Skill 审计报告

quant-experiment-runtime 审计报告.

Quant research experiment executor: discover an offline source database under the workdir's code-repo, build a panel, run a Research Artifact's entry point to compute research-object values, and evaluate IC/ICIR/RANKIC/coverage metrics. Runtime = Experiment Executor; it runs a Research Artifact via a Python-native Entry Point and is agnostic to research-object type and expression form. Self-contained: panel building and IC metrics are implemented inside this skill. The dataset is identified at runtime by discover_data.py (never hard-coded). Use when: a research proposal is ready and you need to actually run the proposed factor/method on real data and get quantitative metrics. Do NOT use for: designing which experiments to run (use experiment-pipeline / paper-planning), debugging a single failed experiment (use experiment-craft), or searching papers (use local-paper-navigator).

实验性 · 审查需审查生成于 2026年10月11日启发式元数据审计
75
审计
70
信任
67
质量
74
安全性
88
维护
92
安装

OpenAgentSkill 信任评分

70
人工审查

OpenAgentSkill 信任评分

Trust Score 帮助 Agent 在安装前判断一个 Skill 是否足以进入候选清单。

GitHub 采用度

信息

62

212 个 GitHub Stars

Star/Fork 活跃度

警告

51

212 个 Star,3 个 Fork; 当前元数据中没有议题活跃度信息

近期维护

通过

88

距上次推送 1 个月

许可证清晰度

通过

86

Apache-2.0

README/SKILL.md 完整度

通过

86

元数据包含足够的用法与工作流上下文

依赖与运行时风险

警告

54

command execution surface, external package install surface

安装可用性

通过

92

npx skills add CamusGIT/EvoQuant --skill quant-experiment-runtime

安装命令安全性

通过

92

标准软件包或运行时安装路径

权限范围

警告

50

shell or command execution, filesystem or document access

仓库证据

通过

86

https://github.com/CamusGIT/EvoQuant/tree/main/EvoQuant/skills/quant-experiment-runtime

审查状态

信息

66

可用 AI 审查数据

Agent 验证结果

信息

54

暂未有 Agent 结果数据

检查项

安装与采用审查

6 通过 · 15 需审查

安装路径

92

通过

npx skills add CamusGIT/EvoQuant --skill quant-experiment-runtime

仓库

88

通过

https://github.com/CamusGIT/EvoQuant/tree/main/EvoQuant/skills/quant-experiment-runtime

许可证

86

通过

Apache-2.0

维护

88

通过

距上次推送 1 个月

AI 审查

55

检查

The skill executes arbitrary code from LLM-generated research artifacts, which inherently requires a secure sandbox environment. The documentation mentions the EvoQuant sandbox but does not explicitly detail sandboxing constraints or risk mitigations within the skill itself.

README/SKILL.md 完整度

86

通过

Usable description available

依赖风险

54

修复

command execution surface, external package install surface

安装命令安全性

92

通过

标准软件包或运行时安装路径

权限范围

50

修复

shell or command execution, filesystem or document access

Star/Fork 活跃度

51

修复

212 个 Star,3 个 Fork; 当前元数据中没有议题活跃度信息

采用度

68

信息

212 个 GitHub Stars

Financial decision safety

58

检查

Research-only use: do not treat output as financial advice or execute a position without human approval.

警告

  • Dependency or permission surface needs review
  • Permission surface may require sandboxing
  • Financial research output is not financial advice; require human review before any live investment decision
  • The skill executes arbitrary code from LLM-generated research artifacts, which inherently requires a secure sandbox environment. The documentation mentions the EvoQuant sandbox but does not explicitly detail sandboxing constraints or risk mitigations within the skill itself.
  • Financial research output is not financial advice; require human review before any live investment decision.
  • Quality score needs review
  • Permission surface needs review: shell or command execution, filesystem or document access
  • Stars/forks activity: 212 stars, 3 forks; issue activity unavailable in current metadata
  • Dependency/runtime risk: command execution surface, external package install surface
  • Permission surface: shell or command execution, filesystem or document access

方法

本报告综合公开元数据、AI 审查输出、仓库活跃度、安装就绪度、OpenAgentSkill 事件、质量评分、信任检查和 Agent 安全门槛;它不是完整的源代码安全审计。

对比相近选项

下一步可审计的相关 Skill