Risk Sample Stream

Which skills recently failed
or triggered trust review

This is not a popularity board. It shows recently reviewed skills that the system believes should be blocked or at least manually reviewed. The point is not how popular they are, but why they should not be installed blindly.

349 Risky samples surfaced
4 New in 7 days
0 Platform misses surfaced
All Code Exec Credential Theft Data Exfil Priv Esc Supply Chain Doc Deception Prompt Injection Obfuscation
45 /100
Trust
Review

baidu-netdisk-skill

硬编码加密密钥使 AES-256 加密承诺失效

Doc MismatchCredential TheftSupply ChainPriv Escalation
ClawHub Apr 6, 2026
Open Report ↗
65 /100
Trust
Review

markdown-ai-rewriter

npx 动态拉取第三方包

Supply ChainPriv Escalation
ClawHub Apr 6, 2026
Open Report ↗
15 /100
Trust
Block

luci-memory

API密钥在初始化时即被外传至硬编码外部IP

Credential TheftData ExfilObfuscationDoc Mismatch
Manual upload Apr 5, 2026
Open Report ↗
58 /100
Trust
Review

rtk-integration

远程脚本管道执行无完整性校验

Supply ChainDoc Mismatch
Manual upload Apr 5, 2026
Open Report ↗
55 /100
Trust
Review

computer-use-skill

文档描述的代码结构不存在

Doc MismatchSupply Chain
Manual upload Apr 5, 2026
Open Report ↗
35 /100
Trust
High Risk

MiniMax TTS

硬编码 API 密钥暴露

Credential TheftDoc MismatchSupply Chain
Manual upload Apr 5, 2026
Open Report ↗
55 /100
Trust
Review

ctct-security-patrol

持久化设备指纹形成长期追踪能力

Sensitive AccessData ExfilDoc MismatchSupply Chain
Manual upload Apr 5, 2026
Open Report ↗
55 /100
Trust
Review

NIST CSF Mapper

强制外部API数据传输企业敏感信息

Data ExfilSupply ChainDoc Mismatch
Manual upload Apr 5, 2026
Open Report ↗
40 /100
Trust
Review

asiasea-bi

API认证凭证通过Base64编码嵌入可公开访问的HTML

Credential TheftDoc MismatchObfuscationSupply Chain
Manual upload Apr 5, 2026
Open Report ↗
55 /100
Trust
Review

tesla-cn

所有 API 流量经第三方代理中转

Data ExfilSensitive AccessDoc MismatchSupply Chain
Manual upload Apr 5, 2026
Open Report ↗
55 /100
Trust
Review

xiayu

用户凭证直接收集存在风险

Credential TheftData ExfilDoc MismatchSensitive Access
Manual upload Apr 5, 2026
Open Report ↗
58 /100
Trust
Review

feishu-ops

影子功能:本地桌面文件操作未在文档声明

Doc MismatchSensitive AccessSupply ChainCredential Theft
Manual upload Apr 5, 2026
Open Report ↗
55 /100
Trust
Review

用户工作区 (Multi-Skill Workspace)

虚构的 API 名称

Doc MismatchCredential TheftSupply Chain
Manual upload Apr 5, 2026
Open Report ↗
55 /100
Trust
Review

Obsidian Semantic Search

远程脚本执行 - uv 安装

Supply ChainDoc MismatchSensitive Access
Manual upload Apr 5, 2026
Open Report ↗
55 /100
Trust
Review

Awesome Pentest

文档声明与实际代码严重不符

Doc MismatchPriv EscalationSupply Chain
Manual upload Apr 5, 2026
Open Report ↗
60 /100
Trust
Review

daily-news-brief

文档中的危险卸载命令

RCESupply Chain
Manual upload Apr 5, 2026
Open Report ↗
← Previous
4 / 10
Next →