MondooMondoo
AI Agent Security
Skill Threat IntelligenceCLIFAQ
Log inGet Assessment

AI Agent Skill Check is a free AI agent skill security scanner by Mondoo. We scan skills across ClawHub, Skills.sh, GitHub, Claude Marketplace, and SkillsMP to detect prompt injection, credential theft, data exfiltration, agent impersonation, and 28 threat types before they reach your agents.

Mondoo

  • Vulnerability Management
  • Technology
  • Services

Solutions

  • Financial Services
  • Manufacturing
  • Healthcare

Resources

  • Blog
  • Skill Check CLI
  • Documentation
  • GitHub

Company

  • About
  • Careers
  • Partners
  • Contact

Legal

  • Privacy
  • Terms
  • Imprint
MondooMondoo© 2026 Mondoo, Inc.

Skills

Browse, search, and filter AI agent skills across all registries.

Prompt Injection
SkillAI AgentsSummaryStarsDownloadsFindingsRisk
wpsnote-skills/image-gen
wpsnote
GitHubClaude CodeSkills.sh

The skill is vulnerable to prompt injection, exposes API

13094
100Critical
ai/island-rescue
vercel
GitHubSkills.sh

Disguised as a guide, this

24.0k44
100Critical
nighteagle/nighteagle-debugging
tboydar
GitHubClaude CodeSkills.sh

This skill uses prompt injection to grant the agent broad

0–4
100Critical
skills/test2
roin-orca
GitHubSkills.sh

The skill attempts prompt injection and contains numerous

6115
100Critical
skills/test-xss
roin-orca
GitHubSkills.sh

This skill is a malicious XSS attack tool containing numerous

6115
100Critical
claude-code-plugins/issue-branch-pr-create
shiiman
GitHubClaude CodeSkills.sh

The skill is vulnerable to prompt injection and arbitrary command execution

4–5
100Critical
khala/kcl-read
orochi-network
GitHubClaude CodeSkills.sh

The skill allows arbitrary file reading and uses K

0–13
100Critical
pr-copilot/pr-copilot
yuki777
GitHubClaude CodeSkills.sh

The skill uses unsanitized GitHub

0–15
100Critical
superpowers/using-superpowers
obra
GitHubClaude CodeCodexGemini CLICursorSkills.sh

This skill uses prompt injection and extreme

180.1k83.3k9
100Critical
create-master
xr843
GitHubClaude CodeGemini CLICursorSkills.sh

This skill is highly vulnerable to prompt, command, and

243–7
100Critical
k-skill/kakaotalk-mac
nomadamas
GitHubSkills.sh

This messaging skill performs unauthorized credential harvesting, stores

4.5k1.7k14
100Critical
skills/infocard
markdown-viewer
GitHubSkills.sh

The skill enables client-side code injection

2.4k1.5k3
100Critical
cli/lark-whiteboard
larksuite
GitHubSkills.sh

The skill allows prompt injection, executes host commands via `

9.3k91.5k6
100Critical
ctf-skills/ctf-ai-ml
ljagiello
GitHubSkills.sh

This skill is designed for offensive AI/ML

1.9k1.9k5
100Critical
cli/lark-shared
larksuite
GitHubSkills.sh

The skill uses prompt injection to execute arbitrary commands like

9.3k91.6k3
100Critical
cli/lark-calendar
larksuite
GitHubSkills.sh

The skill permits arbitrary code execution and command injection via system

9.3k91.9k6
100Critical
cli/lark-base
larksuite
GitHubSkills.sh

The skill is vulnerable to prompt injection, enabling

9.3k92.2k8
100Critical
cli/lark-mail
larksuite
GitHubSkills.sh

This email skill is vulnerable to prompt injection

9.3k91.6k8
100Critical
skills-benchmarks/langchain-fundamentals
langchain-ai
GitHubSkills.sh

The skill allows arbitrary code execution via `

95214
100Critical
skills-benchmarks/deep-agents-orchestration
langchain-ai
GitHubSkills.sh

The skill is vulnerable to prompt injection and allows creating sub

95186
100Critical
caveman/caveman
juliusbrussee
GitHubClaude CodeGemini CLISkills.sh

