Risk Sample Stream

Which skills recently failed
or triggered trust review

This is not a popularity board. It shows recently reviewed skills that the system believes should be blocked or at least manually reviewed. The point is not how popular they are, but why they should not be installed blindly.

349 Risky samples surfaced
4 New in 7 days
0 Platform misses surfaced
All Code Exec Credential Theft Data Exfil Priv Esc Supply Chain Doc Deception Prompt Injection Obfuscation
35 /100
Trust
High Risk

Setup Multi Gateway

硬编码API密钥

Credential TheftDoc MismatchPriv Escalation
Manual upload Apr 5, 2026
Open Report ↗
55 /100
Trust
Review

Awesome Pentest

文档声明与实际代码严重不符

Doc MismatchPriv EscalationSupply Chain
Manual upload Apr 5, 2026
Open Report ↗
55 /100
Trust
Review

ClawSentry

代码高度混淆难以审计

ObfuscationSupply ChainPriv EscalationSensitive Access
Manual upload Apr 5, 2026
Open Report ↗
45 /100
Trust
Review

ekybot-connector

文档声明与实际能力严重不符

Doc MismatchCredential TheftPriv EscalationSensitive Access
Manual upload Apr 5, 2026
Open Report ↗
65 /100
Trust
Review

stremio-cli

文档与代码不一致

Doc MismatchPriv EscalationSupply Chain
Manual upload Apr 5, 2026
Open Report ↗
35 /100
Trust
High Risk

memolecard-auto

Cookie extraction and exfiltration to configurable external server

Credential TheftData ExfilDoc MismatchPriv Escalation
Manual upload Apr 5, 2026
Open Report ↗
8 /100
Trust
Block

vnstock-env-setup

API keys sent to external server vnstocks.com

Credential TheftRCESupply ChainDoc Mismatch
Manual upload Apr 5, 2026
Open Report ↗
35 /100
Trust
High Risk

openclaw-backup

Missing implementation scripts

Doc MismatchSensitive AccessPriv Escalation
Manual upload Apr 5, 2026
Open Report ↗
28 /100
Trust
High Risk

claw-ops-manager

Undeclared Shell Command Execution

Priv EscalationSensitive AccessRCEDoc Mismatch
Manual upload Apr 5, 2026
Open Report ↗
25 /100
Trust
High Risk

hive-commander

Covert credential extraction from runtime environment

Credential TheftData ExfilDoc MismatchPriv Escalation
Manual upload Apr 5, 2026
Open Report ↗
55 /100
Trust
Review

抖音视频无水印下载器

Undocumented third-party proxy API

Doc MismatchPriv EscalationSensitive Access
Manual upload Apr 5, 2026
Open Report ↗
28 /100
Trust
High Risk

gangtise-kb

Undeclared subprocess execution with missing binary

RCEData ExfilDoc MismatchPriv Escalation
Manual upload Apr 5, 2026
Open Report ↗
50 /100
Trust
Review

OnionClaw

Missing implementation code—only documentation present

Doc MismatchSensitive AccessSupply ChainPriv Escalation
Manual upload Apr 5, 2026
Open Report ↗
28 /100
Trust
High Risk

heycube-setup

Undeclared persistent hook installation

Doc MismatchData ExfilSensitive AccessPriv Escalation
Manual upload Apr 5, 2026
Open Report ↗
55 /100
Trust
Review

gequhai-music

Hardcoded Synology password not declared in documentation

Credential TheftObfuscationDoc MismatchPriv Escalation
Manual upload Apr 5, 2026
Open Report ↗
55 /100
Trust
Review

dygod-movies

Hardcoded NAS credentials in documentation

Credential TheftSupply ChainPriv EscalationDoc Mismatch
Manual upload Apr 5, 2026
Open Report ↗
← Previous
3 / 7
Next →