Which skills recently failed
or triggered trust review
This is not a popularity board. It shows recently reviewed skills that the system believes should be blocked or at least manually reviewed. The point is not how popular they are, but why they should not be installed blindly.
browser-automation
Hardcoded billing API key exposed in source code
clawguard-auditor
Embedded reverse shell command patterns
session-reflect
Undeclared shell execution in command files
xhs-crawler
Feishu App Secret hardcoded and documented
aliyun-ai-guardrail
Global fetch interception not declared
qclaw-watchdog
Hardcoded Feishu API Credentials in config.json
capability-evolver-zc
Undeclared shell command execution throughout codebase
update-approval-guard (primary) + instreet + 25+ sub-skills (workspace)
Live InStreet API Key Stored in Plaintext
claw-office-report
Undisclosed data exfiltration — full task text sent to external server
skill-security-vet
Undeclared local/full computer scanning mode
skill-gatekeeper
Undeclared child_process.exec with hardcoded path
ClawSafe AI Skills Portfolio
Hardcoded API key in ClawHub monitoring tool
openclaw-cursor-agent
Dangerous curl|bash pattern in documentation
memex
Hidden Telemetry with Evasion-Intent Comment
superguard
Hidden garbled text in metadata likely containing prompt injection
agent-p2p
Hardcoded default password for admin backend