Which skills recently failed
or triggered trust review
This is not a popularity board. It shows recently reviewed skills that the system believes should be blocked or at least manually reviewed. The point is not how popular they are, but why they should not be installed blindly.
skill-factory
Undeclared shell command execution via execSync
nano-banana-pro
Hardcoded DASHSCOPE_API_KEY in _meta.json
huo15-memory-evolution
Hardcoded API Key in Source Code
awareness-memory
Undeclared session file exfiltration to external cloud
clawguard-threat-detect
Hardcoded Reverse Shell Payloads in Documentation
messenger_send_node
Undeclared Tor Network Routing
grinders-farm
start.sh contains completely unrelated code
resume-jd-matcher
Hardcoded Real API Keys in Configuration
feishu-mcp
Hardcoded Application Secret Exposed
github-code-analyzer
Hardcoded API Credential
qclaw-watchdog
Hardcoded Feishu API Credentials in config.json
skill-security-vet
Undeclared local/full computer scanning mode
skill-gatekeeper
Undeclared child_process.exec with hardcoded path
superguard
Hidden garbled text in metadata likely containing prompt injection
agent-p2p
Hardcoded default password for admin backend
async-command
Hardcoded External IP Address