Risk Sample Stream

Which skills recently failed
or triggered trust review

This is not a popularity board. It shows recently reviewed skills that the system believes should be blocked or at least manually reviewed. The point is not how popular they are, but why they should not be installed blindly.

349 Risky samples surfaced
4 New in 7 days
0 Platform misses surfaced
All Code Exec Credential Theft Data Exfil Priv Esc Supply Chain Doc Deception Prompt Injection Obfuscation
35 /100
Trust
Review

gpt-image-2

未声明的外部网络通信

Doc MismatchData ExfilObfuscation
ClawHub Apr 22, 2026
Open Report ↗
55 /100
Trust
Review

auto-skill-hunter

权限声明与实际能力严重不符

Priv EscalationSupply ChainDoc MismatchSensitive Access
ClawHub Apr 19, 2026
Open Report ↗
50 /100
Trust
Review

E-SafeNet (suspected from encoded content)

SKILL.md 包含异常编码内容

ObfuscationDoc Mismatch
ClawHub Apr 12, 2026
Open Report ↗
60 /100
Trust
Review

wip-readme-format

未声明的文件系统写入权限

Priv EscalationObfuscationSupply ChainDoc Mismatch
ClawHub Apr 6, 2026
Open Report ↗
72 /100
Trust
Review

115-skills

User-Agent包含可疑硬编码IP

Doc MismatchObfuscationSupply ChainPriv Escalation
ClawHub Apr 6, 2026
Open Report ↗
40 /100
Trust
Review

asiasea-bi

API认证凭证通过Base64编码嵌入可公开访问的HTML

Credential TheftDoc MismatchObfuscationSupply Chain
Manual upload Apr 5, 2026
Open Report ↗
55 /100
Trust
Review

ClawSentry

代码高度混淆难以审计

ObfuscationSupply ChainPriv EscalationSensitive Access
Manual upload Apr 5, 2026
Open Report ↗
55 /100
Trust
Review

gequhai-music

Hardcoded Synology password not declared in documentation

Credential TheftObfuscationDoc MismatchPriv Escalation
Manual upload Apr 5, 2026
Open Report ↗
45 /100
Trust
Review

turing-pot-biglog

Undeclared base64 encoding of WebSocket messages

Doc MismatchCredential TheftSupply ChainObfuscation
Manual upload Apr 4, 2026
Open Report ↗
55 /100
Trust
Review

castreader

Undeclared network requests to external API

Doc MismatchSensitive AccessObfuscation
Manual upload Apr 4, 2026
Open Report ↗
60 /100
Trust
Review

openclaw-usage-manager

API tokens stored in plaintext on disk

Credential TheftDoc MismatchPriv EscalationObfuscation
Manual upload Apr 4, 2026
Open Report ↗
55 /100
Trust
Review

feishu-evolver-wrapper

Dynamic code evaluation on untrusted input

ObfuscationPriv EscalationDoc MismatchPrompt Injection
Manual upload Apr 4, 2026
Open Report ↗