Risk Sample Stream

Which skills recently failed
or triggered trust review

This is not a popularity board. It shows recently reviewed skills that the system believes should be blocked or at least manually reviewed. The point is not how popular they are, but why they should not be installed blindly.

510 Risky samples surfaced
12 New in 7 days
0 Platform misses surfaced
All Code Exec Credential Theft Data Exfil Priv Esc Supply Chain Doc Deception Prompt Injection Obfuscation
55 /100
Trust
Review

polish

Phase 1 命令执行未受限

RCEDoc MismatchCredential TheftPriv Escalation
ClawHub 1 day ago
Open Report ↗
28 /100
Trust
High Risk

stellar-trails

GitHub PAT 明文持久化到文件系统

Credential TheftPersistencePriv EscalationSensitive Access
ClawHub 1 day ago
Open Report ↗
30 /100
Trust
High Risk

chrome-use

curl|sh远程脚本执行供应链攻击风险

Supply ChainDoc MismatchPriv Escalation
ClawHub 1 day ago
Open Report ↗
32 /100
Trust
High Risk

GitToQuark

Referenced scripts not included in package

Supply ChainPriv EscalationDoc Mismatch
ClawHub 4 days ago
Open Report ↗
30 /100
Trust
High Risk

perkoon-transfer

Remote script execution without integrity verification

Supply ChainDoc MismatchPriv EscalationSensitive Access
ClawHub 9 days ago
Open Report ↗
40 /100
Trust
Review

klyc-pmm

Server-side code execution not declared in SKILL.md

Doc MismatchCredential TheftPriv EscalationSupply Chain
ClawHub 9 days ago
Open Report ↗
65 /100
Trust
Review

xerg

外部npm包供应链依赖

Supply ChainPriv EscalationDoc Mismatch
ClawHub 10 days ago
Open Report ↗
55 /100
Trust
Review

demo-text-summarizer

未声明的 workflow.taskflow.yaml 阴影功能

Doc MismatchSupply ChainPriv Escalation
ClawHub 11 days ago
Open Report ↗
55 /100
Trust
Review

grok-image-tool-pro

权限声明宽泛且无实际代码支撑

Doc MismatchPriv EscalationSupply Chain
ClawHub 13 days ago
Open Report ↗
35 /100
Trust
High Risk

meta-analysis

Coze API 令牌以可逆混淆形式嵌入源代码,随技能公开发布

Credential TheftData ExfilPriv EscalationSupply Chain
ClawHub 13 days ago
Open Report ↗
35 /100
Trust
Review

job-agent

危险的远程脚本执行安装命令

Supply ChainDoc MismatchPriv Escalation
ClawHub 19 days ago
Open Report ↗
65 /100
Trust
Review

llm-assistant-hub

声明exec但无代码验证

Priv EscalationDoc Mismatch
ClawHub 20 days ago
Open Report ↗
65 /100
Trust
Review

ClawSheet Wizard

公式数据外传到外部 IP

Data ExfilSupply ChainCredential TheftPriv Escalation
ClawHub 21 days ago
Open Report ↗
40 /100
Trust
Review

x402card-agent

远程脚本安装绕过本地审计

Supply ChainDoc MismatchPriv Escalation
ClawHub 23 days ago
Open Report ↗
60 /100
Trust
Review

smyx-fish-surface-symptom-detection-analysis

未声明的阴影功能:subprocess 调用框架

Doc MismatchPriv EscalationSupply ChainSensitive Access
ClawHub 25 days ago
Open Report ↗
58 /100
Trust
Review

rotifer-self-evolving-agent

通过npx动态执行远程npm包

Supply ChainPriv EscalationRCEData Exfil
ClawHub 26 days ago
Open Report ↗
1 / 9
Next →