Skill 审计报告

context-fundamentals 审计报告.

>-

实验性 · 审查需审查生成于 2026年8月23日启发式元数据审计
69
审计
59
信任
57
质量
67
安全性
100
维护
92
安装

OpenAgentSkill 信任评分

59
人工审查

OpenAgentSkill 信任评分

Trust Score 帮助 Agent 在安装前判断一个 Skill 是否足以进入候选清单。

GitHub 采用度

警告

48

33 个 GitHub Stars

Star/Fork 活跃度

警告

43

33 个 Star,3 个 Fork; 当前元数据中没有议题活跃度信息

近期维护

通过

100

距上次推送 2 天

许可证清晰度

警告

42

未知

README/SKILL.md 完整度

信息

70

公开元数据需要更完整的 README/SKILL.md 上下文

依赖与运行时风险

信息

64

credential or environment access, network or browser surface

安装可用性

通过

92

npx skills add shipshitdev/skills --skill context-fundamentals

安装命令安全性

通过

92

标准软件包或运行时安装路径

权限范围

警告

46

secrets or environment access, filesystem or document access

仓库证据

通过

86

https://github.com/shipshitdev/skills/tree/master/bundles/ai-agents/skills/context-fundamentals

审查状态

信息

66

可用 AI 审查数据

Agent 验证结果

信息

54

暂未有 Agent 结果数据

检查项

安装与采用审查

5 通过 · 18 需审查

安装路径

92

通过

npx skills add shipshitdev/skills --skill context-fundamentals

仓库

88

通过

https://github.com/shipshitdev/skills/tree/master/bundles/ai-agents/skills/context-fundamentals

许可证

45

检查

未知

维护

100

通过

距上次推送 2 天

AI 审查

55

检查

Repository license is listed as 'Unknown' in GitHub, but skill metadata and README explicitly state MIT and reference the upstream MIT license. This is a minor compliance ambiguity that should be resolved by confirming/updating the repository license.

README/SKILL.md 完整度

84

通过

Usable description available

依赖风险

64

检查

credential or environment access, network or browser surface

安装命令安全性

92

通过

标准软件包或运行时安装路径

权限范围

46

修复

secrets or environment access, filesystem or document access

Star/Fork 活跃度

43

修复

33 个 Star,3 个 Fork; 当前元数据中没有议题活跃度信息

采用度

42

检查

33 个 GitHub Stars

警告

  • 许可证不清晰
  • Permission surface may require sandboxing
  • Repository license is listed as 'Unknown' in GitHub, but skill metadata and README explicitly state MIT and reference the upstream MIT license. This is a minor compliance ambiguity that should be resolved by confirming/updating the repository license.
  • SKILL.md contains cross-references to non-vendored skills (context-degradation, context-optimization) that are not present in this bundle. The README notes these were intentionally removed from routing, but the references in the body remain and could confuse an agent.
  • The included Python script (context_manager.py) is a utility with token estimation heuristics; it is not production-grade and may be used by an agent without proper validation. This is not a security risk but could lead to inaccurate context handling if used in operational settings.
  • Low GitHub adoption signal
  • Quality score needs review
  • Permission surface needs review: secrets or environment access, filesystem or document access
  • GitHub adoption: 33 GitHub stars
  • Stars/forks activity: 33 stars, 3 forks; issue activity unavailable in current metadata
  • License clarity: Unknown
  • Permission surface: secrets or environment access, filesystem or document access

方法

本报告综合公开元数据、AI 审查输出、仓库活跃度、安装就绪度、OpenAgentSkill 事件、质量评分、信任检查和 Agent 安全门槛;它不是完整的源代码安全审计。

对比相近选项

下一步可审计的相关 Skill