Laporan audit skill

forward-implementation-first Laporan audit.

Keeps an agent building and validating real output instead of servicing its own bookkeeping. Use for multi-stage pipelines, capability roadmaps, long-running implementation loops, migrations, staged data or build runs, and any run where administrative hashes, locks, receipts, dashboards, certification markers, or progress metadata can block correct work. Use when an agent refuses to advance, rewinds finished stages, or reruns unchanged work because a marker is missing or stale.

Eksperimental · TinjauPerlu ditinjauDihasilkan 11 Okt 2026Audit metadata heuristik
75
Audit
68
Kepercayaan
66
Kualitas
79
Keamanan
88
Maintain
92
Pasang

Trust Score OpenAgentSkill

68
Tinjauan manual

Trust Score OpenAgentSkill

The Trust Score helps an agent decide whether a skill is safe enough to shortlist before installation.

Adopsi GitHub

Info

62

163 star GitHub

Aktivitas star/fork

Peringatan

51

163 star dan 4 fork; aktivitas issue tidak tersedia dalam metadata saat ini

Pemeliharaan terbaru

Lulus

88

1 bulan sejak push

Kejelasan lisensi

Lulus

86

MIT

Kelengkapan README/SKILL.md

Lulus

86

Metadata memuat konteks penggunaan dan alur kerja yang cukup

Risiko dependensi/runtime

Lulus

90

Tidak ada petunjuk risiko dependensi besar dalam metadata publik

Ketersediaan pemasangan

Lulus

92

npx skills add Vuk97/forward-implementation-first --skill forward-implementation-first

Keamanan perintah pemasangan

Lulus

92

Jalur pemasangan paket atau runtime standar

Cakupan izin

Peringatan

50

shell or command execution, filesystem or document access

Bukti repositori

Lulus

86

https://github.com/Vuk97/forward-implementation-first/blob/main/SKILL.md

Status peninjauan

Info

66

Data tinjauan AI tersedia

Hasil terbukti Agent

Info

54

Belum ada data hasil Agent

Pemeriksaan

Tinjauan pemasangan dan adopsi

7 Lulus · 11 Perlu ditinjau

Jalur pemasangan

92

Lulus

npx skills add Vuk97/forward-implementation-first --skill forward-implementation-first

Repositori

88

Lulus

https://github.com/Vuk97/forward-implementation-first/blob/main/SKILL.md

Lisensi

86

Lulus

MIT

Pemeliharaan

88

Lulus

1 bulan sejak push

Tinjauan AI

55

Periksa

The skill's instruction to 'remove or downgrade administrative-only gates' could be misapplied if an agent misclassifies a substantive safety check as administrative. The skill does define administrative bookkeeping, but the boundary could be clearer.

Kelengkapan README/SKILL.md

86

Lulus

Usable description available

Risiko dependensi

90

Lulus

Tidak ada petunjuk risiko dependensi besar dalam metadata publik

Keamanan perintah pemasangan

92

Lulus

Jalur pemasangan paket atau runtime standar

Cakupan izin

50

Perbaiki

shell or command execution, filesystem or document access

Aktivitas star/fork

51

Perbaiki

163 star dan 4 fork; aktivitas issue tidak tersedia dalam metadata saat ini

Adopsi

68

Info

163 star GitHub

Peringatan

  • Permission surface may require sandboxing
  • The skill's instruction to 'remove or downgrade administrative-only gates' could be misapplied if an agent misclassifies a substantive safety check as administrative. The skill does define administrative bookkeeping, but the boundary could be clearer.
  • The concept of 'dependency cone' is mentioned but not precisely defined. Agents may need more concrete guidance on how to determine which stages are affected by a change.
  • The skill assumes the agent can reliably distinguish between 'administrative' and 'substantive' metadata. In practice, some hashes or locks may serve dual purposes, and the skill could benefit from explicit examples of ambiguous cases.
  • Quality score needs review
  • Permission surface needs review: shell or command execution, filesystem or document access
  • Stars/forks activity: 163 stars, 4 forks; issue activity unavailable in current metadata
  • Permission surface: shell or command execution, filesystem or document access

Metode

This report combines public metadata, AI review output, repository freshness, install readiness, OpenAgentSkill events, quality scoring, trust checks, and the agent safety gate. It is not a full source-code security review.

Bandingkan opsi sekitar

Skill terkait untuk diaudit berikutnya