스킬 감사 보고서
context-fundamentals 감사 보고서.
>-
OpenAgentSkill 신뢰 점수
OpenAgentSkill 신뢰 점수
Trust Score는 설치 전에 후보 목록에 넣을 만큼 안전한지 Agent가 판단하도록 돕습니다.
GitHub 채택도
경고48
GitHub 스타 33
스타/포크 활동
경고43
스타 33, 포크 3; 현재 메타데이터에서 이슈 활동을 확인할 수 없습니다
최근 유지보수
통과100
마지막 푸시 후 2일
라이선스 명확성
경고42
알 수 없음
README/SKILL.md 완성도
정보70
공개 메타데이터에 더 충실한 README/SKILL.md 맥락이 필요합니다
의존성/런타임 위험
정보64
credential or environment access, network or browser surface
설치 가능 여부
통과92
npx skills add shipshitdev/skills --skill context-fundamentals
설치 명령 안전성
통과92
표준 패키지 또는 런타임 설치 경로
권한 범위
경고46
secrets or environment access, filesystem or document access
저장소 근거
통과86
https://github.com/shipshitdev/skills/tree/master/bundles/ai-agents/skills/context-fundamentals
검토 상태
정보66
AI 검토 데이터를 사용할 수 있습니다
Agent 검증 결과
정보54
아직 Agent 결과 데이터가 없습니다
검사
설치 및 채택 검토
설치 경로
92
npx skills add shipshitdev/skills --skill context-fundamentals
저장소
88
https://github.com/shipshitdev/skills/tree/master/bundles/ai-agents/skills/context-fundamentals
라이선스
45
알 수 없음
유지보수
100
마지막 푸시 후 2일
AI 검토
55
Repository license is listed as 'Unknown' in GitHub, but skill metadata and README explicitly state MIT and reference the upstream MIT license. This is a minor compliance ambiguity that should be resolved by confirming/updating the repository license.
README/SKILL.md 완성도
84
Usable description available
의존성 위험
64
credential or environment access, network or browser surface
설치 명령 안전성
92
표준 패키지 또는 런타임 설치 경로
권한 범위
46
secrets or environment access, filesystem or document access
스타/포크 활동
43
스타 33, 포크 3; 현재 메타데이터에서 이슈 활동을 확인할 수 없습니다
채택도
42
GitHub 스타 33
경고
- 라이선스가 명확하지 않습니다
- Permission surface may require sandboxing
- Repository license is listed as 'Unknown' in GitHub, but skill metadata and README explicitly state MIT and reference the upstream MIT license. This is a minor compliance ambiguity that should be resolved by confirming/updating the repository license.
- SKILL.md contains cross-references to non-vendored skills (context-degradation, context-optimization) that are not present in this bundle. The README notes these were intentionally removed from routing, but the references in the body remain and could confuse an agent.
- The included Python script (context_manager.py) is a utility with token estimation heuristics; it is not production-grade and may be used by an agent without proper validation. This is not a security risk but could lead to inaccurate context handling if used in operational settings.
- Low GitHub adoption signal
- Quality score needs review
- Permission surface needs review: secrets or environment access, filesystem or document access
- GitHub adoption: 33 GitHub stars
- Stars/forks activity: 33 stars, 3 forks; issue activity unavailable in current metadata
- License clarity: Unknown
- Permission surface: secrets or environment access, filesystem or document access
방법
이 보고서는 공개 메타데이터, AI 검토 결과, 저장소 최신성, 설치 준비 상태, OpenAgentSkill 이벤트, 품질 점수, 신뢰 검사와 Agent 안전 게이트를 결합합니다. 전체 소스 코드 보안 감사는 아닙니다.
가까운 옵션 비교