Risk Collection

High-risk skills

These are the skills Driftloom thinks deserve the strongest caution. Not forbidden. Just not the ones you install while half-awake and optimistic.

12 matching skills
Page 1 of 1
label: high_risk
clear filters

007 — Licenca para Auditar

GitHub:sickn33/antigravity-awesome-skills · 007
High Risk

This skill performs security audits, threat modeling, and other security tasks.

Source: Workspace import

Originally ingested from a local workspace copy.

version 0306e8650910
3 findings
OpenClaw disconnected clean
runtime tested
openclaw disconnected clean
no human review yet

Runtime evidence: OpenClaw disconnected runtime validation completed cleanly in the isolated runner.

Used fake placeholder env vars in the sandbox; no real credentials were exposed.

  • OpenClaw is available in the runner image as OpenClaw 2026.3.24 (cff6dc9).
  • The skill matched the basic OpenClaw-oriented layout checks used for disconnected validation.
  • SKILL.md does not explicitly mention OpenClaw; this may still be valid, but intent is less obvious.
  • No safe documented OpenClaw commands or package-script help probes were found; disconnected validation remains mostly structural.
Safety
0
Quality
70
Transparency
37
Operational
92

Automated result: High Risk

Current public label: High Risk

The current label should account for both the file-level review and the fact that the sandbox runtime pass did not come back perfectly clean.

Human review: none yet

The current public label is still relying on automation. A human has not weighed in yet.

Severity mix: 2 low, 1 info

Audit Skills (Premium Universal Security)

GitHub:sickn33/antigravity-awesome-skills · audit-skills
High Risk

This skill appears to be a set of documentation. Driftloom found shell-oriented patterns and destructive commands.

Source: Workspace import

Originally ingested from a local workspace copy.

version 669e2578ab7f
6 findings
static analysis only
uses shell
no human review yet

Runtime evidence: Not recorded yet. Driftloom currently recommends a sandbox runtime check for this version (priority 35).

Safety
0
Quality
94
Transparency
100
Operational
92

Automated result: High Risk

Current public label: High Risk

The skill includes shell commands that could be dangerous, and the documentation-only structure limits automated verification.

Human review: none yet

The current public label is still relying on automation. A human has not weighed in yet.

Severity mix: 2 high, 3 medium, 1 low

Building LLM-Powered Applications with Claude

GitHub:sickn33/antigravity-awesome-skills · claude-api
High Risk

This skill helps you build LLM-powered applications with Claude by reading language-specific documentation.

Source: Workspace import

Originally ingested from a local workspace copy.

version 9e2fe5abca57
4 findings
OpenClaw disconnected clean
runtime tested
openclaw disconnected clean
no human review yet

Runtime evidence: OpenClaw disconnected runtime validation completed cleanly in the isolated runner.

Used fake placeholder env vars in the sandbox; no real credentials were exposed.

  • OpenClaw is available in the runner image as OpenClaw 2026.3.24 (cff6dc9).
  • The skill matched the basic OpenClaw-oriented layout checks used for disconnected validation.
  • SKILL.md does not explicitly mention OpenClaw; this may still be valid, but intent is less obvious.
  • No obvious script files found; disconnected runtime evidence may remain shallow.
  • No safe documented OpenClaw commands or package-script help probes were found; disconnected validation remains mostly structural.
Safety
4
Quality
94
Transparency
22
Operational
92

Automated result: High Risk

Current public label: High Risk

The current label should account for both the file-level review and the fact that the sandbox runtime pass did not come back perfectly clean.

Human review: none yet

The current public label is still relying on automation. A human has not weighed in yet.

Severity mix: 3 low, 1 info

⚡ Bun Development

GitHub:sickn33/antigravity-awesome-skills · bun-development
High Risk

This skill provides a development environment for JavaScript and TypeScript using the Bun runtime.

Source: Workspace import

Originally ingested from a local workspace copy.

version a7e52a79c0ae
4 findings
OpenClaw disconnected clean
runtime tested
openclaw disconnected clean
no human review yet

Runtime evidence: OpenClaw disconnected runtime validation completed cleanly in the isolated runner.

Used fake placeholder env vars in the sandbox; no real credentials were exposed.

  • OpenClaw is available in the runner image as OpenClaw 2026.3.24 (cff6dc9).
  • The skill matched the basic OpenClaw-oriented layout checks used for disconnected validation.
  • SKILL.md does not explicitly mention OpenClaw; this may still be valid, but intent is less obvious.
  • No obvious script files found; disconnected runtime evidence may remain shallow.
  • No safe documented OpenClaw commands or package-script help probes were found; disconnected validation remains mostly structural.
Safety
38
Quality
94
Transparency
79
Operational
92

Automated result: High Risk

Current public label: High Risk

The current label should account for both the file-level review and the fact that the sandbox runtime pass did not come back perfectly clean.

Human review: none yet

The current public label is still relying on automation. A human has not weighed in yet.

