Risk Sample Stream

Which skills recently failed
or triggered trust review

This is not a popularity board. It shows recently reviewed skills that the system believes should be blocked or at least manually reviewed. The point is not how popular they are, but why they should not be installed blindly.

426 Risky samples surfaced
5 New in 7 days
0 Platform misses surfaced
All Code Exec Credential Theft Data Exfil Priv Esc Supply Chain Doc Deception Prompt Injection Obfuscation
60 /100
Trust
Review

url-manager

文档包含危险 Shell 命令

Doc MismatchPriv Escalation
ClawHub 4 days ago
Open Report ↗
55 /100
Trust
Review

dlazy-idea2video

文档-行为严重不符

Doc MismatchPriv EscalationData ExfilPrompt Injection
ClawHub 6 days ago
Open Report ↗
45 /100
Trust
Review

moltspay-skill

Undeclared external npm dependency

Supply ChainDoc MismatchCredential TheftPersistence
ClawHub 19 days ago
Open Report ↗
60 /100
Trust
Review

x402-compute

远程脚本管道执行

Supply ChainSensitive AccessRCEPriv Escalation
ClawHub 21 days ago
Open Report ↗
35 /100
Trust
High Risk

psychology-analysis

静默phoneLogin调用

Doc MismatchCredential TheftSensitive AccessPriv Escalation
ClawHub 29 days ago
Open Report ↗
55 /100
Trust
Review

wechat_bridge

Hardcoded credentials in wechat.yaml

Credential TheftSensitive AccessPriv EscalationDoc Mismatch
ClawHub Jun 24, 2026
Open Report ↗
55 /100
Trust
Review

子网计算服务

Skill repurposed from unrelated gaokao/school service

Doc MismatchPriv EscalationCredential TheftSupply Chain
ClawHub Jun 24, 2026
Open Report ↗
32 /100
Trust
High Risk

auto-skill-hunter

Undeclared shell:WRITE via execSync — git clone

Priv EscalationSupply ChainDoc MismatchSensitive Access
ClawHub Jun 24, 2026
Open Report ↗
35 /100
Trust
High Risk

memphis-cognitive

Remote script execution via curl|bash

Supply ChainDoc MismatchPriv Escalation
ClawHub Jun 24, 2026
Open Report ↗
55 /100
Trust
Review

a2a-article-services

文档声称加密但代码未实现

Doc MismatchSupply ChainPriv EscalationSensitive Access
ClawHub Jun 24, 2026
Open Report ↗
55 /100
Trust
Review

cmd-execution-test

Unrestricted Custom Command Execution

RCESensitive AccessDoc MismatchPriv Escalation
ClawHub Jun 23, 2026
Open Report ↗
58 /100
Trust
Review

agile-workflow

Undeclared Shell Execution Capability

Doc MismatchPriv EscalationSensitive AccessPersistence
ClawHub Jun 22, 2026
Open Report ↗
55 /100
Trust
Review

aibtc

动态执行未版本锁定的远程 npm 包

Supply ChainDoc MismatchSensitive AccessPriv Escalation
ClawHub Jun 22, 2026
Open Report ↗
40 /100
Trust
Review

辛一金虹桥店7天排产预测

Sensitive spreadsheets uploaded to unauthenticated plain-HTTP endpoint

Data ExfilDoc MismatchSupply ChainPriv Escalation
ClawHub Jun 22, 2026
Open Report ↗
35 /100
Trust
High Risk

tunnel-proxy

Unrestricted PTY shell access granted to agent

RCESensitive AccessData ExfilDoc Mismatch
ClawHub Jun 21, 2026
Open Report ↗
43 /100
Trust
Review

ludwitt-university

Server-controlled shell command injection via updateInstructions

Doc MismatchPriv EscalationData ExfilSensitive Access
ClawHub Jun 20, 2026
Open Report ↗
1 / 8
Next →