Evaluasi sebelum pemasangan

dstack-prototyping Laporan evaluasi.

Keputusan pemasangan yang dapat dibaca mesin untuk Agent: kecocokan tugas, Trust Score, Audit Score, keamanan pemasangan, cakupan izin, dan rencana validasi konkret sebelum skill menyentuh workspace.

GagalRisiko tinggiBlokir Kebijakan
70
Laporan evaluasi
72
Kepercayaan
80
Audit
40
Keamanan Agent

do not auto install

Agent safety gate: This skill should not be selected by an agent without explicit human security review.

Gerbang wajib

Pemeriksaan yang harus dilalui Agent sebelum memasang

Buka JSON

Kecocokan tugas

84

Lulus

Task wording matches this skill metadata.

  • Evaluate dstack-prototyping before installing it in an agent workflow
  • Riset
  • Local desktop workflows; Claude Code teams; teams that value GitHub adoption signals

Jalur pemasangan

92

Lulus

Install handoff is available.

  • npx skills add dstackai/dstack --skill dstack-prototyping

Keamanan perintah pemasangan

92

Lulus

Jalur pemasangan paket atau runtime standar

  • npx skills add dstackai/dstack --skill dstack-prototyping

Skor kepercayaan

72

Peringatan

Good trust signals with a few areas worth checking before rollout.

  • Shortlist kuat
  • 2.2K star GitHub
  • MPL-2.0

Skor audit

80

Peringatan

Perlu ditinjau

  • Dependency or permission surface needs review

Gerbang keamanan Agent

40

Gagal

This skill should not be selected by an agent without explicit human security review.

  • Do not auto-install. Inspect the source, dependencies, and permission surface first.
  • Metadata combines secrets access with shell or command execution

Kejelasan lisensi

86

Lulus

MPL-2.0

  • MPL-2.0

Cakupan izin

22

Gagal

secrets or environment access, shell or command execution

  • Shell or command execution: high
  • Network access: medium
  • Filesystem access: medium

Rencana validasi

Langkah Agent berikutnya

  1. 1Inspect repository, README/SKILL.md, license, and recent commits before production use.
  2. 2Install in an isolated workspace or sandbox with no production secrets available.
  3. 3Run the smallest representative task and record files touched, commands run, network access, and outputs.
  4. 4Compare the selected skill against at least one alternative when the eval status is review or failed.
  5. 5Promote only after the agent reports a successful verification result and unresolved warnings are accepted.

Jangan gunakan ketika

Kondisi yang membutuhkan skill lain

  • Tim yang membutuhkan SLA dengan dukungan vendor
  • production agents without a repository review
  • The skill does not explicitly advise on checking for malicious or untrusted images/modules when prototyping, though it points to official sources which mitigates risk.
  • Petunjuk izin berisiko tinggi: Shell or command execution, Secrets or environment access
  • Dependency or permission surface needs review
  • Permission surface may require sandboxing

Pemeriksaan pendukung

Sinyal kepercayaan di balik keputusan

Kelengkapan README/SKILL.md

Lulus

86

Metadata memuat konteks penggunaan dan alur kerja yang cukup

Pemeliharaan terbaru

Lulus

100

1 hari sejak push

Alternatif tersedia

Lulus

82

Alternative skills are available for comparison.