MondooMondoo
AI Agent Security
Skill Threat IntelligenceCLIFAQ
Log inGet Assessment

AI Agent Skill Check is a free AI agent skill security scanner by Mondoo. We scan skills across ClawHub, Skills.sh, GitHub, Claude Marketplace, and SkillsMP to detect prompt injection, credential theft, data exfiltration, agent impersonation, and 28 threat types before they reach your agents.

Mondoo

  • Vulnerability Management
  • Technology
  • Services

Solutions

  • Financial Services
  • Manufacturing
  • Healthcare

Resources

  • Blog
  • Skill Check CLI
  • Documentation
  • GitHub

Company

  • About
  • Careers
  • Partners
  • Contact

Legal

  • Privacy
  • Terms
  • Imprint
MondooMondoo© 2026 Mondoo, Inc.

Skills

Browse, search, and filter AI agent skills across all registries.

SkillAI AgentsSummaryStarsDownloadsFindingsRisk
weslink-claude-marketplace/wiki
weslinkde
GitHubClaude CodeSkills.sh

This skill allows arbitrary code execution, file exfiltration,

0–15
100Critical
webflow-skills/webflow-cli-troubleshooter
webflow
GitHubClaude CodeCursorSkills.sh

This skill allows arbitrary command execution via

64–4
100Critical
agent-skills/wordpress-router
wordpress
GitHubSkills.sh

The skill executes user-provided repository scripts, enabling

1.4k1.4k3
100Critical
claude-code-toolkit/review-loop
winrey
GitHubClaude CodeSkills.sh

The skill is vulnerable to prompt injection

3–3
100Critical
scrapbox-cosense-mcp/cosense
worldnine
GitHubClaude CodeSkills.sh

The skill allows arbitrary code execution via command injection, exposes

45–4
100Critical
agents/anti-reversing-techniques
wshobson
GitHubSkills.sh

The skill provides detailed instructions and functional code for bypassing

34.9k5.7k9
100Critical
webflow-skills/custom-code-management
webflow
GitHubClaude CodeCursorSkills.sh

The skill allows injecting arbitrary, potentially obfuscated, JavaScript

643373
100Critical
dannys-claude/add-backlog
workingdanny911
GitHubClaude CodeSkills.sh

The skill allows arbitrary command execution and command

3–6
100Critical
claude-code-toolkit/finish-feature
winrey
GitHubClaude CodeSkills.sh

This skill allows arbitrary command execution, instruction injection, and

3–6
100Critical
exoshell/ralph-ryan
wquguru
GitHubClaude CodeSkills.sh

The skill allows arbitrary command execution via

38–5
100Critical
wpsnote-skills/image-gen
wpsnote
GitHubClaude CodeSkills.sh

The skill is vulnerable to prompt injection, exposes API

13094
100Critical
skills/competitor-teardown
tool-belt
GitHubClaude CodeSkills.sh

This skill allows arbitrary code execution and command injection via user

414–4
100Critical
agent-skills/wp-interactivity-api
wordpress
GitHubSkills.sh

This skill grants broad filesystem and command execution, enabling arbitrary

1.4k9215
100Critical
json-render/react
vercel-labs
GitHubSkills.sh

This skill is highly vulnerable to arbitrary code execution, data

14.6k1.7k6
100Critical
skills/case-study-writing
tool-belt
GitHubClaude CodeSkills.sh

The skill allows arbitrary Python code execution and

414–2
100Critical
X-Scraper-MCP/fxtwitter
wcfcarolina13
GitHubClaude CodeSkills.sh

This skill allows arbitrary file reads and writes, risking data

0–2
100Critical
claude-context-search-qmd/context-search
vranac
GitHubClaude CodeSkills.sh

The skill allows arbitrary command execution via `

0–3
100Critical
json-render/react-pdf
vercel-labs
GitHubSkills.sh

The skill is vulnerable to arbitrary code execution, SSRF

14.6k7514
100Critical
json-render/next
vercel-labs
GitHubSkills.sh

The skill allows arbitrary code execution and state manipulation through

14.6k2493
100Critical
json-render/mcp
vercel-labs
GitHubSkills.sh

The skill allows arbitrary code execution via its

14.6k5732
100Critical
json-render/core
vercel-labs
GitHubSkills.sh

The skill allows arbitrary code execution, state modification, and

14.6k1.1k5
100Critical
second-brain-claude/product-okr-tracker
viditparashar96
GitHubSkills.sh

The skill is vulnerable to remote code execution

0–3
100Critical
LeanIX-Catalog-Research-Marketplace/create-application
vineetgoyal1
GitHubClaude CodeSkills.sh

This skill attempts to harvest API tokens, executes

0–15
100Critical
skills/background-removal
tool-belt
GitHubClaude CodeSkills.sh

The skill encourages `npx skills add`, enabling arbitrary code execution from npm, posing a significant supply chain risk.

