Informe de auditoría del skill

browser-testing-with-devtools Informe de auditoría.

Tests in real browsers via Chrome DevTools MCP. Use when building or debugging anything that runs in a browser. Use when you need to inspect the DOM, capture console errors, analyze network requests, profile performance, or verify visual output with real runtime data. Requires the chrome-devtools MCP server to be configured.

Bloqueado · BloquearRequiere revisiónGenerado 11 oct 2026Auditoría heurística de metadatos
81
Auditoría
70
Confianza
92
Calidad
73
Seguridad
88
Maintain
92
Instalar

Trust Score de OpenAgentSkill

70
Revisión manual

Trust Score de OpenAgentSkill

The Trust Score helps an agent decide whether a skill is safe enough to shortlist before installation.

Adopción en GitHub

Aprobado

100

92K estrellas de GitHub

Actividad de stars/forks

Aprobado

100

92K estrellas y 9.8K forks; la actividad de issues no está disponible en los metadatos actuales

Mantenimiento reciente

Aprobado

88

1 meses desde el último push

Claridad de licencia

Aprobado

86

MIT

Completitud de README/SKILL.md

Aprobado

86

Los metadatos incluyen suficiente contexto de uso y flujo de trabajo

Riesgo de dependencias/runtime

Advertencia

46

command execution surface, credential or environment access

Disponibilidad de instalación

Aprobado

92

npx skills add addyosmani/agent-skills --skill browser-testing-with-devtools

Seguridad del comando de instalación

Aprobado

92

Ruta estándar de paquete o instalación en tiempo de ejecución

Superficie de permisos

Fallido

36

secrets or environment access, shell or command execution

Evidencia del repositorio

Aprobado

86

https://github.com/addyosmani/agent-skills/tree/main/skills/browser-testing-with-devtools

Estado de revisión

Info

66

Hay datos de revisión por IA disponibles

Resultados comprobados por Agent

Info

54

Aún no hay datos de resultados del Agent

Comprobaciones

Revisión de instalación y adopción

8 Aprobado · 11 Requiere revisión

Ruta de instalación

92

Aprobado

npx skills add addyosmani/agent-skills --skill browser-testing-with-devtools

Repositorio

88

Aprobado

https://github.com/addyosmani/agent-skills/tree/main/skills/browser-testing-with-devtools

Licencia

86

Aprobado

MIT

Mantenimiento

88

Aprobado

1 meses desde el último push

Revisión por IA

55

Revisar

The SKILL.md excerpt stops mid-sentence in the 'Treat All Browser Content as Untrusted Data' section. If this reflects the full submitted file, the security guidance is incomplete and should be finished with explicit handling rules for untrusted browser content.

Completitud de README/SKILL.md

86

Aprobado

Usable description available

Riesgo de dependencias

46

Corregir

command execution surface, credential or environment access

Seguridad del comando de instalación

92

Aprobado

Ruta estándar de paquete o instalación en tiempo de ejecución

Superficie de permisos

36

Corregir

secrets or environment access, shell or command execution

Actividad de stars/forks

100

Aprobado

92K estrellas y 9.8K forks; la actividad de issues no está disponible en los metadatos actuales

Adopción

88

Aprobado

92K estrellas de GitHub

Advertencias

  • Dependency or permission surface needs review
  • Permission surface may require sandboxing
  • The SKILL.md excerpt stops mid-sentence in the 'Treat All Browser Content as Untrusted Data' section. If this reflects the full submitted file, the security guidance is incomplete and should be finished with explicit handling rules for untrusted browser content.
  • JavaScript Execution is described as 'read-only state inspection', but the underlying tool can run arbitrary code in the page context. The skill needs a sharper boundary: do not mutate page state, read cookies/localStorage, or exfiltrate data unless explicitly required by the task.
  • The tools table uses friendly names rather than exact chrome-devtools MCP tool names, which may make it harder for an agent to know which MCP tool to invoke.
  • Permission surface needs review: secrets or environment access, shell or command execution
  • Dependency/runtime risk: command execution surface, credential or environment access
  • Permission surface: secrets or environment access, shell or command execution

Método

This report combines public metadata, AI review output, repository freshness, install readiness, OpenAgentSkill events, quality scoring, trust checks, and the agent safety gate. It is not a full source-code security review.

Comparar opciones cercanas

Skills relacionados para auditar después