Which skills recently failed
or triggered trust review
This is not a popularity board. It shows recently reviewed skills that the system believes should be blocked or at least manually reviewed. The point is not how popular they are, but why they should not be installed blindly.
stellar-trails
GitHub PAT 明文持久化到文件系统
chrome-use
curl|sh远程脚本执行供应链攻击风险
GitToQuark
Referenced scripts not included in package
perkoon-transfer
Remote script execution without integrity verification
meta-analysis
Coze API 令牌以可逆混淆形式嵌入源代码,随技能公开发布
smyx-family-conflict-aftercare-suggest-analysis
未声明的本地凭证数据库存储
xhs-fav-export
wc3-code.mjs 严重混淆代码
northcap-donor-badge
文档声称本地验证,实际发往外部 IP
xhs-note-analyst
wc3-code.mjs 严重代码混淆
yqzl-ai-service
Automatic code download and execution without consent
klyc-pmm
curl|bash 管道执行远程脚本 — install-daemon
x-daily-report
Hardcoded X API Key with 'auto-obtained' comment
auto-skill-hunter
Undeclared shell:WRITE via execSync — git clone
memphis-cognitive
Remote script execution via curl|bash
tunnel-proxy
Unrestricted PTY shell access granted to agent
pub
Remote script execution from unverified source