Informe de auditoría del skill

modlens Informe de auditoría.

Plug-in vision for text-only models. Hard rule: when a file path or URL with an image extension (.png, .jpg, .jpeg, .webp, .gif, .heic, .heif) appears anywhere in the conversation (typed by the user, injected as a `[Image: source: <path>]` line, or inside a tag) and you cannot see that image's content, run this skill on it before any other approach: no self-built OCR, no PIL, no tesseract. Also triggers on pasted-image placeholders such as `[Image #1]` and `[Unsupported Image]`. If you can actually see the image, do not use this skill. When unsure, run `modlens guard` before the first read of a session: a deny verdict means the active model has native vision and must read the image itself. Runs the modlens CLI to convert the image into structured JSON evidence: every word transcribed, layout regions, semantics, visual clues. Also use when the user asks how to install, configure, or switch modlens providers (Gemini API key, OpenAI-compatible endpoints, Claude API or Claude Code CLI).

Bloqueado · BloquearRequiere revisiónGenerado 22 ago 2026Auditoría heurística de metadatos
80
Auditoría
70
Confianza
82
Calidad
71
Seguridad
100
Maintain
92
Instalar

Trust Score de OpenAgentSkill

70
Revisión manual

Trust Score de OpenAgentSkill

The Trust Score helps an agent decide whether a skill is safe enough to shortlist before installation.

Adopción en GitHub

Aprobado

86

3.3K estrellas de GitHub

Actividad de stars/forks

Info

77

3.3K estrellas y 89 forks; la actividad de issues no está disponible en los metadatos actuales

Mantenimiento reciente

Aprobado

100

2 días desde el último push

Claridad de licencia

Aprobado

86

MIT

Completitud de README/SKILL.md

Aprobado

86

Los metadatos incluyen suficiente contexto de uso y flujo de trabajo

Riesgo de dependencias/runtime

Advertencia

46

command execution surface, credential or environment access

Disponibilidad de instalación

Aprobado

92

npx skills add liustack/modlens --skill modlens

Seguridad del comando de instalación

Aprobado

92

Ruta estándar de paquete o instalación en tiempo de ejecución

Superficie de permisos

Fallido

18

secrets or environment access, shell or command execution

Evidencia del repositorio

Aprobado

86

https://github.com/liustack/modlens/tree/main/skills/modlens

Estado de revisión

Info

66

Hay datos de revisión por IA disponibles

Resultados comprobados por Agent

Info

54

Aún no hay datos de resultados del Agent

Comprobaciones

Revisión de instalación y adopción

7 Aprobado · 12 Requiere revisión

Ruta de instalación

92

Aprobado

npx skills add liustack/modlens --skill modlens

Repositorio

88

Aprobado

https://github.com/liustack/modlens/tree/main/skills/modlens

Licencia

86

Aprobado

MIT

Mantenimiento

100

Aprobado

2 días desde el último push

Revisión por IA

55

Revisar

The SKILL.md excerpt appears truncated mid-sentence in the 'Failures' section; ensure the full file is complete and not malformed.

Completitud de README/SKILL.md

86

Aprobado

Usable description available

Riesgo de dependencias

46

Corregir

command execution surface, credential or environment access

Seguridad del comando de instalación

92

Aprobado

Ruta estándar de paquete o instalación en tiempo de ejecución

Superficie de permisos

18

Corregir

secrets or environment access, shell or command execution

Actividad de stars/forks

77

Revisar

3.3K estrellas y 89 forks; la actividad de issues no está disponible en los metadatos actuales

Adopción

88

Aprobado

3.3K estrellas de GitHub

Advertencias

  • Dependency or permission surface needs review
  • Permission surface may require sandboxing
  • The SKILL.md excerpt appears truncated mid-sentence in the 'Failures' section; ensure the full file is complete and not malformed.
  • The skill relies on external network calls and third-party providers, which may raise privacy concerns; this is disclosed but should be emphasized to users.
  • Quality score needs review
  • Permission surface needs review: secrets or environment access, shell or command execution
  • Dependency/runtime risk: command execution surface, credential or environment access
  • Permission surface: secrets or environment access, shell or command execution

Método

This report combines public metadata, AI review output, repository freshness, install readiness, OpenAgentSkill events, quality scoring, trust checks, and the agent safety gate. It is not a full source-code security review.

Comparar opciones cercanas

Skills relacionados para auditar después