Risk Sample Stream

Which skills recently failed
or triggered trust review

This is not a popularity board. It shows recently reviewed skills that the system believes should be blocked or at least manually reviewed. The point is not how popular they are, but why they should not be installed blindly.

510 Risky samples surfaced
12 New in 7 days
0 Platform misses surfaced
All Code Exec Credential Theft Data Exfil Priv Esc Supply Chain Doc Deception Prompt Injection Obfuscation
28 /100
Trust
High Risk

stellar-trails

GitHub PAT 明文持久化到文件系统

Credential TheftPersistencePriv EscalationSensitive Access
ClawHub 1 day ago
Open Report ↗
35 /100
Trust
High Risk

GitToQuark

无实际代码实现

Supply ChainCredential TheftObfuscation
ClawHub 9 days ago
Open Report ↗
35 /100
Trust
High Risk

smyx-pet-grooming-stress-behavior-analysis

未声明的subprocess执行能力

RCECredential TheftDoc MismatchSensitive Access
ClawHub 12 days ago
Open Report ↗
35 /100
Trust
High Risk

meta-analysis

Coze API 令牌以可逆混淆形式嵌入源代码,随技能公开发布

Credential TheftData ExfilPriv EscalationSupply Chain
ClawHub 13 days ago
Open Report ↗
20 /100
Trust
High Risk

smyx-family-conflict-aftercare-suggest-analysis

未声明的本地凭证数据库存储

Doc MismatchCredential TheftData ExfilSupply Chain
ClawHub 16 days ago
Open Report ↗
22 /100
Trust
High Risk

video-content-pipeline

伪造CA证书内置于技能包

ObfuscationCredential TheftDoc MismatchSensitive Access
ClawHub 20 days ago
Open Report ↗
25 /100
Trust
High Risk

xhs-note-analyst

wc3-code.mjs 严重代码混淆

ObfuscationData ExfilDoc MismatchSupply Chain
ClawHub 28 days ago
Open Report ↗
35 /100
Trust
High Risk

psychology-analysis

静默phoneLogin调用

Doc MismatchCredential TheftSensitive AccessPriv Escalation
ClawHub Jun 28, 2026
Open Report ↗
35 /100
Trust
High Risk

x-daily-report

Hardcoded X API Key with 'auto-obtained' comment

Credential TheftDoc MismatchSensitive AccessSupply Chain
ClawHub Jun 24, 2026
Open Report ↗
28 /100
Trust
High Risk

gpt-image-2

Hardcoded external IP with no DNS resolution

Data ExfilDoc MismatchCredential TheftSensitive Access
ClawHub Jun 22, 2026
Open Report ↗
25 /100
Trust
High Risk

birth-system-manager

SKILL.md claims private keys are never displayed, but code prints them to stdout

Doc MismatchCredential TheftSensitive AccessPriv Escalation
ClawHub Jun 18, 2026
Open Report ↗
35 /100
Trust
High Risk

skill-publisher

Hardcoded GitHub Personal Access Token

Credential TheftDoc MismatchSensitive AccessSupply Chain
ClawHub Jun 15, 2026
Open Report ↗
45 /100
Trust
High Risk

agnes-image-gen

Hardcoded real API key in SKILL.md

Credential TheftDoc MismatchPriv Escalation
ClawHub Jun 10, 2026
Open Report ↗
25 /100
Trust
High Risk

ludwitt-university

updateInstructions 远程代码执行通道

RCEDoc MismatchPersistenceCredential Theft
ClawHub Apr 12, 2026
Open Report ↗
35 /100
Trust
High Risk

MiniMax TTS

硬编码 API 密钥暴露

Credential TheftDoc MismatchSupply Chain
Manual upload Apr 5, 2026
Open Report ↗
35 /100
Trust
High Risk

混合工作空间

大量硬编码阿里云API密钥

Credential TheftDoc MismatchSensitive Access
Manual upload Apr 5, 2026
Open Report ↗
1 / 3
Next →