Which skills recently failed
or triggered trust review
This is not a popularity board. It shows recently reviewed skills that the system believes should be blocked or at least manually reviewed. The point is not how popular they are, but why they should not be installed blindly.
memphis-cognitive
Remote script execution via curl|bash
a2a-article-services
文档声称加密但代码未实现
cmd-execution-test
Unrestricted Custom Command Execution
agile-workflow
Undeclared Shell Execution Capability
aibtc
动态执行未版本锁定的远程 npm 包
辛一金虹桥店7天排产预测
Sensitive spreadsheets uploaded to unauthenticated plain-HTTP endpoint
tunnel-proxy
Unrestricted PTY shell access granted to agent
ludwitt-university
Server-controlled shell command injection via updateInstructions
introspection-debugger
Undeclared shell command execution
x-tweet-fetcher
Shell execution not declared in SKILL.md
birth-system-manager
SKILL.md claims private keys are never displayed, but code prints them to stdout
pub
Remote script execution from unverified source
solo-mission
未声明的远程脚本执行(Foundry 安装)
skill-publisher
硬编码 GitHub Personal Access Token
agnes-image-gen
Hardcoded real API key in SKILL.md
superada-workflow-entity-mission-control-bootstrap
外部仓库代码执行