Laporan audit skill
local-ai-app-integration Laporan audit.
Integrates local AI capabilities into applications using Embeddable Lemonade. Use when the user wants to add local AI, offline AI, private AI, on-device AI, a local LLM, local chat, embeddings, image generation, speech-to-text, or text-to-speech to an existing app; replace or supplement OpenAI, Anthropic, Ollama, or other cloud AI APIs with a local backend; only use to convert user apps. Do not use when the user just wants the agent itself to generate images, transcribe, or speak locally in the current workspace, even to cut their own API bill.
Trust Score OpenAgentSkill
Trust Score OpenAgentSkill
The Trust Score helps an agent decide whether a skill is safe enough to shortlist before installation.
Adopsi GitHub
Info62
332 star GitHub
Aktivitas star/fork
Peringatan57
332 star dan 30 fork; aktivitas issue tidak tersedia dalam metadata saat ini
Pemeliharaan terbaru
Lulus88
1 bulan sejak push
Kejelasan lisensi
Lulus86
MIT
Kelengkapan README/SKILL.md
Lulus86
Metadata memuat konteks penggunaan dan alur kerja yang cukup
Risiko dependensi/runtime
Gagal36
command execution surface, credential or environment access
Ketersediaan pemasangan
Lulus92
npx skills add amd/skills --skill local-ai-app-integration
Keamanan perintah pemasangan
Lulus92
Jalur pemasangan paket atau runtime standar
Cakupan izin
Gagal22
secrets or environment access, shell or command execution
Bukti repositori
Lulus86
https://github.com/amd/skills/tree/main/skills/local-ai-app-integration
Status peninjauan
Info66
Data tinjauan AI tersedia
Hasil terbukti Agent
Info54
Belum ada data hasil Agent
Pemeriksaan
Tinjauan pemasangan dan adopsi
Jalur pemasangan
92
npx skills add amd/skills --skill local-ai-app-integration
Repositori
88
https://github.com/amd/skills/tree/main/skills/local-ai-app-integration
Lisensi
86
MIT
Pemeliharaan
88
1 bulan sejak push
Tinjauan AI
55
SKILL.md lacks explicit security guidance for handling API keys, verifying downloaded binaries/models, and avoiding insecure subprocess spawning.
Kelengkapan README/SKILL.md
86
Usable description available
Risiko dependensi
36
command execution surface, credential or environment access
Keamanan perintah pemasangan
92
Jalur pemasangan paket atau runtime standar
Cakupan izin
22
secrets or environment access, shell or command execution
Aktivitas star/fork
57
332 star dan 30 fork; aktivitas issue tidak tersedia dalam metadata saat ini
Adopsi
68
332 star GitHub
Financial decision safety
58
Research-only use: do not treat output as financial advice or execute a position without human approval.
Peringatan
- Dependency or permission surface needs review
- Permission surface may require sandboxing
- Financial research output is not financial advice; require human review before any live investment decision
- SKILL.md lacks explicit security guidance for handling API keys, verifying downloaded binaries/models, and avoiding insecure subprocess spawning.
- The skill mentions 'log every stage' but does not specify that secrets must never be logged; evals include 'secrets' in expected logs, which is ambiguous and could be misinterpreted.
- Financial research output is not financial advice; require human review before any live investment decision.
- Quality score needs review
- Permission surface needs review: secrets or environment access, shell or command execution
- Stars/forks activity: 332 stars, 30 forks; issue activity unavailable in current metadata
- Dependency/runtime risk: command execution surface, credential or environment access
- Permission surface: secrets or environment access, shell or command execution
Metode
This report combines public metadata, AI review output, repository freshness, install readiness, OpenAgentSkill events, quality scoring, trust checks, and the agent safety gate. It is not a full source-code security review.
Bandingkan opsi sekitar