Laporan audit skill

autoskill Laporan audit.

Observe the user's screen via screenpipe, detect repeated research workflows, match them against existing scientific-agent-skills, and draft new skills (or composition recipes that chain existing ones) for the patterns not yet covered. Use when the user asks to analyze their recent work and propose skills based on what they actually do. Requires the screenpipe daemon (https://github.com/screenpipe/screenpipe) running locally on port 3030 — the skill has no other data source and will refuse to run if screenpipe is unreachable. All detection runs locally; only redacted cluster summaries reach the LLM.

Eksperimental · TinjauPerlu ditinjauDihasilkan 23 Agu 2026Audit metadata heuristik
84
Audit
73
Kepercayaan
92
Kualitas
72
Keamanan
100
Maintain
92
Pasang

Trust Score OpenAgentSkill

73
Shortlist kuat

Trust Score OpenAgentSkill

The Trust Score helps an agent decide whether a skill is safe enough to shortlist before installation.

Adopsi GitHub

Lulus

100

34K star GitHub

Aktivitas star/fork

Lulus

97

34K star dan 3.3K fork; aktivitas issue tidak tersedia dalam metadata saat ini

Pemeliharaan terbaru

Lulus

100

3 hari sejak push

Kejelasan lisensi

Lulus

86

MIT license

Kelengkapan README/SKILL.md

Lulus

86

Metadata memuat konteks penggunaan dan alur kerja yang cukup

Risiko dependensi/runtime

Peringatan

46

command execution surface, credential or environment access

Ketersediaan pemasangan

Lulus

92

npx skills add K-Dense-AI/scientific-agent-skills --skill autoskill

Keamanan perintah pemasangan

Lulus

92

Jalur pemasangan paket atau runtime standar

Cakupan izin

Gagal

22

secrets or environment access, shell or command execution

Bukti repositori

Lulus

86

https://github.com/K-Dense-AI/scientific-agent-skills/tree/main/skills/autoskill

Status peninjauan

Info

66

Data tinjauan AI tersedia

Hasil terbukti Agent

Info

54

Belum ada data hasil Agent

Pemeriksaan

Tinjauan pemasangan dan adopsi

8 Lulus · 10 Perlu ditinjau

Jalur pemasangan

92

Lulus

npx skills add K-Dense-AI/scientific-agent-skills --skill autoskill

Repositori

88

Lulus

https://github.com/K-Dense-AI/scientific-agent-skills/tree/main/skills/autoskill

Lisensi

86

Lulus

MIT license

Pemeliharaan

100

Lulus

3 hari sejak push

Tinjauan AI

55

Periksa

The skill depends on the screenpipe daemon and a SCREENPIPE_TOKEN; if the daemon is not running or the token is invalid, the skill will fail. Documentation covers this, but a more explicit error-handling section in SKILL.md could help.

Kelengkapan README/SKILL.md

86

Lulus

Usable description available

Risiko dependensi

46

Perbaiki

command execution surface, credential or environment access

Keamanan perintah pemasangan

92

Lulus

Jalur pemasangan paket atau runtime standar

Cakupan izin

22

Perbaiki

secrets or environment access, shell or command execution

Aktivitas star/fork

97

Lulus

34K star dan 3.3K fork; aktivitas issue tidak tersedia dalam metadata saat ini

Adopsi

88

Lulus

34K star GitHub

Peringatan

  • Dependency or permission surface needs review
  • Permission surface may require sandboxing
  • The skill depends on the screenpipe daemon and a SCREENPIPE_TOKEN; if the daemon is not running or the token is invalid, the skill will fail. Documentation covers this, but a more explicit error-handling section in SKILL.md could help.
  • Cloud backends (Claude/Foundry) are optional but require the user to supply API keys; the skill does not perform additional runtime validation of the endpoint beyond the cleartext check, so a misconfigured (but HTTPS) remote endpoint could receive data. This is acceptable given the user explicitly configures it, but the documentation could emphasise the privacy implications more strongly.
  • Permission surface needs review: secrets or environment access, shell or command execution
  • Dependency/runtime risk: command execution surface, credential or environment access
  • Permission surface: secrets or environment access, shell or command execution

Metode

This report combines public metadata, AI review output, repository freshness, install readiness, OpenAgentSkill events, quality scoring, trust checks, and the agent safety gate. It is not a full source-code security review.

Bandingkan opsi sekitar

Skill terkait untuk diaudit berikutnya