スキル監査レポート
Shai Hulud 2.0 Detector 監査レポート.
Detect npm packages compromised in the Shai-Hulud 2.0 supply chain attack (Nov 2025). Scans for 790+ malicious packages, suspicious scripts, TruffleHog activity, SHA1HULUD runners, and secrets exfiltration. GitHub Action with SARIF support.
OpenAgentSkill Trust Score
OpenAgentSkill Trust Score
Trust Score は、インストール前に候補に入れる安全性を Agent が判断する助けになります。
GitHub 採用度
情報62
GitHub スター 140
スター/フォーク活動
警告57
スター 140、フォーク 35; 現在のメタデータでは Issue 活動を利用できません
最近のメンテナンス
合格88
最終プッシュから 2 か月
ライセンスの明確さ
合格86
MIT
README/SKILL.md の完全性
合格90
メタデータには十分な利用・ワークフロー文脈があります
依存関係/ランタイムのリスク
情報72
認証情報または環境変数アクセス
インストール可否
合格92
npx skills add gensecaihq/Shai-Hulud-2.0-Detector
インストールコマンドの安全性
合格92
標準パッケージまたはランタイムのインストールパス
権限範囲
警告60
secrets or environment access, filesystem or document access
リポジトリ根拠
合格86
https://github.com/gensecaihq/Shai-Hulud-2.0-Detector
レビュー状況
合格88
AI レビューデータを利用できます
Agent 検証結果
情報54
Agent の成果データはまだありません
チェック
インストールと採用のレビュー
インストール経路
92
npx skills add gensecaihq/Shai-Hulud-2.0-Detector
リポジトリ
88
https://github.com/gensecaihq/Shai-Hulud-2.0-Detector
ライセンス
86
MIT
メンテナンス
88
最終プッシュから 2 か月
AI レビュー
88
Approved with no listed issues
README/SKILL.md の完全性
90
Usable description available
依存関係リスク
72
認証情報または環境変数アクセス
インストールコマンドの安全性
92
標準パッケージまたはランタイムのインストールパス
権限範囲
60
secrets or environment access, filesystem or document access
スター/フォーク活動
57
スター 140、フォーク 35; 現在のメタデータでは Issue 活動を利用できません
採用度
68
GitHub スター 140
Financial decision safety
58
Research-only use: do not treat output as financial advice or execute a position without human approval.
警告
- Permission surface may require sandboxing
- Financial research output is not financial advice; require human review before any live investment decision
- Financial research output is not financial advice; require human review before any live investment decision.
- Quality score needs review
- Permission surface needs review: secrets or environment access, filesystem or document access
- Stars/forks activity: 140 stars, 35 forks; issue activity unavailable in current metadata
- Permission surface: secrets or environment access, filesystem or document access
方法
このレポートは公開メタデータ、AI レビュー、リポジトリの鮮度、インストール準備、OpenAgentSkill イベント、品質スコア、信頼チェック、Agent セーフティゲートを統合します。完全なソースコード監査ではありません。
近い選択肢を比較
次に監査する関連スキル
Wazuh
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
16K スター · 監査レポート
Maigret
🕵️♂️ Collect a dossier on a person by username from 3000+ sites
33K スター · 監査レポート
Nuclei
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
29K スター · 監査レポート