Skill 审计报告
moli-cdp-server 审计报告.
Start Moli's CDP server and connect Playwright, Puppeteer, or raw CDP clients. Use to run a headless-browser CDP endpoint, replace a Chromium process, attach over CDP, enable real layout and screenshot surfaces, or diagnose CDP discovery, connection, and target startup—even when Moli is not named.
OpenAgentSkill 信任评分
OpenAgentSkill 信任评分
Trust Score 帮助 Agent 在安装前判断一个 Skill 是否足以进入候选清单。
GitHub 采用度
信息76
974 个 GitHub Stars
Star/Fork 活跃度
信息71
974 个 Star,60 个 Fork; 当前元数据中没有议题活跃度信息
近期维护
通过100
今天有推送
许可证清晰度
通过86
Apache-2.0
README/SKILL.md 完整度
通过86
元数据包含足够的用法与工作流上下文
依赖与运行时风险
信息64
command execution surface, network or browser surface
安装可用性
通过92
npx skills add lexmount/moli --skill moli-cdp-server
安装命令安全性
通过92
标准软件包或运行时安装路径
权限范围
信息62
shell or command execution, network or browser access
仓库证据
通过86
https://github.com/lexmount/moli/tree/main/skills/moli-cdp-server
审查状态
信息66
可用 AI 审查数据
Agent 验证结果
信息54
暂未有 Agent 结果数据
检查项
安装与采用审查
安装路径
92
npx skills add lexmount/moli --skill moli-cdp-server
仓库
88
https://github.com/lexmount/moli/tree/main/skills/moli-cdp-server
许可证
86
Apache-2.0
维护
100
今天有推送
AI 审查
55
The skill blindly installs a binary via curl/PowerShell from GitHub releases without checksum verification, which could be a supply-chain risk if the release is compromised. However, this follows common practice and is not a critical flaw.
README/SKILL.md 完整度
86
Usable description available
依赖风险
64
command execution surface, network or browser surface
安装命令安全性
92
标准软件包或运行时安装路径
权限范围
62
shell or command execution, network or browser access
Star/Fork 活跃度
71
974 个 Star,60 个 Fork; 当前元数据中没有议题活跃度信息
采用度
88
974 个 GitHub Stars
Financial decision safety
58
Research-only use: do not treat output as financial advice or execute a position without human approval.
警告
- Financial research output is not financial advice; require human review before any live investment decision
- The skill blindly installs a binary via curl/PowerShell from GitHub releases without checksum verification, which could be a supply-chain risk if the release is compromised. However, this follows common practice and is not a critical flaw.
- The skill does not explicitly warn that CDP servers exposed on localhost can be accessed by other local processes, and the server itself may allow arbitrary browser automation from local users. This is typical for such tools and acceptable.
- Financial research output is not financial advice; require human review before any live investment decision.
- Quality score needs review
方法
本报告综合公开元数据、AI 审查输出、仓库活跃度、安装就绪度、OpenAgentSkill 事件、质量评分、信任检查和 Agent 安全门槛;它不是完整的源代码安全审计。
对比相近选项