Skill 审计报告

quant-buddy-view 审计报告.

QBV / quant-buddy-view(用户可能写成 /quant-buddy-view、/qbv、qbv 或 QBV)用于把量化数据做成「公开可分享、实时取数」的网页看板/落地页。 Use this skill when the user asks to create, update, publish, verify, retrofit, or reuse a Quant Buddy dashboard/static page/template, including shareable pages, public URLs, formula packages, share shell, cover/essence cards, poster/share behavior, single-stock profile pages, valuation/financial profile pages, index-anomaly boards, multi-factor screeners, and commodity daily pages. 配合 quant-buddy-skill 使用:简单单一 A 股综合分析可在 trace begin 后直接用 static_page.py new_asset_page 返回实时页面;用户给出既有 QuantBuddy 活页 URL 并要求解读时,直接用 static_page.py interpret 读取该页实时数据,不下载 HTML、不暴露签名,也不进入模板或建页流程;其他固定页面请求先用 templates/template 选择带 recommend 标签的在线范式页。自建实时页先按数据性质选择通道:普通行情、估值和财务优先 Data Grant,自定义计算才验证并注册 Formula Package;两类凭证可在同页混用,随后替换凭证/文案、浏览器验收并发布。默认不从本地历史样板目录或低质 HTML 骨架起步。 用户显式唤起 /quant-buddy-view、/qbv、qbv 或 QBV,且请求不是纯咨询/代码维护/文档解释时,默认视为可分享活页任务:简单单一 A 股分析走 new_asset_page 快速终态;其余请求查官方精选+社区范式卡判定 direct/fork/unmatched。默认 dire

已阻止 · 阻止需审查生成于 2026年10月11日启发式元数据审计
72
审计
68
信任
60
质量
74
安全性
88
维护
92
安装

OpenAgentSkill 信任评分

68
人工审查

OpenAgentSkill 信任评分

Trust Score 帮助 Agent 在安装前判断一个 Skill 是否足以进入候选清单。

GitHub 采用度

警告

48

45 个 GitHub Stars

Star/Fork 活跃度

警告

43

45 个 Star,8 个 Fork; 当前元数据中没有议题活跃度信息

近期维护

通过

88

距上次推送 1 个月

许可证清晰度

通过

86

MIT

README/SKILL.md 完整度

信息

76

公开元数据需要更完整的 README/SKILL.md 上下文

依赖与运行时风险

警告

46

command execution surface, credential or environment access

安装可用性

通过

92

npx skills add pseudo-longinus/quant-buddy-view --skill quant-buddy-view

安装命令安全性

通过

92

标准软件包或运行时安装路径

权限范围

失败

22

secrets or environment access, shell or command execution

仓库证据

通过

86

https://github.com/pseudo-longinus/quant-buddy-view/tree/main/skills/quant-buddy-view

审查状态

通过

88

可用 AI 审查数据

Agent 验证结果

信息

54

暂未有 Agent 结果数据

检查项

安装与采用审查

7 通过 · 16 需审查

安装路径

92

通过

npx skills add pseudo-longinus/quant-buddy-view --skill quant-buddy-view

仓库

88

通过

https://github.com/pseudo-longinus/quant-buddy-view/tree/main/skills/quant-buddy-view

许可证

86

通过

MIT

维护

88

通过

距上次推送 1 个月

AI 审查

88

通过

Approved with no listed issues

README/SKILL.md 完整度

84

通过

Usable description available

依赖风险

46

修复

command execution surface, credential or environment access

安装命令安全性

92

通过

标准软件包或运行时安装路径

权限范围

22

修复

secrets or environment access, shell or command execution

Star/Fork 活跃度

43

修复

45 个 Star,8 个 Fork; 当前元数据中没有议题活跃度信息

采用度

42

检查

45 个 GitHub Stars

Financial decision safety

58

检查

Research-only use: do not treat output as financial advice or execute a position without human approval.

警告

  • Dependency or permission surface needs review
  • Permission surface may require sandboxing
  • Financial research output is not financial advice; require human review before any live investment decision
  • Low GitHub adoption signal
  • Financial research output is not financial advice; require human review before any live investment decision.
  • Quality score needs review
  • Permission surface needs review: secrets or environment access, shell or command execution
  • GitHub adoption: 45 GitHub stars
  • Stars/forks activity: 45 stars, 8 forks; issue activity unavailable in current metadata
  • Dependency/runtime risk: command execution surface, credential or environment access
  • Permission surface: secrets or environment access, shell or command execution

方法

本报告综合公开元数据、AI 审查输出、仓库活跃度、安装就绪度、OpenAgentSkill 事件、质量评分、信任检查和 Agent 安全门槛;它不是完整的源代码安全审计。

对比相近选项

下一步可审计的相关 Skill