Informe de auditoría del skill
moli-webfetch Informe de auditoría.
Fetch, inspect, crawl, and capture live, JavaScript-rendered websites with Moli. Use when Codex needs current web content, web research, fact lookup, link following, a bounded crawl, client-rendered or response-gated content, network diagnostics, or a standalone HTML, Markdown, JSON, semantic-tree, viewport or full-document screenshot, PDF, or WPT artifact—even when Moli is not named.
Trust Score de OpenAgentSkill
Trust Score de OpenAgentSkill
The Trust Score helps an agent decide whether a skill is safe enough to shortlist before installation.
Adopción en GitHub
Info76
853 estrellas de GitHub
Actividad de stars/forks
Info71
853 estrellas y 53 forks; la actividad de issues no está disponible en los metadatos actuales
Mantenimiento reciente
Aprobado100
1 días desde el último push
Claridad de licencia
Aprobado86
Apache-2.0
Completitud de README/SKILL.md
Aprobado86
Los metadatos incluyen suficiente contexto de uso y flujo de trabajo
Riesgo de dependencias/runtime
Info64
command execution surface, network or browser surface
Disponibilidad de instalación
Aprobado92
npx skills add lexmount/moli --skill moli-webfetch
Seguridad del comando de instalación
Aprobado92
Ruta estándar de paquete o instalación en tiempo de ejecución
Superficie de permisos
Advertencia48
shell or command execution, filesystem or document access
Evidencia del repositorio
Aprobado86
https://github.com/lexmount/moli/tree/main/skills/moli-webfetch
Estado de revisión
Info66
Hay datos de revisión por IA disponibles
Resultados comprobados por Agent
Info54
Aún no hay datos de resultados del Agent
Comprobaciones
Revisión de instalación y adopción
Ruta de instalación
92
npx skills add lexmount/moli --skill moli-webfetch
Repositorio
88
https://github.com/lexmount/moli/tree/main/skills/moli-webfetch
Licencia
86
Apache-2.0
Mantenimiento
100
1 días desde el último push
Revisión por IA
55
The skill instructs installing a third-party binary via `curl | sh` without checksum verification, which carries supply-chain risk. While the source is a GitHub release, best practice is to recommend verifying the installer's integrity.
Completitud de README/SKILL.md
86
Usable description available
Riesgo de dependencias
64
command execution surface, network or browser surface
Seguridad del comando de instalación
92
Ruta estándar de paquete o instalación en tiempo de ejecución
Superficie de permisos
48
shell or command execution, filesystem or document access
Actividad de stars/forks
71
853 estrellas y 53 forks; la actividad de issues no está disponible en los metadatos actuales
Adopción
88
853 estrellas de GitHub
Advertencias
- Permission surface may require sandboxing
- The skill instructs installing a third-party binary via `curl | sh` without checksum verification, which carries supply-chain risk. While the source is a GitHub release, best practice is to recommend verifying the installer's integrity.
- No explicit rate limiting or politeness policy is mentioned for crawling, though the skill does emphasize bounded crawling with limits.
- Quality score needs review
- Permission surface needs review: shell or command execution, filesystem or document access
- Permission surface: shell or command execution, filesystem or document access
Método
This report combines public metadata, AI review output, repository freshness, install readiness, OpenAgentSkill events, quality scoring, trust checks, and the agent safety gate. It is not a full source-code security review.
Comparar opciones cercanas
Skills relacionados para auditar después
Last30days Skill
Research the last 30 days across Reddit, X, YouTube, Hacker News, Polymarket, GitHub, and the web, then synthesize a grounded brief for an AI agent.
54K Estrellas · Informe de auditoría
Academic Research Skills
Academic Research Skills for Claude Code: research → write → review → revise → finalize
38K Estrellas · Informe de auditoría
GPT Researcher
Run autonomous deep research over web and local sources
28K Estrellas · Informe de auditoría