harden-gitlab-ci

レビュー · 58
Registry に収録

Harden GitLab CI/CD pipelines for supply-chain security — SHA-pin `include:` and CI/CD components, scope the `CI_JOB_TOKEN` allowlist, protect and mask variables, pin job image digests, and use `id_tokens`/OIDC instead of long-lived secrets. Use when adding or auditing a `.gitlab

Verified installs0
スター14
バージョン1.0.0
品質58/100 · 有望
信頼58/100 · Do not auto-install
監査72/100 · 要レビュー

供給アセットの概要

コーディングと開発 Agent

コードレビュー、リポジトリ分析、テスト、CI、GitHub、DevOps、開発ワークフロー向けのスキルです。

カテゴリを見る

シナリオ

GitHub automation

I need my agent to triage GitHub issues, review pull requests, and summarize repository changes.

Agent 適合

Claude Code + CLI + Codex

Codex、Claude Code、Cursor、CLI、またはカスタム Agent に対応します。

インストール

準備完了

npx skills add jrjsmrtn/project-orchestration-skills --skill harden-gitlab-ci

メンテナンス

新しい

最終プッシュから 1 日

リスク

要レビュー

Dependency or permission surface needs review

GitHub 品質

14

58/100 品質 · 66/100 信頼

対象タグ

コーディングGitHub automationセキュリティagent-skill

レビュー注記

Dependency or permission surface needs review · Permission surface may require sandboxing

Agent 導入スコアカード

信頼、監査、インストール準備状況を一目で確認

公開リポジトリのメタデータ、OpenAgentSkill のレビューシグナル、保守の鮮度、インストール準備状況を組み合わせたスコアです。候補選定の目安であり、人によるレビューの代替ではありません。

品質

有望
58

有用な候補ですが、採用前に代替と比較してください。

信頼

Do not auto-install
58

Trust Score v5 found insufficient evidence for agent installation. Treat this as discovery material, not an executable recommendation.

監査

要レビュー
72

インストール準備、安全メタデータ、保守、採用リスクの機械可読なレビュー。

OpenAgentSkill Trust Score v5

インストール前に人のレビュー

Choose a stronger alternative or inspect the source manually before any install attempt.

CodexClaude CodeCursorOpenAgentSkill CLI

スター

GitHub スター 14

リポジトリ活動

スター 14、フォーク 0

メンテナンス

最終プッシュから 1 日

ライセンス

MIT

インストール

npx skills add jrjsmrtn/project-orchestration-skills --skill harden-gitlab-ci

インストール安全性

標準パッケージまたはランタイムのインストールパス

権限範囲

secrets or environment access, shell or command execution

Agent の成果

Agent の成果データはまだありません

ドキュメント

README/SKILL.md の文脈が十分です

リスク概要

本番前にレビュー

  • Low GitHub adoption signal
  • Quality score needs review
  • Permission surface needs review: secrets or environment access, shell or command execution
  • GitHub adoption: 14 GitHub stars

インストール準備状況

インストールパスを利用可能

  • インストールパスを利用できます
  • リポジトリの根拠を利用できます
  • ライセンスが明示されています
  • Agent-Proven の成果エビデンスはまだありません

Agent 可読メタデータ

このスキルの機械可読な判断データ。

このブロックまたは埋め込み JSON を使い、Agent がこのスキルをインストールすべきか、代替を選ぶべきか、先に人のレビューを求めるべきかを判断できます。

JSON を開く

適したタスク

  • GitHub automation ワークフロー
  • Claude Code チーム
  • builders willing to evaluate younger projects
  • Inspect repository metadata

適した Agent

CodexClaude CodeCursorOpenAgentSkill CLICLI

インストール判断

コマンド
npx skills add jrjsmrtn/project-orchestration-skills --skill harden-gitlab-ci
ポリシー
ブロック
人によるレビュー
はい

信頼とリスク

信頼
58/100
監査
72/100
リスクレベル
要レビュー

成果ループ

エンドポイント
/api/agent/outcome
イベント ID
resolve
成果
5

インストールコマンド

npx skills add jrjsmrtn/project-orchestration-skills --skill harden-gitlab-ci

使わない場合

  • ベンダー提供の SLA が必要なチーム
  • production agents without a repository review
  • Low GitHub adoption signal
  • 高リスク権限のヒント: Shell or command execution, Secrets or environment access
  • Dependency or permission surface needs review

Agent セーフティ v2

28/100 · 自動インストールを避ける

Blocked for auto-installブロック

This skill should not be selected by an agent without explicit human security review.

