🚨GoPlus: 21% of ClawHub's Top 100 Skills Contain Explicitly High-Risk Operations
GoPlus Security (@GoPlusZH) released an in-depth security scan report on ClawHub's top 100 skills: 21% of the top 100 skills contain explicitly high-risk operations (such as direct network tunneling, sensitive API calls, or automated messaging).
For these skills, it is recommended to enforce a human-to-human (HITL) verification mechanism before execution to ensure that high-risk operations are manually reviewed.
In addition, 17% of the skills exhibit certain risk signals and should be executed with caution. For users with higher security requirements, it is recommended to enable manual verification for these skills.