Informe de auditoría del skill
gza-code-review-full Informe de auditoría.
Comprehensive pre-release code review assessing test coverage, code duplication, and component interactions
Trust Score de OpenAgentSkill
Trust Score de OpenAgentSkill
The Trust Score helps an agent decide whether a skill is safe enough to shortlist before installation.
Adopción en GitHub
Fallido30
11 estrellas de GitHub
Actividad de stars/forks
Fallido32
11 estrellas y 1 forks; la actividad de issues no está disponible en los metadatos actuales
Mantenimiento reciente
Aprobado100
1 días desde el último push
Claridad de licencia
Aprobado86
MIT
Completitud de README/SKILL.md
Aprobado86
Los metadatos incluyen suficiente contexto de uso y flujo de trabajo
Riesgo de dependencias/runtime
Fallido38
command execution surface, credential or environment access
Disponibilidad de instalación
Aprobado92
npx skills add mhawthorne/gza --skill gza-code-review-full
Seguridad del comando de instalación
Aprobado92
Ruta estándar de paquete o instalación en tiempo de ejecución
Superficie de permisos
Fallido18
secrets or environment access, shell or command execution
Evidencia del repositorio
Aprobado86
https://github.com/mhawthorne/gza/tree/main/src/gza/skills/gza-code-review-full
Estado de revisión
Info66
Hay datos de revisión por IA disponibles
Resultados comprobados por Agent
Info54
Aún no hay datos de resultados del Agent
Comprobaciones
Revisión de instalación y adopción
Ruta de instalación
92
npx skills add mhawthorne/gza --skill gza-code-review-full
Repositorio
88
https://github.com/mhawthorne/gza/tree/main/src/gza/skills/gza-code-review-full
Licencia
86
MIT
Mantenimiento
100
1 días desde el último push
Revisión por IA
55
Skill is highly specific to the gza codebase, limiting reusability for other projects.
Completitud de README/SKILL.md
86
Usable description available
Riesgo de dependencias
38
command execution surface, credential or environment access
Seguridad del comando de instalación
92
Ruta estándar de paquete o instalación en tiempo de ejecución
Superficie de permisos
18
secrets or environment access, shell or command execution
Actividad de stars/forks
32
11 estrellas y 1 forks; la actividad de issues no está disponible en los metadatos actuales
Adopción
42
11 estrellas de GitHub
Advertencias
- Dependency or permission surface needs review
- Permission surface may require sandboxing
- Skill is highly specific to the gza codebase, limiting reusability for other projects.
- Allowed bash commands are constrained to safe patterns, but the skill does not explicitly warn about potential side effects of running tests or mypy (e.g., network access, resource usage).
- The SKILL.md does not include a 'Limitations' section explicitly, though the scope is implied.
- Low GitHub adoption signal
- Quality score needs review
- Permission surface needs review: secrets or environment access, shell or command execution
- GitHub adoption: 11 GitHub stars
- Stars/forks activity: 11 stars, 1 forks; issue activity unavailable in current metadata
- Dependency/runtime risk: command execution surface, credential or environment access
- Permission surface: secrets or environment access, shell or command execution
Método
This report combines public metadata, AI review output, repository freshness, install readiness, OpenAgentSkill events, quality scoring, trust checks, and the agent safety gate. It is not a full source-code security review.
Comparar opciones cercanas
Skills relacionados para auditar después
Code Review
Review a branch or diff against repository standards and the originating spec in two independent analysis passes.
169K Estrellas · Informe de auditoría
Grill With Docs
A relentless interview that pressure-tests a plan against the codebase, sharpens domain language, and updates CONTEXT.md and ADRs when decisions become durable.
165K Estrellas · Informe de auditoría
To Spec
Turn the current conversation and codebase context into a structured implementation spec, then publish it to the configured project issue tracker.
165K Estrellas · Informe de auditoría