Vetix
Vetix — Automated scanning, identification, and assessment of SKILL security risks.
供給アセットの概要
コーディングと開発 Agent
コードレビュー、リポジトリ分析、テスト、CI、GitHub、DevOps、開発ワークフロー向けのスキルです。
シナリオ
コーディング Agent
リポジトリを理解し、コードを編集し、プルリクエストをレビューできるコーディング Agent が必要です。
Agent 適合
Claude Code + CLI + Codex
Codex、Claude Code、Cursor、CLI、またはカスタム Agent に対応します。
インストール
準備完了
npx skills add HuTa0kj/vetix
メンテナンス
新しい
最終プッシュから 20 日
リスク
要レビュー
Dependency or permission surface needs review
GitHub 品質
62
74/100 品質 · 74/100 信頼
対象タグ
レビュー注記
Dependency or permission surface needs review · Permission surface may require sandboxing
Agent 導入スコアカード
信頼、監査、インストール準備状況を一目で確認
公開リポジトリのメタデータ、OpenAgentSkill のレビューシグナル、保守の鮮度、インストール準備状況を組み合わせたスコアです。候補選定の目安であり、人によるレビューの代替ではありません。
品質
強い本番ワークフローの候補に値する堅実な選択肢です。
信頼
サンドボックス限定信頼シグナルが不足または混在する有用な候補です。結果ループがタスク適合を示すまで、隔離されたワークスペースで使用してください。
監査
要レビューインストール準備、安全メタデータ、保守、採用リスクの機械可読なレビュー。
OpenAgentSkill Trust Score v5
インストール前に人のレビュー
実作業で使う前に、サンドボックスでのみ実行し、近い代替と比較してください。
スター
GitHub スター 62
リポジトリ活動
スター 62、フォーク 1
メンテナンス
最終プッシュから 20 日
ライセンス
MIT
インストール
npx skills add HuTa0kj/vetix
インストール安全性
標準パッケージまたはランタイムのインストールパス
権限範囲
secrets or environment access, shell or command execution
Agent の成果
Agent の成果データはまだありません
ドキュメント
README/SKILL.md の文脈が十分です
リスク概要
本番前にレビュー
- Quality score needs review
- Permission surface needs review: secrets or environment access, shell or command execution
- GitHub adoption: 62 GitHub stars
- Stars/forks activity: 62 stars, 1 forks; issue activity unavailable in current metadata
インストール準備状況
インストールパスを利用可能
- インストールパスを利用できます
- リポジトリの根拠を利用できます
- ライセンスが明示されています
- Agent-Proven の成果エビデンスはまだありません
Agent 可読メタデータ
このスキルの機械可読な判断データ。
このブロックまたは埋め込み JSON を使い、Agent がこのスキルをインストールすべきか、代替を選ぶべきか、先に人のレビューを求めるべきかを判断できます。
適したタスク
- Local desktop ワークフロー
- Claude Code チーム
- builders willing to evaluate younger projects
- Navigate local resources
適した Agent
インストール判断
- コマンド
- npx skills add HuTa0kj/vetix
- ポリシー
- ブロック
- 人によるレビュー
- はい
信頼とリスク
- 信頼
- 66/100
- 監査
- 81/100
- リスクレベル
- 要レビュー
成果ループ
- エンドポイント
- /api/agent/outcome
- イベント ID
- resolve
- 成果
- 5
使わない場合
- ベンダー提供の SLA が必要なチーム
- 内部セキュリティレビューのない高コンプライアンス環境
- 現在のメタデータに重大なリスクシグナルはありません
- 高リスク権限のヒント: Shell or command execution, Secrets or environment access
- Dependency or permission surface needs review
Agent セーフティ v2
41/100 · 自動インストールを避ける
This skill should not be selected by an agent without explicit human security review.
Do not auto-install. Inspect the source, dependencies, and permission surface first.
