Skill 审计报告
neo4j-driver-dotnet-skill 审计报告.
Neo4j .NET Driver v6 — IDriver lifecycle, DI registration (singleton), ExecutableQuery
OpenAgentSkill 信任评分
OpenAgentSkill 信任评分
Trust Score 帮助 Agent 在安装前判断一个 Skill 是否足以进入候选清单。
GitHub 采用度
信息62
101 个 GitHub Stars
Star/Fork 活跃度
警告57
101 个 Star,35 个 Fork; 当前元数据中没有议题活跃度信息
近期维护
通过100
距上次推送 3 天
许可证清晰度
通过86
MIT
README/SKILL.md 完整度
通过86
元数据包含足够的用法与工作流上下文
依赖与运行时风险
失败38
command execution surface, credential or environment access
安装可用性
通过92
npx skills add neo4j-contrib/neo4j-skills --skill neo4j-driver-dotnet-skill
安装命令安全性
通过92
标准软件包或运行时安装路径
权限范围
失败18
secrets or environment access, shell or command execution
仓库证据
通过86
https://github.com/neo4j-contrib/neo4j-skills/tree/main/neo4j-driver-dotnet-skill
审查状态
信息66
可用 AI 审查数据
Agent 验证结果
信息54
暂未有 Agent 结果数据
检查项
安装与采用审查
安装路径
92
npx skills add neo4j-contrib/neo4j-skills --skill neo4j-driver-dotnet-skill
仓库
88
https://github.com/neo4j-contrib/neo4j-skills/tree/main/neo4j-driver-dotnet-skill
许可证
86
MIT
维护
100
距上次推送 3 天
AI 审查
55
The skill is purely informational and poses no security risk; however, it includes executable code examples that, if copied verbatim, could expose credentials if not handled properly (mitigated by strong best-practice guidance).
README/SKILL.md 完整度
86
Usable description available
依赖风险
38
command execution surface, credential or environment access
安装命令安全性
92
标准软件包或运行时安装路径
权限范围
18
secrets or environment access, shell or command execution
Star/Fork 活跃度
57
101 个 Star,35 个 Fork; 当前元数据中没有议题活跃度信息
采用度
68
101 个 GitHub Stars
Financial decision safety
58
Research-only use: do not treat output as financial advice or execute a position without human approval.
警告
- Dependency or permission surface needs review
- Permission surface may require sandboxing
- Financial research output is not financial advice; require human review before any live investment decision
- The skill is purely informational and poses no security risk; however, it includes executable code examples that, if copied verbatim, could expose credentials if not handled properly (mitigated by strong best-practice guidance).
- The 'allowed-tools' include Bash and WebFetch, which could be used for unintended actions if the agent is not properly sandboxed, but the skill itself contains no instructions for executing arbitrary commands beyond standard development practices.
- Financial research output is not financial advice; require human review before any live investment decision.
- Quality score needs review
- Permission surface needs review: secrets or environment access, shell or command execution
- Stars/forks activity: 101 stars, 35 forks; issue activity unavailable in current metadata
- Dependency/runtime risk: command execution surface, credential or environment access
- Permission surface: secrets or environment access, shell or command execution
方法
本报告综合公开元数据、AI 审查输出、仓库活跃度、安装就绪度、OpenAgentSkill 事件、质量评分、信任检查和 Agent 安全门槛;它不是完整的源代码安全审计。
对比相近选项