Slowmist warns that ClawHub poses security risks due to its reliance on GitHub one-click login, which is vulnerable to developer credential theft for supply chain attacks. GoPlus scanned the top 100 Skills and discovered that 21% have high-risk vulnerabilities. Additionally, Tencent's SkillHub has sparked copyright disputes, with founders criticizing it for failing to provide support to open-source projects. Users are advised to carefully select Skills and implement security measures to prevent potential attacks.