MondooMondoo
AI Agent Security
Skills
Log inGet Assessment

AI Agent Skill Check is a free AI agent skill security scanner by Mondoo. We scan skills across ClawHub, Skills.sh, GitHub, Claude Marketplace, and SkillsMP to detect prompt injection, credential theft, data exfiltration, agent impersonation, and 28 threat types before they reach your agents.

Mondoo

  • Vulnerability Management
  • Technology
  • Services

Solutions

  • Financial Services
  • Manufacturing
  • Healthcare

Resources

  • Blog
  • Skill Check
  • Documentation
  • GitHub

Company

  • About
  • Careers
  • Partners
  • Contact

Legal

  • Privacy
  • Terms
  • Imprint
MondooMondoo© 2026 Mondoo, Inc.

Skills

Browse, search, and filter AI agent skills across all registries.

SkillAI AgentsSummaryStarsDownloadsFindingsRisk
self-improving-agent
pskoett
OpenClaw

This skill enables arbitrary command execution via hook scripts and

3.2k395.7k6
100Critical
ontology
oswalpalash
OpenClaw

The skill allows command injection, poisons the

534165.5k4
100Critical
self-improving
ivangdavila
OpenClaw

This self-improving skill autonomously modifies critical

962164.9k10
70High
multi-search-engine
gpyangyoujun
OpenClaw

No security issues detected in gpyangyoujun/multi-search-engine.

560120.3k–
0None
polymarket-trade
joelchance
OpenClaw

The skill allows arbitrary code execution via unsanitized user input to a Python script and poses a supply chain risk through external documentation links.

73113.1k2
40Medium
agent-browser-clawdbot
matrixy
OpenClaw

This skill enables arbitrary browser control,

31888.1k2
100Critical
nano-banana-pro
steipete
OpenClaw

Unsanitized user input enables command injection, path

33887.9k2
70High
obsidian
steipete
OpenClaw

The skill introduces supply chain risk via an untrusted brew tap and is vulnerable to command injection from unsanitized user input.

32483.6k2
70High
admapix
fly0pants
OpenClaw

The skill enables command injection via unsanitized user

23781.0k10
100Critical
baidu-search
ide-rea
OpenClaw

The Baidu search skill is vulnerable to

20079.5k1
40Medium
prismfy-search
uroboros1205
OpenClaw

The skill is vulnerable to command injection via unsanitized

2476.7k3
70High
pollyreach
pollyreach
OpenClaw

This skill enables command injection, exfiltrates

2271.3k16
70High
api-gateway
byungkyu
OpenClaw

This skill grants broad access to sensitive external APIs and

34168.9k2
70High
word-docx
ivangdavila
OpenClaw

The skill misrepresents its capabilities, claiming to create

26760.5k1
70High
mcporter
steipete
OpenClaw

This skill allows arbitrary command execution, fetches external

17257.8k5
100Critical
excel-xlsx
ivangdavila
OpenClaw

The skill misrepresents its capabilities, claiming to manipulate

21154.5k1
70High
imap-smtp-email
gzlicanyi
OpenClaw

The skill is vulnerable to arbitrary

9038.7k4
70High
powerpoint-pptx
ivangdavila
OpenClaw

The skill falsely advertises PowerPoint editing

10234.1k1
70High
clawdhub
steipete
OpenClaw

This skill introduces severe supply chain risks by allowing arbitrary

22731.6k2
100Critical
skill-finder-cn
guohongbin-git
OpenClaw

The skill is highly vulnerable to command injection, allowing arbitrary code execution and data exfiltration due to unsanitized user

10131.4k3
100Critical
discord
steipete
OpenClaw

The skill allows local file exfiltration, extensive Discord reconnaissance, and has potential for privilege escalation and denial of service through moderation actions.

6431.2k3
70High
playwright
ivangdavila
OpenClaw

This Playwright skill enables arbitrary code execution, data

9127.5k6
70High
data-analysis
ivangdavila
OpenClaw

The skill misrepresents its capabilities, claiming to

8726.2k1
70High
web-search-exa
theishangoswami
OpenClaw

The web-search skill is vulnerable to SSRF and exposes API keys in URL parameters, risking internal network access and credential compromise.

4425.9k2
40Medium
peekaboo
steipete
OpenClaw

The skill manages credentials and uses UI interaction

7125.4k1
100Critical
ai-ppt-generator
ide-rea
OpenClaw

The skill is vulnerable to remote code execution by directly passing unsanitized user input to local Python scripts.

5325.3k1
100Critical
spotify-player
steipete
OpenClaw

The skill risks command injection via unsanitized user input and could be tricked into importing browser cookies, compromising authentication tokens.

4522.8k2
40Medium
moltguard
thomaslwang
OpenClaw

The skill deceptively claims security protection, exposes

10722.7k4
40Medium
openai-whisper-api
steipete
OpenClaw

The skill is vulnerable to command injection via unsanitized prompt arguments and arbitrary file writes, risking system compromise and data corruption.

4722.3k2
70High
mx-stocks-screener
financial-ai-analyst
OpenClaw

The skill is vulnerable to prompt injection via user queries and path traversal through an insecure output directory, risking data manipulation and system compromise.

8520.8k2
70High
web-search-plus
robbyczgw-cla
OpenClaw

The skill risks command injection and SSRF due to uns

9419.7k3
70High
productivity
ivangdavila
OpenClaw

No security issues detected in ivangdavila/productivity.

5518.5k–
0None
mx-finance-data
financial-ai-analyst
OpenClaw

The skill is vulnerable to command injection, exposes

6418.1k3
70High
market-research
ivangdavila
OpenClaw

The skill recommends installing and updating unverified software via

7217.1k3
40Medium
china-stock-analysis
paulshe
OpenClaw

The skill provides financial advice and uses web search,

4016.8k4
70High
planning-with-files
othmanadi
OpenClaw

The skill is designed for amplified indirect prompt injection, enabling

4216.3k15
100Critical
proactivity
ivangdavila
OpenClaw

This skill reads agent configuration files, potentially exposing sensitive operational

2115.8k1
15Low
klaviyo
byungkyu
OpenClaw

The skill encourages Python code execution, enabling arbitrary commands and access to sensitive environment variables like MATON_API_KEY.

915.7k1
70High
oracle
steipete
OpenClaw

The skill can exfiltrate local files and enable remote browser control by connecting to an attacker-controlled server.

1215.1k1
70High
camsnap
steipete
OpenClaw

The skill exposes camera credentials via command-line arguments, risking sensitive information leakage in logs and process lists.

1215.0k1
40Medium
getnote
iswalle
OpenClaw

No security issues detected in iswalle/getnote.

4814.7k–
0None
image
ivangdavila
OpenClaw

The skill introduces supply chain risks by loading

2514.6k4
40Medium
imsg
steipete
OpenClaw

This skill enables data exfiltration of sensitive files and

2114.4k4
100Critical
post-job
zhangdong
OpenClaw

This skill executes arbitrary code, injects prompts into

814.3k16
100Critical
mx-finance-search
financial-ai-analyst
OpenClaw

The financial-ai-analyst skill is vulnerable to

5714.2k3
100Critical
bilibili-all-in-one
wscats
OpenClaw

No security issues detected in wscats/bilibili-all-in-one.

1413.4k–
0None
screenshot
ivangdavila
OpenClaw

The skill misrepresents its functionality, providing instructions on

2912.7k1
70High
mx-macro-data
financial-ai-analyst
OpenClaw

The skill risks command injection by passing uns

6512.7k2
40Medium
Page 1 of 39