Laporan audit skill
neo4j-driver-dotnet-skill Laporan audit.
Neo4j .NET Driver v6 — IDriver lifecycle, DI registration (singleton), ExecutableQuery
Trust Score OpenAgentSkill
Trust Score OpenAgentSkill
The Trust Score helps an agent decide whether a skill is safe enough to shortlist before installation.
Adopsi GitHub
Info62
101 star GitHub
Aktivitas star/fork
Peringatan57
101 star dan 35 fork; aktivitas issue tidak tersedia dalam metadata saat ini
Pemeliharaan terbaru
Lulus100
2 hari sejak push
Kejelasan lisensi
Lulus86
MIT
Kelengkapan README/SKILL.md
Lulus86
Metadata memuat konteks penggunaan dan alur kerja yang cukup
Risiko dependensi/runtime
Gagal38
command execution surface, credential or environment access
Ketersediaan pemasangan
Lulus92
npx skills add neo4j-contrib/neo4j-skills --skill neo4j-driver-dotnet-skill
Keamanan perintah pemasangan
Lulus92
Jalur pemasangan paket atau runtime standar
Cakupan izin
Gagal18
secrets or environment access, shell or command execution
Bukti repositori
Lulus86
https://github.com/neo4j-contrib/neo4j-skills/tree/main/neo4j-driver-dotnet-skill
Status peninjauan
Info66
Data tinjauan AI tersedia
Hasil terbukti Agent
Info54
Belum ada data hasil Agent
Pemeriksaan
Tinjauan pemasangan dan adopsi
Jalur pemasangan
92
npx skills add neo4j-contrib/neo4j-skills --skill neo4j-driver-dotnet-skill
Repositori
88
https://github.com/neo4j-contrib/neo4j-skills/tree/main/neo4j-driver-dotnet-skill
Lisensi
86
MIT
Pemeliharaan
100
2 hari sejak push
Tinjauan AI
55
The skill is purely informational and poses no security risk; however, it includes executable code examples that, if copied verbatim, could expose credentials if not handled properly (mitigated by strong best-practice guidance).
Kelengkapan README/SKILL.md
86
Usable description available
Risiko dependensi
38
command execution surface, credential or environment access
Keamanan perintah pemasangan
92
Jalur pemasangan paket atau runtime standar
Cakupan izin
18
secrets or environment access, shell or command execution
Aktivitas star/fork
57
101 star dan 35 fork; aktivitas issue tidak tersedia dalam metadata saat ini
Adopsi
68
101 star GitHub
Financial decision safety
58
Research-only use: do not treat output as financial advice or execute a position without human approval.
Peringatan
- Dependency or permission surface needs review
- Permission surface may require sandboxing
- Financial research output is not financial advice; require human review before any live investment decision
- The skill is purely informational and poses no security risk; however, it includes executable code examples that, if copied verbatim, could expose credentials if not handled properly (mitigated by strong best-practice guidance).
- The 'allowed-tools' include Bash and WebFetch, which could be used for unintended actions if the agent is not properly sandboxed, but the skill itself contains no instructions for executing arbitrary commands beyond standard development practices.
- Financial research output is not financial advice; require human review before any live investment decision.
- Quality score needs review
- Permission surface needs review: secrets or environment access, shell or command execution
- Stars/forks activity: 101 stars, 35 forks; issue activity unavailable in current metadata
- Dependency/runtime risk: command execution surface, credential or environment access
- Permission surface: secrets or environment access, shell or command execution
Metode
This report combines public metadata, AI review output, repository freshness, install readiness, OpenAgentSkill events, quality scoring, trust checks, and the agent safety gate. It is not a full source-code security review.
Bandingkan opsi sekitar