Risk Sample Stream

Which skills recently failed
or triggered trust review

This is not a popularity board. It shows recently reviewed skills that the system believes should be blocked or at least manually reviewed. The point is not how popular they are, but why they should not be installed blindly.

510 Risky samples surfaced
12 New in 7 days
0 Platform misses surfaced
All Code Exec Credential Theft Data Exfil Priv Esc Supply Chain Doc Deception Prompt Injection Obfuscation
55 /100
Trust
Review

multi-research

文档包含可疑表述

Doc MismatchPriv EscalationSupply Chain
ClawHub 28 days ago
Open Report ↗
55 /100
Trust
Review

taskfuel

远程脚本管道执行

RCEPriv EscalationDoc Mismatch
ClawHub 28 days ago
Open Report ↗
58 /100
Trust
Review

smyx-child-focus-analysis-analysis

隐式凭证管理机制

Sensitive AccessDoc MismatchData ExfilPriv Escalation
ClawHub Aug 11, 2026
Open Report ↗
65 /100
Trust
Review

coppa-check

--non-interactive 模式影子联网行为

Doc MismatchPriv Escalation
ClawHub Aug 10, 2026
Open Report ↗
55 /100
Trust
Review

precc

危险的远程脚本执行安装方式

RCESupply ChainPriv EscalationDoc Mismatch
ClawHub Aug 8, 2026
Open Report ↗
55 /100
Trust
Review

cloud-ops-orchestrator

文档占位符泛滥

Doc MismatchPriv EscalationSupply Chain
ClawHub Aug 8, 2026
Open Report ↗
50 /100
Trust
Review

sa-master

Hardcoded bearer token in config.json

Doc MismatchCredential TheftData ExfilPriv Escalation
ClawHub Aug 1, 2026
Open Report ↗
32 /100
Trust
High Risk

yqzl-ai-service

Automatic code download and execution without consent

Supply ChainDoc MismatchPriv EscalationSensitive Access
ClawHub Jul 28, 2026
Open Report ↗
60 /100
Trust
Review

url-manager

文档包含危险 Shell 命令

Doc MismatchPriv Escalation
ClawHub Jul 23, 2026
Open Report ↗
55 /100
Trust
Review

dlazy-idea2video

文档-行为严重不符

Doc MismatchPriv EscalationData ExfilPrompt Injection
ClawHub Jul 21, 2026
Open Report ↗
45 /100
Trust
Review

moltspay-skill

Undeclared external npm dependency

Supply ChainDoc MismatchCredential TheftPersistence
ClawHub Jul 8, 2026
Open Report ↗
60 /100
Trust
Review

x402-compute

远程脚本管道执行

Supply ChainSensitive AccessRCEPriv Escalation
ClawHub Jul 6, 2026
Open Report ↗
35 /100
Trust
High Risk

psychology-analysis

静默phoneLogin调用

Doc MismatchCredential TheftSensitive AccessPriv Escalation
ClawHub Jun 28, 2026
Open Report ↗
55 /100
Trust
Review

wechat_bridge

Hardcoded credentials in wechat.yaml

Credential TheftSensitive AccessPriv EscalationDoc Mismatch
ClawHub Jun 24, 2026
Open Report ↗
55 /100
Trust
Review

子网计算服务

Skill repurposed from unrelated gaokao/school service

Doc MismatchPriv EscalationCredential TheftSupply Chain
ClawHub Jun 24, 2026
Open Report ↗
32 /100
Trust
High Risk

auto-skill-hunter

Undeclared shell:WRITE via execSync — git clone

Priv EscalationSupply ChainDoc MismatchSensitive Access
ClawHub Jun 24, 2026
Open Report ↗
← Previous
2 / 9
Next →