Which skills recently failed
or triggered trust review
This is not a popularity board. It shows recently reviewed skills that the system believes should be blocked or at least manually reviewed. The point is not how popular they are, but why they should not be installed blindly.
agent-kanban
硬编码 Gateway Token
ekybot-connector
文档声明与实际能力严重不符
hpr-solver
Undeclared LLM API calls to OpenRouter
fund-daily
Undeclared network API access
cloud-share-downloader
Undeclared credential solicitation
harbor-openclaw
Undeclared network behavior on first load
imap-idle-sneder
Hardcoded email credentials in source code
authenticate-wallet
Unversioned npm package execution
evolution-watcher
Documentation mismatch - file modification not declared
gequhai-music
Hardcoded Synology password not declared in documentation
dygod-movies
Hardcoded NAS credentials in documentation
samantha
Undeclared shell execution via subprocess ping sweep
crewai-team
Hardcoded API credential in 15 Python files
instreet-gomoku
Hardcoded API credential in source code
interactive-infographic
Hardcoded fallback API key in source code
risk-analysis
Hardcoded MySQL credentials in config.yaml