Skill 审计报告
version-bump 审计报告.
Automated semantic versioning and release workflow for Claude Code plugins. Handles version increments across package.json, marketplace.json, plugin.json manifests, build verification, git tagging, GitHub releases, and changelog generation. NPM publishing is the final human-required handoff because the maintainer raised npm security.
OpenAgentSkill 信任评分
OpenAgentSkill 信任评分
Trust Score 帮助 Agent 在安装前判断一个 Skill 是否足以进入候选清单。
GitHub 采用度
通过100
93K 个 GitHub Stars
Star/Fork 活跃度
通过100
93K 个 Star,8.2K 个 Fork; 当前元数据中没有议题活跃度信息
近期维护
通过88
距上次推送 1 个月
许可证清晰度
通过86
Apache-2.0
README/SKILL.md 完整度
信息76
公开元数据需要更完整的 README/SKILL.md 上下文
依赖与运行时风险
警告46
command execution surface, credential or environment access
安装可用性
通过92
npx skills add thedotmack/claude-mem --skill version-bump
安装命令安全性
通过92
标准软件包或运行时安装路径
权限范围
失败22
secrets or environment access, shell or command execution
仓库证据
通过86
https://github.com/thedotmack/claude-mem/tree/main/plugin/skills/version-bump
审查状态
信息66
可用 AI 审查数据
Agent 验证结果
信息54
暂未有 Agent 结果数据
检查项
安装与采用审查
安装路径
92
npx skills add thedotmack/claude-mem --skill version-bump
仓库
88
https://github.com/thedotmack/claude-mem/tree/main/plugin/skills/version-bump
许可证
86
Apache-2.0
维护
88
距上次推送 1 个月
AI 审查
55
The skill references a Discord notification script at ~/Scripts/claude-mem/ which is not included in the skill directory, but it is part of the repository. This could be a minor dependency issue if the environment lacks that script.
README/SKILL.md 完整度
84
Usable description available
依赖风险
46
command execution surface, credential or environment access
安装命令安全性
92
标准软件包或运行时安装路径
权限范围
22
secrets or environment access, shell or command execution
Star/Fork 活跃度
100
93K 个 Star,8.2K 个 Fork; 当前元数据中没有议题活跃度信息
采用度
88
93K 个 GitHub Stars
警告
- Dependency or permission surface needs review
- Permission surface may require sandboxing
- The skill references a Discord notification script at ~/Scripts/claude-mem/ which is not included in the skill directory, but it is part of the repository. This could be a minor dependency issue if the environment lacks that script.
- The skill instructs to run `npm run build-and-sync` which may execute arbitrary build scripts, but this is typical for release workflows and not inherently unsafe.
- Permission surface needs review: secrets or environment access, shell or command execution
- Dependency/runtime risk: command execution surface, credential or environment access
- Permission surface: secrets or environment access, shell or command execution
方法
本报告综合公开元数据、AI 审查输出、仓库活跃度、安装就绪度、OpenAgentSkill 事件、质量评分、信任检查和 Agent 安全门槛;它不是完整的源代码安全审计。
对比相近选项
下一步可审计的相关 Skill
Wazuh
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
16K Stars · 审计报告
Maigret
🕵️♂️ Collect a dossier on a person by username from 3000+ sites
33K Stars · 审计报告
Nuclei
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
29K Stars · 审计报告