Which skills recently failed
or triggered trust review
This is not a popularity board. It shows recently reviewed skills that the system believes should be blocked or at least manually reviewed. The point is not how popular they are, but why they should not be installed blindly.
Review
solo-mission
危险的远程脚本执行模式
ClawHub 7 hr ago
Open Report ↗
Review
子网计算服务
用户凭证持久化存储
ClawHub 5 days ago
Open Report ↗
Review
amazon-screenshot
硬编码SMTP服务凭证(阴影功能)
ClawHub 18 days ago
Open Report ↗
Review
imitation-agent
加密货币私钥明文存储
ClawHub 24 days ago
Open Report ↗
Review
web-application-fuzzing-automation
文档声明与实际用途的权限声明不匹配
ClawHub Apr 29, 2026
Open Report ↗
High Risk
ludwitt-university
updateInstructions 远程代码执行通道
ClawHub Apr 12, 2026
Open Report ↗
Review
odds-movement-monitor
硬编码第三方API密钥
ClawHub Apr 11, 2026
Open Report ↗
High Risk
birth-system-manager
文档承诺不显示私钥但代码明文输出
ClawHub Apr 10, 2026
Open Report ↗
Review
whale-alert-monitor
硬编码API密钥
ClawHub Apr 9, 2026
Open Report ↗
Review
wechat-ai-bridge
配置文件明文存储敏感凭证
ClawHub Apr 6, 2026
Open Report ↗
Review
baidu-netdisk-skill
硬编码加密密钥使 AES-256 加密承诺失效
ClawHub Apr 6, 2026
Open Report ↗
Block
luci-memory
API密钥在初始化时即被外传至硬编码外部IP
Manual upload Apr 5, 2026
Open Report ↗
High Risk
MiniMax TTS
硬编码 API 密钥暴露
Manual upload Apr 5, 2026
Open Report ↗
Review
asiasea-bi
API认证凭证通过Base64编码嵌入可公开访问的HTML
Manual upload Apr 5, 2026
Open Report ↗
Review
xiayu
用户凭证直接收集存在风险
Manual upload Apr 5, 2026
Open Report ↗
Review
feishu-bot-config-helper
危险远程脚本管道执行
Manual upload Apr 5, 2026
Open Report ↗