Risk Sample Stream

Which skills recently failed
or triggered trust review

This is not a popularity board. It shows recently reviewed skills that the system believes should be blocked or at least manually reviewed. The point is not how popular they are, but why they should not be installed blindly.

349 Risky samples surfaced
4 New in 7 days
0 Platform misses surfaced
All Code Exec Credential Theft Data Exfil Priv Esc Supply Chain Doc Deception Prompt Injection Obfuscation
65 /100
Trust
Review

solo-mission

危险的远程脚本执行模式

Supply ChainCredential TheftData ExfilDoc Mismatch
ClawHub 7 hr ago
Open Report ↗
55 /100
Trust
Review

子网计算服务

用户凭证持久化存储

Credential TheftSupply ChainData Exfil
ClawHub 5 days ago
Open Report ↗
58 /100
Trust
Review

ai-redaction-beta

文件数据发送到外部API

Data ExfilDoc MismatchSupply Chain
ClawHub 7 days ago
Open Report ↗
52 /100
Trust
Review

browser-act

无法验证文档-行为一致性

Doc MismatchPriv EscalationSensitive AccessSupply Chain
ClawHub 12 days ago
Open Report ↗
45 /100
Trust
Review

辛一金虹桥店7天排产预测

用户文件上传至外部服务器未声明

Data ExfilDoc MismatchSupply Chain
ClawHub 13 days ago
Open Report ↗
55 /100
Trust
Review

grid-trading-pro

文档描述的通知功能未实现

Doc MismatchSupply Chain
ClawHub 13 days ago
Open Report ↗
60 /100
Trust
Review

amazon-screenshot

硬编码SMTP服务凭证(阴影功能)

Credential TheftPriv EscalationRCESupply Chain
ClawHub 18 days ago
Open Report ↗
65 /100
Trust
Review

maxhub-lemon8

硬编码IP地址规避域名透明度

Doc MismatchSensitive AccessSupply Chain
ClawHub 22 days ago
Open Report ↗
56 /100
Trust
Review

x-tweet-fetcher

Router-agent cmd-queue file I/O undeclared in SKILL.md

Doc MismatchSupply ChainSensitive Access
GitHub 23 days ago
Open Report ↗
55 /100
Trust
Review

imitation-agent

加密货币私钥明文存储

Credential TheftSupply ChainDoc MismatchPriv Escalation
ClawHub 24 days ago
Open Report ↗
58 /100
Trust
Review

lobster-use

危险 Shell 命令 - 远程脚本执行

RCESupply ChainDoc Mismatch
ClawHub 29 days ago
Open Report ↗
58 /100
Trust
Review

nexo-brain

外部 npm 包依赖且无版本锁定

Supply ChainDoc MismatchSensitive Access
ClawHub Apr 28, 2026
Open Report ↗
55 /100
Trust
Review

contextweave-diagrams

文档引用不存在的脚本文件

Doc MismatchSupply Chain
ClawHub Apr 23, 2026
Open Report ↗
60 /100
Trust
Review

polymarket-pro

curl|sh 远程脚本执行模式

RCESupply ChainSensitive Access
ClawHub Apr 23, 2026
Open Report ↗
55 /100
Trust
Review

asoul-support

通过 subprocess 调用外部工具(未声明权限)

Priv EscalationData ExfilDoc MismatchSensitive Access
ClawHub Apr 23, 2026
Open Report ↗
58 /100
Trust
Review

tunnel-proxy

PtySession可执行任意Shell命令

RCESensitive AccessSupply ChainDoc Mismatch
ClawHub Apr 20, 2026
Open Report ↗
1 / 8
Next →