Which skills recently failed
or triggered trust review
This is not a popularity board. It shows recently reviewed skills that the system believes should be blocked or at least manually reviewed. The point is not how popular they are, but why they should not be installed blindly.
Review
code-right
文档声称的核心功能完全未在本地实现
ClawHub May 14, 2026
Open Report ↗
Review
asoul-support
通过 subprocess 调用外部工具(未声明权限)
ClawHub Apr 23, 2026
Open Report ↗
High Risk
tweet-monitor-pro
文档声称零依赖但实际存在外部脚本依赖
ClawHub Apr 19, 2026
Open Report ↗
Review
a2a-article-services
硬编码外部 IP 地址
ClawHub Apr 11, 2026
Open Report ↗
Review
stocktoday-mcp
凭证及查询数据发往未知第三方服务器
ClawHub Apr 6, 2026
Open Report ↗
Review
wechat-ai-bridge
配置文件明文存储敏感凭证
ClawHub Apr 6, 2026
Open Report ↗
Block
luci-memory
API密钥在初始化时即被外传至硬编码外部IP
Manual upload Apr 5, 2026
Open Report ↗
Review
ctct-security-patrol
持久化设备指纹形成长期追踪能力
Manual upload Apr 5, 2026
Open Report ↗
Review
NIST CSF Mapper
强制外部API数据传输企业敏感信息
Manual upload Apr 5, 2026
Open Report ↗
Review
tesla-cn
所有 API 流量经第三方代理中转
Manual upload Apr 5, 2026
Open Report ↗
Review
xiayu
用户凭证直接收集存在风险
Manual upload Apr 5, 2026
Open Report ↗
High Risk
memolecard-auto
Cookie extraction and exfiltration to configurable external server
Manual upload Apr 5, 2026
Open Report ↗
High Risk
hive-commander
Covert credential extraction from runtime environment
Manual upload Apr 5, 2026
Open Report ↗
High Risk
gangtise-kb
Undeclared subprocess execution with missing binary
Manual upload Apr 5, 2026
Open Report ↗
Review
imap-idle-sneder
Hardcoded email credentials in source code
Manual upload Apr 5, 2026
Open Report ↗
High Risk
heycube-setup
Undeclared persistent hook installation
Manual upload Apr 5, 2026
Open Report ↗