Which skills recently failed
or triggered trust review
This is not a popularity board. It shows recently reviewed skills that the system believes should be blocked or at least manually reviewed. The point is not how popular they are, but why they should not be installed blindly.
Review
elevenlabs-toolkit
未声明的环境变量依赖
ClawHub May 1, 2026
Open Report ↗
Review
web-application-fuzzing-automation
文档声明与实际用途的权限声明不匹配
ClawHub Apr 29, 2026
Open Report ↗
Review
nexo-brain
外部 npm 包依赖且无版本锁定
ClawHub Apr 28, 2026
Open Report ↗
Review
contextweave-diagrams
文档引用不存在的脚本文件
ClawHub Apr 23, 2026
Open Report ↗
Review
asoul-support
通过 subprocess 调用外部工具(未声明权限)
ClawHub Apr 23, 2026
Open Report ↗
Review
gpt-image-2
未声明的外部网络通信
ClawHub Apr 22, 2026
Open Report ↗
Review
sage-router
systemctl服务管理未在声明中
ClawHub Apr 21, 2026
Open Report ↗
Review
tunnel-proxy
PtySession可执行任意Shell命令
ClawHub Apr 20, 2026
Open Report ↗
Review
server-log-analysis
config.yaml 包含明文凭证违反安全声明
ClawHub Apr 20, 2026
Open Report ↗
Review
gta-real-estate-skillpay
未声明的网络外传行为
ClawHub Apr 20, 2026
Open Report ↗
Review
news-briefing
未声明的 shell 执行和动态代码注入
ClawHub Apr 20, 2026
Open Report ↗
Review
sharkflow
SKILL.md声明功能远超实际代码能力
ClawHub Apr 20, 2026
Open Report ↗
Review
auto-skill-hunter
权限声明与实际能力严重不符
ClawHub Apr 19, 2026
Open Report ↗
Review
daily-memory-summary
未声明的联系人信息提取功能
ClawHub Apr 19, 2026
Open Report ↗
Review
E-SafeNet (suspected from encoded content)
SKILL.md 包含异常编码内容
ClawHub Apr 12, 2026
Open Report ↗
Review
lifescience-meta-router-internal
声明执行框架但无实际代码
ClawHub Apr 12, 2026
Open Report ↗