Severity mix: 3 low, 1 info

CLAUDE CODE EXPERT - Potencia Maxima

GitHub:sickn33/antigravity-awesome-skills · claude-code-expert
High Risk

This skill appears to be a documentation-heavy guide for using the Claude Code CLI, including setup, configuration, and advanced workflows.

Source: Workspace import

Originally ingested from a local workspace copy.

version 5ec19acccc09
4 findings
static analysis only
uses shell
no human review yet

Runtime evidence: Not recorded yet. Driftloom currently recommends a sandbox runtime check for this version (priority 35).

Safety
29
Quality
94
Transparency
100
Operational
92

Automated result: High Risk

Current public label: High Risk

The presence of shell commands that could be used to install software or delete files, combined with the use of `sudo`, suggests this skill could be used to perform actions that could be harmful.

Human review: none yet

The current public label is still relying on automation. A human has not weighed in yet.

Severity mix: 2 high, 1 medium, 1 low

last30days: Research Any Topic from the Last 30 Days

GitHub:sickn33/antigravity-awesome-skills · last30days
High Risk

This skill researches topics across Reddit, X, and the web to surface current discussions and recommendations.

Source: Workspace import

Originally ingested from a local workspace copy.

version 30ba4c847c14
3 findings
OpenClaw disconnected clean
runtime tested
openclaw disconnected clean
no human review yet

Runtime evidence: OpenClaw disconnected runtime validation completed cleanly in the isolated runner.

Used fake placeholder env vars in the sandbox; no real credentials were exposed.

  • OpenClaw is available in the runner image as OpenClaw 2026.3.24 (cff6dc9).
  • The skill matched the basic OpenClaw-oriented layout checks used for disconnected validation.
  • SKILL.md does not explicitly mention OpenClaw; this may still be valid, but intent is less obvious.
  • No safe documented OpenClaw commands or package-script help probes were found; disconnected validation remains mostly structural.
Safety
0
Quality
100
Transparency
0
Operational
92

Automated result: High Risk

Current public label: High Risk

The current label should account for both the file-level review and the fact that the sandbox runtime pass did not come back perfectly clean.

Human review: none yet

The current public label is still relying on automation. A human has not weighed in yet.

Severity mix: 2 low, 1 info

Loki Mode - Multi-Agent Autonomous Startup System

GitHub:sickn33/antigravity-awesome-skills · loki-mode
High Risk

This skill is a multi-agent autonomous startup system, as described in the documentation. It uses OpenAI, DeepMind, and other AI tools.

Source: Workspace import

Originally ingested from a local workspace copy.

version 251cd17ad0a0
3 findings
OpenClaw disconnected clean
runtime tested
openclaw disconnected clean
no human review yet

Runtime evidence: OpenClaw disconnected runtime validation completed cleanly in the isolated runner.

Used fake placeholder env vars in the sandbox; no real credentials were exposed.

  • OpenClaw is available in the runner image as OpenClaw 2026.3.24 (cff6dc9).
  • The skill matched the basic OpenClaw-oriented layout checks used for disconnected validation.
  • SKILL.md does not explicitly mention OpenClaw; this may still be valid, but intent is less obvious.
  • No safe documented OpenClaw commands or package-script help probes were found; disconnected validation remains mostly structural.
Safety
0
Quality
76
Transparency
0
Operational
92

Automated result: High Risk

Current public label: High Risk

The current label should account for both the file-level review and the fact that the sandbox runtime pass did not come back perfectly clean.

Human review: none yet

The current public label is still relying on automation. A human has not weighed in yet.

Severity mix: 2 low, 1 info

macOS SwiftPM App Packaging (No Xcode)

GitHub:sickn33/antigravity-awesome-skills · macos-spm-app-packaging
High Risk

This skill packages a macOS app built with Swift Package Manager (SwiftPM). It builds, packages, and runs the app without using Xcode.

Source: Workspace import

Originally ingested from a local workspace copy.

version a3c6abae91c2
3 findings
OpenClaw disconnected clean
runtime tested
openclaw disconnected clean
no human review yet

Runtime evidence: OpenClaw disconnected runtime validation completed cleanly in the isolated runner.

Used fake placeholder env vars in the sandbox; no real credentials were exposed.

  • OpenClaw is available in the runner image as OpenClaw 2026.3.24 (cff6dc9).
  • The skill matched the basic OpenClaw-oriented layout checks used for disconnected validation.
  • SKILL.md does not explicitly mention OpenClaw; this may still be valid, but intent is less obvious.
  • No safe documented OpenClaw commands or package-script help probes were found; disconnected validation remains mostly structural.
Safety
44
Quality
100
Transparency
94
Operational
92

Automated result: High Risk

Current public label: High Risk

The current label should account for both the file-level review and the fact that the sandbox runtime pass did not come back perfectly clean.

Human review: none yet

The current public label is still relying on automation. A human has not weighed in yet.

Severity mix: 2 low, 1 info

NotebookLM Research Assistant Skill

GitHub:sickn33/antigravity-awesome-skills · notebooklm
High Risk

This skill interacts with Google NotebookLM to answer questions based on your uploaded documents.

