Which skills recently failed
or triggered trust review
This is not a popularity board. It shows recently reviewed skills that the system believes should be blocked or at least manually reviewed. The point is not how popular they are, but why they should not be installed blindly.
tweet-monitor-pro
文档声称零依赖但实际存在外部脚本依赖
memolecard-auto
Cookie extraction and exfiltration to configurable external server
hive-commander
Covert credential extraction from runtime environment
gangtise-kb
Undeclared subprocess execution with missing binary
heycube-setup
Undeclared persistent hook installation
boss-ai-assistant
Hardcoded DashScope API Key
LLM Proxy
Critical content-blocking disabled — credential exfiltration not prevented
backup-2-github
Hardcoded Default Repository Exposes User Data
uplo-defense
Unpinned npm package execution via npx -y
sensitive-profile-audit
Undeclared SHA256 fingerprinting of credential directories
token-sop
Automatic workflow contribution enabled by default
maxianer
Undeclared external data transmission
self-evolution-engine
Hardcoded Billing API Key in Source Code
awareness-memory
Undeclared session file exfiltration to external cloud
messenger_send_node
Undeclared Tor Network Routing