高
Shell またはコマンド実行
Skill メタデータに端末、CLI、Shell、サブプロセス、またはコマンド実行のワークフローが含まれます。
中
ネットワークアクセス
Skill はリモートページ、API、リポジトリ、外部サービスにアクセスする可能性があります。
中
ファイルシステムアクセス
Skill はプロジェクトファイル、ドキュメント、生成物、ローカルワークスペース状態を読み書きする可能性があります。
高
Secrets or environment access
Skill metadata references credentials, tokens, environment variables, or secret-bearing workflows.
- 高リスク権限のヒント: Shell or command execution, Secrets or environment access
- Dependency or permission surface needs review
インストール先
Agent ワークフローにこのスキルをインストール
公開インストールエンドポイントからコマンド、安全チェックリスト、対象プロンプト、正規リンクを取得します。
OpenAgentSkill CLI
Resolve policy, run the source installer safely, and report a verified install receipt.
$ npx --yes https://github.com/Leon-Drq/openagentskill/releases/download/cli-v0.2.1/openagentskill-0.2.1.tgz install huta0kj-vetixAgent 解決プラン
インストール前に Agent に適合性を検証させます。
Resolve API は第一候補、代替、安全ポリシー、監査メモ、インストール先、Agent がそのまま使えるプロンプトを返します。
JSON を開く
/api/agent/resolve?task=Use%20Vetix%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Resolve テキスト
/api/agent/resolve?task=Use%20Vetix%20for%20an%20agent%20workflow&agent=codex&max_risk=medium&format=text
インストール引き継ぎ
/api/skills/huta0kj-vetix/install
Agent が確認すべきこと
- Resolve API でタスク適合と代替を確認。
- 監査・信頼スコアと安全ポリシーの警告を確認。
- Codex、Claude Code、Cursor、CLI のインストール先互換性を確認。
プロンプトをコピー
Task: Use Vetix in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20Vetix%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/huta0kj-vetix/install
Install command: npx skills add HuTa0kj/vetix
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.Agent 引き継ぎ
別のディレクトリではなく、インストール経路を Agent に渡します。
公開インストールエンドポイントからコマンド、安全チェックリスト、対象プロンプト、正規リンクを取得します。
インストール引き継ぎ
/api/skills/huta0kj-vetix/install
LLM テキスト形式
/api/skills/huta0kj-vetix/install?format=text
代替を探す
/api/skills/search?q=Vetix&limit=3
Agent プロンプト
Use Vetix for this task. Review https://www.openagentskill.com/api/skills/huta0kj-vetix/install, then install with: npx skills add HuTa0kj/vetixRegistry メタデータ
自動スキル選択用の Agent 可読プロファイル。
Registry API 経由で判断、信頼、監査、ユースケース、インストールのシグナルを提供し、UI をスクレイピングせずに Agent が順位付けできます。
Agent 判断パネル
Companion skill for Local desktop
本番採用前にこのスキルを候補化し、近い代替と比較してください。
スタック内の役割
補助スキル
主な適合
Local desktop
信頼ラベル
有力候補
インストールパス
コマンド準備済み
使う場面
- Local desktop ワークフロー
- Claude Code チーム
- builders willing to evaluate younger projects
根拠
- 最近のリポジトリ活動
- インストールコマンドまたは GitHub リポジトリが利用可能
- 品質プロファイル 74/100
- OpenAgentSkill エンゲージメント 3 件
先にレビュー
- 現在のメタデータに重大なリスクシグナルはありません
実装パス
- 1サンドボックスの Agent にインストールし、Local desktop タスクを一度最初から最後まで実行します。
- 2Compare output quality, latency, and failure behavior against at least one alternative.
- 3Promote it into production only after reviewing repository permissions, license, and maintenance signals.
