Risk Sample Stream

Which skills recently failed
or triggered trust review

This is not a popularity board. It shows recently reviewed skills that the system believes should be blocked or at least manually reviewed. The point is not how popular they are, but why they should not be installed blindly.

426 Risky samples surfaced
5 New in 7 days
0 Platform misses surfaced
All Code Exec Credential Theft Data Exfil Priv Esc Supply Chain Doc Deception Prompt Injection Obfuscation
35 /100
Trust
High Risk

perkoon-transfer

远程代码执行(RCE)风险

RCESupply ChainSensitive AccessObfuscation
ClawHub 7 days ago
Open Report ↗
0 /100
Trust
Block

math-calculator

Reverse Shell Payload Embedded in Script

RCEDoc MismatchData ExfilObfuscation
GitHub Jun 24, 2026
Open Report ↗
55 /100
Trust
Review

news-briefing

未声明的封面图生成功能

Doc MismatchObfuscationSensitive Access
ClawHub Jun 21, 2026
Open Report ↗
60 /100
Trust
Review

cloud-compare

文档声明与代码行为不符

Doc MismatchObfuscationSupply ChainSensitive Access
ClawHub Jun 14, 2026
Open Report ↗
35 /100
Trust
Review

gpt-image-2

未声明的外部网络通信

Doc MismatchData ExfilObfuscation
ClawHub Apr 22, 2026
Open Report ↗
55 /100
Trust
Review

auto-skill-hunter

权限声明与实际能力严重不符

Priv EscalationSupply ChainDoc MismatchSensitive Access
ClawHub Apr 19, 2026
Open Report ↗
50 /100
Trust
Review

E-SafeNet (suspected from encoded content)

SKILL.md 包含异常编码内容

ObfuscationDoc Mismatch
ClawHub Apr 12, 2026
Open Report ↗
60 /100
Trust
Review

wip-readme-format

未声明的文件系统写入权限

Priv EscalationObfuscationSupply ChainDoc Mismatch
ClawHub Apr 6, 2026
Open Report ↗
72 /100
Trust
Review

115-skills

User-Agent包含可疑硬编码IP

Doc MismatchObfuscationSupply ChainPriv Escalation
ClawHub Apr 6, 2026
Open Report ↗
15 /100
Trust
Block

luci-memory

API密钥在初始化时即被外传至硬编码外部IP

Credential TheftData ExfilObfuscationDoc Mismatch
Manual upload Apr 5, 2026
Open Report ↗
40 /100
Trust
Review

asiasea-bi

API认证凭证通过Base64编码嵌入可公开访问的HTML

Credential TheftDoc MismatchObfuscationSupply Chain
Manual upload Apr 5, 2026
Open Report ↗
55 /100
Trust
Review

ClawSentry

代码高度混淆难以审计

ObfuscationSupply ChainPriv EscalationSensitive Access
Manual upload Apr 5, 2026
Open Report ↗
35 /100
Trust
High Risk

dianping-api

Remote Script Execution via curl|bash

Supply ChainObfuscationDoc Mismatch
Manual upload Apr 5, 2026
Open Report ↗
25 /100
Trust
High Risk

hive-commander

Covert credential extraction from runtime environment

Credential TheftData ExfilDoc MismatchPriv Escalation
Manual upload Apr 5, 2026
Open Report ↗
55 /100
Trust
Review

gequhai-music

Hardcoded Synology password not declared in documentation

Credential TheftObfuscationDoc MismatchPriv Escalation
Manual upload Apr 5, 2026
Open Report ↗
38 /100
Trust
High Risk

monid

Remote script execution via curl|bash from mutable branch

RCEPriv EscalationCredential TheftDoc Mismatch
Manual upload Apr 4, 2026
Open Report ↗
1 / 2
Next →