스킬 감사 보고서
rl-protect-scan 감사 보고서.
Supply chain security gate. MUST be invoked BEFORE running any install command (npm install, pip install, gem install), before editing manifest/lock files (package.json, requirements.txt, pyproject.toml, Gemfile), before writing imports/requires for packages not already in the project, and before recommending packages. Also invoke when updating or downgrading package versions. This skill scans packages with rl-protect and gates the action on the result. Never skip — invoke proactively even if the user did not ask for a scan.
OpenAgentSkill 신뢰 점수
OpenAgentSkill 신뢰 점수
Trust Score는 설치 전에 후보 목록에 넣을 만큼 안전한지 Agent가 판단하도록 돕습니다.
GitHub 채택도
경고48
GitHub 스타 27
스타/포크 활동
경고43
스타 27, 포크 0; 현재 메타데이터에서 이슈 활동을 확인할 수 없습니다
최근 유지보수
통과88
마지막 푸시 후 2개월
라이선스 명확성
통과86
MIT
README/SKILL.md 완성도
통과86
메타데이터에 충분한 사용 및 워크플로 맥락이 포함되어 있습니다
의존성/런타임 위험
경고44
command execution surface, credential or environment access
설치 가능 여부
통과92
npx skills add reversinglabs/rl-protect-skills --skill rl-protect-scan
설치 명령 안전성
통과92
표준 패키지 또는 런타임 설치 경로
권한 범위
실패22
secrets or environment access, shell or command execution
저장소 근거
통과86
https://github.com/reversinglabs/rl-protect-skills/tree/main/plugins/rl-protect-scan/skills/rl-protect-scan
검토 상태
경고46
AI 검토 승인이 없습니다
Agent 검증 결과
정보54
아직 Agent 결과 데이터가 없습니다
검사
설치 및 채택 검토
설치 경로
92
npx skills add reversinglabs/rl-protect-skills --skill rl-protect-scan
저장소
88
https://github.com/reversinglabs/rl-protect-skills/tree/main/plugins/rl-protect-scan/skills/rl-protect-scan
라이선스
86
MIT
유지보수
88
마지막 푸시 후 2개월
AI 검토
55
Review approval is missing
README/SKILL.md 완성도
86
Usable description available
의존성 위험
44
command execution surface, credential or environment access
설치 명령 안전성
92
표준 패키지 또는 런타임 설치 경로
권한 범위
22
secrets or environment access, shell or command execution
스타/포크 활동
43
스타 27, 포크 0; 현재 메타데이터에서 이슈 활동을 확인할 수 없습니다
채택도
42
GitHub 스타 27
경고
- Dependency or permission surface needs review
- Permission surface may require sandboxing
- Low GitHub adoption signal
- AI 검토 승인이 없습니다
- Quality score needs review
- Permission surface needs review: secrets or environment access, shell or command execution
- GitHub adoption: 27 GitHub stars
- Stars/forks activity: 27 stars, 0 forks; issue activity unavailable in current metadata
- Dependency/runtime risk: command execution surface, credential or environment access
- Permission surface: secrets or environment access, shell or command execution
- Review status: AI review approval is missing
방법
이 보고서는 공개 메타데이터, AI 검토 결과, 저장소 최신성, 설치 준비 상태, OpenAgentSkill 이벤트, 품질 점수, 신뢰 검사와 Agent 안전 게이트를 결합합니다. 전체 소스 코드 보안 감사는 아닙니다.
가까운 옵션 비교
다음으로 감사할 관련 스킬
Wazuh
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
16K 스타 · 감사 보고서
Maigret
🕵️♂️ Collect a dossier on a person by username from 3000+ sites
33K 스타 · 감사 보고서
Nuclei
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
29K 스타 · 감사 보고서