Which skills recently failed
or triggered trust review
This is not a popularity board. It shows recently reviewed skills that the system believes should be blocked or at least manually reviewed. The point is not how popular they are, but why they should not be installed blindly.
Review
cmd-execution-test
影子功能 - 未声明的任意命令执行能力
ClawHub Apr 9, 2026
Open Report ↗
Review
botlearn
SKILL.md 未声明 cmd_scan 的完整数据收集范围
ClawHub Apr 7, 2026
Open Report ↗
Review
typescript-package-manager
远程脚本管道执行
ClawHub Apr 6, 2026
Open Report ↗
Review
agent-guardian
Python 依赖无版本锁定
ClawHub Apr 6, 2026
Open Report ↗
Review
wip-readme-format
未声明的文件系统写入权限
ClawHub Apr 6, 2026
Open Report ↗
Review
bt-download
未声明的外部网络访问
ClawHub Apr 6, 2026
Open Report ↗
Review
pumpclaw-agent
SKILL.md声明与代码行为不符:交易签名
ClawHub Apr 6, 2026
Open Report ↗
Review
nim-ensemble / free-scaling
Copilot token刷新机制未在文档中声明
ClawHub Apr 6, 2026
Open Report ↗
Review
task-progress-stream
状态文件写入未声明
ClawHub Apr 6, 2026
Open Report ↗
Review
agile-workflow
硬编码用户目录路径
ClawHub Apr 6, 2026
Open Report ↗
Review
115-skills
User-Agent包含可疑硬编码IP
ClawHub Apr 6, 2026
Open Report ↗
Review
baidu-netdisk-skill
硬编码加密密钥使 AES-256 加密承诺失效
ClawHub Apr 6, 2026
Open Report ↗
Review
markdown-ai-rewriter
npx 动态拉取第三方包
ClawHub Apr 6, 2026
Open Report ↗
Review
feishu-bot-config-helper
危险远程脚本管道执行
Manual upload Apr 5, 2026
Open Report ↗
Review
feishu-ops
影子功能:本地桌面文件操作未在文档声明
Manual upload Apr 5, 2026
Open Report ↗
Review
Awesome Pentest
文档声明与实际代码严重不符
Manual upload Apr 5, 2026
Open Report ↗