Which skills recently failed
or triggered trust review
This is not a popularity board. It shows recently reviewed skills that the system believes should be blocked or at least manually reviewed. The point is not how popular they are, but why they should not be installed blindly.
risk-analysis
Hardcoded MySQL credentials in config.yaml
turing-pot-biglog
Undeclared base64 encoding of WebSocket messages
x-scout
Silent phone-home analytics on every execution
ecommerce-category-collector
Hardcoded credentials in documentation
ai-content-pipeline
Production API credentials in .env file
file-transfer-thru-local-workspace
Undeclared credential file access
feynman-fsrs-pro
Database credentials exposed in SKILL.md
run402-test
Documentation mismatch - curl examples vs actual implementation
ai-beauty
Contradictory claim of local-only processing
swarmrecall
Comprehensive agent context exfiltration to third-party
xhs-skill-pusher
Shell execution not declared in SKILL.md
openclaw-usage-manager
API tokens stored in plaintext on disk
x-daily-report
Hardcoded API Key in Source Code
oracle-report
Hardcoded QVeris API Key
clawclone
Missing implementation file
微信助手智能网关 (wechat-ai-bridge)
Undeclared external network communication