Do not auto-install. Inspect the source, dependencies, and permission surface first.

API で解決

Shell またはコマンド実行

Skill メタデータに端末、CLI、Shell、サブプロセス、またはコマンド実行のワークフローが含まれます。

ネットワークアクセス

Skill はリモートページ、API、リポジトリ、外部サービスにアクセスする可能性があります。

ファイルシステムアクセス

Skill はプロジェクトファイル、ドキュメント、生成物、ローカルワークスペース状態を読み書きする可能性があります。

Secrets or environment access

Skill metadata references credentials, tokens, environment variables, or secret-bearing workflows.

  • 高リスク権限のヒント: Shell or command execution, Secrets or environment access
  • Dependency or permission surface needs review

インストール先

Agent ワークフローにこのスキルをインストール

公開インストールエンドポイントからコマンド、安全チェックリスト、対象プロンプト、正規リンクを取得します。

skill install

OpenAgentSkill CLI

Resolve policy, run the source installer safely, and report a verified install receipt.

$ npx --yes https://github.com/Leon-Drq/openagentskill/releases/download/cli-v0.2.1/openagentskill-0.2.1.tgz install jrjsmrtn-harden-gitlab-ci

Agent 解決プラン

インストール前に Agent に適合性を検証させます。

Resolve API は第一候補、代替、安全ポリシー、監査メモ、インストール先、Agent がそのまま使えるプロンプトを返します。

テキストプランを開く

Agent が確認すべきこと

  • Resolve API でタスク適合と代替を確認。
  • 監査・信頼スコアと安全ポリシーの警告を確認。
  • Codex、Claude Code、Cursor、CLI のインストール先互換性を確認。

プロンプトをコピー

Task: Use harden-gitlab-ci in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20harden-gitlab-ci%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/jrjsmrtn-harden-gitlab-ci/install
Install command: npx skills add jrjsmrtn/project-orchestration-skills --skill harden-gitlab-ci
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.

Agent 引き継ぎ

別のディレクトリではなく、インストール経路を Agent に渡します。

公開インストールエンドポイントからコマンド、安全チェックリスト、対象プロンプト、正規リンクを取得します。

Install API を開く

Agent プロンプト

Use harden-gitlab-ci for this task. Review https://www.openagentskill.com/api/skills/jrjsmrtn-harden-gitlab-ci/install, then install with: npx skills add jrjsmrtn/project-orchestration-skills --skill harden-gitlab-ci

Registry メタデータ

自動スキル選択用の Agent 可読プロファイル。

Registry API 経由で判断、信頼、監査、ユースケース、インストールのシグナルを提供し、UI をスクレイピングせずに Agent が順位付けできます。

Manifest を開く

Agent 適合

60/100

GitHub automation

プラットフォーム

Claude Code

監査レポート

要レビュー · 72/100

インストール準備、安全メタデータ、保守、採用リスクの機械可読なレビュー。

監査レポートを見る評価レポートを見る

Agent 判断パネル

Fallback candidate for GitHub automation

まずこのスキルでプロトタイプを作り、代替候補を用意してください。

60
準備状況
プロトタイプ
段階

スタック内の役割

代替候補

主な適合

GitHub automation

信頼ラベル

まずプロトタイプ

インストールパス

コマンド準備済み

使う場面

  • GitHub automation ワークフロー
  • Claude Code チーム
  • builders willing to evaluate younger projects

根拠

  • 最近のリポジトリ活動
  • インストールコマンドまたは GitHub リポジトリが利用可能
  • 品質プロファイル 58/100
  • OpenAgentSkill エンゲージメント 8 件

先にレビュー

  • Low GitHub adoption signal

実装パス

  1. 1サンドボックスの Agent にインストールし、GitHub automation タスクを一度最初から最後まで実行します。
  2. 2Compare output quality, latency, and failure behavior against at least one alternative.
  3. 3Promote it into production only after reviewing repository permissions, license, and maintenance signals.

信頼プロファイル

Do not auto-install

Trust Score v5 found insufficient evidence for agent installation. Treat this as discovery material, not an executable recommendation.

