automation-standards
Scraping + AI-provider standards — the Scraper trait & SCRAPERS registry, selector resilience, rate-limiting/cancellation, and the provider-abstraction (zero-change) rule for embeddings/streaming/prompts. Load for changes under scraping/, ai_provider/, packages/prompts, documents
供给资产档案
研究与知识工作
Deep research, source comparison, literature review, RAG, knowledge search, and reports.
场景
RAG and knowledge
I need my agent to build a RAG workflow over documents and retrieve reliable context.
适配 Agent
Claude Code + OpenAI Agents + Browser agents
适用于 Codex、Claude Code、Cursor、CLI 或自定义 Agent。
安装
就绪
npx skills add saeedkolivand/ai-job-hunter-app --skill automation-standards
维护状态
新鲜
距上次推送 2 天
风险
需审查
Dependency or permission surface needs review
GitHub 质量
48
63/100 质量 · 62/100 信任
覆盖标签
审查说明
Dependency or permission surface needs review · Permission surface may require sandboxing
Agent 采用评分卡
一眼查看信任、审计与安装准备度
这些分数综合公开仓库元数据、OpenAgentSkill 审查信号、维护新鲜度与安装准备度。它用于候选筛选,不替代人工审查。
质量
有潜力有用的候选项,但采用前应与替代方案比较。
信任
Do not auto-installTrust Score v5 found insufficient evidence for agent installation. Treat this as discovery material, not an executable recommendation.
审计
需审查对安装准备度、安全元数据、维护情况与采用风险的机器可读审查。
OpenAgentSkill 信任评分 v5
安装前需人工审查
Choose a stronger alternative or inspect the source manually before any install attempt.
Stars
48 个 GitHub Stars
仓库活跃度
48 个 Star,3 个 Fork
维护状态
距上次推送 2 天
许可证
NOASSERTION
安装
npx skills add saeedkolivand/ai-job-hunter-app --skill automation-standards
安装安全性
标准软件包或运行时安装路径
权限范围
secrets or environment access, shell or command execution
Agent 结果
暂未有 Agent 结果数据
文档
Usable metadata, review docs
风险摘要
生产前审查
- Repository license is NOASSERTION; the skill itself does not state a license, which may cause reuse ambiguity.
- Low GitHub adoption signal
- Quality score needs review
- Permission surface needs review: secrets or environment access, shell or command execution
安装准备度
安装路径可用
- 安装路径可用
- 仓库证据可用
- 已声明许可证
- 暂无 Agent 验证结果证据
Agent 可读元数据
这个 Skill 的机器可读决策数据。
使用此区块或内嵌 JSON 判断 Agent 是否应安装该 Skill、选择替代方案,或先请求人工审查。
适用任务
- GitHub automation 工作流
- Claude Code 团队
- builders willing to evaluate younger projects
- Inspect repository metadata
适用 Agent
安装决策
- 命令
- npx skills add saeedkolivand/ai-job-hunter-app --skill automation-standards
- 策略
- 阻止
- 人工审查
- 是
信任与风险
- 信任
- 54/100
- 审计
- 72/100
- 风险级别
- 需审查
结果闭环
- 端点
- /api/agent/outcome
- 事件 ID
- resolve
- 结果
- 5
安装命令
npx skills add saeedkolivand/ai-job-hunter-app --skill automation-standards不适用场景
- 需要厂商支持 SLA 的团队
- production agents without a repository review
- Low GitHub adoption signal
- Repository license is NOASSERTION; the skill itself does not state a license, which may cause reuse ambiguity.
- 高风险权限提示:Shell or command execution, Secrets or environment access
Agent 安全 v2
24/100 · 避免自动安装
This skill should not be selected by an agent without explicit human security review.
Do not auto-install. Inspect the source, dependencies, and permission surface first.
高
Shell 或命令执行
Skill 元数据引用了终端、CLI、Shell、子进程或命令执行工作流。
中
Browser automation
Skill may drive a browser or interact with web pages.
