Which skills recently failed
or triggered trust review
This is not a popularity board. It shows recently reviewed skills that the system believes should be blocked or at least manually reviewed. The point is not how popular they are, but why they should not be installed blindly.
ludwitt-university
updateInstructions 远程代码执行通道
birth-system-manager
文档承诺不显示私钥但代码明文输出
MiniMax TTS
硬编码 API 密钥暴露
混合工作空间
大量硬编码阿里云API密钥
Setup Multi Gateway
硬编码API密钥
Bitget Trader
SKILL.md嵌入了真实API凭证
grok-swarm
未声明的shell执行功能
memolecard-auto
Browser session cookies exfiltrated to arbitrary URL
hive-commander
Covert credential extraction from runtime environment
face-analysis
Hardcoded Database Credentials in config.yaml
Email Analyzer
Hardcoded Email Authorization Code
boss-ai-assistant
Hardcoded DashScope API Key
LLM Proxy
Critical content-blocking disabled — credential exfiltration not prevented
monid
Remote script execution via curl|bash from mutable branch
moodle-connector
Hardcoded default password in MCP server bypasses security requirement
uplo-defense
Unpinned npm package execution via npx -y