58
OpenAgentSkill Trust Score

GitHub 採用度

修正

GitHub スター 14

スター/フォーク活動

修正

スター 14、フォーク 0; 現在のメタデータでは Issue 活動を利用できません

最近のメンテナンス

合格

最終プッシュから 1 日

ライセンスの明確さ

合格

MIT

良いシグナル

  • AI レビュー承認済み
  • インストールパスを利用できます
  • リポジトリの根拠を利用できます
  • 最近保守されたリポジトリ
  • インストールコマンドに明確な高リスクパターンはありません
  • 成果ループは準備済みですが、最初の実行が必要です

インストール前にレビュー

  • Low GitHub adoption signal
  • Quality score needs review
  • Permission surface needs review: secrets or environment access, shell or command execution
  • GitHub adoption: 14 GitHub stars
  • Stars/forks activity: 14 stars, 0 forks; issue activity unavailable in current metadata
  • Dependency/runtime risk: command execution surface, credential or environment access
  • Permission surface: secrets or environment access, shell or command execution
  • 実際の Agent 成果レポートはまだありません
  • 無人インストールの前に人によるレビューが必要です

推奨アクション

Choose a stronger alternative or inspect the source manually before any install attempt.

品質プロファイル

有望 Agent ワークフロー向けの候補

有用な候補ですが、採用前に代替と比較してください。

58
GitHub スター
14
鮮度
1 日前
インストール準備完了
はい
ライセンス
MIT
インストール前にレビュー: Low GitHub adoption signal

ワークフロー適合

このスキルを使うシナリオ

ワークフロー適合

完全なワークフローに追加

代替候補

インストール前に比較

このタスクに適する可能性のある類似スキル。

すべて比較

概要

--- name: harden-gitlab-ci description: Harden GitLab CI/CD pipelines for supply-chain security — SHA-pin `include:` and CI/CD components, scope the `CI_JOB_TOKEN` allowlist, protect and mask variables, pin job image digests, and use `id_tokens`/OIDC instead of long-lived secrets. Use when adding or auditing a `.gitlab-ci.yml`, before making a GitLab project public, when a supply-chain review flags CI gaps, or when standardizing pipeline hardening across GitLab projects (gitlab.com or self-hosted). GitLab-specific by design — for GitHub Actions use `harden-github-actions`; Forgejo/Gitea Actions are out of scope. metadata: author: "Georges Martin <jrjsmrtn@gmail.com>" version: "0.1.34" license: MIT ---

# Harden GitLab CI

Harden GitLab CI/CD pipelines against supply-chain attack: pin what runs, minimise what it can reach, and stop long-lived secrets from existing at all.

> **GitLab-specific by design.** Like `harden-github-actions`, this skill is deliberately bound to one > forge. The controls are properties of the GitLab CI execution model — `include:` resolution, the > `CI_JOB_TOKEN` allowlist, project/group variable scoping, `id_tokens` — not portable concepts in > GitLab syntax. It is a **sibling** of `harden-github-actions`, not a translation of it: the two > forges differ in what the risks *are*, not merely in how they are spelled.

## When to Use

- When adding a `.gitlab-ci.yml` to a project (after `setup-git-hooks`) - When auditing an existing pipeline before making a GitLab project public - When a supply-chain review (or the `supply-chain` skill) flags CI hardening gaps - When standardising pipeline hardening across GitLab projects

**Not for:** GitHub Actions (use `harden-github-actions`) or Forgejo/Gitea Actions. The controls do not carry over — say so rather than approximating.

## Required Inputs

1. **Repository** — a GitLab project (auto-detected from git remotes). **Self-hosted GitLab is a first-class target**, not an exception: authenticate once and every control below is identical. 2. **Project visibility** — public/internal or private. Phases 3 and 4 branch on it: public and internal projects expose pipeline artifacts to unauthenticated users, and fork merge requests are the main variable-exfiltration route. 3. **Scope** — what to run: - `audit` — report findings against the checklist below; **no writes** (default) - `fix` — apply the mechanical fixes (pin includes/components/images), leave judgment calls to the maintainer - `full` — `audit`, then `fix` after confirmation

## The GitLab Threat Model — What Actually Differs

Where the risk sits differs from GitHub Actions; the controls are not one-for-one equivalents:

| Concern | GitHub Actions | GitLab CI | |---|---|---| | Third-party code execution | `uses: actions/x@ref` from the Marketplace | **`include:` + CI/CD Catalog components** — same class of risk, different keyword | | Ambient credential | `GITHUB_TOKEN` with repo-wide default scopes | **`CI_JOB_TOKEN`** — defaults to *own project only*; risk is a widened allowlist | | Secret exfiltration surface | workflow can read all repo secrets | **variable scoping** — protected/masked/environment-scoped, plus fork-MR exposure | | Provenance / keyless auth | OIDC via `id-token: write` | **`id_tokens:` with an `aud` claim** | | Runner trust | GitHub-hosted vs self-hosted | **shared vs group/project runners**, `privileged` Docker, `shell` executor |

