安装前评估
status 评估报告.
为 Agent 提供机器可读的安装决策:任务匹配、Trust Score、Audit Score、安装安全、权限范围,以及在 Skill 进入工作区前的具体验证计划。
人工审查
Test manually in an isolated workspace and compare against safer alternatives.
必要关卡
Agent 安装前必须通过的检查
任务匹配度
84
任务描述与此 Skill 的元数据匹配。
- Evaluate status before installing it in an agent workflow
- 设计与创意
- Browser automation workflows; Claude Code teams; builders willing to evaluate younger projects
安装路径
92
可用安装交接信息。
- npx skills add LeeYudok/agents-scaffold --skill status
安装命令安全性
92
标准软件包或运行时安装路径
- npx skills add LeeYudok/agents-scaffold --skill status
信任评分
65
Potentially useful, but at least one trust signal needs human inspection.
- 人工审查
- 20 个 GitHub Stars
- MIT
审计评分
73
需审查
- Running build/check commands (e.g., npm run build, cargo check) can have side effects and may execute arbitrary scripts from the repository.
Agent 安全门槛
49
Sparse or mixed signals. Useful for discovery, but not for autonomous installation.
- Test manually in an isolated workspace and compare against safer alternatives.
- 高风险权限提示:Shell 或命令执行
许可证清晰度
86
MIT
- MIT
权限范围
76
Shell 或命令执行
- Shell or command execution: high
- Network access: medium
验证计划
Agent 接下来应执行什么
- 1在生产使用前检查仓库、README/SKILL.md、许可证与最近提交。
- 2在没有生产密钥的隔离工作区或沙盒中安装。
- 3运行最小代表性任务,并记录访问的文件、执行的命令、网络访问和输出。
- 4当评估状态为“审查”或“失败”时,至少与一个替代 Skill 比较。
- 5只有在 Agent 报告验证成功且已接受未解决警告后,才提升到更高环境。
不适用场景
需要改用其他 Skill 的情况
- 需要厂商支持 SLA 的团队
- production agents without a repository review
- Low GitHub adoption signal
- Running build/check commands (e.g., npm run build, cargo check) can have side effects and may execute arbitrary scripts from the repository.
- 暂未有 OpenAgentSkill 使用反馈数据
- 高风险权限提示:Shell 或命令执行
辅助检查
支撑该决策的信任信号
README/SKILL.md 完整度
通过86
元数据包含足够的用法与工作流上下文
近期维护
通过100
今天有推送
可用替代方案
通过82
有可用于比较的替代 Skill。