Skill 审计报告
github-ci 审计报告.
Write and maintain GitHub Actions CI workflows, including workflow YAML structure, triggers, runners, matrix builds, caching, testing patterns, and secrets management. Use when working with .github/workflows, GitHub Actions, CI pipelines, workflow dispatch, or action configuration.
OpenAgentSkill 信任评分
OpenAgentSkill 信任评分
Trust Score 帮助 Agent 在安装前判断一个 Skill 是否足以进入候选清单。
GitHub 采用度
失败30
14 个 GitHub Stars
Star/Fork 活跃度
失败32
14 个 Star,1 个 Fork; 当前元数据中没有议题活跃度信息
近期维护
通过88
距上次推送 2 个月
许可证清晰度
通过86
MIT
README/SKILL.md 完整度
信息76
公开元数据需要更完整的 README/SKILL.md 上下文
依赖与运行时风险
警告44
command execution surface, credential or environment access
安装可用性
通过92
npx skills add greedychipmunk/agent-skills --skill github-ci
安装命令安全性
通过92
标准软件包或运行时安装路径
权限范围
失败36
secrets or environment access, shell or command execution
仓库证据
通过86
https://github.com/greedychipmunk/agent-skills/tree/main/github-ci
审查状态
信息66
可用 AI 审查数据
Agent 验证结果
信息54
暂未有 Agent 结果数据
检查项
安装与采用审查
安装路径
92
npx skills add greedychipmunk/agent-skills --skill github-ci
仓库
88
https://github.com/greedychipmunk/agent-skills/tree/main/github-ci
许可证
86
MIT
维护
88
距上次推送 2 个月
AI 审查
55
Resource files reference deprecated GitHub runner versions (e.g., ubuntu-18.04, macos-12) which are no longer available or have limited support.
README/SKILL.md 完整度
84
Usable description available
依赖风险
44
command execution surface, credential or environment access
安装命令安全性
92
标准软件包或运行时安装路径
权限范围
36
secrets or environment access, shell or command execution
Star/Fork 活跃度
32
14 个 Star,1 个 Fork; 当前元数据中没有议题活跃度信息
采用度
42
14 个 GitHub Stars
警告
- Dependency or permission surface needs review
- Permission surface may require sandboxing
- Resource files reference deprecated GitHub runner versions (e.g., ubuntu-18.04, macos-12) which are no longer available or have limited support.
- SKILL.md lacks an explicit 'Limitations' section, though the content implies safe boundaries (e.g., warnings about pull_request_target).
- Low GitHub adoption signal
- Quality score needs review
- Permission surface needs review: secrets or environment access, shell or command execution
- GitHub adoption: 14 GitHub stars
- Stars/forks activity: 14 stars, 1 forks; issue activity unavailable in current metadata
- Dependency/runtime risk: command execution surface, credential or environment access
- Permission surface: secrets or environment access, shell or command execution
方法
本报告综合公开元数据、AI 审查输出、仓库活跃度、安装就绪度、OpenAgentSkill 事件、质量评分、信任检查和 Agent 安全门槛;它不是完整的源代码安全审计。
对比相近选项
下一步可审计的相关 Skill
Wazuh
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
16K Stars · 审计报告
Maigret
🕵️♂️ Collect a dossier on a person by username from 3000+ sites
33K Stars · 审计报告
Nuclei
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
29K Stars · 审计报告