Which skills recently failed
or triggered trust review
This is not a popularity board. It shows recently reviewed skills that the system believes should be blocked or at least manually reviewed. The point is not how popular they are, but why they should not be installed blindly.
openclaw-backup
Missing implementation scripts
claw-ops-manager
Undeclared Shell Command Execution
hpr-solver
Undeclared LLM API calls to OpenRouter
fund-daily
Undeclared network API access
stock-prediction
Undeclared shell command execution
hive-commander
Covert credential extraction from runtime environment
抖音视频无水印下载器
Undocumented third-party proxy API
cloud-share-downloader
Undeclared credential solicitation
research-archive-query
Undeclared subprocess/shell execution
gangtise-kb
Undeclared subprocess execution with missing binary
harbor-openclaw
Undeclared network behavior on first load
airoom.ltd-Global-Finance-Data-Platform
HTTP target URL without TLS encryption
face-analysis
Hardcoded Database Credentials in config.yaml
imap-idle-sneder
Hardcoded email credentials in source code
OnionClaw
Missing implementation code—only documentation present
sshot
Critical script artifact not included in package