Laporan audit skill

grok-build-cli Laporan audit.

Invoke the locally installed Grok Build CLI from Codex and return Grok's response. Use whenever the user asks Codex to call, consult, run, or delegate a prompt to Grok or Grok Build, including Grok web/X searches and agentic Grok tasks. This Skill covers only the invocation mechanism, process monitoring, and response capture; it does not prescribe the task itself.

Diblokir · BlokirPerlu ditinjauDihasilkan 11 Okt 2026Audit metadata heuristik
76
Audit
68
Kepercayaan
75
Kualitas
74
Keamanan
88
Maintain
92
Pasang

Trust Score OpenAgentSkill

68
Tinjauan manual

Trust Score OpenAgentSkill

The Trust Score helps an agent decide whether a skill is safe enough to shortlist before installation.

Adopsi GitHub

Lulus

86

1.4K star GitHub

Aktivitas star/fork

Info

77

1.4K star dan 162 fork; aktivitas issue tidak tersedia dalam metadata saat ini

Pemeliharaan terbaru

Lulus

88

1 bulan sejak push

Kejelasan lisensi

Lulus

86

NOASSERTION

Kelengkapan README/SKILL.md

Lulus

86

Metadata memuat konteks penggunaan dan alur kerja yang cukup

Risiko dependensi/runtime

Peringatan

54

command execution surface, credential or environment access

Ketersediaan pemasangan

Lulus

92

npx skills add Pluviobyte/rnskill --skill grok-build-cli

Keamanan perintah pemasangan

Lulus

92

Jalur pemasangan paket atau runtime standar

Cakupan izin

Gagal

36

secrets or environment access, shell or command execution

Bukti repositori

Lulus

86

https://github.com/Pluviobyte/rnskill/tree/main/skills/grok-build-cli

Status peninjauan

Info

66

Data tinjauan AI tersedia

Hasil terbukti Agent

Info

54

Belum ada data hasil Agent

Pemeriksaan

Tinjauan pemasangan dan adopsi

7 Lulus · 13 Perlu ditinjau

Jalur pemasangan

92

Lulus

npx skills add Pluviobyte/rnskill --skill grok-build-cli

Repositori

88

Lulus

https://github.com/Pluviobyte/rnskill/tree/main/skills/grok-build-cli

Lisensi

86

Lulus

NOASSERTION

Pemeliharaan

88

Lulus

1 bulan sejak push

Tinjauan AI

55

Periksa

No license file or SPDX license identifier is present; GitHub reports NOASSERTION, so reuse and attribution terms are unclear.

Kelengkapan README/SKILL.md

86

Lulus

Usable description available

Risiko dependensi

54

Perbaiki

command execution surface, credential or environment access

Keamanan perintah pemasangan

92

Lulus

Jalur pemasangan paket atau runtime standar

Cakupan izin

36

Perbaiki

secrets or environment access, shell or command execution

Aktivitas star/fork

77

Periksa

1.4K star dan 162 fork; aktivitas issue tidak tersedia dalam metadata saat ini

Adopsi

88

Lulus

1.4K star GitHub

Peringatan

  • Dependency or permission surface needs review
  • Permission surface may require sandboxing
  • No license file or SPDX license identifier is present; GitHub reports NOASSERTION, so reuse and attribution terms are unclear.
  • The SKILL.md suggests `grok --single 'PROMPT'`, which places prompt text directly in a shell command. A prompt containing quotes or shell metacharacters could break out of the quoted argument and cause unintended command execution.
  • Setup is assumed: the skill does not explain how to install/configure the `grok` CLI or how to handle cases where `grok models` fails besides reporting and offering `grok login`.
  • Quality score needs review
  • Permission surface needs review: secrets or environment access, shell or command execution
  • Dependency/runtime risk: command execution surface, credential or environment access
  • Permission surface: secrets or environment access, shell or command execution

Metode

This report combines public metadata, AI review output, repository freshness, install readiness, OpenAgentSkill events, quality scoring, trust checks, and the agent safety gate. It is not a full source-code security review.

Bandingkan opsi sekitar

Skill terkait untuk diaudit berikutnya