Which skills recently failed
or triggered trust review
This is not a popularity board. It shows recently reviewed skills that the system believes should be blocked or at least manually reviewed. The point is not how popular they are, but why they should not be installed blindly.
Review
fulcra-onboarding
远程脚本执行 (curl|sh 模式)
ClawHub 2 days ago
Open Report ↗
Review
amazon-screenshot
硬编码SMTP服务凭证(阴影功能)
ClawHub 18 days ago
Open Report ↗
Review
lobster-use
危险 Shell 命令 - 远程脚本执行
ClawHub 29 days ago
Open Report ↗
Review
polymarket-pro
curl|sh 远程脚本执行模式
ClawHub Apr 23, 2026
Open Report ↗
Review
tunnel-proxy
PtySession可执行任意Shell命令
ClawHub Apr 20, 2026
Open Report ↗
High Risk
ludwitt-university
updateInstructions 远程代码执行通道
ClawHub Apr 12, 2026
Open Report ↗
Review
cmd-execution-test
影子功能 - 未声明的任意命令执行能力
ClawHub Apr 9, 2026
Open Report ↗
Review
typescript-package-manager
远程脚本管道执行
ClawHub Apr 6, 2026
Open Report ↗
Review
math-utils
命令注入漏洞
ClawHub Apr 6, 2026
Open Report ↗
Review
moltspay_skill
npm 全局安装 moltspay 无版本锁定
ClawHub Apr 6, 2026
Open Report ↗
High Risk
skill-registry-unified
未声明的远程代码执行
ClawHub Apr 6, 2026
Open Report ↗
Review
aibtc
未声明的远程代码执行
ClawHub Apr 6, 2026
Open Report ↗
Review
task-progress-stream
状态文件写入未声明
ClawHub Apr 6, 2026
Open Report ↗
Review
agile-workflow
硬编码用户目录路径
ClawHub Apr 6, 2026
Open Report ↗
Review
feishu-bot-config-helper
危险远程脚本管道执行
Manual upload Apr 5, 2026
Open Report ↗
Review
daily-news-brief
文档中的危险卸载命令
Manual upload Apr 5, 2026
Open Report ↗