Risk Sample Stream

Which skills recently failed
or triggered trust review

This is not a popularity board. It shows recently reviewed skills that the system believes should be blocked or at least manually reviewed. The point is not how popular they are, but why they should not be installed blindly.

510 Risky samples surfaced
12 New in 7 days
0 Platform misses surfaced
All Code Exec Credential Theft Data Exfil Priv Esc Supply Chain Doc Deception Prompt Injection Obfuscation
28 /100
Trust
High Risk

stellar-trails

GitHub PAT 明文持久化到文件系统

Credential TheftPersistencePriv EscalationSensitive Access
ClawHub 1 day ago
Open Report ↗
30 /100
Trust
High Risk

chrome-use

curl|sh远程脚本执行供应链攻击风险

Supply ChainDoc MismatchPriv Escalation
ClawHub 1 day ago
Open Report ↗
32 /100
Trust
High Risk

GitToQuark

Referenced scripts not included in package

Supply ChainPriv EscalationDoc Mismatch
ClawHub 4 days ago
Open Report ↗
30 /100
Trust
High Risk

perkoon-transfer

Remote script execution without integrity verification

Supply ChainDoc MismatchPriv EscalationSensitive Access
ClawHub 9 days ago
Open Report ↗
35 /100
Trust
High Risk

meta-analysis

Coze API 令牌以可逆混淆形式嵌入源代码,随技能公开发布

Credential TheftData ExfilPriv EscalationSupply Chain
ClawHub 13 days ago
Open Report ↗
32 /100
Trust
High Risk

yqzl-ai-service

Automatic code download and execution without consent

Supply ChainDoc MismatchPriv EscalationSensitive Access
ClawHub Jul 28, 2026
Open Report ↗
35 /100
Trust
High Risk

psychology-analysis

静默phoneLogin调用

Doc MismatchCredential TheftSensitive AccessPriv Escalation
ClawHub Jun 28, 2026
Open Report ↗
32 /100
Trust
High Risk

auto-skill-hunter

Undeclared shell:WRITE via execSync — git clone

Priv EscalationSupply ChainDoc MismatchSensitive Access
ClawHub Jun 24, 2026
Open Report ↗
35 /100
Trust
High Risk

memphis-cognitive

Remote script execution via curl|bash

Supply ChainDoc MismatchPriv Escalation
ClawHub Jun 24, 2026
Open Report ↗
35 /100
Trust
High Risk

tunnel-proxy

Unrestricted PTY shell access granted to agent

RCESensitive AccessData ExfilDoc Mismatch
ClawHub Jun 21, 2026
Open Report ↗
25 /100
Trust
High Risk

birth-system-manager

SKILL.md claims private keys are never displayed, but code prints them to stdout

Doc MismatchCredential TheftSensitive AccessPriv Escalation
ClawHub Jun 18, 2026
Open Report ↗
30 /100
Trust
High Risk

pub

Remote script execution from unverified source

Supply ChainRCEPriv EscalationDoc Mismatch
ClawHub Jun 18, 2026
Open Report ↗
25 /100
Trust
High Risk

skill-publisher

硬编码 GitHub Personal Access Token

Credential TheftDoc MismatchSensitive AccessPriv Escalation
ClawHub Jun 11, 2026
Open Report ↗
45 /100
Trust
High Risk

agnes-image-gen

Hardcoded real API key in SKILL.md

Credential TheftDoc MismatchPriv Escalation
ClawHub Jun 10, 2026
Open Report ↗
35 /100
Trust
High Risk

superada-workflow-entity-mission-control-bootstrap

外部仓库代码执行

Supply ChainRCEDoc MismatchPriv Escalation
ClawHub Jun 3, 2026
Open Report ↗
35 /100
Trust
High Risk

tweet-monitor-pro

文档声称零依赖但实际存在外部脚本依赖

Doc MismatchPriv EscalationSupply ChainSensitive Access
ClawHub Apr 19, 2026
Open Report ↗
1 / 3
Next →