Skill 审计报告

guidelines-advisor 审计报告.

Smart contract development advisor based on Trail of Bits' best practices. Analyzes codebase to generate documentation/specifications, review architecture, check upgradeability patterns, assess implementation quality, identify pitfalls, review dependencies, and evaluate testing. Provides actionable recommendations.

已审查 · 审查需审查生成于 2026年8月24日启发式元数据审计
84
审计
76
信任
85
质量
81
安全性
100
维护
92
安装

OpenAgentSkill 信任评分

76
强候选

OpenAgentSkill 信任评分

Trust Score 帮助 Agent 在安装前判断一个 Skill 是否足以进入候选清单。

GitHub 采用度

通过

94

6.8K 个 GitHub Stars

Star/Fork 活跃度

通过

88

6.8K 个 Star,585 个 Fork; 当前元数据中没有议题活跃度信息

近期维护

通过

100

今天有推送

许可证清晰度

通过

86

CC-BY-SA-4.0

README/SKILL.md 完整度

通过

86

元数据包含足够的用法与工作流上下文

依赖与运行时风险

通过

82

database surface

安装可用性

通过

92

npx skills add trailofbits/skills --skill guidelines-advisor

安装命令安全性

通过

92

标准软件包或运行时安装路径

权限范围

信息

74

filesystem or document access, database access

仓库证据

通过

86

https://github.com/trailofbits/skills/tree/main/plugins/building-secure-contracts/skills/guidelines-advisor

审查状态

信息

66

可用 AI 审查数据

Agent 验证结果

信息

54

暂未有 Agent 结果数据

检查项

安装与采用审查

9 通过 · 6 需审查

安装路径

92

通过

npx skills add trailofbits/skills --skill guidelines-advisor

仓库

88

通过

https://github.com/trailofbits/skills/tree/main/plugins/building-secure-contracts/skills/guidelines-advisor

许可证

86

通过

CC-BY-SA-4.0

维护

100

通过

今天有推送

AI 审查

55

检查

The skill's security posture is sound as it only analyzes code and generates recommendations; no destructive or high-risk operations are performed.

README/SKILL.md 完整度

86

通过

Usable description available

依赖风险

82

通过

database surface

安装命令安全性

92

通过

标准软件包或运行时安装路径

权限范围

74

检查

filesystem or document access, database access

Star/Fork 活跃度

88

通过

6.8K 个 Star,585 个 Fork; 当前元数据中没有议题活跃度信息

采用度

88

通过

6.8K 个 GitHub Stars

警告

  • The skill's security posture is sound as it only analyzes code and generates recommendations; no destructive or high-risk operations are performed.
  • Minor concern: the skill references external resources (ASSESSMENT_AREAS.md, EXAMPLE_REPORT.md) that are included, but their completeness is not fully verified in this review.
  • The skill does not explicitly state limitations or safe operating boundaries in SKILL.md, which could be improved.
  • Quality score needs review

方法

本报告综合公开元数据、AI 审查输出、仓库活跃度、安装就绪度、OpenAgentSkill 事件、质量评分、信任检查和 Agent 安全门槛;它不是完整的源代码安全审计。

对比相近选项

下一步可审计的相关 Skill