> **GitLab has a marketplace-shaped supply chain**: the **CI/CD Catalog** of components. Assuming > otherwise — that only GitHub has this problem — skips the pinning discipline entirely. GitLab's > own docs (*CI/CD components → Best practices*) say to "Pin CI/CD components to a specific commit > SHA (preferred) or release version tag to ensure the integrity of the component used in a > pipeline."

## Workflow

### Phase 1: Detect Context

1. Confirm the forge is GitLab and the CLI is authenticated: ```bash git remote -v glab auth status # self-hosted: glab auth login --hostname gitlab.internal.example ``` If the remote is GitHub or Forgejo, **stop** and point at the right sibling skill. 2. Locate the pipeline config. `glab ci lint` **defaults to `.gitlab-ci.yml` in the current directory**, but a project may relocate it (Settings → CI/CD → General pipelines → CI/CD configuration file). If it is relocated, `cd` to its directory or pass its path/URL — a bare lint would silently validate the wrong file, or nothing. 3. Validate it parses before changing anything: ```bash glab ci lint # or: glab ci lint <path-or-url> ``` 4. Inventory the third-party surface — run these and triage every hit (`CONFIG` = the config path):

```bash # Components/includes on a moving target: ~latest, a partial semver, or a branch grep -nE '@(~latest|[0-9]+(\.[0-9]+)?$|main|master)' "$CONFIG"

# include: project blocks — then confirm each has a `ref:` pinned to a 40-char SHA. # A missing ref: is a finding: it silently defaults to the target project's HEAD. grep -nA3 'include:' "$CONFIG" | grep -E 'project:|ref:' grep -nE '^\s*ref:\s*(?![0-9a-f]{40}\s*$)' -P "$CONFIG" # ref: present but not a SHA

# Remote includes — no auth, no ref to pin; each one is a trust-boundary decision grep -nE '^\s*-?\s*remote:' "$CONFIG"

# Images/services not pinned by digest (covers `image:` and `- name:` service entries; # the negative lookahead is what keeps already-pinned `foo:1@sha256:…` from false-positiving) grep -nPE '^\s*-?\s*(image|name):\s*(?!.*@sha256:)' "$CONFIG"

# Deprecated JWTs (see Phase 5) and inline secrets grep -nE 'CI_JOB_JWT' "$CONFIG"

# Runner isolation escapes grep -nE 'privileged:\s*true|executor:\s*shell' "$CONFIG" .gitlab-runner/*.toml 2>/dev/null ```

Treat every hit as a finding to justify or fix — not as noise to skim.

### Phase 2: Pin the Third-Party Supply Chain

This is the highest-value control — the direct analogue of SHA-pinning actions.

**CI/CD components** (`include: component`) — pin to a **commit SHA**:

```yaml include: # BAD — a moving target; ~latest re-resolves on every run - component: $CI_SERVER_FQDN/my-org/security-components/secret-detection@~latest

# GOOD — immutable - component: $CI_SERVER_FQDN/my-org/security-components/secret-detection@e3262fdd0914fa823210cdb79a8c421e2cef79d8 ```

Version resolution precedence, and why `~latest` is unsafe: a **commit SHA** is exact; a **tag** (`1.0.0`) is mutable unless the project protects its tags — and if a tag and SHA share a name, the SHA wins; a **branch** is fully mutable; `~latest`/partial semver re-resolves to whatever the Catalog last published. Prefer SHA; accept a release tag only when the component project protects tags.

