Risk Sample Stream

Which skills recently failed
or triggered trust review

This is not a popularity board. It shows recently reviewed skills that the system believes should be blocked or at least manually reviewed. The point is not how popular they are, but why they should not be installed blindly.

426 Risky samples surfaced
5 New in 7 days
0 Platform misses surfaced
All Code Exec Credential Theft Data Exfil Priv Esc Supply Chain Doc Deception Prompt Injection Obfuscation
62 /100
Trust
Review

sage-router

systemctl服务管理未在声明中

Priv EscalationDoc Mismatch
ClawHub Apr 21, 2026
Open Report ↗
58 /100
Trust
Review

news-briefing

未声明的 shell 执行和动态代码注入

Doc MismatchSupply ChainPriv Escalation
ClawHub Apr 20, 2026
Open Report ↗
35 /100
Trust
High Risk

tweet-monitor-pro

文档声称零依赖但实际存在外部脚本依赖

Doc MismatchPriv EscalationSupply ChainSensitive Access
ClawHub Apr 19, 2026
Open Report ↗
50 /100
Trust
Review

daily-memory-summary

未声明的联系人信息提取功能

Doc MismatchSensitive AccessPriv Escalation
ClawHub Apr 19, 2026
Open Report ↗
55 /100
Trust
Review

lifescience-meta-router-internal

声明执行框架但无实际代码

Doc MismatchPriv Escalation
ClawHub Apr 12, 2026
Open Report ↗
55 /100
Trust
Review

odds-movement-monitor

硬编码API密钥暴露

Credential TheftDoc MismatchPriv Escalation
ClawHub Apr 11, 2026
Open Report ↗
55 /100
Trust
Review

self-evolution-engine

硬编码API密钥暴露

Credential TheftDoc MismatchSupply ChainPriv Escalation
ClawHub Apr 10, 2026
Open Report ↗
60 /100
Trust
Review

dating

ManoBrowser 脚本连接外部数据采集服务端点

Data ExfilPriv EscalationDoc MismatchSupply Chain
ClawHub Apr 10, 2026
Open Report ↗
55 /100
Trust
Review

botlearn

SKILL.md 未声明 cmd_scan 的完整数据收集范围

Doc MismatchSupply ChainSensitive AccessPriv Escalation
ClawHub Apr 7, 2026
Open Report ↗
55 /100
Trust
Review

typescript-package-manager

远程脚本管道执行

RCEDoc MismatchPriv EscalationSupply Chain
ClawHub Apr 6, 2026
Open Report ↗
68 /100
Trust
Review

agent-guardian

Python 依赖无版本锁定

Supply ChainPriv EscalationSensitive Access
ClawHub Apr 6, 2026
Open Report ↗
60 /100
Trust
Review

wip-readme-format

未声明的文件系统写入权限

Priv EscalationObfuscationSupply ChainDoc Mismatch
ClawHub Apr 6, 2026
Open Report ↗
55 /100
Trust
Review

bt-download

未声明的外部网络访问

Doc MismatchSupply ChainPriv EscalationSensitive Access
ClawHub Apr 6, 2026
Open Report ↗
45 /100
Trust
Review

pumpclaw-agent

SKILL.md声明与代码行为不符:交易签名

Doc MismatchSensitive AccessSupply ChainPriv Escalation
ClawHub Apr 6, 2026
Open Report ↗
60 /100
Trust
Review

nim-ensemble / free-scaling

Copilot token刷新机制未在文档中声明

Doc MismatchPriv EscalationSupply Chain
ClawHub Apr 6, 2026
Open Report ↗
72 /100
Trust
Review

115-skills

User-Agent包含可疑硬编码IP

Doc MismatchObfuscationSupply ChainPriv Escalation
ClawHub Apr 6, 2026
Open Report ↗
← Previous
3 / 8
Next →