Which skills recently failed
or triggered trust review
This is not a popularity board. It shows recently reviewed skills that the system believes should be blocked or at least manually reviewed. The point is not how popular they are, but why they should not be installed blindly.
Review
solo-mission
危险的远程脚本执行模式
ClawHub 7 hr ago
Open Report ↗
Review
子网计算服务
用户凭证持久化存储
ClawHub 5 days ago
Open Report ↗
Review
amazon-screenshot
硬编码SMTP服务凭证(阴影功能)
ClawHub 18 days ago
Open Report ↗
Review
imitation-agent
加密货币私钥明文存储
ClawHub 24 days ago
Open Report ↗
Review
web-application-fuzzing-automation
文档声明与实际用途的权限声明不匹配
ClawHub Apr 29, 2026
Open Report ↗
Review
odds-movement-monitor
硬编码第三方API密钥
ClawHub Apr 11, 2026
Open Report ↗
Review
self-evolution-engine
硬编码API密钥暴露
ClawHub Apr 10, 2026
Open Report ↗
Review
whale-alert-monitor
硬编码API密钥
ClawHub Apr 9, 2026
Open Report ↗
Review
wechat-ai-bridge
配置文件明文存储敏感凭证
ClawHub Apr 6, 2026
Open Report ↗
Review
baidu-netdisk-skill
硬编码加密密钥使 AES-256 加密承诺失效
ClawHub Apr 6, 2026
Open Report ↗
Review
asiasea-bi
API认证凭证通过Base64编码嵌入可公开访问的HTML
Manual upload Apr 5, 2026
Open Report ↗
Review
xiayu
用户凭证直接收集存在风险
Manual upload Apr 5, 2026
Open Report ↗
Review
feishu-bot-config-helper
危险远程脚本管道执行
Manual upload Apr 5, 2026
Open Report ↗
Review
feishu-ops
影子功能:本地桌面文件操作未在文档声明
Manual upload Apr 5, 2026
Open Report ↗
Review
recognize_intent
硬编码外部IP地址
Manual upload Apr 5, 2026
Open Report ↗
Review
用户工作区 (Multi-Skill Workspace)
虚构的 API 名称
Manual upload Apr 5, 2026
Open Report ↗