Which skills recently failed
or triggered trust review
This is not a popularity board. It shows recently reviewed skills that the system believes should be blocked or at least manually reviewed. The point is not how popular they are, but why they should not be installed blindly.
Novai360 智能市场分析
Undeclared network access to third-party API
doctor-check
API key validation method unspecified
xclaw-skill
Undocumented private key storage in plaintext
memory-compactor
Documentation-only skill with unverifiable behavior
onetrust
Third-party credential proxy without transparency
blood-pressure-therapy
Undeclared external URL references
PathClaw
Hardcoded External IP Address
authlock
Shell command injection vulnerability in --exec
claw-wallet
Unsigned closed-source binary execution without integrity verification
edge
Undeclared shell execution via npx spawn
skill-state-manager
Credential Harvesting Framework
video-to-text
Undeclared subprocess execution via execSync
youdaonote
Dangerous curl|bash installation pattern documented
bitable_to_feishu_webhook
Data exfiltration via undeclared webhook URL
self-evolution-engine
Hardcoded API Key
affiliate-skills
Remote Script Execution via Pipe-to-Shell