Skill 审计报告

novel-characters 审计报告.

从小说或短故事里拆出角色表、人物画像、形象提示词、音色提示词, 并给每个角色出角色设定图(左半身像 + 右全身三视图 + 细节条),产出 JSON + Markdown + 可交互的 report.html。 报告语言可指定(--lang),默认中文,任意语言都支持; 出图风格可指定(--style),默认半写实,也可以出吉卜力动画风。 零依赖、零 API key,用当前会话额度;出图走 codex 内置 $imagegen(可选)。 Use when asked to 拆小说角色、分析人物、生成角色卡、character sheets from a novel。

已阻止 · 阻止需审查生成于 2026年10月11日启发式元数据审计
77
审计
69
信任
78
质量
72
安全性
88
维护
92
安装

OpenAgentSkill 信任评分

69
人工审查

OpenAgentSkill 信任评分

Trust Score 帮助 Agent 在安装前判断一个 Skill 是否足以进入候选清单。

GitHub 采用度

通过

86

2.6K 个 GitHub Stars

Star/Fork 活跃度

通过

83

2.6K 个 Star,333 个 Fork; 当前元数据中没有议题活跃度信息

近期维护

通过

88

距上次推送 2 个月

许可证清晰度

通过

86

Apache-2.0

README/SKILL.md 完整度

通过

86

元数据包含足够的用法与工作流上下文

依赖与运行时风险

警告

46

command execution surface, credential or environment access

安装可用性

通过

92

npx skills add eternityspring/shuohao-skills --skill novel-characters

安装命令安全性

通过

92

标准软件包或运行时安装路径

权限范围

失败

24

secrets or environment access, shell or command execution

仓库证据

通过

86

https://github.com/eternityspring/shuohao-skills/tree/main/skills/novel-characters

审查状态

信息

66

可用 AI 审查数据

Agent 验证结果

信息

54

暂未有 Agent 结果数据

检查项

安装与采用审查

8 通过 · 11 需审查

安装路径

92

通过

npx skills add eternityspring/shuohao-skills --skill novel-characters

仓库

88

通过

https://github.com/eternityspring/shuohao-skills/tree/main/skills/novel-characters

许可证

86

通过

Apache-2.0

维护

88

通过

距上次推送 2 个月

AI 审查

55

检查

The provided SKILL.md excerpt is truncated mid-Step-6, so the full end-to-end command set including validate/render was not fully visible in the review materials.

README/SKILL.md 完整度

86

通过

Usable description available

依赖风险

46

修复

command execution surface, credential or environment access

安装命令安全性

92

通过

标准软件包或运行时安装路径

权限范围

24

修复

secrets or environment access, shell or command execution

Star/Fork 活跃度

83

通过

2.6K 个 Star,333 个 Fork; 当前元数据中没有议题活跃度信息

采用度

88

通过

2.6K 个 GitHub Stars

警告

  • Dependency or permission surface needs review
  • Permission surface may require sandboxing
  • The provided SKILL.md excerpt is truncated mid-Step-6, so the full end-to-end command set including validate/render was not fully visible in the review materials.
  • Source text processed by the skill is untrusted and could contain prompt-injection-like instructions aimed at the LLM or subagents; the skill does not explicitly instruct agents to ignore instructions embedded in novel content.
  • Quality score needs review
  • Permission surface needs review: secrets or environment access, shell or command execution
  • Dependency/runtime risk: command execution surface, credential or environment access
  • Permission surface: secrets or environment access, shell or command execution

方法

本报告综合公开元数据、AI 审查输出、仓库活跃度、安装就绪度、OpenAgentSkill 事件、质量评分、信任检查和 Agent 安全门槛;它不是完整的源代码安全审计。