Skill 审计报告

ai-assist-prototype 审计报告.

Build self-contained, double-click-to-open HTML prototypes so the user can vet an interface before it gets built. One file holds several structurally different variants of a page, app screen, component, flow, or terminal/TUI layout (rendered in-browser), plus a draggable Design Deck for flipping between variants, tuning fonts, colors, spacing, shape, motion and 'feel' with live dials, trying vibe presets, checking viewport sizes and light/dark, pinning comments on elements, and an 'Export to LLM' button that copies the chosen variant and every dial value as a handoff block to paste back to the agent. Use this whenever the user wants to prototype, mock up, wireframe, explore options for, or sanity-check a UI (landing page, dashboard, settings page, onboarding, form, mobile screen, component, CLI/TUI layout), or says 'what should this look like', 'show me a few options', 'let me tweak it before we build', 'vet the design'. Also use it when the user pastes a block starting with 'AI-ASSIST

已阻止 · 阻止需审查生成于 2026年8月22日启发式元数据审计
69
审计
59
信任
61
质量
62
安全性
100
维护
92
安装

OpenAgentSkill 信任评分

59
人工审查

OpenAgentSkill 信任评分

Trust Score 帮助 Agent 在安装前判断一个 Skill 是否足以进入候选清单。

GitHub 采用度

警告

48

88 个 GitHub Stars

Star/Fork 活跃度

警告

48

88 个 Star,12 个 Fork; 当前元数据中没有议题活跃度信息

近期维护

通过

100

今天有推送

许可证清晰度

警告

42

未知

README/SKILL.md 完整度

通过

86

元数据包含足够的用法与工作流上下文

依赖与运行时风险

失败

36

command execution surface, credential or environment access

安装可用性

通过

92

npx skills add jparkerweb/ai-assist-skills --skill ai-assist-prototype

安装命令安全性

通过

92

标准软件包或运行时安装路径

权限范围

失败

18

secrets or environment access, shell or command execution

仓库证据

通过

86

https://github.com/jparkerweb/ai-assist-skills/tree/main/skills/ai-assist-prototype

审查状态

信息

66

可用 AI 审查数据

Agent 验证结果

信息

54

暂未有 Agent 结果数据

检查项

安装与采用审查

5 通过 · 18 需审查

安装路径

92

通过

npx skills add jparkerweb/ai-assist-skills --skill ai-assist-prototype

仓库

88

通过

https://github.com/jparkerweb/ai-assist-skills/tree/main/skills/ai-assist-prototype

许可证

45

检查

未知

维护

100

通过

今天有推送

AI 审查

55

检查

Repository license is unknown (GitHub detected 'Unknown'), which creates legal ambiguity for users and contributors.

README/SKILL.md 完整度

86

通过

Usable description available

依赖风险

36

修复

command execution surface, credential or environment access

安装命令安全性

92

通过

标准软件包或运行时安装路径

权限范围

18

修复

secrets or environment access, shell or command execution

Star/Fork 活跃度

48

修复

88 个 Star,12 个 Fork; 当前元数据中没有议题活跃度信息

采用度

68

信息

88 个 GitHub Stars

Financial decision safety

58

检查

Research-only use: do not treat output as financial advice or execute a position without human approval.

警告

  • 许可证不清晰
  • Dependency or permission surface needs review
  • Permission surface may require sandboxing
  • Financial research output is not financial advice; require human review before any live investment decision
  • Repository license is unknown (GitHub detected 'Unknown'), which creates legal ambiguity for users and contributors.
  • The skill relies on a local build script (scripts/build-prototype.mjs) that is not reviewed here; its behavior should be audited to ensure it does not introduce security risks (e.g., path traversal, arbitrary code execution).
  • Financial research output is not financial advice; require human review before any live investment decision.
  • Quality score needs review
  • Permission surface needs review: secrets or environment access, shell or command execution
  • GitHub adoption: 88 GitHub stars
  • Stars/forks activity: 88 stars, 12 forks; issue activity unavailable in current metadata
  • License clarity: Unknown

方法

本报告综合公开元数据、AI 审查输出、仓库活跃度、安装就绪度、OpenAgentSkill 事件、质量评分、信任检查和 Agent 安全门槛;它不是完整的源代码安全审计。

对比相近选项

下一步可审计的相关 Skill