Skill 审计报告

open-map-stack 审计报告.

Use textual agent instructions for GIS and geospatial work: source discovery and provenance, vector/raster/point-cloud pipelines, CRS and metric analysis, spatial SQL, routing and isochrones, QGIS projects, tile generation, and web maps. Use advanced tools and formats such as OSM, Overture, STAC, Sentinel/Landsat, LiDAR, GeoPackage, GeoParquet, COG, PMTiles, WMS/WFS/OGC APIs, GDAL, GeoPandas, DuckDB Spatial, PostGIS, QGIS, MapLibre, and Estonian spatial data including ETAK and EPSG:3301. Open-first, with hosted services when scale or reliability requires them. Do not use for casual map references, simple place lookups, or ordinary travel directions without analytical GIS work.

实验性 · 审查需审查生成于 2026年10月11日启发式元数据审计
71
审计
63
信任
62
质量
74
安全性
88
维护
92
安装

OpenAgentSkill 信任评分

63
人工审查

OpenAgentSkill 信任评分

Trust Score 帮助 Agent 在安装前判断一个 Skill 是否足以进入候选清单。

GitHub 采用度

警告

48

68 个 GitHub Stars

Star/Fork 活跃度

警告

48

68 个 Star,11 个 Fork; 当前元数据中没有议题活跃度信息

近期维护

通过

88

距上次推送 1 个月

许可证清晰度

通过

86

MIT

README/SKILL.md 完整度

通过

86

元数据包含足够的用法与工作流上下文

依赖与运行时风险

警告

56

command execution surface, network or browser surface

安装可用性

通过

92

npx skills add jaakla/openmapstack --skill open-map-stack

安装命令安全性

通过

92

标准软件包或运行时安装路径

权限范围

警告

50

shell or command execution, network or browser access

仓库证据

通过

86

https://github.com/jaakla/openmapstack/blob/main/SKILL.md

审查状态

信息

66

可用 AI 审查数据

Agent 验证结果

信息

54

暂未有 Agent 结果数据

检查项

安装与采用审查

6 通过 · 15 需审查

安装路径

92

通过

npx skills add jaakla/openmapstack --skill open-map-stack

仓库

88

通过

https://github.com/jaakla/openmapstack/blob/main/SKILL.md

许可证

86

通过

MIT

维护

88

通过

距上次推送 1 个月

AI 审查

55

检查

SKILL.md does not include explicit setup/installation requirements (e.g., installing the openmapstack CLI, GDAL, PostGIS, DuckDB Spatial), so an agent may not know how to bootstrap the environment.

README/SKILL.md 完整度

86

通过

Usable description available

依赖风险

56

修复

command execution surface, network or browser surface

安装命令安全性

92

通过

标准软件包或运行时安装路径

权限范围

50

修复

shell or command execution, network or browser access

Star/Fork 活跃度

48

修复

68 个 Star,11 个 Fork; 当前元数据中没有议题活跃度信息

采用度

68

信息

68 个 GitHub Stars

警告

  • Dependency or permission surface needs review
  • Permission surface may require sandboxing
  • SKILL.md does not include explicit setup/installation requirements (e.g., installing the openmapstack CLI, GDAL, PostGIS, DuckDB Spatial), so an agent may not know how to bootstrap the environment.
  • The skill relies on references/project-spec.md as mandatory reading, but that file is not present in the submitted skill bundle; it needs to be included or the agent needs clear instructions to clone/open the repository.
  • Security guidance for untrusted geodata is implicit rather than explicit; downloaded features and external API responses could contain prompt-injection style content, and API credentials should be handled through environment variables or secret stores.
  • Quality score needs review
  • Permission surface needs review: shell or command execution, network or browser access
  • GitHub adoption: 68 GitHub stars
  • Stars/forks activity: 68 stars, 11 forks; issue activity unavailable in current metadata
  • Dependency/runtime risk: command execution surface, network or browser surface
  • Permission surface: shell or command execution, network or browser access

方法

本报告综合公开元数据、AI 审查输出、仓库活跃度、安装就绪度、OpenAgentSkill 事件、质量评分、信任检查和 Agent 安全门槛;它不是完整的源代码安全审计。

对比相近选项

下一步可审计的相关 Skill