Skill 审计报告

instagram-marketing 审计报告.

Plan, draft, audit, and publish content for Instagram. Use when the user wants to write a caption with a first-125-char hook, plan a slide-by-slide carousel, reverse-engineer the hook from a viral Reel or carousel, size hashtags the 2026 way, remove AI tells from a caption, or plan a week of Reels and carousels. Instagram requires media on every post, so the skills write the caption and the user supplies the image or video; posts publish via the Publora API draft, upload, schedule flow.

已阻止 · 阻止需审查生成于 2026年8月23日启发式元数据审计
71
审计
62
信任
59
质量
70
安全性
100
维护
92
安装

OpenAgentSkill 信任评分

62
人工审查

OpenAgentSkill 信任评分

Trust Score 帮助 Agent 在安装前判断一个 Skill 是否足以进入候选清单。

GitHub 采用度

失败

30

17 个 GitHub Stars

Star/Fork 活跃度

失败

32

17 个 Star,1 个 Fork; 当前元数据中没有议题活跃度信息

近期维护

通过

100

今天有推送

许可证清晰度

通过

86

MIT

README/SKILL.md 完整度

通过

86

元数据包含足够的用法与工作流上下文

依赖与运行时风险

警告

54

credential or environment access, external package install surface

安装可用性

通过

92

npx skills add sergebulaev/instagram-skills --skill instagram-marketing

安装命令安全性

通过

92

标准软件包或运行时安装路径

权限范围

失败

22

secrets or environment access, shell or command execution

仓库证据

通过

86

https://github.com/sergebulaev/instagram-skills/tree/main/.codex-marketplace/instagram-skills

审查状态

信息

66

可用 AI 审查数据

Agent 验证结果

信息

54

暂未有 Agent 结果数据

检查项

安装与采用审查

6 通过 · 16 需审查

安装路径

92

通过

npx skills add sergebulaev/instagram-skills --skill instagram-marketing

仓库

88

通过

https://github.com/sergebulaev/instagram-skills/tree/main/.codex-marketplace/instagram-skills

许可证

86

通过

MIT

维护

100

通过

今天有推送

AI 审查

55

检查

The custom poster tier (INSTAGRAM_SKILLS_CUSTOM_POSTER) runs a user-supplied command via subprocess; if the environment variable is set unsafely or includes untrusted input, it could be a vector for arbitrary command execution. However, it is opt-in and requires explicit user configuration.

README/SKILL.md 完整度

86

通过

Usable description available

依赖风险

54

修复

credential or environment access, external package install surface

安装命令安全性

92

通过

标准软件包或运行时安装路径

权限范围

22

修复

secrets or environment access, shell or command execution

Star/Fork 活跃度

32

修复

17 个 Star,1 个 Fork; 当前元数据中没有议题活跃度信息

采用度

42

检查

17 个 GitHub Stars

警告

  • Dependency or permission surface needs review
  • Permission surface may require sandboxing
  • The custom poster tier (INSTAGRAM_SKILLS_CUSTOM_POSTER) runs a user-supplied command via subprocess; if the environment variable is set unsafely or includes untrusted input, it could be a vector for arbitrary command execution. However, it is opt-in and requires explicit user configuration.
  • The skill relies on third-party services (Publora, Apify, Pixfaro) which may have data handling and privacy implications; these are not controlled by the skill itself.
  • Low GitHub adoption signal
  • Quality score needs review
  • Permission surface needs review: secrets or environment access, shell or command execution
  • GitHub adoption: 17 GitHub stars
  • Stars/forks activity: 17 stars, 1 forks; issue activity unavailable in current metadata
  • Dependency/runtime risk: credential or environment access, external package install surface
  • Permission surface: secrets or environment access, shell or command execution

方法

本报告综合公开元数据、AI 审查输出、仓库活跃度、安装就绪度、OpenAgentSkill 事件、质量评分、信任检查和 Agent 安全门槛;它不是完整的源代码安全审计。

对比相近选项

下一步可审计的相关 Skill