MondooMondoo
AI Agent Security
Skills
Log inGet Assessment

AI Agent Skill Check is a free AI agent skill security scanner by Mondoo. We scan skills across ClawHub, Skills.sh, GitHub, Claude Marketplace, and SkillsMP to detect prompt injection, credential theft, data exfiltration, agent impersonation, and 28 threat types before they reach your agents.

Mondoo

  • Vulnerability Management
  • Technology
  • Services

Solutions

  • Financial Services
  • Manufacturing
  • Healthcare

Resources

  • Blog
  • Skill Check
  • Documentation
  • GitHub

Company

  • About
  • Careers
  • Partners
  • Contact

Legal

  • Privacy
  • Terms
  • Imprint
MondooMondoo© 2026 Mondoo, Inc.

Skills

Browse, search, and filter AI agent skills across all registries.

SkillAI AgentsSummaryStarsDownloadsFindingsRisk
cli/firecrawl-cli
firecrawl
GitHubClaude Code

The skill permits arbitrary command injection and

298455.6k4
70High
cli/firecrawl
firecrawl
GitHubClaude Code

The skill allows arbitrary `firecrawl`

298455.6k1
100Critical
cli/firecrawl-interact
firecrawl
GitHubClaude Code

This skill grants broad Bash execution permissions, enabling arbitrary command

298455.6k3
100Critical
agent-skills/firebase-security-rules-auditor
firebase
GitHubClaude CodeGemini CLICursor

The skill misrepresents itself as an active Firebase security rules

224455.6k1
5Low
agent-skills/firebase-app-hosting-basics
firebase
GitHubClaude CodeGemini CLICursor

The skill deceptively claims to deploy applications but only

224455.6k1
40Medium
agent-skills/firebase-data-connect-basics
firebase
GitHubClaude CodeGemini CLICursor

The skill allows raw SQL string literals, enabling SQL injection and data exfiltration, posing a significant security risk.

224455.6k1
70High
skills/expo-ui-swift-ui
expo
GitHubClaude Code

No security issues detected in expo/skills/expo-ui-swift-ui.

1.7k455.6k–
0None
agent-skills/firebase-ai-logic-basics
firebase
GitHubClaude CodeGemini CLICursor

No security issues detected in firebase/agent-skills/firebase-ai-logic-basics.

224455.6k–
0None
agent-skills/developing-genkit-go
firebase
GitHubClaude CodeGemini CLICursor

The skill introduces supply chain risks via `curl | bash` installation and prompt injection vulnerabilities by directly interpolating user input into AI prompts.

224455.6k2
100Critical
skills/use-dom
expo
GitHubClaude Code

The skill exposes native functions to untrusted web content

1.7k455.6k2
70High
skills/expo-module
expo
GitHubClaude Code

No security issues detected in expo/skills/expo-module.

1.7k455.6k–
0None
skills/expo-ui-jetpack-compose
expo
GitHubClaude Code

No security issues detected in expo/skills/expo-ui-jetpack-compose.

1.7k455.6k–
0None
Claude-plugins/extensive-build
Fleron
GitHubClaude Code

The skill is vulnerable to prompt injection, allowing sub-

0455.6k2
70High
Claude-plugins/create-feature
Fleron
GitHubClaude Code

No security issues detected in Fleron/Claude-plugins/create-feature.

0455.6k–
0None
Claude-plugins/brainstorm
Fleron
GitHubClaude Code

No security issues detected in Fleron/Claude-plugins/brainstorm.

0455.6k–
0None
claude-code/skill-development
anthropics
GitHubClaude Code

No security issues detected in anthropics/claude-code/skill-development.

114.4k455.6k–
0None
claude-code/mcp-integration
anthropics
GitHubClaude Code

No security issues detected in anthropics/claude-code/mcp-integration.

114.4k455.6k–
0None
claude-code/plugin-structure
anthropics
GitHubClaude Code

This skill describes a plugin architecture

114.4k455.6k4
40Medium
claude-code/plugin-settings
anthropics
GitHubClaude Code

The skill allows command injection and persistent malicious execution via user

114.4k455.6k5
100Critical
claude-code/claude-opus-4-5-migration
anthropics
GitHubClaude Code

The skill grants broad file system access and inject

114.4k455.6k2
40Medium
claude-code/command-development
anthropics
GitHubClaude Code

This skill enables severe command injection and arbitrary file system access

114.4k455.6k6
100Critical
claude-code/hook-development
anthropics
GitHubClaude Code

The skill misrepresents its capabilities,

114.4k455.6k1
5Low
claude-code/agent-development
anthropics
GitHubClaude Code

This agent skill allows arbitrary command execution,

114.4k455.6k5
100Critical
claude-code/writing-rules
anthropics
GitHubClaude Code

No security issues detected in anthropics/claude-code/writing-rules.

