스킬 감사 보고서

moli-cdp-server 감사 보고서.

Start Moli's CDP server and connect Playwright, Puppeteer, or raw CDP clients. Use to run a headless-browser CDP endpoint, replace a Chromium process, attach over CDP, enable real layout and screenshot surfaces, or diagnose CDP discovery, connection, and target startup—even when Moli is not named.

실험적 · 검토검토 필요생성됨 2026년 8월 22일휴리스틱 메타데이터 감사
80
감사
73
신뢰
76
품질
77
보안
100
유지보수
92
설치

OpenAgentSkill 신뢰 점수

73
강력한 후보

OpenAgentSkill 신뢰 점수

Trust Score는 설치 전에 후보 목록에 넣을 만큼 안전한지 Agent가 판단하도록 돕습니다.

GitHub 채택도

정보

76

GitHub 스타 853

스타/포크 활동

정보

71

스타 853, 포크 53; 현재 메타데이터에서 이슈 활동을 확인할 수 없습니다

최근 유지보수

통과

100

오늘 푸시됨

라이선스 명확성

통과

86

Apache-2.0

README/SKILL.md 완성도

통과

86

메타데이터에 충분한 사용 및 워크플로 맥락이 포함되어 있습니다

의존성/런타임 위험

정보

64

command execution surface, network or browser surface

설치 가능 여부

통과

92

npx skills add lexmount/moli --skill moli-cdp-server

설치 명령 안전성

통과

92

표준 패키지 또는 런타임 설치 경로

권한 범위

정보

62

shell or command execution, network or browser access

저장소 근거

통과

86

https://github.com/lexmount/moli/tree/main/skills/moli-cdp-server

검토 상태

정보

66

AI 검토 데이터를 사용할 수 있습니다

Agent 검증 결과

정보

54

아직 Agent 결과 데이터가 없습니다

검사

설치 및 채택 검토

7 통과 · 10 검토 필요

설치 경로

92

통과

npx skills add lexmount/moli --skill moli-cdp-server

저장소

88

통과

https://github.com/lexmount/moli/tree/main/skills/moli-cdp-server

라이선스

86

통과

Apache-2.0

유지보수

100

통과

오늘 푸시됨

AI 검토

55

확인

The skill blindly installs a binary via curl/PowerShell from GitHub releases without checksum verification, which could be a supply-chain risk if the release is compromised. However, this follows common practice and is not a critical flaw.

README/SKILL.md 완성도

86

통과

Usable description available

의존성 위험

64

확인

command execution surface, network or browser surface

설치 명령 안전성

92

통과

표준 패키지 또는 런타임 설치 경로

권한 범위

62

확인

shell or command execution, network or browser access

스타/포크 활동

71

확인

스타 853, 포크 53; 현재 메타데이터에서 이슈 활동을 확인할 수 없습니다

채택도

88

통과

GitHub 스타 853

Financial decision safety

58

확인

Research-only use: do not treat output as financial advice or execute a position without human approval.

경고

  • Financial research output is not financial advice; require human review before any live investment decision
  • The skill blindly installs a binary via curl/PowerShell from GitHub releases without checksum verification, which could be a supply-chain risk if the release is compromised. However, this follows common practice and is not a critical flaw.
  • The skill does not explicitly warn that CDP servers exposed on localhost can be accessed by other local processes, and the server itself may allow arbitrary browser automation from local users. This is typical for such tools and acceptable.
  • Financial research output is not financial advice; require human review before any live investment decision.
  • Quality score needs review

방법

이 보고서는 공개 메타데이터, AI 검토 결과, 저장소 최신성, 설치 준비 상태, OpenAgentSkill 이벤트, 품질 점수, 신뢰 검사와 Agent 안전 게이트를 결합합니다. 전체 소스 코드 보안 감사는 아닙니다.

가까운 옵션 비교

다음으로 감사할 관련 스킬