Évaluation avant installation
agentfootprint Rapport d’évaluation.
Une décision d’installation lisible par machine pour les Agents : adéquation à la tâche, Trust Score, Audit Score, sécurité d’installation, surface de permissions et plan de validation concret avant de toucher l’espace de travail.
do not auto install
Audit score: Risky
Gates requis
Vérifications qu’un Agent doit réussir avant installation
Adéquation à la tâche
94
Task wording matches this skill metadata.
- Evaluate agentfootprint before installing it in an agent workflow
- Design et création
- RAG and knowledge workflows; Claude Code teams; builders willing to evaluate younger projects
Chemin d’installation
92
Install handoff is available.
- npx skills add footprintjs/agentfootprint --skill agentfootprint
Sécurité de la commande d’installation
92
Chemin d’installation standard de package ou runtime
- npx skills add footprintjs/agentfootprint --skill agentfootprint
Score de confiance
63
Potentially useful, but at least one trust signal needs human inspection.
- Revue manuelle
- 20 stars GitHub
- MIT
Score d’audit
71
Risqué
- Dependency or permission surface needs review
Contrôle de sécurité Agent
23
This skill should not be selected by an agent without explicit human security review.
- Do not auto-install. Inspect the source, dependencies, and permission surface first.
- Audit risk exceeds the requested agent policy
Clarté de licence
86
MIT
- MIT
Surface de permissions
24
secrets or environment access, shell or command execution
- Shell or command execution: high
- Browser automation: medium
- Network access: medium
Plan de validation
Ce que l’Agent doit faire ensuite
- 1Inspect repository, README/SKILL.md, license, and recent commits before production use.
- 2Install in an isolated workspace or sandbox with no production secrets available.
- 3Run the smallest representative task and record files touched, commands run, network access, and outputs.
- 4Compare the selected skill against at least one alternative when the eval status is review or failed.
- 5Promote only after the agent reports a successful verification result and unresolved warnings are accepted.
Ne pas utiliser quand
Conditions exigeant une autre skill
- Équipes qui nécessitent un SLA soutenu par le fournisseur
- production agents without a repository review
- Low GitHub adoption signal
- The SKILL.md excerpt is truncated, but the provided content is comprehensive and well-structured.
- Audit risk risky exceeds max_risk=medium
- Indices de permissions à haut risque : Shell or command execution, Secrets or environment access
Vérifications complémentaires
Signaux de confiance derrière la décision
Complétude README/SKILL.md
Validé86
Les métadonnées incluent suffisamment de contexte d’usage et de workflow
Maintenance récente
Validé100
2 jours depuis le dernier push
Alternatives disponibles
Validé82
Alternative skills are available for comparison.