信頼プロファイル
サンドボックス限定
信頼シグナルが不足または混在する有用な候補です。結果ループがタスク適合を示すまで、隔離されたワークスペースで使用してください。
GitHub 採用度
確認GitHub スター 62
スター/フォーク活動
確認スター 62、フォーク 1; 現在のメタデータでは Issue 活動を利用できません
最近のメンテナンス
合格最終プッシュから 20 日
ライセンスの明確さ
合格MIT
良いシグナル
- AI レビュー承認済み
- インストールパスを利用できます
- リポジトリの根拠を利用できます
- 最近保守されたリポジトリ
- インストールコマンドに明確な高リスクパターンはありません
- 成果ループは準備済みですが、最初の実行が必要です
インストール前にレビュー
- Quality score needs review
- Permission surface needs review: secrets or environment access, shell or command execution
- GitHub adoption: 62 GitHub stars
- Stars/forks activity: 62 stars, 1 forks; issue activity unavailable in current metadata
- Dependency/runtime risk: command execution surface, credential or environment access
- Permission surface: secrets or environment access, shell or command execution
- 実際の Agent 成果レポートはまだありません
- 無人インストールの前に人によるレビューが必要です
推奨アクション
実作業で使う前に、サンドボックスでのみ実行し、近い代替と比較してください。
品質プロファイル
強い Agent ワークフロー向けの候補
本番ワークフローの候補に値する堅実な選択肢です。
ワークフロー適合
このスキルを使うシナリオ
Operate local tools
Local desktop
I need my agent to operate local files and desktop apps in a repeatable workflow.
Build and ship code
Coding agents
I need a coding agent that can understand a repository, edit code, and review pull requests.
Investigate faster
Research agents
I need my agent to research a topic, compare sources, and produce a concise report.
ワークフロー適合
完全なワークフローに追加
Find, compare, and synthesize
Research report agent
A workflow for agents that gather sources, compare claims, summarize long material, and draft useful research briefs.
Inspect, patch, and verify code
Coding review agent
A workflow for software agents that inspect repositories, review pull requests, generate tests, and turn findings into shippable patches.
Turn skills into distribution
Content growth agent
A workflow for turning newly indexed skills into SEO briefs, social drafts, comparison pages, and reusable publishing workflows.
代替候補
インストール前に比較
このタスクに適する可能性のある類似スキル。
Khazix Skills
A collection of practical, installable AI agent skills for disk cleanup, AI news retrieval, and project management, following the Agent Skills standard.
Awesome Claude Skills
A curated list of resources and tools for enhancing Claude AI workflows.
Claude Scientific Skills
A comprehensive collection of ready-to-use scientific and research skills for AI agents.
概要
# Vetix
An LLM-agent-based scanner for [SKILL](https://docs.claude.com/en/docs/claude-code/skills) directories. Vetix pairs deterministic plugin rules with an LLM behavioral analyst so that both obvious indicators of compromise and subtle, obfuscated attack chains get caught in a single pass.
[中文文档](./README_CN.md)
## Features
- **Plugin-based static scanning** — rules catch deterministic security risks. - **LLM cross-validation** — every plugin hit is re-judged against the real file content by an LLM, so high-recall rules don't drown the final report. - **Behavioral analysis agent** — inside a virtual filesystem, traces the full chain "instruction → tool call → host impact" to uncover risks the rules miss: disguised commands, Base64 payloads, remote code loading, prompt injection, credential theft, persistence, and more. - **Defense-in-depth sandbox** — virtual filesystems, explicit read allow-lists, and a blanket write deny isolate the real host. - **LangSmith tracing** — every agent run is observable end-to-end.
