Skill audit report
安全专家。专注于应用安全、威胁建模、安全合规和数据保护。提供安全审查、漏洞扫描、安全配置和合规检查。用于构建安全可靠的应用系统。
OpenAgentSkill Trust Score
The Trust Score helps an agent decide whether a skill is safe enough to shortlist before installation.
GitHub adoption
WARN48
48 GitHub stars
Stars/forks activity
WARN43
48 stars, 7 forks; issue activity unavailable in current metadata
Recent maintenance
PASS100
16d since push
License clarity
PASS86
MIT
README/SKILL.md completeness
INFO70
Public metadata needs stronger README/SKILL.md context
Dependency/runtime risk
INFO64
credential or environment access, network or browser surface
Install availability
PASS92
npx skills add huangwb8/skills --skill security-specialist
Install command safety
PASS92
standard package or runtime install path
Permission surface
WARN60
secrets or environment access, network or browser access
Repository evidence
PASS86
https://github.com/huangwb8/skills/tree/main/skills/alpha/awesome-code/agents/security-specialist
Review status
INFO66
AI review data available
Agent Proven outcomes
INFO54
No agent outcome data yet
Checks
Install path
92
npx skills add huangwb8/skills --skill security-specialist
Repository
88
https://github.com/huangwb8/skills/tree/main/skills/alpha/awesome-code/agents/security-specialist
License
86
MIT
Maintenance
100
16d since push
AI review
55
SKILL.md is written entirely in Chinese; non-Chinese users may need translation, but this is not a functional defect.
README/SKILL.md completeness
84
Usable description available
Dependency risk
64
credential or environment access, network or browser surface
Install command safety
92
standard package or runtime install path
Permission surface
60
secrets or environment access, network or browser access
Stars/forks activity
43
48 stars, 7 forks; issue activity unavailable in current metadata
Adoption
42
48 GitHub stars
Warnings
Method
This report combines public metadata, AI review output, repository freshness, install readiness, OpenAgentSkill events, quality scoring, trust checks, and the agent safety gate. It is not a full source-code security review.