Skill 审计报告
bootstrap-project 审计报告.
Bootstrap a new project at a chosen graduation tier (t0 minimum, t1 decision-tracked, t2 full pattern language) following AI-Assisted Project Orchestration best practices. Use when starting a new software project, promoting an existing project to a higher tier, or converting an existing project for AI-assisted development.
OpenAgentSkill 信任评分
OpenAgentSkill 信任评分
Trust Score 帮助 Agent 在安装前判断一个 Skill 是否足以进入候选清单。
GitHub 采用度
失败30
14 个 GitHub Stars
Star/Fork 活跃度
失败32
14 个 Star,0 个 Fork; 当前元数据中没有议题活跃度信息
近期维护
通过100
距上次推送 1 天
许可证清晰度
通过86
MIT
README/SKILL.md 完整度
通过86
元数据包含足够的用法与工作流上下文
依赖与运行时风险
警告46
command execution surface, credential or environment access
安装可用性
通过92
npx skills add jrjsmrtn/project-orchestration-skills --skill bootstrap-project
安装命令安全性
通过92
标准软件包或运行时安装路径
权限范围
失败22
secrets or environment access, shell or command execution
仓库证据
通过86
https://github.com/jrjsmrtn/project-orchestration-skills/tree/main/skills/bootstrap-project
审查状态
信息66
可用 AI 审查数据
Agent 验证结果
信息54
暂未有 Agent 结果数据
检查项
安装与采用审查
安装路径
92
npx skills add jrjsmrtn/project-orchestration-skills --skill bootstrap-project
仓库
88
https://github.com/jrjsmrtn/project-orchestration-skills/tree/main/skills/bootstrap-project
许可证
86
MIT
维护
100
距上次推送 1 天
AI 审查
55
The provided SKILL.md excerpt is truncated; the full workflow, outputs, and limitations are not visible in the review material.
README/SKILL.md 完整度
86
Usable description available
依赖风险
46
command execution surface, credential or environment access
安装命令安全性
92
标准软件包或运行时安装路径
权限范围
22
secrets or environment access, shell or command execution
Star/Fork 活跃度
32
14 个 Star,0 个 Fork; 当前元数据中没有议题活跃度信息
采用度
42
14 个 GitHub Stars
Financial decision safety
58
Research-only use: do not treat output as financial advice or execute a position without human approval.
警告
- Dependency or permission surface needs review
- Permission surface may require sandboxing
- Financial research output is not financial advice; require human review before any live investment decision
- The provided SKILL.md excerpt is truncated; the full workflow, outputs, and limitations are not visible in the review material.
- No explicit safety boundaries are stated (e.g., confirmation before overwriting existing files, avoiding destructive commands).
- Low GitHub adoption signal
- Financial research output is not financial advice; require human review before any live investment decision.
- Quality score needs review
- Permission surface needs review: secrets or environment access, shell or command execution
- GitHub adoption: 14 GitHub stars
- Stars/forks activity: 14 stars, 0 forks; issue activity unavailable in current metadata
- Dependency/runtime risk: command execution surface, credential or environment access
方法
本报告综合公开元数据、AI 审查输出、仓库活跃度、安装就绪度、OpenAgentSkill 事件、质量评分、信任检查和 Agent 安全门槛;它不是完整的源代码安全审计。
对比相近选项