スキル監査レポート
code-security 監査レポート.
Runs Semgrep security scans on the current project to detect vulnerabilities, secrets leakage, and OWASP Top 10 issues. Use when the user asks for security scanning, vulnerability detection, code auditing, secrets checking, or says things like 安全扫描, 代码扫描, 扫漏洞, 安全检查, 漏洞检测, 扫一下安全.
OpenAgentSkill Trust Score
OpenAgentSkill Trust Score
Trust Score は、インストール前に候補に入れる安全性を Agent が判断する助けになります。
GitHub 採用度
情報62
GitHub スター 169
スター/フォーク活動
警告57
スター 169、フォーク 49; 現在のメタデータでは Issue 活動を利用できません
最近のメンテナンス
合格88
最終プッシュから 2 か月
ライセンスの明確さ
合格86
MIT
README/SKILL.md の完全性
合格86
メタデータには十分な利用・ワークフロー文脈があります
依存関係/ランタイムのリスク
失敗36
command execution surface, credential or environment access
インストール可否
合格92
npx skills add KimYx0207/Kim_Service --skill code-security
インストールコマンドの安全性
合格92
標準パッケージまたはランタイムのインストールパス
権限範囲
失敗36
secrets or environment access, shell or command execution
リポジトリ根拠
合格86
https://github.com/KimYx0207/Kim_Service/tree/main/skills/semgrep-skill
レビュー状況
情報66
AI レビューデータを利用できます
Agent 検証結果
情報54
Agent の成果データはまだありません
チェック
インストールと採用のレビュー
インストール経路
92
npx skills add KimYx0207/Kim_Service --skill code-security
リポジトリ
88
https://github.com/KimYx0207/Kim_Service/tree/main/skills/semgrep-skill
ライセンス
86
MIT
メンテナンス
88
最終プッシュから 2 か月
AI レビュー
55
The skill instructs the agent to run `pip install semgrep` if not installed, which modifies the system environment; this is acceptable but should be noted as a potential side effect.
README/SKILL.md の完全性
86
Usable description available
依存関係リスク
36
command execution surface, credential or environment access
インストールコマンドの安全性
92
標準パッケージまたはランタイムのインストールパス
権限範囲
36
secrets or environment access, shell or command execution
スター/フォーク活動
57
スター 169、フォーク 49; 現在のメタデータでは Issue 活動を利用できません
採用度
68
GitHub スター 169
警告
- Dependency or permission surface needs review
- Permission surface may require sandboxing
- The skill instructs the agent to run `pip install semgrep` if not installed, which modifies the system environment; this is acceptable but should be noted as a potential side effect.
- The skill uses `semgrep scan --config auto` which may require network access to fetch rules; this is expected but could be a concern in offline environments.
- Quality score needs review
- Permission surface needs review: secrets or environment access, shell or command execution
- Stars/forks activity: 169 stars, 49 forks; issue activity unavailable in current metadata
- Dependency/runtime risk: command execution surface, credential or environment access
- Permission surface: secrets or environment access, shell or command execution
方法
このレポートは公開メタデータ、AI レビュー、リポジトリの鮮度、インストール準備、OpenAgentSkill イベント、品質スコア、信頼チェック、Agent セーフティゲートを統合します。完全なソースコード監査ではありません。
近い選択肢を比較
次に監査する関連スキル
Wazuh
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
16K スター · 監査レポート
Maigret
🕵️♂️ Collect a dossier on a person by username from 3000+ sites
33K スター · 監査レポート
Nuclei
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
29K スター · 監査レポート