414–1
100Critical
chrome-test-runner-plugin/chrome-testing
victor-qin
GitHubClaude CodeSkills.sh

This QA testing skill allows arbitrary JavaScript execution and extensive data collection, posing a significant risk for data ex

0–5
100Critical
skills/ai-social-media-content
tool-belt
GitHubClaude CodeSkills.sh

This skill enables arbitrary code execution, command injection

414–8
100Critical
emulate/google
vercel-labs
GitHubSkills.sh

This skill is vulnerable to SSRF and arbitrary curl commands, allowing internal network access, data exfiltration, and reconnaissance.

1.2k703
100Critical
workflow/workflow-init
vercel
GitHubSkills.sh

The skill executes broad commands, modifies files, and makes arbitrary network requests based on external, mutable content, posing a significant supply chain and system compromise risk.

2.0k9885
100Critical
emulate/emulate
vercel-labs
GitHubSkills.sh

The skill allows arbitrary command execution, local file inclusion,

1.2k555
100Critical
skills/ai-content-pipeline
tool-belt
GitHubClaude CodeSkills.sh

The skill allows broad `infsh` command execution via

414–2
100Critical
claude-skills/web-design-guidelines
vercel-labs
GitHubSkills.sh

This skill fetches unverified remote instructions that can

26.2k1767
100Critical
sandbox/sandbox
vercel
GitHubSkills.sh

The sandbox skill allows arbitrary root command execution,

115756
100Critical
workflow/workflow
vercel
GitHubSkills.sh

The skill actively promotes arbitrary code execution and command injection

2.0k2.0k8
100Critical
skills/ai-marketing-videos
tool-belt
GitHubClaude CodeSkills.sh

The skill allows arbitrary Bash command execution, enabling data

414–5
100Critical
skills/ai-automation-workflows
tool-belt
GitHubClaude CodeSkills.sh

The skill allows command and prompt injection, enabling data

414–4
100Critical
vercel-plugin/marketplace
vercel
GitHubClaude CodeCursorSkills.sh

This Vercel plugin allows attackers to exfiltrate sensitive project data by manipulating the drain URL to a malicious endpoint.

1572211
100Critical
skills/agent-browser
tool-belt
GitHubClaude CodeSkills.sh

The skill allows arbitrary command execution, JavaScript injection, file

414–6
100Critical
skills/agent-tools
tool-belt
GitHubClaude CodeSkills.sh

The skill allows remote code execution,

414–8
100Critical
aurora-smart-home/ha-integration-dev
tonylofgren
GitHubClaude CodeSkills.sh

This skill generates Home Assistant code with full filesystem access,

3895
100Critical
skills/agent-ui
tool-belt
GitHubClaude CodeSkills.sh

The skill directly manipulates the user's browser

414–3
100Critical
date-planner/date-plan
tonyyont
GitHubClaude CodeSkills.sh

The skill directly executes arbitrary code and Git commands with

1–14
100Critical
skills/upstash-box-js
upstash
GitHubClaude CodeCursorSkills.sh

This skill allows arbitrary code execution, file

3307
100Critical
toby-plugins/gemini-delegate
tobyilee
GitHubClaude CodeSkills.sh

This skill delegates tasks to Gemini with auto-approve and

19–13
100Critical
examples/web-design-guidelines
vercel
GitHubSkills.sh

This skill fetches and executes arbitrary instructions from an unverified

5.1k1117
100Critical
ai/update-provider-models
vercel
GitHubSkills.sh

The skill allows arbitrary shell command execution and file system manipulation

24.0k1193
100Critical
before-and-after/before-and-after
vercel-labs
GitHubSkills.sh

The skill permits arbitrary command arguments and script paths, leading

1978543
100Critical
hpc/hpc
ultimatile
GitHubClaude CodeSkills.sh

The skill allows arbitrary command execution on remote HPC

0–4
100Critical
ai/update-provider-models
vercel-labs
GitHubSkills.sh

The skill is vulnerable to remote code execution, code injection

24.0k214
100Critical
Page 1 of 288