Which skills recently failed
or triggered trust review
This is not a popularity board. It shows recently reviewed skills that the system believes should be blocked or at least manually reviewed. The point is not how popular they are, but why they should not be installed blindly.
cmd-execution-test
Unrestricted Custom Command Execution
sa-master
Hardcoded API bearer token in config.json
agile-workflow
Undeclared Shell Execution Capability
imitation-agent
Server-generated crypto wallet private key stored in plaintext
辛一金虹桥店7天排产预测
Sensitive spreadsheets uploaded to unauthenticated plain-HTTP endpoint
gpt-image-2
Hardcoded external IP with no DNS resolution
pm-master
Bearer 令牌硬编码于配置文件中随分发包传播
tunnel-proxy
Unrestricted PTY shell access granted to agent
a2a-article-services
Undeclared filesystem WRITE access
yqzl-ai-service
财务票据数据发送至外部IP
ludwitt-university
Server-controlled shell command injection via updateInstructions
introspection-debugger
Undeclared shell command execution
precc
curl|bash 远程脚本执行
news-briefing
Command injection via user-supplied --topic
birth-system-manager
SKILL.md claims private keys are never displayed, but code prints them to stdout
pub
Remote script execution from unverified source