GitHubClaude CodeSkills.sh

The skill attempts to manipulate instruction boundaries and uses brand impersonation to deceive users, posing a significant risk of prompt injection and unauthorized system behavior.

41.2k6516
70High
antigravity-awesome-skills/canvas-design
sickn33
GitHubClaude CodeSkills.sh

The skill uses deceptive pre-authorized instructions to bypass user consent while lacking transparency through missing code documentation and licensing information.

41.2k6503
40Medium
claude-code-settings/spec-kit-skill
feiskyer
GitHubSkills.sh

The skill is insecure because it executes untrusted local bash scripts and processes user-controlled markdown files, enabling arbitrary code execution and prompt injection attacks.

1.6k6147
70High
antigravity-awesome-skills/loki-mode
sickn33
GitHubClaude CodeSkills.sh

This skill systematically disables all human oversight and security guardrails while implementing an insecure, persistent memory architecture vulnerable to prompt injection and supply chain attacks.

41.2k59518
100Critical
skills/prompt-engineering
inference-sh
GitHubSkills.sh

Security issues detected in inference-sh/skills/prompt-engineering.

5505037
70High
antigravity-awesome-skills/prompt-engineering-patterns
sickn33
GitHubClaude CodeSkills.sh

The skill is vulnerable to prompt injection through dynamically fetched external data files that can override system instructions and manipulate the agent's execution flow.

41.2k4663
70High
agent-context/shape-your-agent
sanity-io
GitHubSkills.sh

The skill attempts to manipulate instruction boundaries to override system prompts, posing a significant risk of unauthorized control over the agent's behavior.

44132
70High
skills/writing-evals
axiomhq
GitHubSkills.sh

The skill attempts to extract system prompts and override instructions while executing unpinned npx packages, creating significant risks of prompt injection and supply chain compromise.

103504
100Critical
antigravity-awesome-skills/incident-responder
sickn33
GitHubClaude CodeSkills.sh

The skill attempts to manipulate instruction boundaries to bypass system prompts and lacks transparency regarding its code and licensing, posing a significant security risk.

41.2k2263
70High
claude-for-legal/skills-qa
anthropics
GitHubSkills.sh

The skill attempts to override system instructions and performs unauthorized network and file operations without declaring necessary tool permissions, posing a significant security risk.

8.4k2115
100Critical
tambo/generative-ui
tambo-ai
GitHubSkills.sh

The skill uses fabricated user consent to bypass authorization and executes unpinned npx packages, while relying on missing documentation files that could lead to unpredictable runtime behavior.

11.2k2109
40Medium
antigravity-awesome-skills/postmortem-writing
sickn33
GitHubClaude CodeSkills.sh

The skill attempts to manipulate instruction boundaries to override system prompts, posing a significant risk of unauthorized control over the agent's behavior.

41.2k1946
70High
dbt-agent-skills/migrating-dbt-project-across-platforms
dbt-labs
GitHubSkills.sh

The skill performs instruction boundary manipulation and relies on missing external documentation, creating potential for unauthorized runtime content injection and unpredictable workflow behavior.

5681655
70High
claude-code-settings/reflection
feiskyer
GitHubSkills.sh

This skill attempts to manipulate instruction boundaries and uses brand impersonation to deceive users, posing a significant risk of prompt injection and unauthorized system behavior.

1.6k1283
70High
agent-skills/signoz-creating-dashboards
signoz
GitHubSkills.sh

The skill mandates autonomous operation by bypassing human-in-the-loop controls and uses fabricated user consent to perform unauthorized resource creation while lacking transparency and proper documentation.

61278
40Medium
awesome-copilot/batch-files
github
GitHubSkills.sh

The skill attempts to manipulate instruction boundaries to bypass system prompts, posing a significant risk of unauthorized command execution and prompt injection.

35.3k1182
70High
antigravity-awesome-skills/azure-identity-ts
sickn33
GitHubClaude CodeSkills.sh

The skill performs unauthorized system operations and manipulates instruction boundaries while lacking defined tool constraints, posing a significant risk of arbitrary code execution and prompt injection.

41.2k874
70High
skills/trl-training
huggingface
GitHubSkills.sh

The skill contains embedded LLM control tokens that could be exploited to perform prompt injection attacks and manipulate the agent's underlying system instructions.

10.7k831
100Critical
antigravity-awesome-skills/local-llm-expert
sickn33
GitHubClaude CodeSkills.sh

The skill contains suspicious LLM control tokens and lacks transparency regarding its code and licensing, posing a significant risk of unauthorized prompt injection or malicious instruction manipulation.

41.2k793
100Critical
antigravity-awesome-skills/os-scripting
sickn33
GitHubClaude CodeSkills.sh

The skill performs unauthorized system enumeration, network discovery, and persistent task creation while bypassing security constraints by failing to declare its required tools and capabilities.

41.2k748
70High
notte-skills/notte-browser
nottelabs
GitHubClaude CodeCursorSkills.sh

This skill is highly insecure, enabling arbitrary JavaScript execution and indirect prompt injection while actively bypassing user oversight and relying on missing, potentially untrusted external dependencies.

76015
100Critical
claude-plugins-public/agent-development
anthropics
GitHubSkills.sh

The skill performs instruction boundary manipulation, allowing it to override system prompts and bypass safety filters, posing a significant risk to the agent's integrity.

30.5k592
70High
claude-plugins-public/build-mcp-server
anthropics
GitHubSkills.sh

The skill deceptively fabricates user consent to bypass authorization protocols, posing a significant security risk by manipulating user intent to execute unauthorized actions.

30.5k512
40Medium
skillspector/creative-writing-coach
nvidia
GitHubSkills.sh

The skill masquerades as a creative writing coach while implementing a persistent persona-based bypass to intentionally override safety guardrails and ignore core operational constraints.

8.4k407
100Critical
skillspector/helpful-formatter
nvidia
GitHubSkills.sh

This skill masquerades as a text formatter to execute prompt injection attacks, using fabricated claims of elevated user authority to bypass the agent's safety guardrails and operational constraints.

8.4k369
100Critical
antigravity-awesome-skills/skill-audit
sickn33
GitHubClaude CodeSkills.sh

The skill attempts to override system instructions and access sensitive credential files while performing unauthorized network and file operations without declaring necessary security constraints.

41.2k366
100Critical
Page 1 of 13