Which skills recently failed
or triggered trust review
This is not a popularity board. It shows recently reviewed skills that the system believes should be blocked or at least manually reviewed. The point is not how popular they are, but why they should not be installed blindly.
Review
feishu-ops
影子功能:本地桌面文件操作未在文档声明
Manual upload Apr 5, 2026
Open Report ↗
Review
recognize_intent
硬编码外部IP地址
Manual upload Apr 5, 2026
Open Report ↗
High Risk
混合工作空间
大量硬编码阿里云API密钥
Manual upload Apr 5, 2026
Open Report ↗
High Risk
Setup Multi Gateway
硬编码API密钥
Manual upload Apr 5, 2026
Open Report ↗
Review
用户工作区 (Multi-Skill Workspace)
虚构的 API 名称
Manual upload Apr 5, 2026
Open Report ↗
Review
agent-kanban
硬编码 Gateway Token
Manual upload Apr 5, 2026
Open Report ↗
Review
ekybot-connector
文档声明与实际能力严重不符
Manual upload Apr 5, 2026
Open Report ↗
High Risk
grok-swarm
未声明的shell执行功能
Manual upload Apr 5, 2026
Open Report ↗
High Risk
memolecard-auto
Browser session cookies exfiltrated to arbitrary URL
Manual upload Apr 5, 2026
Open Report ↗
Block
vnstock-env-setup
API keys sent to external server vnstocks.com
Manual upload Apr 5, 2026
Open Report ↗
Review
hpr-solver
Undeclared LLM API calls to OpenRouter
Manual upload Apr 5, 2026
Open Report ↗
Review
fund-daily
Undeclared network API access
Manual upload Apr 5, 2026
Open Report ↗
High Risk
hive-commander
Covert credential extraction from runtime environment
Manual upload Apr 5, 2026
Open Report ↗
Review
cloud-share-downloader
Undeclared credential solicitation
Manual upload Apr 5, 2026
Open Report ↗
Review
harbor-openclaw
Undeclared network behavior on first load
Manual upload Apr 5, 2026
Open Report ↗
High Risk
face-analysis
Hardcoded Database Credentials in config.yaml
Manual upload Apr 5, 2026
Open Report ↗