Risk Sample Stream

Which skills recently failed
or triggered trust review

This is not a popularity board. It shows recently reviewed skills that the system believes should be blocked or at least manually reviewed. The point is not how popular they are, but why they should not be installed blindly.

426 Risky samples surfaced
5 New in 7 days
0 Platform misses surfaced
All Code Exec Credential Theft Data Exfil Priv Esc Supply Chain Doc Deception Prompt Injection Obfuscation
58 /100
Trust
Review

news-briefing

未声明的 shell 执行和动态代码注入

Doc MismatchSupply ChainPriv Escalation
ClawHub Apr 20, 2026
Open Report ↗
55 /100
Trust
Review

sharkflow

SKILL.md声明功能远超实际代码能力

Doc MismatchSupply Chain
ClawHub Apr 20, 2026
Open Report ↗
55 /100
Trust
Review

auto-skill-hunter

权限声明与实际能力严重不符

Priv EscalationSupply ChainDoc MismatchSensitive Access
ClawHub Apr 19, 2026
Open Report ↗
40 /100
Trust
Review

odds-movement-monitor

硬编码第三方API密钥

Credential TheftDoc MismatchSupply Chain
ClawHub Apr 11, 2026
Open Report ↗
55 /100
Trust
Review

skills-collection

网络出站声明与实际行为不符

Doc MismatchSupply Chain
ClawHub Apr 11, 2026
Open Report ↗
55 /100
Trust
Review

self-evolution-engine

硬编码API密钥暴露

Credential TheftDoc MismatchSupply ChainPriv Escalation
ClawHub Apr 10, 2026
Open Report ↗
58 /100
Trust
Review

dex-arbitrage

硬编码API密钥暴露

Credential TheftDoc MismatchSupply Chain
ClawHub Apr 9, 2026
Open Report ↗
45 /100
Trust
Review

whale-alert-monitor

硬编码API密钥

Credential TheftDoc MismatchSupply ChainSensitive Access
ClawHub Apr 9, 2026
Open Report ↗
65 /100
Trust
Review

fin-advisor

未声明的网络访问能力

Doc MismatchSensitive AccessSupply Chain
ClawHub Apr 9, 2026
Open Report ↗
45 /100
Trust
Review

Memphis Cognitive Engine

远程脚本执行 - Memphis安装

Supply ChainDoc MismatchSensitive Access
ClawHub Apr 9, 2026
Open Report ↗
60 /100
Trust
Review

cmd-execution-test

影子功能 - 未声明的任意命令执行能力

Doc MismatchRCEPriv EscalationSupply Chain
ClawHub Apr 9, 2026
Open Report ↗
65 /100
Trust
Review

mindkeeper

文档未声明可触发远程脚本执行

Doc MismatchSupply ChainSensitive Access
ClawHub Apr 7, 2026
Open Report ↗
55 /100
Trust
Review

botlearn

SKILL.md 未声明 cmd_scan 的完整数据收集范围

Doc MismatchSupply ChainSensitive AccessPriv Escalation
ClawHub Apr 7, 2026
Open Report ↗
55 /100
Trust
Review

typescript-package-manager

远程脚本管道执行

RCEDoc MismatchPriv EscalationSupply Chain
ClawHub Apr 6, 2026
Open Report ↗
55 /100
Trust
Review

file-transfer-thru-local-workspace

服务暴露在公网监听

Sensitive AccessDoc MismatchSupply Chain
ClawHub Apr 6, 2026
Open Report ↗
68 /100
Trust
Review

agent-guardian

Python 依赖无版本锁定

Supply ChainPriv EscalationSensitive Access
ClawHub Apr 6, 2026
Open Report ↗
← Previous
4 / 10
Next →