中
网络访问
Skill 可能访问远程页面、API、仓库或外部服务。
中
文件系统访问
Skill 可能读取或写入项目文件、文档、生成产物或本地工作区状态。
- 高风险权限提示:Shell or command execution, Secrets or environment access
- Dependency or permission surface needs review
安装目标
在你的 Agent 工作流中安装此 Skill
通过公开安装端点获取命令、安全清单、目标提示词和该 Skill 的规范链接。
OpenAgentSkill CLI
Resolve policy, run the source installer safely, and report a verified install receipt.
$ npx --yes https://github.com/Leon-Drq/openagentskill/releases/download/cli-v0.2.1/openagentskill-0.2.1.tgz install saeedkolivand-automation-standardsAgent 解析计划
让 Agent 在安装前验证匹配度。
Resolve API 返回首选 Skill、替代方案、安全策略、审计说明、安装目标和可直接执行的提示词,无需抓取此页面。
打开 JSON
/api/agent/resolve?task=Use%20automation-standards%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Resolve 文本
/api/agent/resolve?task=Use%20automation-standards%20for%20an%20agent%20workflow&agent=codex&max_risk=medium&format=text
安装交接
/api/skills/saeedkolivand-automation-standards/install
Agent 应检查
- 从 Resolve API 检查任务匹配与替代方案。
- 检查审计评分、信任评分和安全策略警告。
- 检查 Codex、Claude Code、Cursor 或 CLI 的安装目标兼容性。
复制提示词
Task: Use automation-standards in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20automation-standards%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/saeedkolivand-automation-standards/install
Install command: npx skills add saeedkolivand/ai-job-hunter-app --skill automation-standards
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.Agent 交接
把安装路径交给 Agent,而不是再给一个目录页。
通过公开安装端点获取命令、安全清单、目标提示词和该 Skill 的规范链接。
安装交接
/api/skills/saeedkolivand-automation-standards/install
LLM 文本格式
/api/skills/saeedkolivand-automation-standards/install?format=text
寻找替代方案
/api/skills/search?q=automation-standards&limit=3
Agent 提示词
Use automation-standards for this task. Review https://www.openagentskill.com/api/skills/saeedkolivand-automation-standards/install, then install with: npx skills add saeedkolivand/ai-job-hunter-app --skill automation-standardsRegistry 元数据
用于自动选择 Skill 的 Agent 可读档案。
本页通过 Registry API 提供相同的决策、信任、审计、场景和安装信号,让 Agent 无需抓取界面即可排序。
Manifest
/api/registry/manifest/saeedkolivand-automation-standards
LLM 文本
/api/registry/manifest/saeedkolivand-automation-standards?format=text
安装别名
/api/registry/install/saeedkolivand-automation-standards
推荐
/api/registry/recommend?task=Use%20automation-standards%20in%20an%20agent%20workflow&limit=3
适配 Agent
GitHub automation
平台
Claude Code, OpenAI Agents, Browser agents
Agent 决策面板
Fallback candidate for GitHub automation
先用此 Skill 做原型验证,并保留备选方案。
栈中角色
备选候选
主要匹配
GitHub automation
信任标签
先做原型验证
安装路径
命令已就绪
适用场景
- GitHub automation 工作流
- Claude Code 团队
- builders willing to evaluate younger projects
证据
- 仓库近期活跃
- 已提供安装命令或 GitHub 仓库
- 63/100 质量档案
- 7 个 OpenAgentSkill 交互事件
先审查
- Low GitHub adoption signal
- Repository license is NOASSERTION; the skill itself does not state a license, which may cause reuse ambiguity.
实施路径
- 1在沙盒 Agent 中安装它,并端到端完成一次GitHub automation任务。
- 2Compare output quality, latency, and failure behavior against at least one alternative.
- 3Promote it into production only after reviewing repository permissions, license, and maintenance signals.
信任档案
Do not auto-install
Trust Score v5 found insufficient evidence for agent installation. Treat this as discovery material, not an executable recommendation.
