Skill 审计报告

azure-ai 审计报告.

Use for Azure AI: Search, Speech, OpenAI, Document Intelligence. Helps with search, vector/hybrid search, speech-to-text, text-to-speech, transcription, OCR. WHEN: AI Search, query search, vector search, hybrid search, semantic search, speech-to-text, text-to-speech, transcribe, OCR, convert text to speech.

实验性 · 审查需审查生成于 2026年10月11日启发式元数据审计
74
审计
67
信任
67
质量
77
安全性
88
维护
92
安装

OpenAgentSkill 信任评分

67
人工审查

OpenAgentSkill 信任评分

Trust Score 帮助 Agent 在安装前判断一个 Skill 是否足以进入候选清单。

GitHub 采用度

信息

62

248 个 GitHub Stars

Star/Fork 活跃度

信息

62

248 个 Star,196 个 Fork; 当前元数据中没有议题活跃度信息

近期维护

通过

88

距上次推送 1 个月

许可证清晰度

通过

86

MIT

README/SKILL.md 完整度

信息

76

公开元数据需要更完整的 README/SKILL.md 上下文

依赖与运行时风险

信息

72

命令执行范围

安装可用性

通过

92

npx skills add microsoft/GitHub-Copilot-for-Azure --skill azure-ai

安装命令安全性

通过

92

标准软件包或运行时安装路径

权限范围

信息

62

shell or command execution, filesystem or document access

仓库证据

通过

86

https://github.com/microsoft/GitHub-Copilot-for-Azure/tree/main/plugins/azure-skills/skills/azure-ai

审查状态

信息

66

可用 AI 审查数据

Agent 验证结果

信息

54

暂未有 Agent 结果数据

检查项

安装与采用审查

6 通过 · 8 需审查

安装路径

92

通过

npx skills add microsoft/GitHub-Copilot-for-Azure --skill azure-ai

仓库

88

通过

https://github.com/microsoft/GitHub-Copilot-for-Azure/tree/main/plugins/azure-skills/skills/azure-ai

许可证

86

通过

MIT

维护

88

通过

距上次推送 1 个月

AI 审查

55

检查

SKILL.md does not instruct the agent to treat retrieved search results, OCR text, or transcriptions as untrusted data; malicious content could contain prompt-injection instructions.

README/SKILL.md 完整度

84

通过

Usable description available

依赖风险

72

检查

命令执行范围

安装命令安全性

92

通过

标准软件包或运行时安装路径

权限范围

62

检查

shell or command execution, filesystem or document access

Star/Fork 活跃度

62

检查

248 个 Star,196 个 Fork; 当前元数据中没有议题活跃度信息

采用度

68

信息

248 个 GitHub Stars

警告

  • SKILL.md does not instruct the agent to treat retrieved search results, OCR text, or transcriptions as untrusted data; malicious content could contain prompt-injection instructions.
  • No explicit limitations, failure modes, or safe operating boundaries are documented (e.g., what the skill should not do, missing index/service errors, access-denied handling).
  • Metadata version is '0.0.0-placeholder', suggesting the skill is not finalized.
  • Quality score needs review

方法

本报告综合公开元数据、AI 审查输出、仓库活跃度、安装就绪度、OpenAgentSkill 事件、质量评分、信任检查和 Agent 安全门槛;它不是完整的源代码安全审计。