Risk Sample Stream

Which skills recently failed
or triggered trust review

This is not a popularity board. It shows recently reviewed skills that the system believes should be blocked or at least manually reviewed. The point is not how popular they are, but why they should not be installed blindly.

426 Risky samples surfaced
5 New in 7 days
0 Platform misses surfaced
All Code Exec Credential Theft Data Exfil Priv Esc Supply Chain Doc Deception Prompt Injection Obfuscation
55 /100
Trust
Review

alibabacloud-workbench-cli

curl|bash 远程脚本执行

Supply ChainCredential TheftDoc Mismatch
ClawHub 17 hr ago
Open Report ↗
55 /100
Trust
Review

tkseller

凭证以明文发送至外部服务器

Credential TheftSensitive AccessSupply ChainDoc Mismatch
ClawHub 15 days ago
Open Report ↗
45 /100
Trust
Review

xclawskill

文档引用不存在的核心脚本

Doc MismatchCredential TheftData ExfilSupply Chain
ClawHub 17 days ago
Open Report ↗
45 /100
Trust
Review

moltspay-skill

Undeclared external npm dependency

Supply ChainDoc MismatchCredential TheftPersistence
ClawHub 19 days ago
Open Report ↗
55 /100
Trust
Review

smyx-eye-anomaly-detection-analysis

读取未声明的敏感文件 data/smyx-api-key.txt

Sensitive AccessRCECredential TheftDoc Mismatch
ClawHub 29 days ago
Open Report ↗
35 /100
Trust
High Risk

psychology-analysis

静默phoneLogin调用

Doc MismatchCredential TheftSensitive AccessPriv Escalation
ClawHub 29 days ago
Open Report ↗
55 /100
Trust
Review

wechat_bridge

Hardcoded credentials in wechat.yaml

Credential TheftSensitive AccessPriv EscalationDoc Mismatch
ClawHub Jun 24, 2026
Open Report ↗
35 /100
Trust
High Risk

x-daily-report

Hardcoded X API Key with 'auto-obtained' comment

Credential TheftDoc MismatchSensitive AccessSupply Chain
ClawHub Jun 24, 2026
Open Report ↗
45 /100
Trust
Review

search

Undeclared shell execution via api.exec()

Doc MismatchCredential Theft
ClawHub Jun 24, 2026
Open Report ↗
55 /100
Trust
Review

odds-movement-monitor-v2026

Hardcoded Billing API Key

Credential TheftDoc MismatchSensitive Access
ClawHub Jun 24, 2026
Open Report ↗
55 /100
Trust
Review

子网计算服务

Skill repurposed from unrelated gaokao/school service

Doc MismatchPriv EscalationCredential TheftSupply Chain
ClawHub Jun 24, 2026
Open Report ↗
58 /100
Trust
Review

polymarket-pro

Dangerous curl|bash installation documented

Supply ChainCredential TheftDoc Mismatch
ClawHub Jun 24, 2026
Open Report ↗
0 /100
Trust
Block

math-calculator

Reverse Shell Payload Embedded in Script

RCEDoc MismatchData ExfilObfuscation
GitHub Jun 24, 2026
Open Report ↗
45 /100
Trust
Review

sa-master

Hardcoded API bearer token in config.json

Credential TheftData ExfilDoc Mismatch
ClawHub Jun 22, 2026
Open Report ↗
60 /100
Trust
Review

imitation-agent

Server-generated crypto wallet private key stored in plaintext

Credential TheftDoc MismatchSensitive Access
ClawHub Jun 22, 2026
Open Report ↗
28 /100
Trust
High Risk

gpt-image-2

Hardcoded external IP with no DNS resolution

Data ExfilDoc MismatchCredential TheftSensitive Access
ClawHub Jun 22, 2026
Open Report ↗
1 / 7
Next →