Which skills recently failed
or triggered trust review
This is not a popularity board. It shows recently reviewed skills that the system believes should be blocked or at least manually reviewed. The point is not how popular they are, but why they should not be installed blindly.
tweet-monitor-pro
文档声称零依赖但实际存在外部脚本依赖
whale-alert-monitor
硬编码API密钥未在文档声明
ludwitt-university
updateInstructions 远程代码执行通道
birth-system-manager
文档承诺不显示私钥但代码明文输出
skill-registry-unified
未声明的远程代码执行
MiniMax TTS
硬编码 API 密钥暴露
grok-swarm
未声明的shell执行功能
dianping-api
Remote Script Execution via curl|bash
face-analysis
Hardcoded Database Credentials in config.yaml
heycube-setup
Undeclared persistent hook installation
boss-ai-assistant
Hardcoded DashScope API Key
LLM Proxy
Critical content-blocking disabled — credential exfiltration not prevented
monid
Remote script execution via curl|bash from mutable branch
backup-2-github
Hardcoded Default Repository Exposes User Data
uplo-defense
Unpinned npm package execution via npx -y
VLAN Linux Client Skill
Remote script piped to bash without integrity verification