Which skills recently failed
or triggered trust review
This is not a popularity board. It shows recently reviewed skills that the system believes should be blocked or at least manually reviewed. The point is not how popular they are, but why they should not be installed blindly.
hive-commander
Covert credential extraction from runtime environment
抖音视频无水印下载器
Undocumented third-party proxy API
cloud-share-downloader
Undeclared credential solicitation
research-archive-query
Undeclared subprocess/shell execution
gangtise-kb
Undeclared subprocess execution with missing binary
harbor-openclaw
Undeclared network behavior on first load
airoom.ltd-Global-Finance-Data-Platform
HTTP target URL without TLS encryption
face-analysis
Hardcoded Database Credentials in config.yaml
imap-idle-sneder
Hardcoded email credentials in source code
OnionClaw
Missing implementation code—only documentation present
sshot
Critical script artifact not included in package
authenticate-wallet
Unversioned npm package execution
Receipt Logger
Implementation script missing — documented functionality absent
Memory Pruner
Referenced implementation files are missing
Self-Audit
Declared entry point does not exist
heycube-setup
Undeclared persistent hook installation