**`include: project`** — `ref:` accepts a branch, tag, **or commit SHA**. Pin it:

```yaml include: - project: 'my-group/ci-templates' ref: 787123b47f14b552955ca2786bc9542ae66fee5b # not `main` file: '/templates/build.yml' ```

`ref:` is optional and **defaults to the project's HEAD** — an unpinned `include: project` silently tracks someone else's default branch. Treat a missing `ref:` as a finding, not a style nit.

**`include: remote`** — a public URL fetched over HTTP(S) with **no authentication support**. It is the weakest link: whoever controls that URL controls your pipeline, and there is no ref to pin. Prefer `component` or `project`. If a remote include is unavoidable, use a URL that embeds an immutable revision (a raw file path containing a commit SHA, not `/raw/main/`), and treat the host as part of your trust boundary.

**`include: template`** and **`include: local`** are GitLab-shipped or in-repo — no pinning needed.

**Resolving a tag to a SHA** — for a component or template project:

```bash # .id is the full commit SHA; :sha accepts a branch or tag name glab api "projects/my-org%2Fsecurity-components/repository/commits/1.0.0" --jq '.id' ```

`:fullpath` also works in place of the URL-encoded path when acting on the current project. For a non-GitLab-hosted template, `git ls-remote <url> refs/tags/<tag>` resolves the same thing.

**Job images and services** — pin by digest, keeping the tag for readability:

```yaml # BAD — mutable image: python:3.13 services: - postgres:18 ```

```yaml # GOOD — immutable, still readable image: python:3.13@sha256:<digest> services: - name: postgres:18@sha256:<digest> ```

Resolve digests with `skopeo inspect docker://python:3.13 --format '{{.Digest}}'`. This mirrors `setup-container-security`'s base-image rule; the reasoning and the bump procedure are the same.

### Phase 3: Scope the Job Token

`CI_JOB_TOKEN` is minted per job, scoped to the triggering user's access level, masked in logs, and revoked when the job ends. **By default it reaches only its own project** — so the work here is mostly *keeping* it that way. But verify the default actually holds before auditing anything else:

- **First, confirm the allowlist is enforced at all.** Under **Settings → CI/CD → Job token permissions**, the project may be set to either *"This project and any groups and projects in the allowlist"* (restricted — the default) or **"All groups and projects"** (permissive). GitLab's warning is unambiguous: *"If you disable the CI/CD job token allowlist, jobs from any project can access your project with a job token… You should only disable this setting for testing or a similar reason."* A project in the permissive mode has **no allowlist to audit** — that is the worst case and the finding. Fix it before reviewing entries. (Self-managed admins can force the restricted mode instance-wide via *Enable and enforce job token allowlist for all projects*.) - Then audit the allowlist: **Settings → CI/CD → Job token permissions → CI/CD job token allowlist**. Every entry is a project that may authenticate *into* this one. Justify each; remove the rest. (Limit: 200 entries — an allowlist near that size is a finding in itself.) - Adding to the allowlist **grants no new permissions** — the user must already have access. It widens *reachability*, not authority. Do not treat allowlist membership as an access grant. - Prefer the **fine-grained permissions** setting (limiting the token to a specific set of REST endpoints) over all-or-nothing allowlisting. - **Public/internal projects**: unauthenticated users can fetch artifacts from public pipelines regardless of the allowlist. If artifacts are sensitive, set feature visibility to *Only project members*. - Review the authentication log periodically for unexpected cross-project token use.

### Phase 4: Variables and Secrets

- **Never put secrets in `.gitlab-ci.yml`.** It is readable by anyone with repo access; it holds non-sensitive configuration only. Secrets live in project/group settings or a secrets manager. - **Protected** = available only to pipelines on protected branches/tags. **Masked** = redacted as `[MASKED]` in job logs. They solve different problems — set both for real secrets: ```bash # Read the secret into a variable; never inline it or echo it read -rs SECRET_VALUE glab variable set DEPLOY_TOKEN "$SECRET_VALUE" --masked --protected glab variable list -F json --jq '.[] | select(.masked==false or .protected==false) | .key' ``` That second command is the audit: any secret-shaped key it prints is a finding. - **Masking has hard constraints** — the value must be a single line, no spaces, ≥ 8 characters, and (with expansion enabled) use only `_ : @ - + . ~ = /` beyond alphanumerics. A secret that cannot be masked is a secret that will eventually appear in a log; regenerate it in a maskable format rather than shipping it unmasked. - **Masking is not a security boundary.** GitLab's own docs (*CI/CD variables → Mask a CI/CD variable*) state it "is not a guaranteed way to prevent malicious users from accessing variable values" — it defeats accid

