Skill 审计报告
dev-workflow 审计报告.
The complete development workflow for SkillHub contributors including local dev, staging validation, testing, and PR creation. Ensures agents follow the correct sequence of steps.
OpenAgentSkill 信任评分
OpenAgentSkill 信任评分
Trust Score 帮助 Agent 在安装前判断一个 Skill 是否足以进入候选清单。
GitHub 采用度
通过86
5.0K 个 GitHub Stars
Star/Fork 活跃度
通过83
5.0K 个 Star,823 个 Fork; 当前元数据中没有议题活跃度信息
近期维护
通过88
距上次推送 1 个月
许可证清晰度
通过86
Apache-2.0
README/SKILL.md 完整度
通过86
元数据包含足够的用法与工作流上下文
依赖与运行时风险
失败28
command execution surface, credential or environment access
安装可用性
通过92
npx skills add iflytek/skillhub --skill dev-workflow
安装命令安全性
通过92
标准软件包或运行时安装路径
权限范围
失败18
secrets or environment access, shell or command execution
仓库证据
通过86
https://github.com/iflytek/skillhub/tree/main/.agents/skills/dev-workflow
审查状态
信息66
可用 AI 审查数据
Agent 验证结果
信息54
暂未有 Agent 结果数据
检查项
安装与采用审查
安装路径
92
npx skills add iflytek/skillhub --skill dev-workflow
仓库
88
https://github.com/iflytek/skillhub/tree/main/.agents/skills/dev-workflow
许可证
86
Apache-2.0
维护
88
距上次推送 1 个月
AI 审查
55
The skill documents hardcoded staging/bootstrap credentials (admin/Admin@staging2026 and admin/ChangeMe!2026). These are likely local-only, but the SKILL.md does not explicitly warn agents to never use them outside the local/staging environment.
README/SKILL.md 完整度
86
Usable description available
依赖风险
28
command execution surface, credential or environment access
安装命令安全性
92
标准软件包或运行时安装路径
权限范围
18
secrets or environment access, shell or command execution
Star/Fork 活跃度
83
5.0K 个 Star,823 个 Fork; 当前元数据中没有议题活跃度信息
采用度
88
5.0K 个 GitHub Stars
警告
- Dependency or permission surface needs review
- Permission surface may require sandboxing
- The skill documents hardcoded staging/bootstrap credentials (admin/Admin@staging2026 and admin/ChangeMe!2026). These are likely local-only, but the SKILL.md does not explicitly warn agents to never use them outside the local/staging environment.
- Some Makefile commands are destructive (dev-all-reset, db-reset, staging-down) but there is no explicit confirmation or caution step before running them.
- Quality score needs review
- Permission surface needs review: secrets or environment access, shell or command execution
- Dependency/runtime risk: command execution surface, credential or environment access
- Permission surface: secrets or environment access, shell or command execution
方法
本报告综合公开元数据、AI 审查输出、仓库活跃度、安装就绪度、OpenAgentSkill 事件、质量评分、信任检查和 Agent 安全门槛;它不是完整的源代码安全审计。
对比相近选项
下一步可审计的相关 Skill
Code Review
Review a branch or diff against repository standards and the originating spec in two independent analysis passes.
169K Stars · 审计报告
Appsmith
Platform to build admin panels, internal tools, and dashboards. Integrates with 25+ databases and any API.
41K Stars · 审计报告
Implement
Implement work from an approved spec or ticket set, run focused and full tests, invoke code review, and commit the result to the current branch.
176K Stars · 审计报告