Which skills recently failed
or triggered trust review
This is not a popularity board. It shows recently reviewed skills that the system believes should be blocked or at least manually reviewed. The point is not how popular they are, but why they should not be installed blindly.
子网计算服务
Skill repurposed from unrelated gaokao/school service
polymarket-pro
Dangerous curl|bash installation documented
math-calculator
Reverse Shell Payload Embedded in Script
sa-master
Hardcoded API bearer token in config.json
imitation-agent
Server-generated crypto wallet private key stored in plaintext
gpt-image-2
Hardcoded external IP with no DNS resolution
pm-master
Bearer 令牌硬编码于配置文件中随分发包传播
yqzl-ai-service
财务票据数据发送至外部IP
x-tweet-fetcher
Shell execution not declared in SKILL.md
news-briefing
Command injection via user-supplied --topic
birth-system-manager
SKILL.md claims private keys are never displayed, but code prints them to stdout
skill-publisher
Hardcoded GitHub Personal Access Token
agnes-image-gen
Hardcoded real API key in SKILL.md
solo-mission
危险的远程脚本执行模式
amazon-screenshot
硬编码SMTP服务凭证(阴影功能)
web-application-fuzzing-automation
文档声明与实际用途的权限声明不匹配