技術詳細

バージョン
1.0.0
ライセンス
MIT
最終更新
2026年8月21日
公開日
2026年8月21日

判断の要約

代替候補

60
準備完了
プロトタイプ
段階

最近のリポジトリ活動

監査

インストールレビュー

インストールと採用のレビュー

72
要レビュー
セキュリティ
72/100
メンテナンス
100/100
インストール
92/100
完全な監査を開く評価レポートを見る

Agent 実証エビデンス

Agent 実証エビデンス

Resolve、レビュー、インストール、限定実行後の成果レポート。

0
実証済み
Needs first agent run自動インストール: 先にレビュー最新: 不明
成功率
直近の失敗
成果
0
出力品質
失敗
0
非該当
0
インストール数
0
リスクによりブロック
0
設定が必要
0
本番
0

Agent の実行結果はまだありません。最初の実行では /api/agent/outcome を通じて成功、設定要件、リスクによるブロック、失敗、非該当を報告できます。

インストール

Agent ワークフローに追加

無料・オープンソース. 本番 Agent にインストールする前にレポートを確認してください。

成長ループ

共有キット

X

harden-gitlab-ci 用のシナリオベース草案です。X へ手動投稿できます。

キュレーターノート
harden-gitlab-ci: Harden GitLab CI/CD pipelines for supply-chain security — SHA-pin `include:` and CI/CD compon...

14 stars

https://www.openagentskill.com/skills/jrjsmrtn-harden-gitlab-ci?ref=x
X 下書きを開く
任意:インストールコマンド付きの返信
Listing + install path for harden-gitlab-ci:
https://www.openagentskill.com/skills/jrjsmrtn-harden-gitlab-ci?ref=x

Install: npx skills add jrjsmrtn/project-orchestration-skills --skill harden-gitlab-ci
返信の下書きを開く

掲載元

Registry により登録

申請可能

この掲載は公開ソースから登録されており、メンテナー申請が承認されるまで公式として表示されません。

作成者
jrjsmrtn
インデックス作成者
OpenAgentSkill コミュニティインデックス

帰属は公開リポジトリまたは作成者プロフィールにリンクされています。作成者は掲載を申請して所有権シグナルを更新できます。

このスキルを申請

所有者の申請

このスキル掲載を申請

この Registry により登録 掲載は jrjsmrtn に帰属していますが、まだ公式として表示されていません。申請すると、確認済み所有者シグナルが追加され、今後の公開、インストール、監査更新の信頼性が高まります。

クリエイター被リンクキット

README にエビデンスバッジを追加

開発者がリポジトリを評価する場所で、正規掲載、現在の信頼・監査シグナル、実際の Agent-Proven エビデンスを表示します。

[![Listed on OpenAgentSkill](https://www.openagentskill.com/api/badge/jrjsmrtn-harden-gitlab-ci?metric=listed&label=Listed)](https://www.openagentskill.com/skills/jrjsmrtn-harden-gitlab-ci)
[![OpenAgentSkill Trust](https://www.openagentskill.com/api/badge/jrjsmrtn-harden-gitlab-ci?metric=trust&label=Trust)](https://www.openagentskill.com/skills/jrjsmrtn-harden-gitlab-ci)
[![OpenAgentSkill Audit](https://www.openagentskill.com/api/badge/jrjsmrtn-harden-gitlab-ci?metric=audit&label=Audit)](https://www.openagentskill.com/skills/jrjsmrtn-harden-gitlab-ci/audit)
[![Agent Proven](https://www.openagentskill.com/api/badge/jrjsmrtn-harden-gitlab-ci?metric=proven&label=Agent%20Proven)](https://www.openagentskill.com/skills/jrjsmrtn-harden-gitlab-ci)

作者

J

jrjsmrtn

@jrjsmrtn

プラットフォーム適合

健全性シグナル

GitHub スター
14
品質スコア
32/100
最終 GitHub プッシュ
2026年8月21日
フレームワークのヒント
不明
OpenAgentSkill 閲覧数
8
インストールコピー数
0
外部クリック
0

コミュニティシグナル

このスキルが Agent ワークフローに役立つかを共有してください。集約されたフィードバックがランキングを改善します。

信頼と安全性

Do not auto-install

58
  • GitHub 採用度GitHub スター 14修正
  • スター/フォーク活動スター 14、フォーク 0; 現在のメタデータでは Issue 活動を利用できません修正
  • 最近のメンテナンス最終プッシュから 1 日合格
  • ライセンスの明確さMIT合格
  • README/SKILL.md の完全性メタデータには十分な利用・ワークフロー文脈があります合格
  • 依存関係/ランタイムのリスクcommand execution surface, credential or environment access修正