Evaluasi sebelum pemasangan

vercel-react-best-practices Laporan evaluasi.

Keputusan pemasangan yang dapat dibaca mesin untuk Agent: kecocokan tugas, Trust Score, Audit Score, keamanan pemasangan, cakupan izin, dan rencana validasi konkret sebelum skill menyentuh workspace.

Perlu ditinjauRisiko sedangTinjau Kebijakan
79
Laporan evaluasi
77
Kepercayaan
87
Audit
55
Keamanan Agent

Tinjauan manual

Test manually in an isolated workspace and compare against safer alternatives.

Gerbang wajib

Pemeriksaan yang harus dilalui Agent sebelum memasang

Buka JSON

Kecocokan tugas

84

Lulus

Task wording matches this skill metadata.

  • Evaluate vercel-react-best-practices before installing it in an agent workflow
  • Desain dan kreatif
  • GitHub automation workflows; Claude Code teams; teams that value GitHub adoption signals

Jalur pemasangan

92

Lulus

Install handoff is available.

  • npx skills add CherryHQ/cherry-studio --skill vercel-react-best-practices

Keamanan perintah pemasangan

92

Lulus

Jalur pemasangan paket atau runtime standar

  • npx skills add CherryHQ/cherry-studio --skill vercel-react-best-practices

Skor kepercayaan

77

Peringatan

Good trust signals with a few areas worth checking before rollout.

  • Shortlist kuat
  • 51K star GitHub
  • MIT

Skor audit

87

Peringatan

Perlu ditinjau

  • Permission surface may require sandboxing

Gerbang keamanan Agent

55

Peringatan

Sparse or mixed signals. Useful for discovery, but not for autonomous installation.

  • Test manually in an isolated workspace and compare against safer alternatives.
  • Petunjuk izin berisiko tinggi: Secrets or environment access

Kejelasan lisensi

86

Lulus

MIT

  • MIT

Cakupan izin

60

Peringatan

filesystem or document access, network or browser access

  • Network access: medium
  • Filesystem access: medium
  • Secrets or environment access: high

Rencana validasi

Langkah Agent berikutnya

  1. 1Inspect repository, README/SKILL.md, license, and recent commits before production use.
  2. 2Install in an isolated workspace or sandbox with no production secrets available.
  3. 3Run the smallest representative task and record files touched, commands run, network access, and outputs.
  4. 4Compare the selected skill against at least one alternative when the eval status is review or failed.
  5. 5Promote only after the agent reports a successful verification result and unresolved warnings are accepted.

Jangan gunakan ketika

Kondisi yang membutuhkan skill lain

  • Tim yang membutuhkan SLA dengan dukungan vendor
  • production agents without a repository review
  • SKILL.md only provides a high-level quick reference with rule names and categories, lacking the detailed explanations, code examples, and workflow steps needed for an agent to correctly apply the guidelines. It is effectively a summary rather than a self-contained skill.
  • Petunjuk izin berisiko tinggi: Secrets or environment access
  • Permission surface may require sandboxing
  • Inconsistency in rule count: the description in SKILL.md states 'Contains 62 rules' while AGENTS.md and README mention '40+ rules'. This discrepancy undermines clarity.

Pemeriksaan pendukung

Sinyal kepercayaan di balik keputusan

Kelengkapan README/SKILL.md

Lulus

86

Metadata memuat konteks penggunaan dan alur kerja yang cukup

Pemeliharaan terbaru

Lulus

100

1 hari sejak push

Alternatif tersedia

Lulus

82

Alternative skills are available for comparison.