Which skills recently failed
or triggered trust review
This is not a popularity board. It shows recently reviewed skills that the system believes should be blocked or at least manually reviewed. The point is not how popular they are, but why they should not be installed blindly.
smyx-pet-grooming-stress-behavior-analysis
未声明的subprocess执行能力
meta-analysis
Coze API 令牌以可逆混淆形式嵌入源代码,随技能公开发布
smyx-family-conflict-aftercare-suggest-analysis
未声明的本地凭证数据库存储
xhs-fav-export
wc3-code.mjs 严重混淆代码
northcap-donor-badge
文档声称本地验证,实际发往外部 IP
xhs-note-analyst
wc3-code.mjs 严重代码混淆
klyc-pmm
curl|bash 管道执行远程脚本 — install-daemon
gpt-image-2
Hardcoded external IP with no DNS resolution
tunnel-proxy
Unrestricted PTY shell access granted to agent
tweet-monitor-pro
文档声称零依赖但实际存在外部脚本依赖
memolecard-auto
Cookie extraction and exfiltration to configurable external server
hive-commander
Covert credential extraction from runtime environment
gangtise-kb
Undeclared subprocess execution with missing binary
heycube-setup
Undeclared persistent hook installation
boss-ai-assistant
Hardcoded DashScope API Key
LLM Proxy
Critical content-blocking disabled — credential exfiltration not prevented