Which skills recently failed
or triggered trust review
This is not a popularity board. It shows recently reviewed skills that the system believes should be blocked or at least manually reviewed. The point is not how popular they are, but why they should not be installed blindly.
Review
mindkeeper
文档未声明可触发远程脚本执行
ClawHub Apr 7, 2026
Open Report ↗
Review
botlearn
SKILL.md 未声明 cmd_scan 的完整数据收集范围
ClawHub Apr 7, 2026
Open Report ↗
Review
typescript-package-manager
远程脚本管道执行
ClawHub Apr 6, 2026
Open Report ↗
Review
file-transfer-thru-local-workspace
服务暴露在公网监听
ClawHub Apr 6, 2026
Open Report ↗
Review
agent-guardian
Python 依赖无版本锁定
ClawHub Apr 6, 2026
Open Report ↗
Review
math-utils
命令注入漏洞
ClawHub Apr 6, 2026
Open Report ↗
Review
wip-readme-format
未声明的文件系统写入权限
ClawHub Apr 6, 2026
Open Report ↗
High Risk
skill-registry-unified
未声明的远程代码执行
ClawHub Apr 6, 2026
Open Report ↗
Review
layered-memory
外部脚本缺失导致功能不可用
ClawHub Apr 6, 2026
Open Report ↗
Review
gpt-chat
未声明的HTTP服务器
ClawHub Apr 6, 2026
Open Report ↗
Review
stocktoday-mcp
凭证及查询数据发往未知第三方服务器
ClawHub Apr 6, 2026
Open Report ↗
Review
bt-download
未声明的外部网络访问
ClawHub Apr 6, 2026
Open Report ↗
Review
nim-ensemble / free-scaling
Copilot token刷新机制未在文档中声明
ClawHub Apr 6, 2026
Open Report ↗
Review
introspection-debugger
Webhook 通知机制发送完整错误报告到外部端点
ClawHub Apr 6, 2026
Open Report ↗
Review
wechat-ai-bridge
配置文件明文存储敏感凭证
ClawHub Apr 6, 2026
Open Report ↗
Review
115-skills
User-Agent包含可疑硬编码IP
ClawHub Apr 6, 2026
Open Report ↗