Laporan audit skill

data-science-python-stack Laporan audit.

Opinionated Python stack for data-science / ML work — one library per job, organized into tiers (mandatory / user choice / optional / transitive). SKILL.md is the index; per-library `references/<library>.md` files carry scope, "pick this when" / "pick something else when", and pairings. TRIGGER when (any of these): (1) **a library import fails** in this stack's domain — the answer is install, not substitute (see § "Missing dependency"); (2) **a library choice has to be made** — explicitly (the user asks "which library for X?") or implicitly (code is about to introduce a new dependency, or the project is being scaffolded and the tabular library hasn't been picked yet); (3) starting a new Python data-science / ML project; (4) the user or current code reaches for a substitute outside the stack (xgboost, lightgbm, black, isort, flake8, poetry, hatch), or reaches for `mlflow` to log params/metrics, or for `cross_val_score` + handwritten reporting — redirect: tracking → `skore` Project API,

Diblokir · BlokirPerlu ditinjauDihasilkan 11 Okt 2026Audit metadata heuristik
76
Audit
73
Kepercayaan
62
Kualitas
73
Keamanan
100
Maintain
92
Pasang

Trust Score OpenAgentSkill

73
Shortlist kuat

Trust Score OpenAgentSkill

The Trust Score helps an agent decide whether a skill is safe enough to shortlist before installation.

Adopsi GitHub

Info

62

122 star GitHub

Aktivitas star/fork

Peringatan

51

122 star dan 8 fork; aktivitas issue tidak tersedia dalam metadata saat ini

Pemeliharaan terbaru

Lulus

100

30 hari sejak push

Kejelasan lisensi

Lulus

86

BSD-3-Clause

Kelengkapan README/SKILL.md

Lulus

86

Metadata memuat konteks penggunaan dan alur kerja yang cukup

Risiko dependensi/runtime

Info

64

credential or environment access, network or browser surface

Ketersediaan pemasangan

Lulus

92

npx skills add probabl-ai/skills --skill data-science-python-stack

Keamanan perintah pemasangan

Lulus

92

Jalur pemasangan paket atau runtime standar

Cakupan izin

Gagal

22

secrets or environment access, shell or command execution

Bukti repositori

Lulus

86

https://github.com/probabl-ai/skills/tree/main/skills/data-science-python-stack

Status peninjauan

Peringatan

46

Persetujuan tinjauan AI belum ada

Hasil terbukti Agent

Info

54

Belum ada data hasil Agent

Pemeriksaan

Tinjauan pemasangan dan adopsi

6 Lulus · 14 Perlu ditinjau

Jalur pemasangan

92

Lulus

npx skills add probabl-ai/skills --skill data-science-python-stack

Repositori

88

Lulus

https://github.com/probabl-ai/skills/tree/main/skills/data-science-python-stack

Lisensi

86

Lulus

BSD-3-Clause

Pemeliharaan

100

Lulus

30 hari sejak push

Tinjauan AI

55

Periksa

Review approval is missing

Kelengkapan README/SKILL.md

86

Lulus

Usable description available

Risiko dependensi

64

Periksa

credential or environment access, network or browser surface

Keamanan perintah pemasangan

92

Lulus

Jalur pemasangan paket atau runtime standar

Cakupan izin

22

Perbaiki

secrets or environment access, shell or command execution

Aktivitas star/fork

51

Perbaiki

122 star dan 8 fork; aktivitas issue tidak tersedia dalam metadata saat ini

Adopsi

68

Info

122 star GitHub

Financial decision safety

58

Periksa

Research-only use: do not treat output as financial advice or execute a position without human approval.

Peringatan

  • Permission surface may require sandboxing
  • Financial research output is not financial advice; require human review before any live investment decision
  • Persetujuan tinjauan AI belum ada
  • Financial research output is not financial advice; require human review before any live investment decision.
  • Quality score needs review
  • Permission surface needs review: secrets or environment access, shell or command execution
  • Stars/forks activity: 122 stars, 8 forks; issue activity unavailable in current metadata
  • Permission surface: secrets or environment access, shell or command execution
  • Review status: AI review approval is missing

Metode

This report combines public metadata, AI review output, repository freshness, install readiness, OpenAgentSkill events, quality scoring, trust checks, and the agent safety gate. It is not a full source-code security review.

Bandingkan opsi sekitar

Skill terkait untuk diaudit berikutnya