GitHub 采用度
检查48 个 GitHub Stars
Star/Fork 活跃度
检查48 个 Star,3 个 Fork; 当前元数据中没有议题活跃度信息
近期维护
通过距上次推送 2 天
许可证清晰度
通过NOASSERTION
积极信号
- AI 审查已通过
- 安装路径可用
- 仓库证据可用
- 近期维护的仓库
- 安装命令未发现明显高风险模式
- 结果闭环已就绪,但需要首次真实 Agent 运行
安装前审查
- Repository license is NOASSERTION; the skill itself does not state a license, which may cause reuse ambiguity.
- Low GitHub adoption signal
- Quality score needs review
- Permission surface needs review: secrets or environment access, shell or command execution
- GitHub adoption: 48 GitHub stars
- Stars/forks activity: 48 stars, 3 forks; issue activity unavailable in current metadata
- Dependency/runtime risk: command execution surface, credential or environment access
- Permission surface: secrets or environment access, shell or command execution
- 暂未有真实 Agent 结果报告
- 无人值守安装前需要人工审查
建议操作
Choose a stronger alternative or inspect the source manually before any install attempt.
质量档案
有潜力 适用于 Agent 工作流的候选
有用的候选项,但采用前应与替代方案比较。
工作流匹配
在这些场景使用此 Skill
Manage repositories
GitHub automation
I need my agent to triage GitHub issues, review pull requests, and summarize repository changes.
Collect structured data
Web scraping
I need my agent to scrape websites and extract structured data from pages.
Search private knowledge
RAG and knowledge
I need my agent to build a RAG workflow over documents and retrieve reliable context.
工作流匹配
加入完整工作流
Scrape, clean, and reuse web data
Web data pipeline
A practical workflow for agents that crawl public pages, extract clean content, normalize data, and hand it to downstream research or RAG workflows.
Ingest, retrieve, and cite
RAG knowledge base
A workflow for document-heavy agents that ingest files, create searchable knowledge, retrieve relevant context, and answer with grounded sources.
Operate and verify web apps
Browser QA agent
A workflow for agents that navigate products, fill forms, take screenshots, and verify real user flows across web applications.
替代方案短名单
安装前对比
可能适合该任务的相近 Skill。
UI-TARS Desktop
Run multimodal agents that operate desktop interfaces
MoneyPrinterTurbo
利用AI大模型,一键生成高清短视频 Generate short videos with one click using AI LLM.
Cua
Open-source infrastructure for Computer-Use Agents. Sandboxes, SDKs, and benchmarks to train and evaluate AI agents that can control full desktops (macOS, Linux, Windows).
概览
--- name: automation-standards description: Scraping + AI-provider standards — the Scraper trait & SCRAPERS registry, selector resilience, rate-limiting/cancellation, and the provider-abstraction (zero-change) rule for embeddings/streaming/prompts. Load for changes under scraping/, ai_provider/, packages/prompts, documents/embed. ---
# Automation standards (scraping + AI-provider)
Authoritative: `docs/knowledge/automation-domain.md`.
## Scraping
- Register via the registry — `scraping/boards/mod.rs` (`SCRAPERS`, `Scraper` trait, `ScraperMode` Http/Browser). Don't special-case boards outside the registry. - **Selector resilience** — core boards need fallback selectors; a brittle single-selector parse on a core board is HIGH. - **Reliability** — honor the cancellation token in `ScrapeContext`; bounded retries with backoff; per-board rate limits; graceful failure recovery (don't poison the queue). - **Sessions/cookies** — handled safely; never log credentials/cookies (security lens → `tauri-security-reviewer`).
## AI provider (the architectural rule — HIGH if violated)
- **No business logic depends on provider-specific APIs.** All providers implement a shared interface; adding OpenAI/Anthropic/Gemini/Ollama/OpenRouter/LM Studio = **config + adapter only**. - **Embeddings** — versioned; on model/space change, invalidation must run (stale embeddings are HIGH). - **Streaming** — partial responses + cancellation handled; no leaks on cancel. - **Prompts** (`packages/prompts`) — provider-aware + locale-driven, pure TS, zero deps; reusable/composable templates. - **Cost** — minimize token/context; pick the cheapest viable model.
