Informe de auditoría del skill

context-fundamentals Informe de auditoría.

>-

Experimental · RevisarRequiere revisiónGenerado 23 ago 2026Auditoría heurística de metadatos
69
Auditoría
59
Confianza
57
Calidad
67
Seguridad
100
Maintain
92
Instalar

Trust Score de OpenAgentSkill

59
Revisión manual

Trust Score de OpenAgentSkill

The Trust Score helps an agent decide whether a skill is safe enough to shortlist before installation.

Adopción en GitHub

Advertencia

48

33 estrellas de GitHub

Actividad de stars/forks

Advertencia

43

33 estrellas y 3 forks; la actividad de issues no está disponible en los metadatos actuales

Mantenimiento reciente

Aprobado

100

2 días desde el último push

Claridad de licencia

Advertencia

42

Desconocido

Completitud de README/SKILL.md

Info

70

Los metadatos públicos necesitan más contexto de README/SKILL.md

Riesgo de dependencias/runtime

Info

64

credential or environment access, network or browser surface

Disponibilidad de instalación

Aprobado

92

npx skills add shipshitdev/skills --skill context-fundamentals

Seguridad del comando de instalación

Aprobado

92

Ruta estándar de paquete o instalación en tiempo de ejecución

Superficie de permisos

Advertencia

46

secrets or environment access, filesystem or document access

Evidencia del repositorio

Aprobado

86

https://github.com/shipshitdev/skills/tree/master/bundles/ai-agents/skills/context-fundamentals

Estado de revisión

Info

66

Hay datos de revisión por IA disponibles

Resultados comprobados por Agent

Info

54

Aún no hay datos de resultados del Agent

Comprobaciones

Revisión de instalación y adopción

5 Aprobado · 18 Requiere revisión

Ruta de instalación

92

Aprobado

npx skills add shipshitdev/skills --skill context-fundamentals

Repositorio

88

Aprobado

https://github.com/shipshitdev/skills/tree/master/bundles/ai-agents/skills/context-fundamentals

Licencia

45

Revisar

Desconocido

Mantenimiento

100

Aprobado

2 días desde el último push

Revisión por IA

55

Revisar

Repository license is listed as 'Unknown' in GitHub, but skill metadata and README explicitly state MIT and reference the upstream MIT license. This is a minor compliance ambiguity that should be resolved by confirming/updating the repository license.

Completitud de README/SKILL.md

84

Aprobado

Usable description available

Riesgo de dependencias

64

Revisar

credential or environment access, network or browser surface

Seguridad del comando de instalación

92

Aprobado

Ruta estándar de paquete o instalación en tiempo de ejecución

Superficie de permisos

46

Corregir

secrets or environment access, filesystem or document access

Actividad de stars/forks

43

Corregir

33 estrellas y 3 forks; la actividad de issues no está disponible en los metadatos actuales

Adopción

42

Revisar

33 estrellas de GitHub

Advertencias

  • La licencia no está clara
  • Permission surface may require sandboxing
  • Repository license is listed as 'Unknown' in GitHub, but skill metadata and README explicitly state MIT and reference the upstream MIT license. This is a minor compliance ambiguity that should be resolved by confirming/updating the repository license.
  • SKILL.md contains cross-references to non-vendored skills (context-degradation, context-optimization) that are not present in this bundle. The README notes these were intentionally removed from routing, but the references in the body remain and could confuse an agent.
  • The included Python script (context_manager.py) is a utility with token estimation heuristics; it is not production-grade and may be used by an agent without proper validation. This is not a security risk but could lead to inaccurate context handling if used in operational settings.
  • Low GitHub adoption signal
  • Quality score needs review
  • Permission surface needs review: secrets or environment access, filesystem or document access
  • GitHub adoption: 33 GitHub stars
  • Stars/forks activity: 33 stars, 3 forks; issue activity unavailable in current metadata
  • License clarity: Unknown
  • Permission surface: secrets or environment access, filesystem or document access

Método

This report combines public metadata, AI review output, repository freshness, install readiness, OpenAgentSkill events, quality scoring, trust checks, and the agent safety gate. It is not a full source-code security review.

Comparar opciones cercanas

Skills relacionados para auditar después