스킬 감사 보고서
cairo-vulnerability-scanner 감사 보고서.
Scans Cairo/StarkNet smart contracts for 6 critical vulnerabilities including felt252 arithmetic overflow, L1-L2 messaging issues, address conversion problems, and signature replay. Use when auditing StarkNet projects.
OpenAgentSkill 신뢰 점수
OpenAgentSkill 신뢰 점수
Trust Score는 설치 전에 후보 목록에 넣을 만큼 안전한지 Agent가 판단하도록 돕습니다.
GitHub 채택도
통과94
GitHub 스타 6.8K
스타/포크 활동
통과88
스타 6.8K, 포크 585; 현재 메타데이터에서 이슈 활동을 확인할 수 없습니다
최근 유지보수
통과100
오늘 푸시됨
라이선스 명확성
통과86
CC-BY-SA-4.0
README/SKILL.md 완성도
통과86
메타데이터에 충분한 사용 및 워크플로 맥락이 포함되어 있습니다
의존성/런타임 위험
정보72
명령 실행 범위
설치 가능 여부
통과92
npx skills add trailofbits/skills --skill cairo-vulnerability-scanner
설치 명령 안전성
통과92
표준 패키지 또는 런타임 설치 경로
권한 범위
정보62
shell or command execution, filesystem or document access
저장소 근거
통과86
https://github.com/trailofbits/skills/tree/main/plugins/building-secure-contracts/skills/cairo-vulnerability-scanner
검토 상태
정보66
AI 검토 데이터를 사용할 수 있습니다
Agent 검증 결과
정보54
아직 Agent 결과 데이터가 없습니다
검사
설치 및 채택 검토
설치 경로
92
npx skills add trailofbits/skills --skill cairo-vulnerability-scanner
저장소
88
https://github.com/trailofbits/skills/tree/main/plugins/building-secure-contracts/skills/cairo-vulnerability-scanner
라이선스
86
CC-BY-SA-4.0
유지보수
100
오늘 푸시됨
AI 검토
55
SKILL.md does not explicitly list its own limitations (e.g., that it focuses on Cairo 1.x and may miss issues outside the six patterns).
README/SKILL.md 완성도
86
Usable description available
의존성 위험
72
명령 실행 범위
설치 명령 안전성
92
표준 패키지 또는 런타임 설치 경로
권한 범위
62
shell or command execution, filesystem or document access
스타/포크 활동
88
스타 6.8K, 포크 585; 현재 메타데이터에서 이슈 활동을 확인할 수 없습니다
채택도
88
GitHub 스타 6.8K
Financial decision safety
20
Potential execution surface detected; do not connect live broker, exchange, wallet, or payment credentials.
경고
- Financial research output is not financial advice; require human review before any live investment decision
- Potential broker, wallet, exchange, or real-money execution surface; sandbox and explicit approval are required
- SKILL.md does not explicitly list its own limitations (e.g., that it focuses on Cairo 1.x and may miss issues outside the six patterns).
- The skill references Caracal installation via `cargo install` but does not warn about potential supply chain risks of running arbitrary code; users should review before executing.
- Financial research output is not financial advice; require human review before any live investment decision.
- This skill may touch real-money trading, broker, wallet, or exchange operations; use only in a sandbox with explicit approval.
- Quality score needs review
방법
이 보고서는 공개 메타데이터, AI 검토 결과, 저장소 최신성, 설치 준비 상태, OpenAgentSkill 이벤트, 품질 점수, 신뢰 검사와 Agent 안전 게이트를 결합합니다. 전체 소스 코드 보안 감사는 아닙니다.
가까운 옵션 비교
다음으로 감사할 관련 스킬
Wazuh
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
16K 스타 · 감사 보고서
Maigret
🕵️♂️ Collect a dossier on a person by username from 3000+ sites
33K 스타 · 감사 보고서
Nuclei
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
29K 스타 · 감사 보고서