Risk Sample Stream

Which skills recently failed
or triggered trust review

This is not a popularity board. It shows recently reviewed skills that the system believes should be blocked or at least manually reviewed. The point is not how popular they are, but why they should not be installed blindly.

510 Risky samples surfaced
12 New in 7 days
0 Platform misses surfaced
All Code Exec Credential Theft Data Exfil Priv Esc Supply Chain Doc Deception Prompt Injection Obfuscation
35 /100
Trust
High Risk

smyx-pet-grooming-stress-behavior-analysis

未声明的subprocess执行能力

RCECredential TheftDoc MismatchSensitive Access
ClawHub 12 days ago
Open Report ↗
20 /100
Trust
High Risk

smyx-family-conflict-aftercare-suggest-analysis

未声明的本地凭证数据库存储

Doc MismatchCredential TheftData ExfilSupply Chain
ClawHub 16 days ago
Open Report ↗
20 /100
Trust
High Risk

klyc-pmm

curl|bash 管道执行远程脚本 — install-daemon

Supply ChainDoc MismatchSensitive AccessData Exfil
ClawHub Jul 28, 2026
Open Report ↗
35 /100
Trust
High Risk

perkoon-transfer

远程代码执行(RCE)风险

RCESupply ChainSensitive AccessObfuscation
ClawHub Jul 20, 2026
Open Report ↗
28 /100
Trust
High Risk

summarize

远程 Shell 脚本执行(curl|bash 管道)

RCEDoc MismatchSensitive Access
ClawHub Jul 5, 2026
Open Report ↗
35 /100
Trust
High Risk

tunnel-proxy

Unrestricted PTY shell access granted to agent

RCESensitive AccessData ExfilDoc Mismatch
ClawHub Jun 21, 2026
Open Report ↗
30 /100
Trust
High Risk

pub

Remote script execution from unverified source

Supply ChainRCEPriv EscalationDoc Mismatch
ClawHub Jun 18, 2026
Open Report ↗
35 /100
Trust
High Risk

superada-workflow-entity-mission-control-bootstrap

外部仓库代码执行

Supply ChainRCEDoc MismatchPriv Escalation
ClawHub Jun 3, 2026
Open Report ↗
25 /100
Trust
High Risk

ludwitt-university

updateInstructions 远程代码执行通道

RCEDoc MismatchPersistenceCredential Theft
ClawHub Apr 12, 2026
Open Report ↗
32 /100
Trust
High Risk

skill-registry-unified

未声明的远程代码执行

RCEDoc MismatchSupply ChainSensitive Access
ClawHub Apr 6, 2026
Open Report ↗
35 /100
Trust
High Risk

grok-swarm

未声明的shell执行功能

Doc MismatchRCECredential TheftSupply Chain
Manual upload Apr 5, 2026
Open Report ↗
28 /100
Trust
High Risk

claw-ops-manager

Undeclared Shell Command Execution

Priv EscalationSensitive AccessRCEDoc Mismatch
Manual upload Apr 5, 2026
Open Report ↗
28 /100
Trust
High Risk

gangtise-kb

Undeclared subprocess execution with missing binary

RCEData ExfilDoc MismatchPriv Escalation
Manual upload Apr 5, 2026
Open Report ↗
32 /100
Trust
High Risk

LLM Proxy

Critical content-blocking disabled — credential exfiltration not prevented

Credential TheftDoc MismatchSensitive AccessRCE
Manual upload Apr 4, 2026
Open Report ↗
38 /100
Trust
High Risk

monid

Remote script execution via curl|bash from mutable branch

RCEPriv EscalationCredential TheftDoc Mismatch
Manual upload Apr 4, 2026
Open Report ↗
35 /100
Trust
High Risk

openviking-context

Undeclared curl|bash remote script execution

RCECredential TheftSupply ChainDoc Mismatch
Manual upload Apr 4, 2026
Open Report ↗
1 / 2
Next →