Laporan audit skill

constraint-driven-development Laporan audit.

Establishes a project's quality bar as a written contract and stops agents quietly lowering it. Interviews the user on which dimensions matter, supplies sane default thresholds when they have no number in mind, records everything in CONSTRAINTS.md, and watches the diff for a weakened bar — new @ts-ignore or eslint-disable suppressions, skipped or deleted tests, assertions stripped out, unimplemented stubs, thresholds edited down. Use when no quality bar is written down, when the user says "set up constraints" or "define our standards", when an agent keeps silencing checks or skipping tests to get to green, when you need a coverage or performance threshold and don't know what number to pick, or when an agent writes more code than anyone will read.

Diblokir · BlokirPerlu ditinjauDihasilkan 11 Okt 2026Audit metadata heuristik
81
Audit
70
Kepercayaan
92
Kualitas
72
Keamanan
88
Maintain
92
Pasang

Trust Score OpenAgentSkill

70
Tinjauan manual

Trust Score OpenAgentSkill

The Trust Score helps an agent decide whether a skill is safe enough to shortlist before installation.

Adopsi GitHub

Lulus

100

91K star GitHub

Aktivitas star/fork

Lulus

100

91K star dan 9.8K fork; aktivitas issue tidak tersedia dalam metadata saat ini

Pemeliharaan terbaru

Lulus

88

1 bulan sejak push

Kejelasan lisensi

Lulus

86

MIT

Kelengkapan README/SKILL.md

Lulus

86

Metadata memuat konteks penggunaan dan alur kerja yang cukup

Risiko dependensi/runtime

Peringatan

44

command execution surface, credential or environment access

Ketersediaan pemasangan

Lulus

92

npx skills add addyosmani/agent-skills --skill constraint-driven-development

Keamanan perintah pemasangan

Lulus

92

Jalur pemasangan paket atau runtime standar

Cakupan izin

Gagal

36

secrets or environment access, shell or command execution

Bukti repositori

Lulus

86

https://github.com/addyosmani/agent-skills/tree/main/skills/constraint-driven-development

Status peninjauan

Info

66

Data tinjauan AI tersedia

Hasil terbukti Agent

Info

54

Belum ada data hasil Agent

Pemeriksaan

Tinjauan pemasangan dan adopsi

8 Lulus · 14 Perlu ditinjau

Jalur pemasangan

92

Lulus

npx skills add addyosmani/agent-skills --skill constraint-driven-development

Repositori

88

Lulus

https://github.com/addyosmani/agent-skills/tree/main/skills/constraint-driven-development

Lisensi

86

Lulus

MIT

Pemeliharaan

88

Lulus

1 bulan sejak push

Tinjauan AI

55

Periksa

The submitted SKILL.md excerpt is truncated mid-sentence during the interview questions, so the full instructions for Step 2 defaults and remaining process steps are not visible in this review payload.

Kelengkapan README/SKILL.md

86

Lulus

Usable description available

Risiko dependensi

44

Perbaiki

command execution surface, credential or environment access

Keamanan perintah pemasangan

92

Lulus

Jalur pemasangan paket atau runtime standar

Cakupan izin

36

Perbaiki

secrets or environment access, shell or command execution

Aktivitas star/fork

100

Lulus

91K star dan 9.8K fork; aktivitas issue tidak tersedia dalam metadata saat ini

Adopsi

88

Lulus

91K star GitHub

Financial decision safety

58

Periksa

Research-only use: do not treat output as financial advice or execute a position without human approval.

Peringatan

  • Dependency or permission surface needs review
  • Permission surface may require sandboxing
  • Financial research output is not financial advice; require human review before any live investment decision
  • The submitted SKILL.md excerpt is truncated mid-sentence during the interview questions, so the full instructions for Step 2 defaults and remaining process steps are not visible in this review payload.
  • No explicit security guidance is present in the excerpt about handling untrusted project files or avoiding accidental execution of malicious scripts when running the test suite or linters.
  • The floor-guard reference implementation is truncated at the import statement, making it impossible to fully verify redaction, exit-code handling, and diff-scope logic from the submitted files.
  • Financial research output is not financial advice; require human review before any live investment decision.
  • Permission surface needs review: secrets or environment access, shell or command execution
  • Dependency/runtime risk: command execution surface, credential or environment access
  • Permission surface: secrets or environment access, shell or command execution

Metode

This report combines public metadata, AI review output, repository freshness, install readiness, OpenAgentSkill events, quality scoring, trust checks, and the agent safety gate. It is not a full source-code security review.

Bandingkan opsi sekitar

Skill terkait untuk diaudit berikutnya