Laporan audit skill

gza-code-review-interactive Laporan audit.

Review changes on current branch and output a structured review. Optionally post to PR with --pr flag, or apply non-blocking follow-ups inline with --apply-followups.

Eksperimental · TinjauPerlu ditinjauDihasilkan 22 Agu 2026Audit metadata heuristik
73
Audit
68
Kepercayaan
57
Kualitas
75
Keamanan
100
Maintain
92
Pasang

Trust Score OpenAgentSkill

68
Tinjauan manual

Trust Score OpenAgentSkill

The Trust Score helps an agent decide whether a skill is safe enough to shortlist before installation.

Adopsi GitHub

Gagal

30

11 star GitHub

Aktivitas star/fork

Gagal

32

11 star dan 1 fork; aktivitas issue tidak tersedia dalam metadata saat ini

Pemeliharaan terbaru

Lulus

100

1 hari sejak push

Kejelasan lisensi

Lulus

86

MIT

Kelengkapan README/SKILL.md

Lulus

86

Metadata memuat konteks penggunaan dan alur kerja yang cukup

Risiko dependensi/runtime

Info

72

Cakupan eksekusi perintah

Ketersediaan pemasangan

Lulus

92

npx skills add mhawthorne/gza --skill gza-code-review-interactive

Keamanan perintah pemasangan

Lulus

92

Jalur pemasangan paket atau runtime standar

Cakupan izin

Peringatan

50

shell or command execution, filesystem or document access

Bukti repositori

Lulus

86

https://github.com/mhawthorne/gza/tree/main/src/gza/skills/gza-code-review-interactive

Status peninjauan

Info

66

Data tinjauan AI tersedia

Hasil terbukti Agent

Info

54

Belum ada data hasil Agent

Pemeriksaan

Tinjauan pemasangan dan adopsi

6 Lulus · 13 Perlu ditinjau

Jalur pemasangan

92

Lulus

npx skills add mhawthorne/gza --skill gza-code-review-interactive

Repositori

88

Lulus

https://github.com/mhawthorne/gza/tree/main/src/gza/skills/gza-code-review-interactive

Lisensi

86

Lulus

MIT

Pemeliharaan

100

Lulus

1 hari sejak push

Tinjauan AI

55

Periksa

The skill reads AGENTS.md, REVIEW.md, and project docs as context for the review subagent without explicitly stating that these files should be treated as untrusted data. A malicious repo could inject instructions into these files to influence the subagent's behavior (prompt injection).

Kelengkapan README/SKILL.md

86

Lulus

Usable description available

Risiko dependensi

72

Periksa

Cakupan eksekusi perintah

Keamanan perintah pemasangan

92

Lulus

Jalur pemasangan paket atau runtime standar

Cakupan izin

50

Perbaiki

shell or command execution, filesystem or document access

Aktivitas star/fork

32

Perbaiki

11 star dan 1 fork; aktivitas issue tidak tersedia dalam metadata saat ini

Adopsi

42

Periksa

11 star GitHub

Peringatan

  • Permission surface may require sandboxing
  • The skill reads AGENTS.md, REVIEW.md, and project docs as context for the review subagent without explicitly stating that these files should be treated as untrusted data. A malicious repo could inject instructions into these files to influence the subagent's behavior (prompt injection).
  • Low GitHub adoption signal
  • Quality score needs review
  • Permission surface needs review: shell or command execution, filesystem or document access
  • GitHub adoption: 11 GitHub stars
  • Stars/forks activity: 11 stars, 1 forks; issue activity unavailable in current metadata
  • Permission surface: shell or command execution, filesystem or document access

Metode

This report combines public metadata, AI review output, repository freshness, install readiness, OpenAgentSkill events, quality scoring, trust checks, and the agent safety gate. It is not a full source-code security review.

Bandingkan opsi sekitar

Skill terkait untuk diaudit berikutnya