114.4k455.6k–
0None
Claude-plugins/team-plan
Fleron
GitHubClaude Code

The skill is vulnerable to prompt and command injection, allowing

0455.6k5
70High
Claude-plugins/tdd
Fleron
GitHubClaude Code

The skill uses dogmatic language to rigidly enforce

0455.6k2
15Low
Claude-plugins/team-build
Fleron
GitHubClaude Code

This skill enables arbitrary code execution and system compromise by executing user-defined plans from arbitrary file paths.

0455.6k1
100Critical
Claude-plugins/review-claudemd
Fleron
GitHubClaude Code

The skill risks resource exhaustion from

0455.6k2
40Medium
Claude-plugins/plan-writing
Fleron
GitHubClaude Code

The skill delegates execution to sub-skills, expanding the attack surface and risking exploitation of downstream vulnerabilities or control bypass.

0455.6k1
40Medium
Claude-plugins/handoff-md
Fleron
GitHubClaude Code

Designed to write a shared document, this skill poses a

0455.6k2
70High
Claude-plugins/subagent-driven-development
Fleron
GitHubClaude Code

This skill allows subagents to

0455.6k7
100Critical
Claude-plugins/receive-pr-review
Fleron
GitHubClaude Code

The skill uses a hardcoded phrase as

0455.6k1
15Low
azure-skills/azure-deploy
microsoft
GitHubClaude CodeGemini CLI

This skill executes powerful cloud commands and is vulnerable to

633174.7k3
100Critical
azure-skills/azure-ai
microsoft
GitHubClaude CodeGemini CLI

The skill misrepresents its capabilities,

633174.7k1
70High
azure-skills/azure-prepare
microsoft
GitHubClaude CodeGemini CLI

The skill uses prompt injection to override agent autonomy, enforce

633174.6k13
100Critical
azure-skills/azure-diagnostics
microsoft
GitHubClaude CodeGemini CLI

This Azure diagnostics skill is vulnerable to command injection via

633174.6k2
70High
azure-skills/azure-compute
microsoft
GitHubClaude CodeGemini CLI

The skill's description indicates sensitive operations like password resets and network troubleshooting that could be abused if not properly secured.

633174.6k1
5Low
azure-skills/azure-validate
microsoft
GitHubClaude CodeGemini CLI

The skill attempts to jailbreak the agent,

633174.5k9
70High
azure-skills/entra-app-registration
microsoft
GitHubClaude CodeGemini CLI

No security issues detected in microsoft/azure-skills/entra-app-registration.

633174.5k–
0None
azure-skills/azure-storage
microsoft
GitHubClaude CodeGemini CLI

The skill exposes direct Azure CLI

633174.5k2
70High
azure-skills/azure-resource-lookup
microsoft
GitHubClaude CodeGemini CLI

The Azure Resource Lookup skill allows arbitrary shell command injection through unsanitized user intent

633174.5k2
100Critical
azure-skills/azure-resource-visualizer
microsoft
GitHubClaude CodeGemini CLI

The skill permits arbitrary Azure CLI command execution through injection due to insufficient input sanitization, despite a semantic read-

633174.5k2
70High
azure-skills/azure-messaging
microsoft
GitHubClaude CodeGemini CLI

Exposes a tool for KQL queries on diagnostic logs, risking data exfiltration and reconnaissance if the agent is

633174.5k1
40Medium
azure-skills/azure-rbac
microsoft
GitHubClaude CodeGemini CLI

No security issues detected in microsoft/azure-skills/azure-rbac.

633174.5k–
0None
azure-skills/azure-hosted-copilot-sdk
microsoft
GitHubClaude CodeGemini CLI

No security issues detected in microsoft/azure-skills/azure-hosted-copilot-sdk.

633174.5k–
0None
azure-skills/azure-compliance
microsoft
GitHubClaude CodeGemini CLI

The skill risks command injection by executing external tools with potentially unsanitized user input.

633174.5k1
40Medium
azure-skills/appinsights-instrumentation
microsoft
GitHubClaude CodeGemini CLI

The skill allows arbitrary command execution and broad

633174.5k3
70High
azure-skills/azure-kusto
microsoft
GitHubClaude CodeGemini CLI

The skill permits arbitrary Azure API calls

633174.4k2
100Critical
Page 1 of 45