最近有哪些 skills
不值得默认信任
这不是热度榜。这里展示的是最近被送来判断、且系统认为需要阻止或至少人工复核的 skills。重点不是它们多流行,而是为什么它们不该被直接装进环境。
fund-daily
Undeclared network API access
stock-prediction
Undeclared shell command execution
hive-commander
Covert credential extraction from runtime environment
抖音视频无水印下载器
Undocumented third-party proxy API
cloud-share-downloader
Undeclared credential solicitation
research-archive-query
Undeclared subprocess/shell execution
gangtise-kb
Undeclared subprocess execution with missing binary
harbor-openclaw
Undeclared network behavior on first load
airoom.ltd-Global-Finance-Data-Platform
HTTP target URL without TLS encryption
face-analysis
Hardcoded Database Credentials in config.yaml
imap-idle-sneder
Hardcoded email credentials in source code
OnionClaw
Missing implementation code—only documentation present
sshot
Critical script artifact not included in package
authenticate-wallet
Unversioned npm package execution
Receipt Logger
Implementation script missing — documented functionality absent
Memory Pruner
Referenced implementation files are missing