Risk Sample Stream

Which skills recently failed
or triggered trust review

This is not a popularity board. It shows recently reviewed skills that the system believes should be blocked or at least manually reviewed. The point is not how popular they are, but why they should not be installed blindly.

426 Risky samples surfaced
5 New in 7 days
0 Platform misses surfaced
All Code Exec Credential Theft Data Exfil Priv Esc Supply Chain Doc Deception Prompt Injection Obfuscation
55 /100
Trust
Review

PRECC

curl|bash 远程脚本执行

Supply ChainDoc Mismatch
Manual upload Apr 5, 2026
Open Report ↗
55 /100
Trust
Review

ClawSentry

代码高度混淆难以审计

ObfuscationSupply ChainPriv EscalationSensitive Access
Manual upload Apr 5, 2026
Open Report ↗
50 /100
Trust
Review

agent-cli

危险curl|bash管道安装命令

Supply ChainDoc Mismatch
Manual upload Apr 5, 2026
Open Report ↗
35 /100
Trust
High Risk

grok-swarm

未声明的shell执行功能

Doc MismatchRCECredential TheftSupply Chain
Manual upload Apr 5, 2026
Open Report ↗
65 /100
Trust
Review

stremio-cli

文档与代码不一致

Doc MismatchPriv EscalationSupply Chain
Manual upload Apr 5, 2026
Open Report ↗
35 /100
Trust
High Risk

dianping-api

Remote Script Execution via curl|bash

Supply ChainObfuscationDoc Mismatch
Manual upload Apr 5, 2026
Open Report ↗
8 /100
Trust
Block

vnstock-env-setup

API keys sent to external server vnstocks.com

Credential TheftRCESupply ChainDoc Mismatch
Manual upload Apr 5, 2026
Open Report ↗
50 /100
Trust
Review

fund-daily

Undeclared network API access

Doc MismatchCredential TheftSupply Chain
Manual upload Apr 5, 2026
Open Report ↗
55 /100
Trust
Review

research-archive-query

Undeclared subprocess/shell execution

Doc MismatchSupply Chain
Manual upload Apr 5, 2026
Open Report ↗
65 /100
Trust
Review

harbor-openclaw

Undeclared network behavior on first load

Doc MismatchSensitive AccessSupply ChainCredential Theft
Manual upload Apr 5, 2026
Open Report ↗
60 /100
Trust
Review

airoom.ltd-Global-Finance-Data-Platform

HTTP target URL without TLS encryption

Sensitive AccessDoc MismatchSupply Chain
Manual upload Apr 5, 2026
Open Report ↗
35 /100
Trust
High Risk

face-analysis

Hardcoded Database Credentials in config.yaml

Credential TheftDoc MismatchSupply ChainSensitive Access
Manual upload Apr 5, 2026
Open Report ↗
55 /100
Trust
Review

imap-idle-sneder

Hardcoded email credentials in source code

Credential TheftDoc MismatchData ExfilSupply Chain
Manual upload Apr 5, 2026
Open Report ↗
50 /100
Trust
Review

OnionClaw

Missing implementation code—only documentation present

Doc MismatchSensitive AccessSupply ChainPriv Escalation
Manual upload Apr 5, 2026
Open Report ↗
55 /100
Trust
Review

authenticate-wallet

Unversioned npm package execution

Supply ChainDoc MismatchCredential Theft
Manual upload Apr 5, 2026
Open Report ↗
28 /100
Trust
High Risk

heycube-setup

Undeclared persistent hook installation

Doc MismatchData ExfilSensitive AccessPriv Escalation
Manual upload Apr 5, 2026
Open Report ↗
← Previous
7 / 12
Next →