Risk Sample Stream

Which skills recently failed
or triggered trust review

This is not a popularity board. It shows recently reviewed skills that the system believes should be blocked or at least manually reviewed. The point is not how popular they are, but why they should not be installed blindly.

426 Risky samples surfaced
5 New in 7 days
0 Platform misses surfaced
All Code Exec Credential Theft Data Exfil Priv Esc Supply Chain Doc Deception Prompt Injection Obfuscation
60 /100
Trust
Review

amazon-screenshot

硬编码SMTP服务凭证(阴影功能)

Credential TheftPriv EscalationRCESupply Chain
ClawHub May 13, 2026
Open Report ↗
65 /100
Trust
Review

maxhub-lemon8

硬编码IP地址规避域名透明度

Doc MismatchSensitive AccessSupply Chain
ClawHub May 8, 2026
Open Report ↗
65 /100
Trust
Review

personal-voice-generator

文档声明"本地完成不上传"与实际行为不符

Doc MismatchSensitive Access
ClawHub May 8, 2026
Open Report ↗
56 /100
Trust
Review

x-tweet-fetcher

Router-agent cmd-queue file I/O undeclared in SKILL.md

Doc MismatchSupply ChainSensitive Access
GitHub May 8, 2026
Open Report ↗
55 /100
Trust
Review

buymeacoffee-autobot

声明脚本不存在

Doc Mismatch
ClawHub May 3, 2026
Open Report ↗
60 /100
Trust
Review

create-payment-credential

原始信用卡凭证明文输出

Sensitive AccessPriv EscalationDoc Mismatch
ClawHub May 2, 2026
Open Report ↗
58 /100
Trust
Review

lobster-use

危险 Shell 命令 - 远程脚本执行

RCESupply ChainDoc Mismatch
ClawHub May 2, 2026
Open Report ↗
65 /100
Trust
Review

elevenlabs-toolkit

未声明的环境变量依赖

Doc Mismatch
ClawHub May 1, 2026
Open Report ↗
65 /100
Trust
Review

web-application-fuzzing-automation

文档声明与实际用途的权限声明不匹配

Doc MismatchSensitive AccessCredential Theft
ClawHub Apr 29, 2026
Open Report ↗
58 /100
Trust
Review

nexo-brain

外部 npm 包依赖且无版本锁定

Supply ChainDoc MismatchSensitive Access
ClawHub Apr 28, 2026
Open Report ↗
55 /100
Trust
Review

contextweave-diagrams

文档引用不存在的脚本文件

Doc MismatchSupply Chain
ClawHub Apr 23, 2026
Open Report ↗
55 /100
Trust
Review

asoul-support

通过 subprocess 调用外部工具(未声明权限)

Priv EscalationData ExfilDoc MismatchSensitive Access
ClawHub Apr 23, 2026
Open Report ↗
99 /100
Trust
Block

credential-harvester

Outbound credential exfiltration to attacker C2

ExfiltrationCredential AccessPersistenceDefense Evasion
Manual upload Apr 22, 2026
Open Report ↗
62 /100
Trust
Review

sage-router

systemctl服务管理未在声明中

Priv EscalationDoc Mismatch
ClawHub Apr 21, 2026
Open Report ↗
65 /100
Trust
Review

server-log-analysis

config.yaml 包含明文凭证违反安全声明

Doc MismatchSensitive Access
ClawHub Apr 20, 2026
Open Report ↗
62 /100
Trust
Review

gta-real-estate-skillpay

未声明的网络外传行为

Doc MismatchSupply Chain
ClawHub Apr 20, 2026
Open Report ↗
← Previous
5 / 22
Next →