Skill 审计报告

opencli 审计报告.

用 OpenCLI 驱动用户本机那个真实的、已登录的 Chrome,或调用它的 160+ 站点 adapter。任何需要登录态的页面操作都从这里开始——读登录后的后台、抓没有 API 的表格、填表提交、跑一个站点命令、把页面数据取回来。也覆盖会话命名与租约纪律("我的标签页被别人抢了")、批量取数与落盘、adapter 的编写与自修复、opencli doctor 排障。用户提到 opencli、浏览器自动化、用我的浏览器、驱动 Chrome、登录态、抓后台数据、抓表格、导出报表、填表、自动点击、截图、adapter、doctor 报错、session 撞名、标签页被抢、tab 泄漏,或说"打开这个页面看看""帮我登录后台查一下""这个站没有 API"时,务必使用本 Skill。只要动作会落在浏览器上,先读这里再动手。

实验性 · 审查需审查生成于 2026年8月24日启发式元数据审计
75
审计
67
信任
64
质量
75
安全性
100
维护
92
安装

OpenAgentSkill 信任评分

67
人工审查

OpenAgentSkill 信任评分

Trust Score 帮助 Agent 在安装前判断一个 Skill 是否足以进入候选清单。

GitHub 采用度

警告

48

50 个 GitHub Stars

Star/Fork 活跃度

警告

48

50 个 Star,35 个 Fork; 当前元数据中没有议题活跃度信息

近期维护

通过

100

今天有推送

许可证清晰度

通过

86

MIT

README/SKILL.md 完整度

通过

86

元数据包含足够的用法与工作流上下文

依赖与运行时风险

信息

64

command execution surface, network or browser surface

安装可用性

通过

92

npx skills add yan-labs/yan-skills --skill opencli

安装命令安全性

通过

92

标准软件包或运行时安装路径

权限范围

警告

48

shell or command execution, filesystem or document access

仓库证据

通过

86

https://github.com/yan-labs/yan-skills/tree/main/opencli

审查状态

信息

66

可用 AI 审查数据

Agent 验证结果

信息

54

暂未有 Agent 结果数据

检查项

安装与采用审查

6 通过 · 15 需审查

安装路径

92

通过

npx skills add yan-labs/yan-skills --skill opencli

仓库

88

通过

https://github.com/yan-labs/yan-skills/tree/main/opencli

许可证

86

通过

MIT

维护

100

通过

今天有推送

AI 审查

55

检查

SKILL.md is very long and dense (mainly in Chinese), which may reduce readability for some users, but it is comprehensive.

README/SKILL.md 完整度

86

通过

Usable description available

依赖风险

64

检查

command execution surface, network or browser surface

安装命令安全性

92

通过

标准软件包或运行时安装路径

权限范围

48

修复

shell or command execution, filesystem or document access

Star/Fork 活跃度

48

修复

50 个 Star,35 个 Fork; 当前元数据中没有议题活跃度信息

采用度

68

信息

50 个 GitHub Stars

Financial decision safety

58

检查

Research-only use: do not treat output as financial advice or execute a position without human approval.

警告

  • Permission surface may require sandboxing
  • Financial research output is not financial advice; require human review before any live investment decision
  • SKILL.md is very long and dense (mainly in Chinese), which may reduce readability for some users, but it is comprehensive.
  • The skill relies on a specific fork (yan-labs/OpenCLI) and clearly documents differences from upstream, which is good but may cause confusion if users attempt to use the upstream version.
  • Financial research output is not financial advice; require human review before any live investment decision.
  • Quality score needs review
  • Permission surface needs review: shell or command execution, filesystem or document access
  • GitHub adoption: 50 GitHub stars
  • Stars/forks activity: 50 stars, 35 forks; issue activity unavailable in current metadata
  • Permission surface: shell or command execution, filesystem or document access

方法

本报告综合公开元数据、AI 审查输出、仓库活跃度、安装就绪度、OpenAgentSkill 事件、质量评分、信任检查和 Agent 安全门槛;它不是完整的源代码安全审计。

对比相近选项

下一步可审计的相关 Skill