Vorinstallations-Eval
critique Eval-Bericht.
Eine maschinenlesbare Installationsentscheidung für Agents: Task-Fit, Trust Score, Audit Score, Installationssicherheit, Berechtigungsumfang und ein konkreter Validierungsplan vor dem Einsatz im Workspace.
do not auto install
Audit score: Risky
Erforderliche Gates
Prüfungen, die ein Agent vor der Installation bestehen muss
Aufgabenpassung
94
Task wording matches this skill metadata.
- Evaluate critique before installing it in an agent workflow
- Sicherheit
- GitHub automation workflows; Claude Code teams; teams that value GitHub adoption signals
Installationspfad
92
Install handoff is available.
- npx skills add nexu-io/open-design --skill critique
Sicherheit des Installationsbefehls
92
Standard-Paket- oder Laufzeit-Installationspfad
- npx skills add nexu-io/open-design --skill critique
Vertrauenswert
88
Strong OpenAgentSkill Trust Score across adoption, recent maintenance, license clarity, documentation, dependency/runtime risk, install safety, permission surface, and install availability.
- Produktionskandidat
- 90K GitHub-Stars
- Apache-2.0
Audit-Score
92
Riskant
- Potential broker, wallet, exchange, or real-money execution surface; sandbox and explicit approval are required
Agent-Sicherheitsprüfung
76
This skill should not be selected by an agent without explicit human security review.
- Do not auto-install. Inspect the source, dependencies, and permission surface first.
- Audit risk exceeds the requested agent policy
Lizenzklarheit
86
Apache-2.0
- Apache-2.0
Berechtigungsumfang
86
Dateisystem- oder Dokumentzugriff
- Network access: medium
- Filesystem access: medium
Validierungsplan
Was der Agent als Nächstes tun sollte
- 1Inspect repository, README/SKILL.md, license, and recent commits before production use.
- 2Install in an isolated workspace or sandbox with no production secrets available.
- 3Run the smallest representative task and record files touched, commands run, network access, and outputs.
- 4Compare the selected skill against at least one alternative when the eval status is review or failed.
- 5Promote only after the agent reports a successful verification result and unresolved warnings are accepted.
Nicht verwenden, wenn
Bedingungen für eine andere Skill
- Teams, die ein vom Anbieter unterstütztes SLA benötigen
- Hochregulierte Umgebungen ohne interne Sicherheitsprüfung
- No major risk signals from current metadata
- Audit risk risky exceeds max_risk=medium
- Potential broker, wallet, exchange, or real-money execution surface; sandbox and explicit approval are required
- This skill may touch real-money trading, broker, wallet, or exchange operations; use only in a sandbox with explicit approval.
Unterstützende Prüfungen
Vertrauenssignale hinter der Entscheidung
README/SKILL.md-Vollständigkeit
Bestanden86
Metadaten enthalten ausreichend Nutzungs- und Workflow-Kontext
Aktuelle Wartung
Bestanden100
2 Tage seit dem letzten Push
Alternativen verfügbar
Bestanden82
Alternative skills are available for comparison.