Which skills recently failed
or triggered trust review
This is not a popularity board. It shows recently reviewed skills that the system believes should be blocked or at least manually reviewed. The point is not how popular they are, but why they should not be installed blindly.
claw-wallet
Unsigned closed-source binary execution without integrity verification
edge
Undeclared shell execution via npx spawn
skill-state-manager
Credential Harvesting Framework
video-to-text
Undeclared subprocess execution via execSync
youdaonote
Dangerous curl|bash installation pattern documented
github-code-analyzer
Hardcoded API Credential
bitable_to_feishu_webhook
Data exfiltration via undeclared webhook URL
affiliate-skills
Remote Script Execution via Pipe-to-Shell
browser-automation
Hardcoded billing API key exposed in source code
clawguard-auditor
Embedded reverse shell command patterns
session-reflect
Undeclared shell execution in command files
xhs-crawler
Feishu App Secret hardcoded and documented
aliyun-ai-guardrail
Global fetch interception not declared
qclaw-watchdog
Hardcoded Feishu API Credentials in config.json
capability-evolver-zc
Undeclared shell command execution throughout codebase
update-approval-guard (primary) + instreet + 25+ sub-skills (workspace)
Live InStreet API Key Stored in Plaintext