Vorinstallations-Eval
archive Eval-Bericht.
Eine maschinenlesbare Installationsentscheidung für Agents: Task-Fit, Trust Score, Audit Score, Installationssicherheit, Berechtigungsumfang und ein konkreter Validierungsplan vor dem Einsatz im Workspace.
do not auto install
Permission surface: secrets or environment access, filesystem or document access
Erforderliche Gates
Prüfungen, die ein Agent vor der Installation bestehen muss
Aufgabenpassung
84
Task wording matches this skill metadata.
- Evaluate archive before installing it in an agent workflow
- Recherche
- RAG and knowledge workflows; Claude Code teams; teams that value GitHub adoption signals
Installationspfad
92
Install handoff is available.
- npx skills add ReScienceLab/opc-skills --skill archive
Sicherheit des Installationsbefehls
92
Standard-Paket- oder Laufzeit-Installationspfad
- npx skills add ReScienceLab/opc-skills --skill archive
Vertrauenswert
71
Potentially useful, but at least one trust signal needs human inspection.
- Manuelle Prüfung
- 1.8K GitHub-Stars
- Apache-2.0
Audit-Score
78
Prüfung nötig
- Permission surface may require sandboxing
Agent-Sicherheitsprüfung
46
Sparse or mixed signals. Useful for discovery, but not for autonomous installation.
- Test manually in an isolated workspace and compare against safer alternatives.
- Hinweise auf Hochrisiko-Berechtigungen: Secrets or environment access
Lizenzklarheit
86
Apache-2.0
- Apache-2.0
Berechtigungsumfang
48
secrets or environment access, filesystem or document access
- Network access: medium
- Filesystem access: medium
- Secrets or environment access: high
Validierungsplan
Was der Agent als Nächstes tun sollte
- 1Inspect repository, README/SKILL.md, license, and recent commits before production use.
- 2Install in an isolated workspace or sandbox with no production secrets available.
- 3Run the smallest representative task and record files touched, commands run, network access, and outputs.
- 4Compare the selected skill against at least one alternative when the eval status is review or failed.
- 5Promote only after the agent reports a successful verification result and unresolved warnings are accepted.
Nicht verwenden, wenn
Bedingungen für eine andere Skill
- Teams, die ein vom Anbieter unterstütztes SLA benötigen
- production agents without a repository review
- The SessionStart hook loads .archive/MEMORY.md into the model context without sanitization or explicit untrusted-data boundaries. Archived content from previous sessions could contain prompt-injection-like instructions or sensitive material.
- Hinweise auf Hochrisiko-Berechtigungen: Secrets or environment access
- Permission surface may require sandboxing
- The skill instructs that .archive/ must be in .gitignore, but it does not verify or enforce this, so sensitive local notes could accidentally be committed.
Unterstützende Prüfungen
Vertrauenssignale hinter der Entscheidung
README/SKILL.md-Vollständigkeit
Warnung76
Öffentliche Metadaten benötigen mehr README/SKILL.md-Kontext
Aktuelle Wartung
Bestanden88
1 Monate seit dem letzten Push
Alternativen verfügbar
Bestanden82
Alternative skills are available for comparison.