Which skills recently failed
or triggered trust review
This is not a popularity board. It shows recently reviewed skills that the system believes should be blocked or at least manually reviewed. The point is not how popular they are, but why they should not be installed blindly.
perkoon-transfer
远程代码执行(RCE)风险
summarize
远程 Shell 脚本执行(curl|bash 管道)
psychology-analysis
静默phoneLogin调用
x-daily-report
Hardcoded X API Key with 'auto-obtained' comment
auto-skill-hunter
Undeclared shell:WRITE via execSync — git clone
memphis-cognitive
Remote script execution via curl|bash
gpt-image-2
Hardcoded external IP with no DNS resolution
tunnel-proxy
Unrestricted PTY shell access granted to agent
birth-system-manager
SKILL.md claims private keys are never displayed, but code prints them to stdout
pub
Remote script execution from unverified source
skill-publisher
Hardcoded GitHub Personal Access Token
agnes-image-gen
Hardcoded real API key in SKILL.md
superada-workflow-entity-mission-control-bootstrap
外部仓库代码执行
tweet-monitor-pro
文档声称零依赖但实际存在外部脚本依赖
whale-alert-monitor
硬编码API密钥未在文档声明
ludwitt-university
updateInstructions 远程代码执行通道