Risk Sample Stream

Which skills recently failed
or triggered trust review

This is not a popularity board. It shows recently reviewed skills that the system believes should be blocked or at least manually reviewed. The point is not how popular they are, but why they should not be installed blindly.

426 Risky samples surfaced
5 New in 7 days
0 Platform misses surfaced
All Code Exec Credential Theft Data Exfil Priv Esc Supply Chain Doc Deception Prompt Injection Obfuscation
35 /100
Trust
High Risk

perkoon-transfer

远程代码执行(RCE)风险

RCESupply ChainSensitive AccessObfuscation
ClawHub 7 days ago
Open Report ↗
28 /100
Trust
High Risk

summarize

远程 Shell 脚本执行(curl|bash 管道)

RCEDoc MismatchSensitive Access
ClawHub 22 days ago
Open Report ↗
35 /100
Trust
High Risk

psychology-analysis

静默phoneLogin调用

Doc MismatchCredential TheftSensitive AccessPriv Escalation
ClawHub 29 days ago
Open Report ↗
35 /100
Trust
High Risk

x-daily-report

Hardcoded X API Key with 'auto-obtained' comment

Credential TheftDoc MismatchSensitive AccessSupply Chain
ClawHub Jun 24, 2026
Open Report ↗
32 /100
Trust
High Risk

auto-skill-hunter

Undeclared shell:WRITE via execSync — git clone

Priv EscalationSupply ChainDoc MismatchSensitive Access
ClawHub Jun 24, 2026
Open Report ↗
35 /100
Trust
High Risk

memphis-cognitive

Remote script execution via curl|bash

Supply ChainDoc MismatchPriv Escalation
ClawHub Jun 24, 2026
Open Report ↗
28 /100
Trust
High Risk

gpt-image-2

Hardcoded external IP with no DNS resolution

Data ExfilDoc MismatchCredential TheftSensitive Access
ClawHub Jun 22, 2026
Open Report ↗
35 /100
Trust
High Risk

tunnel-proxy

Unrestricted PTY shell access granted to agent

RCESensitive AccessData ExfilDoc Mismatch
ClawHub Jun 21, 2026
Open Report ↗
25 /100
Trust
High Risk

birth-system-manager

SKILL.md claims private keys are never displayed, but code prints them to stdout

Doc MismatchCredential TheftSensitive AccessPriv Escalation
ClawHub Jun 18, 2026
Open Report ↗
30 /100
Trust
High Risk

pub

Remote script execution from unverified source

Supply ChainRCEPriv EscalationDoc Mismatch
ClawHub Jun 18, 2026
Open Report ↗
35 /100
Trust
High Risk

skill-publisher

Hardcoded GitHub Personal Access Token

Credential TheftDoc MismatchSensitive AccessSupply Chain
ClawHub Jun 15, 2026
Open Report ↗
45 /100
Trust
High Risk

agnes-image-gen

Hardcoded real API key in SKILL.md

Credential TheftDoc MismatchPriv Escalation
ClawHub Jun 10, 2026
Open Report ↗
35 /100
Trust
High Risk

superada-workflow-entity-mission-control-bootstrap

外部仓库代码执行

Supply ChainRCEDoc MismatchPriv Escalation
ClawHub Jun 3, 2026
Open Report ↗
35 /100
Trust
High Risk

tweet-monitor-pro

文档声称零依赖但实际存在外部脚本依赖

Doc MismatchPriv EscalationSupply ChainSensitive Access
ClawHub Apr 19, 2026
Open Report ↗
30 /100
Trust
High Risk

whale-alert-monitor

硬编码API密钥未在文档声明

Doc MismatchSensitive AccessSupply Chain
ClawHub Apr 12, 2026
Open Report ↗
25 /100
Trust
High Risk

ludwitt-university

updateInstructions 远程代码执行通道

RCEDoc MismatchPersistenceCredential Theft
ClawHub Apr 12, 2026
Open Report ↗
1 / 6
Next →