Which skills recently failed
or triggered trust review
This is not a popularity board. It shows recently reviewed skills that the system believes should be blocked or at least manually reviewed. The point is not how popular they are, but why they should not be installed blindly.
wip-readme-format
未声明的文件系统写入权限
115-skills
User-Agent包含可疑硬编码IP
luci-memory
API密钥在初始化时即被外传至硬编码外部IP
asiasea-bi
API认证凭证通过Base64编码嵌入可公开访问的HTML
ClawSentry
代码高度混淆难以审计
dianping-api
Remote Script Execution via curl|bash
hive-commander
Covert credential extraction from runtime environment
gequhai-music
Hardcoded Synology password not declared in documentation
monid
Remote script execution via curl|bash from mutable branch
Unknown (E-SafeNet LOCK visible in binary)
Binary content in SKILL.md
turing-pot-biglog
Undeclared base64 encoding of WebSocket messages
mind-wander
Undeclared arbitrary Python code execution via sandbox_run()
minimal-agent
Unrestricted Arbitrary Command Execution via V1 Mode
castreader
Undeclared network requests to external API
openclaw-usage-manager
API tokens stored in plaintext on disk
feishu-evolver-wrapper
Dynamic code evaluation on untrusted input