Risk Sample Stream

Which skills recently failed
or triggered trust review

This is not a popularity board. It shows recently reviewed skills that the system believes should be blocked or at least manually reviewed. The point is not how popular they are, but why they should not be installed blindly.

426 Risky samples surfaced
5 New in 7 days
0 Platform misses surfaced
All Code Exec Credential Theft Data Exfil Priv Esc Supply Chain Doc Deception Prompt Injection Obfuscation
55 /100
Trust
Review

code-right

文档声称的核心功能完全未在本地实现

Doc MismatchData ExfilPriv Escalation
ClawHub May 14, 2026
Open Report ↗
55 /100
Trust
Review

asoul-support

通过 subprocess 调用外部工具(未声明权限)

Priv EscalationData ExfilDoc MismatchSensitive Access
ClawHub Apr 23, 2026
Open Report ↗
35 /100
Trust
High Risk

tweet-monitor-pro

文档声称零依赖但实际存在外部脚本依赖

Doc MismatchPriv EscalationSupply ChainSensitive Access
ClawHub Apr 19, 2026
Open Report ↗
55 /100
Trust
Review

a2a-article-services

硬编码外部 IP 地址

Supply ChainData ExfilDoc MismatchSensitive Access
ClawHub Apr 11, 2026
Open Report ↗
55 /100
Trust
Review

stocktoday-mcp

凭证及查询数据发往未知第三方服务器

Data ExfilSupply ChainDoc Mismatch
ClawHub Apr 6, 2026
Open Report ↗
45 /100
Trust
Review

wechat-ai-bridge

配置文件明文存储敏感凭证

Credential TheftData ExfilDoc MismatchSupply Chain
ClawHub Apr 6, 2026
Open Report ↗
15 /100
Trust
Block

luci-memory

API密钥在初始化时即被外传至硬编码外部IP

Credential TheftData ExfilObfuscationDoc Mismatch
Manual upload Apr 5, 2026
Open Report ↗
55 /100
Trust
Review

ctct-security-patrol

持久化设备指纹形成长期追踪能力

Sensitive AccessData ExfilDoc MismatchSupply Chain
Manual upload Apr 5, 2026
Open Report ↗
55 /100
Trust
Review

NIST CSF Mapper

强制外部API数据传输企业敏感信息

Data ExfilSupply ChainDoc Mismatch
Manual upload Apr 5, 2026
Open Report ↗
55 /100
Trust
Review

tesla-cn

所有 API 流量经第三方代理中转

Data ExfilSensitive AccessDoc MismatchSupply Chain
Manual upload Apr 5, 2026
Open Report ↗
55 /100
Trust
Review

xiayu

用户凭证直接收集存在风险

Credential TheftData ExfilDoc MismatchSensitive Access
Manual upload Apr 5, 2026
Open Report ↗
35 /100
Trust
High Risk

memolecard-auto

Cookie extraction and exfiltration to configurable external server

Credential TheftData ExfilDoc MismatchPriv Escalation
Manual upload Apr 5, 2026
Open Report ↗
25 /100
Trust
High Risk

hive-commander

Covert credential extraction from runtime environment

Credential TheftData ExfilDoc MismatchPriv Escalation
Manual upload Apr 5, 2026
Open Report ↗
28 /100
Trust
High Risk

gangtise-kb

Undeclared subprocess execution with missing binary

RCEData ExfilDoc MismatchPriv Escalation
Manual upload Apr 5, 2026
Open Report ↗
55 /100
Trust
Review

imap-idle-sneder

Hardcoded email credentials in source code

Credential TheftDoc MismatchData ExfilSupply Chain
Manual upload Apr 5, 2026
Open Report ↗
28 /100
Trust
High Risk

heycube-setup

Undeclared persistent hook installation

Doc MismatchData ExfilSensitive AccessPriv Escalation
Manual upload Apr 5, 2026
Open Report ↗
← Previous
2 / 4
Next →