## Detection Categories
The behavioral analysis agent classifies risks into 10 categories:
| Category | Description | |---|---| | Remote Execution | Remote code loading and execution, including `curl\|sh`, `wget\|bash`, and unofficial package installations | | Data Exfiltration | Unauthorized collection and transmission of sensitive data to external addresses | | Persistence | Backdoor mechanisms that survive reboots — crontab injection, SSH key planting, startup item modification | | Destructive | Actions that corrupt data, delete files, or otherwise damage the host system | | Obfuscation | Deliberate concealment of malicious payloads via Base64/Hex encoding, blank-line hiding, or disguised commands | | Command Injection | Injection of arbitrary shell commands through unsanitized input or instruction manipulation | | Privilege Escalation | Attempts to gain elevated permissions beyond what the skill's stated function requires | | Sensitive File Acc
プラットフォーム互換性
技術詳細
- バージョン
- 1.0.0
- ライセンス
- MIT
- 最終更新
- 2026年8月18日
- 公開日
- 2026年8月1日
フレームワークとツール
判断の要約
補助スキル
最近のリポジトリ活動
Agent 実証エビデンス
Agent 実証エビデンス
Resolve、レビュー、インストール、限定実行後の成果レポート。
- 成功率
- —
- 直近の失敗
- —
- 成果
- 0
- 出力品質
- —
- 失敗
- 0
- 非該当
- 0
- インストール数
- 0
- リスクによりブロック
- 0
- 設定が必要
- 0
- 本番
- 0
Agent の実行結果はまだありません。最初の実行では /api/agent/outcome を通じて成功、設定要件、リスクによるブロック、失敗、非該当を報告できます。
成長ループ
共有キット
Vetix 用のシナリオベース草案です。X へ手動投稿できます。
For a real agent workflow, this is a skill worth shortlisting before another blank prompt. Vetix: Vetix — Automated scanning, identification, and assessment of SKILL security risks. 62 stars https://www.openagentskill.com/skills/huta0kj-vetix?ref=x
任意:インストールコマンド付きの返信
Listing + install path for Vetix: https://www.openagentskill.com/skills/huta0kj-vetix?ref=x Install: npx skills add HuTa0kj/vetix
掲載元
コミュニティにより登録
この掲載は公開ソースから登録されており、メンテナー申請が承認されるまで公式として表示されません。
- 作成者
- HuTa0kj
- インデックス作成者
- OpenAgentSkill コミュニティインデックス
帰属は公開リポジトリまたは作成者プロフィールにリンクされています。作成者は掲載を申請して所有権シグナルを更新できます。
このスキルを申請所有者の申請
このスキル掲載を申請
この コミュニティにより登録 掲載は HuTa0kj に帰属していますが、まだ公式として表示されていません。申請すると、確認済み所有者シグナルが追加され、今後の公開、インストール、監査更新の信頼性が高まります。
クリエイター被リンクキット
README にエビデンスバッジを追加
開発者がリポジトリを評価する場所で、正規掲載、現在の信頼・監査シグナル、実際の Agent-Proven エビデンスを表示します。
[](https://www.openagentskill.com/skills/huta0kj-vetix)
[](https://www.openagentskill.com/skills/huta0kj-vetix)
[](https://www.openagentskill.com/skills/huta0kj-vetix/audit)
[](https://www.openagentskill.com/skills/huta0kj-vetix)作者
HuTa0kj
@huta0kj
プラットフォーム適合
健全性シグナル
- GitHub スター
- 62
- 品質スコア
- 45/100
- 最終 GitHub プッシュ
- 2026年8月3日
- フレームワークのヒント
- 1
- OpenAgentSkill 閲覧数
- 3
- インストールコピー数
- 0
- 外部クリック
- 0
コミュニティシグナル
このスキルが Agent ワークフローに役立つかを共有してください。集約されたフィードバックがランキングを改善します。
信頼と安全性
サンドボックス限定
- GitHub 採用度GitHub スター 62確認
- スター/フォーク活動スター 62、フォーク 1; 現在のメタデータでは Issue 活動を利用できません確認
- 最近のメンテナンス最終プッシュから 20 日合格
- ライセンスの明確さMIT合格
- README/SKILL.md の完全性メタデータには十分な利用・ワークフロー文脈があります合格
- 依存関係/ランタイムのリスクcommand execution surface, credential or environment access確認
関連スキル
Khazix Skills
A collection of practical, installable AI agent skills for disk cleanup, AI news retrieval, and project management, following the Agent Skills standard.
19.6K スターAwesome Claude Skills
A curated list of resources and tools for enhancing Claude AI workflows.
65.9K スターClaude Scientific Skills
A comprehensive collection of ready-to-use scientific and research skills for AI agents.
31.2K スター