## External standards & best-practices (verified 2026-06-19)
### AI / LLM (cross-provider — Claude specifics live in the `claude-api` skill)
- **OWASP Top 10 for LLM Apps (2025)** — https://genai.owasp.org/llm-top-10/ - **LLM01 Prompt Injection** (direct + indirect) — **segregate/label untrusted external content** (scraped JD/résumé text is untrusted; never concatenate raw into the instruction block); constrain model role; deterministically validate output; least-privilege tool tokens; human-in-the-loop on high-risk actions. No fool-proof fix → layer defenses. - **LLM05 Improper Output Handling** — treat output as untrusted; parse/validate (Zod/serde) before it reaches IPC/files/render; never `eval`/shell/SQL with raw output. - **LLM02 Sensitive-Info Disclosure** + **LLM07 System-Prompt Leakage** — strip PII/secrets from prompts + logs; no secrets in system prompts. **LLM06 Excessive Agency** — minimal tools/permissions; gate side-effects behind user confirmation. - **Structured output** — prefer native tool/function-calling with constrained decoding over free-text JSON; schemas guarantee _shape_, not _values_ — still validate. - **Streaming** — SSE is the cross-provider standard; handle partial/aborted streams, disable proxy buffering, support cancellation, prefer partial+error over silent regen. - **Retries/idempotency** — backoff + jitter; retry only idempotent reads; idempotency key/ledger for mutating tool calls. - **Cost/caching** — static prefix first (system prompt + tool schemas) to maximize prompt-cache hits; instrument hit-rate. - **Evals** — version prompts; rerun a fixed eval set on every prompt/model/provider change (2026 models ship faster than your releases and silently shift behavior).
### Scraping — legality & resilience
> Scope: scrape **public, logged-out** job postings (listings/JD text), not candidate PII or auth-walled pages. Stay in that lane.
- **Public + logged-out only.** Public-data scraping isn't "unauthorized access" under the CFAA (hiQ; narrowed by Van Buren). **Never** log in, bypass CAPTCHAs, rotate IPs to evade blocks, or defeat auth — that flips CFAA + breach risk. https://www.quinnemanuel.com/the-firm/news-events/client-alert-meta-v-bright-data-significant-decision-for-web-scraping-industry/ - ⚠️ **ToS/contract is the real exposure.** _Meta v. Bright Data_ (Jan 2024): logged-OUT scrapers aren't ToS-bound; **logged-in scraping stays bound.** But 2025 _LinkedIn v. Proxycurl_ etc. show boards winning on contract — treat LinkedIn/Indeed-class sites with named anti-scraping ToS as **registry-gated, conservative**. - ⚠️ **EU/GDPR** — "public" ≠ free to process personal data; needs lawful basis + the EDPB Opinion 28/2024 three-step legitimate-interest test (+ respect robots.txt, exclude sensitive data, minimize). Clearview fines show "public" is no shield. https://iapp.org/news/a/the-state-of-web-scraping-in-the-eu - **robots.txt (RFC 9309)** — obey it; on 5xx/unreachable assume disallow; cache ≤24h. **Identify honestly** (stable descriptive UA, no browser spoofing to evade). Rate-limit + backoff per host; honor `Retry-After`/429. https://www.rfc-editor.org/rfc/rfc9309.html - **Resilience** — semantic selectors (ARIA roles, `data-*`, JSON-LD `JobPosting`) over brittle CSS/xpath; version-aware fallback chains; detect drift + **fail loudly** (no silent empty results); each board isolated in the `SCRAPERS` registry. Accept anti-bot reality: **back off / disable a scraper rather than fingerprint-spoof** (spoofing is the legal red line).
