Which skills recently failed
or triggered trust review
This is not a popularity board. It shows recently reviewed skills that the system believes should be blocked or at least manually reviewed. The point is not how popular they are, but why they should not be installed blindly.
safe-flow-solana-skill
Undocumented shell command execution
figma-agent
Undeclared scanning of Claude Code credential store
dex-arbitrage
Undeclared mandatory payment/billing system
flyai-transit-tour
Undeclared shell execution in workflow
Memory Workflow
Undeclared LLM data transmission
Novai360 智能市场分析
Undeclared network access to third-party API
doctor-check
API key validation method unspecified
xclaw-skill
Undocumented private key storage in plaintext
memory-compactor
Documentation-only skill with unverifiable behavior
grinders-farm
start.sh contains completely unrelated code
resume-jd-matcher
Hardcoded Real API Keys in Configuration
onetrust
Third-party credential proxy without transparency
blood-pressure-therapy
Undeclared external URL references
feishu-mcp
Hardcoded Application Secret Exposed
PathClaw
Hardcoded External IP Address
authlock
Shell command injection vulnerability in --exec