Which skills recently failed
or triggered trust review
This is not a popularity board. It shows recently reviewed skills that the system believes should be blocked or at least manually reviewed. The point is not how popular they are, but why they should not be installed blindly.
High Risk
stremio-cli
Explicit false statement about script status
Manual upload Apr 4, 2026
Open Report ↗
High Risk
Enterprise Security
Undeclared shell execution via execSync
Manual upload Apr 4, 2026
Open Report ↗
High Risk
minimal-agent
Unrestricted Arbitrary Command Execution via V1 Mode
Manual upload Apr 4, 2026
Open Report ↗
High Risk
product-demo-video
Destructive `rm -rf` glob command in install script
Manual upload Apr 4, 2026
Open Report ↗
High Risk
zanna-aperta
Undeclared arbitrary Docker command execution
Manual upload Apr 4, 2026
Open Report ↗
High Risk
skill-factory
Undeclared shell command execution via execSync
Manual upload Apr 4, 2026
Open Report ↗
High Risk
clawguard-threat-detect
Hardcoded Reverse Shell Payloads in Documentation
Manual upload Apr 4, 2026
Open Report ↗
High Risk
grinders-farm
start.sh contains completely unrelated code
Manual upload Apr 3, 2026
Open Report ↗