Rapport d’audit du skill
moli-cdp-server Rapport d’audit.
Start Moli's CDP server and connect Playwright, Puppeteer, or raw CDP clients. Use to run a headless-browser CDP endpoint, replace a Chromium process, attach over CDP, enable real layout and screenshot surfaces, or diagnose CDP discovery, connection, and target startup—even when Moli is not named.
Trust Score OpenAgentSkill
Trust Score OpenAgentSkill
The Trust Score helps an agent decide whether a skill is safe enough to shortlist before installation.
Adoption GitHub
Info76
853 stars GitHub
Activité stars/forks
Info71
853 stars et 53 forks; l’activité des issues n’est pas disponible dans les métadonnées actuelles
Maintenance récente
Validé100
1 jours depuis le dernier push
Clarté de licence
Validé86
Apache-2.0
Complétude README/SKILL.md
Validé86
Les métadonnées incluent suffisamment de contexte d’usage et de workflow
Risque dépendances/runtime
Info64
command execution surface, network or browser surface
Disponibilité de l’installation
Validé92
npx skills add lexmount/moli --skill moli-cdp-server
Sécurité de la commande d’installation
Validé92
Chemin d’installation standard de package ou runtime
Surface de permissions
Info62
shell or command execution, network or browser access
Preuve du dépôt
Validé86
https://github.com/lexmount/moli/tree/main/skills/moli-cdp-server
État de revue
Info66
Données de revue IA disponibles
Résultats prouvés par Agent
Info54
Pas encore de données de résultats Agent
Vérifications
Revue d’installation et d’adoption
Chemin d’installation
92
npx skills add lexmount/moli --skill moli-cdp-server
Dépôt
88
https://github.com/lexmount/moli/tree/main/skills/moli-cdp-server
Licence
86
Apache-2.0
Maintenance
100
1 jours depuis le dernier push
Revue IA
55
The skill blindly installs a binary via curl/PowerShell from GitHub releases without checksum verification, which could be a supply-chain risk if the release is compromised. However, this follows common practice and is not a critical flaw.
Complétude README/SKILL.md
86
Usable description available
Risque de dépendances
64
command execution surface, network or browser surface
Sécurité de la commande d’installation
92
Chemin d’installation standard de package ou runtime
Surface de permissions
62
shell or command execution, network or browser access
Activité stars/forks
71
853 stars et 53 forks; l’activité des issues n’est pas disponible dans les métadonnées actuelles
Adoption
88
853 stars GitHub
Financial decision safety
58
Research-only use: do not treat output as financial advice or execute a position without human approval.
Avertissements
- Financial research output is not financial advice; require human review before any live investment decision
- The skill blindly installs a binary via curl/PowerShell from GitHub releases without checksum verification, which could be a supply-chain risk if the release is compromised. However, this follows common practice and is not a critical flaw.
- The skill does not explicitly warn that CDP servers exposed on localhost can be accessed by other local processes, and the server itself may allow arbitrary browser automation from local users. This is typical for such tools and acceptable.
- Financial research output is not financial advice; require human review before any live investment decision.
- Quality score needs review
Méthode
This report combines public metadata, AI review output, repository freshness, install readiness, OpenAgentSkill events, quality scoring, trust checks, and the agent safety gate. It is not a full source-code security review.
Comparer les options proches