Which skills recently failed
or triggered trust review
This is not a popularity board. It shows recently reviewed skills that the system believes should be blocked or at least manually reviewed. The point is not how popular they are, but why they should not be installed blindly.
gpt-image-2
Hardcoded external IP with no DNS resolution
tunnel-proxy
Unrestricted PTY shell access granted to agent
tweet-monitor-pro
文档声称零依赖但实际存在外部脚本依赖
memolecard-auto
Cookie extraction and exfiltration to configurable external server
hive-commander
Covert credential extraction from runtime environment
gangtise-kb
Undeclared subprocess execution with missing binary
heycube-setup
Undeclared persistent hook installation
boss-ai-assistant
Hardcoded DashScope API Key
LLM Proxy
Critical content-blocking disabled — credential exfiltration not prevented
backup-2-github
Hardcoded Default Repository Exposes User Data
uplo-defense
Unpinned npm package execution via npx -y
sensitive-profile-audit
Undeclared SHA256 fingerprinting of credential directories
token-sop
Automatic workflow contribution enabled by default
maxianer
Undeclared external data transmission
self-evolution-engine
Hardcoded Billing API Key in Source Code
awareness-memory
Undeclared session file exfiltration to external cloud