Source: Workspace import

Originally ingested from a local workspace copy.

version 1bcac70d5efe
3 findings
OpenClaw disconnected clean
runtime tested
openclaw disconnected clean
no human review yet

Runtime evidence: OpenClaw disconnected runtime validation completed cleanly in the isolated runner.

Used fake placeholder env vars in the sandbox; no real credentials were exposed.

  • OpenClaw is available in the runner image as OpenClaw 2026.3.24 (cff6dc9).
  • The skill matched the basic OpenClaw-oriented layout checks used for disconnected validation.
  • SKILL.md does not explicitly mention OpenClaw; this may still be valid, but intent is less obvious.
  • No safe documented OpenClaw commands or package-script help probes were found; disconnected validation remains mostly structural.
Safety
38
Quality
100
Transparency
46
Operational
92

Automated result: High Risk

Current public label: High Risk

The current label should account for both the file-level review and the fact that the sandbox runtime pass did not come back perfectly clean.

Human review: none yet

The current public label is still relying on automation. A human has not weighed in yet.

Severity mix: 2 low, 1 info

Skill: Instagram Integration

GitHub:sickn33/antigravity-awesome-skills · instagram
High Risk

This skill integrates with Instagram via the Graph API, allowing for posting, analytics, and comment management.

Source: Workspace import

Originally ingested from a local workspace copy.

version 7632d379b127
3 findings
OpenClaw disconnected clean
runtime tested
openclaw disconnected clean
no human review yet

Runtime evidence: OpenClaw disconnected runtime validation completed cleanly in the isolated runner.

Used fake placeholder env vars in the sandbox; no real credentials were exposed.

  • OpenClaw is available in the runner image as OpenClaw 2026.3.24 (cff6dc9).
  • The skill matched the basic OpenClaw-oriented layout checks used for disconnected validation.
  • SKILL.md does not explicitly mention OpenClaw; this may still be valid, but intent is less obvious.
  • No safe documented OpenClaw commands or package-script help probes were found; disconnected validation remains mostly structural.
Safety
28
Quality
100
Transparency
40
Operational
92

Automated result: High Risk

Current public label: High Risk

The current label should account for both the file-level review and the fact that the sandbox runtime pass did not come back perfectly clean.

Human review: none yet

The current public label is still relying on automation. A human has not weighed in yet.

Severity mix: 2 low, 1 info

Telegram Bot API - Integracao Profissional

GitHub:sickn33/antigravity-awesome-skills · telegram
High Risk

This skill integrates with the Telegram Bot API, offering features like bot setup, messaging, webhooks, and inline keyboards.

Source: Workspace import

Originally ingested from a local workspace copy.

version cf4b45c24ecc
3 findings
OpenClaw disconnected clean
runtime tested
openclaw disconnected clean
no human review yet

Runtime evidence: OpenClaw disconnected runtime validation completed cleanly in the isolated runner.

Used fake placeholder env vars in the sandbox; no real credentials were exposed.

  • OpenClaw is available in the runner image as OpenClaw 2026.3.24 (cff6dc9).
  • The skill matched the basic OpenClaw-oriented layout checks used for disconnected validation.
  • SKILL.md does not explicitly mention OpenClaw; this may still be valid, but intent is less obvious.
  • No safe documented OpenClaw commands or package-script help probes were found; disconnected validation remains mostly structural.
Safety
0
Quality
94
Transparency
0
Operational
92

Automated result: High Risk

Current public label: High Risk

The current label should account for both the file-level review and the fact that the sandbox runtime pass did not come back perfectly clean.

Human review: none yet

The current public label is still relying on automation. A human has not weighed in yet.

Severity mix: 2 low, 1 info

WhatsApp Cloud API - Integracao Profissional

GitHub:sickn33/antigravity-awesome-skills · whatsapp-cloud-api
High Risk

This skill integrates with the WhatsApp Business Cloud API to send messages, use templates, and automate customer service.

Source: Workspace import

Originally ingested from a local workspace copy.

version 97c61e840140
3 findings
OpenClaw disconnected clean
runtime tested
openclaw disconnected clean
no human review yet

Runtime evidence: OpenClaw disconnected runtime validation completed cleanly in the isolated runner.

Used fake placeholder env vars in the sandbox; no real credentials were exposed.

  • OpenClaw is available in the runner image as OpenClaw 2026.3.24 (cff6dc9).
  • The skill matched the basic OpenClaw-oriented layout checks used for disconnected validation.
  • SKILL.md does not explicitly mention OpenClaw; this may still be valid, but intent is less obvious.
  • No safe documented OpenClaw commands or package-script help probes were found; disconnected validation remains mostly structural.
Safety
0
Quality
100
Transparency
0
Operational
92

Automated result: High Risk

Current public label: High Risk

The current label should account for both the file-level review and the fact that the sandbox runtime pass did not come back perfectly clean.

Human review: none yet

The current public label is still relying on automation. A human has not weighed in yet.

Severity mix: 2 low, 1 info