安装前评估

Flashswap Arbitrage Avalanche 评估报告.

为 Agent 提供机器可读的安装决策:任务匹配、Trust Score、Audit Score、安装安全、权限范围,以及在 Skill 进入工作区前的具体验证计划。

失败高风险阻止 策略
58
评估报告
69
信任
61
审计
33
Agent 安全

do not auto install

Audit score: Risky

必要关卡

Agent 安装前必须通过的检查

打开 JSON

任务匹配度

94

通过

任务描述与此 Skill 的元数据匹配。

  • Evaluate Flashswap Arbitrage Avalanche before installing it in an agent workflow
  • web3-analytics
  • RAG and knowledge workflows; Claude Code teams; builders willing to evaluate younger projects

安装路径

92

通过

可用安装交接信息。

  • npx skills add cjthoma1/flashswap-arbitrage-avalanche

安装命令安全性

92

通过

标准软件包或运行时安装路径

  • npx skills add cjthoma1/flashswap-arbitrage-avalanche

信任评分

69

警告

Potentially useful, but at least one trust signal needs human inspection.

  • 人工审查
  • 140 个 GitHub Stars
  • BSD-3-Clause

审计评分

61

失败

高风险

  • Permission surface may require sandboxing

Agent 安全门槛

33

失败

This skill should not be selected by an agent without explicit human security review.

  • Do not auto-install. Inspect the source, dependencies, and permission surface first.
  • Audit risk exceeds the requested agent policy

许可证清晰度

86

通过

BSD-3-Clause

  • BSD-3-Clause

权限范围

60

警告

secrets or environment access, filesystem or document access

  • Network access: medium
  • Filesystem access: medium
  • Secrets or environment access: high

验证计划

Agent 接下来应执行什么

  1. 1在生产使用前检查仓库、README/SKILL.md、许可证与最近提交。
  2. 2在没有生产密钥的隔离工作区或沙盒中安装。
  3. 3运行最小代表性任务,并记录访问的文件、执行的命令、网络访问和输出。
  4. 4当评估状态为“审查”或“失败”时,至少与一个替代 Skill 比较。
  5. 5只有在 Agent 报告验证成功且已接受未解决警告后,才提升到更高环境。

不适用场景

需要改用其他 Skill 的情况

  • teams that require actively maintained dependencies
  • production agents without a repository review
  • Repository looks stale
  • Audit risk risky exceeds max_risk=medium
  • 高风险权限提示:Secrets or environment access
  • Permission surface may require sandboxing

辅助检查

支撑该决策的信任信号

README/SKILL.md 完整度

通过

90

元数据包含足够的用法与工作流上下文

近期维护

失败

22

距上次推送 4 年

可用替代方案

通过

82

有可用于比较的替代 Skill。