Risk Sample Stream

Which skills recently failed
or triggered trust review

This is not a popularity board. It shows recently reviewed skills that the system believes should be blocked or at least manually reviewed. The point is not how popular they are, but why they should not be installed blindly.

510 Risky samples surfaced
12 New in 7 days
0 Platform misses surfaced
All Code Exec Credential Theft Data Exfil Priv Esc Supply Chain Doc Deception Prompt Injection Obfuscation
35 /100
Trust
High Risk

memphis-cognitive

Remote script execution via curl|bash

Supply ChainDoc MismatchPriv Escalation
ClawHub Jun 24, 2026
Open Report ↗
55 /100
Trust
Review

a2a-article-services

文档声称加密但代码未实现

Doc MismatchSupply ChainPriv EscalationSensitive Access
ClawHub Jun 24, 2026
Open Report ↗
55 /100
Trust
Review

cmd-execution-test

Unrestricted Custom Command Execution

RCESensitive AccessDoc MismatchPriv Escalation
ClawHub Jun 23, 2026
Open Report ↗
58 /100
Trust
Review

agile-workflow

Undeclared Shell Execution Capability

Doc MismatchPriv EscalationSensitive AccessPersistence
ClawHub Jun 22, 2026
Open Report ↗
55 /100
Trust
Review

aibtc

动态执行未版本锁定的远程 npm 包

Supply ChainDoc MismatchSensitive AccessPriv Escalation
ClawHub Jun 22, 2026
Open Report ↗
40 /100
Trust
Review

辛一金虹桥店7天排产预测

Sensitive spreadsheets uploaded to unauthenticated plain-HTTP endpoint

Data ExfilDoc MismatchSupply ChainPriv Escalation
ClawHub Jun 22, 2026
Open Report ↗
35 /100
Trust
High Risk

tunnel-proxy

Unrestricted PTY shell access granted to agent

RCESensitive AccessData ExfilDoc Mismatch
ClawHub Jun 21, 2026
Open Report ↗
43 /100
Trust
Review

ludwitt-university

Server-controlled shell command injection via updateInstructions

Doc MismatchPriv EscalationData ExfilSensitive Access
ClawHub Jun 20, 2026
Open Report ↗
45 /100
Trust
Review

introspection-debugger

Undeclared shell command execution

Doc MismatchPriv EscalationSupply ChainData Exfil
ClawHub Jun 20, 2026
Open Report ↗
65 /100
Trust
Review

x-tweet-fetcher

Shell execution not declared in SKILL.md

Doc MismatchCredential TheftPriv Escalation
GitHub Jun 19, 2026
Open Report ↗
25 /100
Trust
High Risk

birth-system-manager

SKILL.md claims private keys are never displayed, but code prints them to stdout

Doc MismatchCredential TheftSensitive AccessPriv Escalation
ClawHub Jun 18, 2026
Open Report ↗
30 /100
Trust
High Risk

pub

Remote script execution from unverified source

Supply ChainRCEPriv EscalationDoc Mismatch
ClawHub Jun 18, 2026
Open Report ↗
65 /100
Trust
Review

solo-mission

未声明的远程脚本执行(Foundry 安装)

Supply ChainPriv EscalationDoc Mismatch
ClawHub Jun 16, 2026
Open Report ↗
25 /100
Trust
High Risk

skill-publisher

硬编码 GitHub Personal Access Token

Credential TheftDoc MismatchSensitive AccessPriv Escalation
ClawHub Jun 11, 2026
Open Report ↗
45 /100
Trust
High Risk

agnes-image-gen

Hardcoded real API key in SKILL.md

Credential TheftDoc MismatchPriv Escalation
ClawHub Jun 10, 2026
Open Report ↗
35 /100
Trust
High Risk

superada-workflow-entity-mission-control-bootstrap

外部仓库代码执行

Supply ChainRCEDoc MismatchPriv Escalation
ClawHub Jun 3, 2026
Open Report ↗
← Previous
3 / 9
Next →