THREAT LEADERBOARD

Threat Intelligence

Continuous monitoring for malicious AI skills that other platforms miss

271 New threats in the last 7 days
12 Malicious
75 High Risk
184 Suspicious
38 Suspicious
#221 odds-movement-monitor

盘口变化监控助手 - 实时监控体育博彩盘口变化

Hardcoded API ...Undeclared pay...Documentation ...
2 days ago
35 Suspicious
#222 feishu-bot-config-helper

飞书机器人配置助手 - 在飞书对话中直接配置新机器人

RCEPriv EscalationCredential TheftDoc Mismatch
1 day ago
35 Suspicious
#223 harbor-openclaw

Persistent cross-session memory, credential isolation, and schema learning for OpenClaw ag...

Doc MismatchSensitive AccessSupply ChainCredential Theft
1 day ago
35 Suspicious
#224 Memory Pruner

Intelligent memory management for agents. Keep only what matters, prune the rest.

Doc Mismatch
1 day ago
35 Suspicious
#225 lowcode-platform-development

Automates low-code platform creation with Vue2+ElementUI frontend and Java Spring Boot bac...

Doc Mismatch
1 day ago
35 Suspicious
#226 gougoubi-activate-and-stake-risklp

Activate Gougoubi proposal conditions and stake risk LP per condition in one deterministic...

Doc Mismatch
1 day ago
35 Suspicious
#227 clawschool

龙虾学校智力测试 — AI agent IQ benchmark that fetches questions from clawschool.teamolab.com, exec...

Doc MismatchPriv Escalation
1 day ago
35 Suspicious
#228 run402-test

Test skill for Run402 — provision AI-native Postgres databases with REST API, auth, and ro...

Doc MismatchSensitive AccessCredential Theft
1 day ago
35 Suspicious
#229 ClawSafe AI Skills Portfolio

A multi-skill repository containing 20+ AI agent skills for e-commerce, productivity, heal...

Hardcoded API ...Undeclared bro...False-positive...
2 days ago
35 Suspicious
#230 whale-alert-monitor

Cryptocurrency whale wallet alert monitoring assistant — tracks large transfers, exchange ...

Hardcoded API ...Undeclared ext...SkillPay prici...
2 days ago
35 Suspicious
#231 seedance-creator

AI video/image generation assistant for ByteDance's 即梦 (Seedance 2.0) platform

Remote script ...No script tran...Legitimate use...
2 days ago
35 Suspicious
#232 metacomp_visionx_kyt

Check Web3 wallet or transaction security using MetaComp VisionX

npx远程执行安装命令API密钥明文传递供应商信息隐瞒
3 days ago
35 Suspicious
#233 mingquan-mcp

提供鸣泉雨课堂账户和班级相关查询服务,包括用户ID、开班列表、班级数据、预警名单、今日授课及作业公告完成情况查询等。

影子功能 — claw_re...文档缺失 allowed-t...静默数据外传
3 days ago
35 Suspicious
#234 silicaclaw-owner-push

Monitor SilicaClaw public broadcasts and push owner-relevant summaries through OpenClaw's ...

文档-行为差异(阴影功能)未声明的文件系统 WRITE命令执行能力未声明
3 days ago
35 Suspicious
#235 openclaw-free-search

免 API Key 的 DuckDuckGo 网页搜索工具

未声明的 shell 执行文档-行为差异
3 days ago
32 Suspicious
#236 evermind-ai-everos

EverOS OpenClaw Plugin - 持久化自然语言记忆插件,通过ContextEngine API实现自动记忆召回和保存

Doc MismatchSupply ChainSensitive Access
1 day ago
32 Suspicious
#237 cms-meeting-monitor

从 CMS AI慧记 拉取会议内容,支持字幕模式和静默模式两种监控方式

Doc MismatchPriv EscalationSupply ChainSensitive Access
1 day ago
31 Suspicious
#238 chattts

High-quality, conversational Text-to-Speech (TTS) generation via local ChatTTS API

Sensitive AccessDoc Mismatch
1 day ago
30 Suspicious
#239 authlock

MFA-bound secret protection with TOTP encryption

Shell injectio...Sensitive path...Remote executi...
2 days ago
← Previous 12 / 12