Risk Sample Stream

Which skills recently failed
or triggered trust review

This is not a popularity board. It shows recently reviewed skills that the system believes should be blocked or at least manually reviewed. The point is not how popular they are, but why they should not be installed blindly.

349 Risky samples surfaced
4 New in 7 days
0 Platform misses surfaced
All Code Exec Credential Theft Data Exfil Priv Esc Supply Chain Doc Deception Prompt Injection Obfuscation
50 /100
Trust
Review

E-SafeNet (suspected from encoded content)

SKILL.md 包含异常编码内容

ObfuscationDoc Mismatch
ClawHub Apr 12, 2026
Open Report ↗
25 /100
Trust
High Risk

ludwitt-university

updateInstructions 远程代码执行通道

RCEDoc MismatchPersistenceCredential Theft
ClawHub Apr 12, 2026
Open Report ↗
55 /100
Trust
Review

lifescience-meta-router-internal

声明执行框架但无实际代码

Doc MismatchPriv Escalation
ClawHub Apr 12, 2026
Open Report ↗
40 /100
Trust
Review

odds-movement-monitor

硬编码第三方API密钥

Credential TheftDoc MismatchSupply Chain
ClawHub Apr 11, 2026
Open Report ↗
55 /100
Trust
Review

skills-collection

网络出站声明与实际行为不符

Doc MismatchSupply Chain
ClawHub Apr 11, 2026
Open Report ↗
55 /100
Trust
Review

a2a-article-services

硬编码外部 IP 地址

Supply ChainData ExfilDoc MismatchSensitive Access
ClawHub Apr 11, 2026
Open Report ↗
60 /100
Trust
Review

dating

ManoBrowser 脚本连接外部数据采集服务端点

Data ExfilPriv EscalationDoc MismatchSupply Chain
ClawHub Apr 10, 2026
Open Report ↗
32 /100
Trust
High Risk

birth-system-manager

文档承诺不显示私钥但代码明文输出

Doc MismatchCredential TheftSupply ChainSensitive Access
ClawHub Apr 10, 2026
Open Report ↗
65 /100
Trust
Review

fin-advisor

未声明的网络访问能力

Doc MismatchSensitive AccessSupply Chain
ClawHub Apr 9, 2026
Open Report ↗
45 /100
Trust
Review

Memphis Cognitive Engine

远程脚本执行 - Memphis安装

Supply ChainDoc MismatchSensitive Access
ClawHub Apr 9, 2026
Open Report ↗
60 /100
Trust
Review

cmd-execution-test

影子功能 - 未声明的任意命令执行能力

Doc MismatchRCEPriv EscalationSupply Chain
ClawHub Apr 9, 2026
Open Report ↗
65 /100
Trust
Review

mindkeeper

文档未声明可触发远程脚本执行

Doc MismatchSupply ChainSensitive Access
ClawHub Apr 7, 2026
Open Report ↗
55 /100
Trust
Review

botlearn

SKILL.md 未声明 cmd_scan 的完整数据收集范围

Doc MismatchSupply ChainSensitive AccessPriv Escalation
ClawHub Apr 7, 2026
Open Report ↗
55 /100
Trust
Review

typescript-package-manager

远程脚本管道执行

RCEDoc MismatchPriv EscalationSupply Chain
ClawHub Apr 6, 2026
Open Report ↗
50 /100
Trust
Review

math-utils

命令注入漏洞

RCEDoc MismatchSupply Chain
ClawHub Apr 6, 2026
Open Report ↗
60 /100
Trust
Review

wip-readme-format

未声明的文件系统写入权限

Priv EscalationObfuscationSupply ChainDoc Mismatch
ClawHub Apr 6, 2026
Open Report ↗
← Previous
3 / 15
Next →