スキル監査レポート
moli-cdp-server 監査レポート.
Start Moli's CDP server and connect Playwright, Puppeteer, or raw CDP clients. Use to run a headless-browser CDP endpoint, replace a Chromium process, attach over CDP, enable real layout and screenshot surfaces, or diagnose CDP discovery, connection, and target startup—even when Moli is not named.
OpenAgentSkill Trust Score
OpenAgentSkill Trust Score
Trust Score は、インストール前に候補に入れる安全性を Agent が判断する助けになります。
GitHub 採用度
情報76
GitHub スター 853
スター/フォーク活動
情報71
スター 853、フォーク 53; 現在のメタデータでは Issue 活動を利用できません
最近のメンテナンス
合格100
最終プッシュから 1 日
ライセンスの明確さ
合格86
Apache-2.0
README/SKILL.md の完全性
合格86
メタデータには十分な利用・ワークフロー文脈があります
依存関係/ランタイムのリスク
情報64
command execution surface, network or browser surface
インストール可否
合格92
npx skills add lexmount/moli --skill moli-cdp-server
インストールコマンドの安全性
合格92
標準パッケージまたはランタイムのインストールパス
権限範囲
情報62
shell or command execution, network or browser access
リポジトリ根拠
合格86
https://github.com/lexmount/moli/tree/main/skills/moli-cdp-server
レビュー状況
情報66
AI レビューデータを利用できます
Agent 検証結果
情報54
Agent の成果データはまだありません
チェック
インストールと採用のレビュー
インストール経路
92
npx skills add lexmount/moli --skill moli-cdp-server
リポジトリ
88
https://github.com/lexmount/moli/tree/main/skills/moli-cdp-server
ライセンス
86
Apache-2.0
メンテナンス
100
最終プッシュから 1 日
AI レビュー
55
The skill blindly installs a binary via curl/PowerShell from GitHub releases without checksum verification, which could be a supply-chain risk if the release is compromised. However, this follows common practice and is not a critical flaw.
README/SKILL.md の完全性
86
Usable description available
依存関係リスク
64
command execution surface, network or browser surface
インストールコマンドの安全性
92
標準パッケージまたはランタイムのインストールパス
権限範囲
62
shell or command execution, network or browser access
スター/フォーク活動
71
スター 853、フォーク 53; 現在のメタデータでは Issue 活動を利用できません
採用度
88
GitHub スター 853
Financial decision safety
58
Research-only use: do not treat output as financial advice or execute a position without human approval.
警告
- Financial research output is not financial advice; require human review before any live investment decision
- The skill blindly installs a binary via curl/PowerShell from GitHub releases without checksum verification, which could be a supply-chain risk if the release is compromised. However, this follows common practice and is not a critical flaw.
- The skill does not explicitly warn that CDP servers exposed on localhost can be accessed by other local processes, and the server itself may allow arbitrary browser automation from local users. This is typical for such tools and acceptable.
- Financial research output is not financial advice; require human review before any live investment decision.
- Quality score needs review
方法
このレポートは公開メタデータ、AI レビュー、リポジトリの鮮度、インストール準備、OpenAgentSkill イベント、品質スコア、信頼チェック、Agent セーフティゲートを統合します。完全なソースコード監査ではありません。
近い選択肢を比較