Risk Sample Stream

Which skills recently failed
or triggered trust review

This is not a popularity board. It shows recently reviewed skills that the system believes should be blocked or at least manually reviewed. The point is not how popular they are, but why they should not be installed blindly.

510 Risky samples surfaced
12 New in 7 days
0 Platform misses surfaced
All Code Exec Credential Theft Data Exfil Priv Esc Supply Chain Doc Deception Prompt Injection Obfuscation
28 /100
Trust
High Risk

stellar-trails

GitHub PAT 明文持久化到文件系统

Credential TheftPersistencePriv EscalationSensitive Access
ClawHub 1 day ago
Open Report ↗
30 /100
Trust
High Risk

chrome-use

curl|sh远程脚本执行供应链攻击风险

Supply ChainDoc MismatchPriv Escalation
ClawHub 1 day ago
Open Report ↗
32 /100
Trust
High Risk

GitToQuark

Referenced scripts not included in package

Supply ChainPriv EscalationDoc Mismatch
ClawHub 4 days ago
Open Report ↗
30 /100
Trust
High Risk

perkoon-transfer

Remote script execution without integrity verification

Supply ChainDoc MismatchPriv EscalationSensitive Access
ClawHub 9 days ago
Open Report ↗
35 /100
Trust
High Risk

meta-analysis

Coze API 令牌以可逆混淆形式嵌入源代码,随技能公开发布

Credential TheftData ExfilPriv EscalationSupply Chain
ClawHub 13 days ago
Open Report ↗
20 /100
Trust
High Risk

smyx-family-conflict-aftercare-suggest-analysis

未声明的本地凭证数据库存储

Doc MismatchCredential TheftData ExfilSupply Chain
ClawHub 16 days ago
Open Report ↗
32 /100
Trust
High Risk

xhs-fav-export

wc3-code.mjs 严重混淆代码

ObfuscationDoc MismatchSupply ChainData Exfil
ClawHub 19 days ago
Open Report ↗
32 /100
Trust
High Risk

northcap-donor-badge

文档声称本地验证,实际发往外部 IP

Doc MismatchSupply ChainData Exfil
ClawHub 20 days ago
Open Report ↗
25 /100
Trust
High Risk

xhs-note-analyst

wc3-code.mjs 严重代码混淆

ObfuscationData ExfilDoc MismatchSupply Chain
ClawHub 28 days ago
Open Report ↗
32 /100
Trust
High Risk

yqzl-ai-service

Automatic code download and execution without consent

Supply ChainDoc MismatchPriv EscalationSensitive Access
ClawHub Jul 28, 2026
Open Report ↗
20 /100
Trust
High Risk

klyc-pmm

curl|bash 管道执行远程脚本 — install-daemon

Supply ChainDoc MismatchSensitive AccessData Exfil
ClawHub Jul 28, 2026
Open Report ↗
35 /100
Trust
High Risk

x-daily-report

Hardcoded X API Key with 'auto-obtained' comment

Credential TheftDoc MismatchSensitive AccessSupply Chain
ClawHub Jun 24, 2026
Open Report ↗
32 /100
Trust
High Risk

auto-skill-hunter

Undeclared shell:WRITE via execSync — git clone

Priv EscalationSupply ChainDoc MismatchSensitive Access
ClawHub Jun 24, 2026
Open Report ↗
35 /100
Trust
High Risk

memphis-cognitive

Remote script execution via curl|bash

Supply ChainDoc MismatchPriv Escalation
ClawHub Jun 24, 2026
Open Report ↗
35 /100
Trust
High Risk

tunnel-proxy

Unrestricted PTY shell access granted to agent

RCESensitive AccessData ExfilDoc Mismatch
ClawHub Jun 21, 2026
Open Report ↗
30 /100
Trust
High Risk

pub

Remote script execution from unverified source

Supply ChainRCEPriv EscalationDoc Mismatch
ClawHub Jun 18, 2026
Open Report ↗
1 / 4
Next →