Which skills recently failed
or triggered trust review
This is not a popularity board. It shows recently reviewed skills that the system believes should be blocked or at least manually reviewed. The point is not how popular they are, but why they should not be installed blindly.
ekybot-connector
文档声明与实际能力严重不符
grok-swarm
未声明的shell执行功能
memolecard-auto
Browser session cookies exfiltrated to arbitrary URL
vnstock-env-setup
API keys sent to external server vnstocks.com
hpr-solver
Undeclared LLM API calls to OpenRouter
fund-daily
Undeclared network API access
hive-commander
Covert credential extraction from runtime environment
cloud-share-downloader
Undeclared credential solicitation
harbor-openclaw
Undeclared network behavior on first load
face-analysis
Hardcoded Database Credentials in config.yaml
imap-idle-sneder
Hardcoded email credentials in source code
authenticate-wallet
Unversioned npm package execution
Email Analyzer
Hardcoded Email Authorization Code
evolution-watcher
Documentation mismatch - file modification not declared
gequhai-music
Hardcoded Synology password not declared in documentation
dygod-movies
Hardcoded NAS credentials in documentation