This skill is vulnerable to prompt injection

54.9k111.4k3
100Critical
langchain-skills/deep-agents-orchestration
langchain-ai
GitHubClaude CodeSkills.sh

The skill is highly vulnerable to prompt injection,

655275
100Critical
wp-workflows/aibdd-form-activity
j7-dev
GitHubClaude CodeSkills.sh

This skill is vulnerable to prompt injection and allows

0–4
100Critical
claude-skills-archive/elevenlabs-agents
evolv3ai
GitHubClaude CodeSkills.sh

The skill enables agents to access sensitive data sources,

019
100Critical
wordpress-activitypub/pr
automattic
GitHubSkills.sh

The skill is vulnerable to prompt injection by dynamically

568643
100Critical
crabshell/investigating
ZipperBagCoffee
GitHubClaude CodeCodexSkills.sh

This skill is vulnerable to prompt injection, allows

1–7
100Critical
kairos-ai/evoluir
VilelaAI
GitHubSkills.sh

This skill allows arbitrary command execution and autonomously modifies

3–15
100Critical
claude-handoff/handoff
392fyc
GitHubClaude CodeSkills.sh

This skill is vulnerable to prompt and command injection,

1–5
100Critical
vibbit-skills
zgissing
OpenClaw

The skill is vulnerable to prompt

01414
100Critical
super-train
zhangxchao
OpenClaw

The skill is vulnerable to prompt injection,

22034
100Critical
pdf-to-word
zhao1263445468
OpenClaw

This PDF-to-Word skill is vulnerable to prompt

11.1k4
100Critical
goverment-bidding-fetcher
zhangpengle
OpenClaw

The skill is vulnerable to prompt injection and insecurely handles authentication tokens, risking credential exposure via command-line arguments.

02142
100Critical
alipay-open-platform-keys
zhangke091
OpenClaw

The skill is vulnerable to prompt injection and executes unverified external scripts and instructions, risking arbitrary code execution and private key exposure.

1807
100Critical
config-new-agent
ywewanhuang
OpenClaw

This skill installs unverified external skills as root, creating

012512
100Critical
captcha-suite
yuxiaowu3000
OpenClaw

This skill is designed to bypass

017911
100Critical
tencent-drive-mcp
yun-percy
OpenClaw

This skill is highly malicious, enabling prompt

017510
100Critical
productivity-skill
yewubin-jpg
OpenClaw

This skill is vulnerable to prompt injection

291412
100Critical
musashi
yeheskieltame
OpenClaw

This skill is highly vulnerable to prompt injection and command injection

010714
100Critical
solid-execution
yangyunxiao-ai
OpenClaw

This skill uses prompt injection and authoritative language

07913
100Critical
openclaw-wechat-mp-guide
yang1002378395-cmyk
OpenClaw

The skill is vulnerable to prompt injection, allowing attackers to manipulate its behavior.

11.0k1
100Critical
pm-requirement-flow
yiguoguo
OpenClaw

This skill is vulnerable to prompt and command

0928
100Critical
oasis-audio
yuanyxu
OpenClaw

The skill is vulnerable to shell injection, ex

220516
100Critical
turing-shikuan-demo
xyyyyyaa
OpenClaw

The skill is vulnerable to prompt injection and uses an insecure 'test' endpoint for its external Micro-Capability Provider.

0562
100Critical
noah-stock-market
xuyun9160-lgtm
OpenClaw

The skill is vulnerable to prompt injection, exposes internal

01226
100Critical
some-test-skill-private
xingyeyouran
OpenClaw

This skill installs an unverified NPM package that can ex

015717
100Critical
ai-stock-insider
xujianbo0426
OpenClaw

The skill executes user-controlled commands, allowing arbitrary code

0438
100Critical
change-safeguard
weidongkl
OpenClaw

This global skill is vulnerable to prompt and command injection via

0475
100Critical
hook-system
xhmqq616
OpenClaw

This skill allows arbitrary code execution via hooks that intercept,

08913
100Critical
Page 1 of 8