インストール前評価

moli-cdp-server 評価レポート.

Agent 向けの機械可読なインストール判断です。タスク適合、Trust Score、Audit Score、インストール安全性、権限範囲、ワークスペースに触れる前の具体的な検証プランを含みます。

要レビュー中リスクレビュー ポリシー
72
評価レポート
73
信頼
80
監査
52
Agent セーフティ

手動レビュー

Test manually in an isolated workspace and compare against safer alternatives.

必須ゲート

インストール前に Agent が通過すべきチェック

JSON を開く

タスク適合

84

合格

タスク文言はこのスキルのメタデータと一致しています。

  • Evaluate moli-cdp-server before installing it in an agent workflow
  • 自動化
  • Browser automation workflows; Claude Code teams; teams that value GitHub adoption signals

インストール経路

92

合格

インストールの引き継ぎ情報を利用できます。

  • npx skills add lexmount/moli --skill moli-cdp-server

インストールコマンドの安全性

92

合格

標準パッケージまたはランタイムのインストールパス

  • npx skills add lexmount/moli --skill moli-cdp-server

信頼スコア

73

警告

Good trust signals with a few areas worth checking before rollout.

  • 有力候補
  • GitHub スター 974
  • Apache-2.0

監査スコア

80

警告

要レビュー

  • Financial research output is not financial advice; require human review before any live investment decision

Agent 安全ゲート

52

警告

Sparse or mixed signals. Useful for discovery, but not for autonomous installation.

  • Test manually in an isolated workspace and compare against safer alternatives.
  • 高リスク権限のヒント: Shell またはコマンド実行

ライセンスの明確さ

86

合格

Apache-2.0

  • Apache-2.0

権限範囲

62

警告

shell or command execution, network or browser access

  • Shell or command execution: high
  • Browser automation: medium
  • Network access: medium

検証プラン

Agent が次に行うこと

  1. 1本番利用前にリポジトリ、README/SKILL.md、ライセンス、最近のコミットを確認してください。
  2. 2本番シークレットがない隔離ワークスペースまたはサンドボックスにインストールしてください。
  3. 3最小の代表タスクを実行し、操作したファイル、実行コマンド、ネットワークアクセス、出力を記録してください。
  4. 4評価状態がレビューまたは失敗の場合、選択したスキルを少なくとも 1 つの代替と比較してください。
  5. 5Agent が検証成功を報告し、未解決の警告が受容された後にのみ昇格してください。

使わない場合

別のスキルが必要な条件

  • ベンダー提供の SLA が必要なチーム
  • production agents without a repository review
  • The skill blindly installs a binary via curl/PowerShell from GitHub releases without checksum verification, which could be a supply-chain risk if the release is compromised. However, this follows common practice and is not a critical flaw.
  • 高リスク権限のヒント: Shell またはコマンド実行
  • Financial research output is not financial advice; require human review before any live investment decision
  • The skill does not explicitly warn that CDP servers exposed on localhost can be accessed by other local processes, and the server itself may allow arbitrary browser automation from local users. This is typical for such tools and acceptable.

補助チェック

判断を支える信頼シグナル

README/SKILL.md の完全性

合格

86

メタデータには十分な利用・ワークフロー文脈があります

最近のメンテナンス

合格

100

本日プッシュ

代替候補あり

合格

82

比較できる代替スキルがあります。