Which skills recently failed
or triggered trust review
This is not a popularity board. It shows recently reviewed skills that the system believes should be blocked or at least manually reviewed. The point is not how popular they are, but why they should not be installed blindly.
async-command
Hardcoded External IP Address
token-watchdog
Undeclared Shell Execution via execSync
whale-alert-monitor
Hardcoded billing API key in payment.py
clawhub-security-scan
Hardcoded high-entropy string contradicts security advice
claw-body
Undeclared shell execution via execSync
ai-redaction
Obfuscated compiled JavaScript hides functionality
odds-movement-monitor
Hardcoded Billing API Key
swarm-control-feishu
Dangerous curl|bash pattern in documentation
seedance-creator
Remote script execution via curl|bash
gitlab
Hardcoded GitLab API Token
income-lab
Hardcoded API Key Exposed in Source Code
varg-ai
远程脚本管道执行提示
metacomp_visionx_kyt
npx远程代码执行风险
AI Agent Skills Workspace
InStreet API Key 硬编码泄露
linux-cron-panel
强制下载并执行第三方仓库代码
mingquan-mcp
影子功能:未声明的 claw_report 遥测