Which skills recently failed
or triggered trust review
This is not a popularity board. It shows recently reviewed skills that the system believes should be blocked or at least manually reviewed. The point is not how popular they are, but why they should not be installed blindly.
xhs-skill-pusher
Shell execution not declared in SKILL.md
openclaw-usage-manager
API tokens stored in plaintext on disk
oracle-report
Hardcoded QVeris API Key
clawclone
Missing implementation file
微信助手智能网关 (wechat-ai-bridge)
Undeclared external network communication
self-evolution-engine
Hardcoded Billing API Key in Source Code
security-defense-line
Hardcoded API Key in Source Code
long-term-memory
Hardcoded API Key in Source Code
rewrite_question
Network capability declared as NONE but actual traffic exists
sql_audit
Hardcoded JWT token in source code
nano-banana-pro
Hardcoded DASHSCOPE_API_KEY in _meta.json
huo15-memory-evolution
Hardcoded API Key in Source Code
hostlink
No allowed-tools declaration despite full shell access
Bitget Trader
Exposed API Credentials in Plaintext
messenger_send_node
Undeclared Tor Network Routing
figma-agent
Undeclared scanning of Claude Code credential store