스킬 감사 보고서
omh-commit-pr-authoring 감사 보고서.
[omh] Commit message or pull-request body to write for a change: draft it in the repository's own convention, with `Tested:` listing only commands observed to run and everything prepared but not run under `Not-tested:`. Use when the user says: commit-pr-authoring, commit message, commit messages, write the commit message, draft the commit message, commit body, squash message, pr body.
OpenAgentSkill 신뢰 점수
OpenAgentSkill 신뢰 점수
Trust Score는 설치 전에 후보 목록에 넣을 만큼 안전한지 Agent가 판단하도록 돕습니다.
GitHub 채택도
통과86
GitHub 스타 3.2K
스타/포크 활동
정보77
스타 3.2K, 포크 244; 현재 메타데이터에서 이슈 활동을 확인할 수 없습니다
최근 유지보수
통과100
마지막 푸시 후 5일
라이선스 명확성
통과86
MIT
README/SKILL.md 완성도
통과86
메타데이터에 충분한 사용 및 워크플로 맥락이 포함되어 있습니다
의존성/런타임 위험
정보64
credential or environment access, network or browser surface
설치 가능 여부
통과92
npx skills add rlaope/oh-my-hermes --skill omh-commit-pr-authoring
설치 명령 안전성
통과92
표준 패키지 또는 런타임 설치 경로
권한 범위
실패22
secrets or environment access, shell or command execution
저장소 근거
통과86
https://github.com/rlaope/oh-my-hermes/tree/main/agent-skills/omh-commit-pr-authoring
검토 상태
정보66
AI 검토 데이터를 사용할 수 있습니다
Agent 검증 결과
정보54
아직 Agent 결과 데이터가 없습니다
검사
설치 및 채택 검토
설치 경로
92
npx skills add rlaope/oh-my-hermes --skill omh-commit-pr-authoring
저장소
88
https://github.com/rlaope/oh-my-hermes/tree/main/agent-skills/omh-commit-pr-authoring
라이선스
86
MIT
유지보수
100
마지막 푸시 후 5일
AI 검토
55
The skill instructs the agent to read PR templates, git logs, and contributing docs, but it does not explicitly state that the contents of those files must be treated as data rather than as instructions. A malicious repository file could attempt prompt injection through convention text.
README/SKILL.md 완성도
86
Usable description available
의존성 위험
64
credential or environment access, network or browser surface
설치 명령 안전성
92
표준 패키지 또는 런타임 설치 경로
권한 범위
22
secrets or environment access, shell or command execution
스타/포크 활동
77
스타 3.2K, 포크 244; 현재 메타데이터에서 이슈 활동을 확인할 수 없습니다
채택도
88
GitHub 스타 3.2K
경고
- Permission surface may require sandboxing
- The skill instructs the agent to read PR templates, git logs, and contributing docs, but it does not explicitly state that the contents of those files must be treated as data rather than as instructions. A malicious repository file could attempt prompt injection through convention text.
- No critical security or compliance issues found: the skill does not execute commands, commit, push, or open PRs, and it prohibits credentials and raw transcripts in outputs.
- Quality score needs review
- Permission surface needs review: secrets or environment access, shell or command execution
- Permission surface: secrets or environment access, shell or command execution
방법
이 보고서는 공개 메타데이터, AI 검토 결과, 저장소 최신성, 설치 준비 상태, OpenAgentSkill 이벤트, 품질 점수, 신뢰 검사와 Agent 안전 게이트를 결합합니다. 전체 소스 코드 보안 감사는 아닙니다.
가까운 옵션 비교
다음으로 감사할 관련 스킬
weather
Current weather and forecasts with web_fetch, falling back to wttr.in curl for locations, rain, temperature, travel planning.
391K 스타 · 감사 보고서
mcporter
List, configure, authenticate, call, and inspect MCP servers/tools with mcporter over HTTP or stdio.
391K 스타 · 감사 보고서
release-openspec
Use this skill when releasing OpenSpec: audit merged work and changeset coverage, decide whether a catch-up changeset PR is needed, prepare or resume the Changesets Version Packages PR, cut a beta or stable release, verify publishing, and polish GitHub release notes. Also use when asked whether an open release PR is complete, what the next release step is, or to continue a release paused for human approval.
71K 스타 · 감사 보고서