Risk Sample Stream

Which skills recently failed
or triggered trust review

This is not a popularity board. It shows recently reviewed skills that the system believes should be blocked or at least manually reviewed. The point is not how popular they are, but why they should not be installed blindly.

349 Risky samples surfaced
4 New in 7 days
0 Platform misses surfaced
All Code Exec Credential Theft Data Exfil Priv Esc Supply Chain Doc Deception Prompt Injection Obfuscation
40 /100
Trust
Review

odds-movement-monitor

硬编码第三方API密钥

Credential TheftDoc MismatchSupply Chain
ClawHub Apr 11, 2026
Open Report ↗
55 /100
Trust
Review

skills-collection

网络出站声明与实际行为不符

Doc MismatchSupply Chain
ClawHub Apr 11, 2026
Open Report ↗
55 /100
Trust
Review

a2a-article-services

硬编码外部 IP 地址

Supply ChainData ExfilDoc MismatchSensitive Access
ClawHub Apr 11, 2026
Open Report ↗
55 /100
Trust
Review

self-evolution-engine

硬编码API密钥暴露

Credential TheftDoc MismatchSupply ChainPriv Escalation
ClawHub Apr 10, 2026
Open Report ↗
60 /100
Trust
Review

dating

ManoBrowser 脚本连接外部数据采集服务端点

Data ExfilPriv EscalationDoc MismatchSupply Chain
ClawHub Apr 10, 2026
Open Report ↗
45 /100
Trust
Review

whale-alert-monitor

硬编码API密钥

Credential TheftDoc MismatchSupply ChainSensitive Access
ClawHub Apr 9, 2026
Open Report ↗
65 /100
Trust
Review

fin-advisor

未声明的网络访问能力

Doc MismatchSensitive AccessSupply Chain
ClawHub Apr 9, 2026
Open Report ↗
45 /100
Trust
Review

Memphis Cognitive Engine

远程脚本执行 - Memphis安装

Supply ChainDoc MismatchSensitive Access
ClawHub Apr 9, 2026
Open Report ↗
60 /100
Trust
Review

cmd-execution-test

影子功能 - 未声明的任意命令执行能力

Doc MismatchRCEPriv EscalationSupply Chain
ClawHub Apr 9, 2026
Open Report ↗
65 /100
Trust
Review

mindkeeper

文档未声明可触发远程脚本执行

Doc MismatchSupply ChainSensitive Access
ClawHub Apr 7, 2026
Open Report ↗
55 /100
Trust
Review

botlearn

SKILL.md 未声明 cmd_scan 的完整数据收集范围

Doc MismatchSupply ChainSensitive AccessPriv Escalation
ClawHub Apr 7, 2026
Open Report ↗
55 /100
Trust
Review

typescript-package-manager

远程脚本管道执行

RCEDoc MismatchPriv EscalationSupply Chain
ClawHub Apr 6, 2026
Open Report ↗
50 /100
Trust
Review

math-utils

命令注入漏洞

RCEDoc MismatchSupply Chain
ClawHub Apr 6, 2026
Open Report ↗
58 /100
Trust
Review

moltspay_skill

npm 全局安装 moltspay 无版本锁定

Supply ChainDoc MismatchRCE
ClawHub Apr 6, 2026
Open Report ↗
60 /100
Trust
Review

wip-readme-format

未声明的文件系统写入权限

Priv EscalationObfuscationSupply ChainDoc Mismatch
ClawHub Apr 6, 2026
Open Report ↗
55 /100
Trust
Review

layered-memory

外部脚本缺失导致功能不可用

Supply ChainDoc Mismatch
ClawHub Apr 6, 2026
Open Report ↗
← Previous
3 / 12
Next →