**Common mistakes:** concatenating scraped/untrusted text into the instruction block (LLM01); trusting structured-output _values_ because the _shape_ validated; proxy buffering killing streaming; retrying non-idempotent tool calls; secrets in system prompts; shipping a prompt change with no eval gate; logging in / bypassing CAPTCHA-or-rate-limits to scrape; treating "public" EU personal data as free; brittle selectors with no fallback/drift alarm.
技术详情
- 版本
- 1.0.0
- 许可证
- NOASSERTION
- 最近更新
- 2026年8月20日
- 发布时间
- 2026年8月20日
决策摘要
备选候选
仓库近期活跃
Agent 验证证据
Agent 验证证据
来自解析、审查、安装和一次小范围运行后的结果报告。
- 成功率
- —
- 近期失败
- —
- 结果
- 0
- 输出质量
- —
- 失败
- 0
- 不相关
- 0
- 安装次数
- 0
- 风险拦截
- 0
- 需要配置
- 0
- 生产环境
- 0
暂时没有 Agent 结果数据。首次 Agent 执行可以通过 /api/agent/outcome 报告成功、需要设置、风险拦截、失败或不相关。
增长闭环
分享工具包
为 automation-standards 准备的场景化草稿,可手动发布到 X。
automation-standards: Scraping + AI-provider standards — the Scraper trait & SCRAPERS registry, selector resilience... 48 stars https://www.openagentskill.com/skills/saeedkolivand-automation-standards?ref=x
可选:带安装命令的回复
Listing + install path for automation-standards: https://www.openagentskill.com/skills/saeedkolivand-automation-standards?ref=x Install: npx skills add saeedkolivand/ai-job-hunter-app --skill automation-standards
收录来源
Registry 收录
此列表来自公开来源,维护者认领获批前不会标记为官方。
- 收录方
- OpenAgentSkill 社区索引
归属链接指向公开仓库或创作者主页。创作者可认领列表以更新所有权信号。
认领此 Skill所有者认领
认领此 Skill 页面
这条 Registry 收录 列表归属于 saeedkolivand,但尚未标记为官方。认领后可增加已验证所有者信号,使后续发布、安装和审计更新更值得信赖。
创作者外链工具包
将证据徽章加入你的 README
在开发者评估仓库的位置展示规范页面、当前信任与审计信号,以及真实的 Agent 验证证据。
[](https://www.openagentskill.com/skills/saeedkolivand-automation-standards)
[](https://www.openagentskill.com/skills/saeedkolivand-automation-standards)
[](https://www.openagentskill.com/skills/saeedkolivand-automation-standards/audit)
[](https://www.openagentskill.com/skills/saeedkolivand-automation-standards)作者
saeedkolivand
@saeedkolivand
健康信号
- GitHub Stars
- 48
- 质量评分
- 35/100
- 最近 GitHub 推送
- 2026年8月20日
- 框架提示
- 未知
- OpenAgentSkill 浏览量
- 7
- 复制安装命令
- 0
- 跳转点击
- 0
社区信号
告诉我们这个 Skill 是否对你的 Agent 工作流有帮助。汇总反馈会持续改善排序。
信任与安全
Do not auto-install
- GitHub 采用度48 个 GitHub Stars检查
- Star/Fork 活跃度48 个 Star,3 个 Fork; 当前元数据中没有议题活跃度信息检查
- 近期维护距上次推送 2 天通过
- 许可证清晰度NOASSERTION通过
- README/SKILL.md 完整度公开元数据需要更完整的 README/SKILL.md 上下文信息
- 依赖与运行时风险command execution surface, credential or environment access修复
相关 Skill
UI-TARS Desktop
Run multimodal agents that operate desktop interfaces
37.0K StarsMoneyPrinterTurbo
利用AI大模型,一键生成高清短视频 Generate short videos with one click using AI LLM.
88.5K StarsCua
Open-source infrastructure for Computer-Use Agents. Sandboxes, SDKs, and benchmarks to train and evaluate AI agents that can control full desktops (macOS, Linux, Windows).
21.4K Stars