Laporan audit skill

docker-compose-launch Laporan audit.

Launch worktree-scoped local services for issue implementation when a monorepo skill requires database dependencies.

Diblokir · BlokirPerlu ditinjauDihasilkan 23 Agu 2026Audit metadata heuristik
72
Audit
63
Kepercayaan
63
Kualitas
70
Keamanan
100
Maintain
92
Pasang

Trust Score OpenAgentSkill

63
Tinjauan manual

Trust Score OpenAgentSkill

The Trust Score helps an agent decide whether a skill is safe enough to shortlist before installation.

Adopsi GitHub

Peringatan

48

37 star GitHub

Aktivitas star/fork

Peringatan

43

37 star dan 6 fork; aktivitas issue tidak tersedia dalam metadata saat ini

Pemeliharaan terbaru

Lulus

100

4 hari sejak push

Kejelasan lisensi

Lulus

86

Apache-2.0

Kelengkapan README/SKILL.md

Info

76

Metadata publik memerlukan konteks README/SKILL.md yang lebih kuat

Risiko dependensi/runtime

Peringatan

54

credential or environment access, external package install surface

Ketersediaan pemasangan

Lulus

92

npx skills add aliengiraffe/vigilante --skill docker-compose-launch

Keamanan perintah pemasangan

Lulus

92

Jalur pemasangan paket atau runtime standar

Cakupan izin

Gagal

18

secrets or environment access, shell or command execution

Bukti repositori

Lulus

86

https://github.com/aliengiraffe/vigilante/tree/main/skills/docker-compose-launch

Status peninjauan

Info

66

Data tinjauan AI tersedia

Hasil terbukti Agent

Info

54

Belum ada data hasil Agent

Pemeriksaan

Tinjauan pemasangan dan adopsi

6 Lulus · 16 Perlu ditinjau

Jalur pemasangan

92

Lulus

npx skills add aliengiraffe/vigilante --skill docker-compose-launch

Repositori

88

Lulus

https://github.com/aliengiraffe/vigilante/tree/main/skills/docker-compose-launch

Lisensi

86

Lulus

Apache-2.0

Pemeliharaan

100

Lulus

4 hari sejak push

Tinjauan AI

55

Periksa

The skill does not specify how to handle multiple service types simultaneously or how to generate fallback compose files when no repository-native mechanism exists.

Kelengkapan README/SKILL.md

84

Lulus

Usable description available

Risiko dependensi

54

Perbaiki

credential or environment access, external package install surface

Keamanan perintah pemasangan

92

Lulus

Jalur pemasangan paket atau runtime standar

Cakupan izin

18

Perbaiki

secrets or environment access, shell or command execution

Aktivitas star/fork

43

Perbaiki

37 star dan 6 fork; aktivitas issue tidak tersedia dalam metadata saat ini

Adopsi

42

Periksa

37 star GitHub

Peringatan

  • Dependency or permission surface needs review
  • Permission surface may require sandboxing
  • The skill does not specify how to handle multiple service types simultaneously or how to generate fallback compose files when no repository-native mechanism exists.
  • Readiness checks are mentioned but not detailed (e.g., health endpoints, port checks, or timeout handling).
  • Low GitHub adoption signal
  • Quality score needs review
  • Permission surface needs review: secrets or environment access, shell or command execution
  • GitHub adoption: 37 GitHub stars
  • Stars/forks activity: 37 stars, 6 forks; issue activity unavailable in current metadata
  • Dependency/runtime risk: credential or environment access, external package install surface
  • Permission surface: secrets or environment access, shell or command execution

Metode

This report combines public metadata, AI review output, repository freshness, install readiness, OpenAgentSkill events, quality scoring, trust checks, and the agent safety gate. It is not a full source-code security review.

Bandingkan opsi sekitar

Skill terkait untuk diaudit berikutnya