skill-sentry
Agent Skill 安装前静态安全审计工具:本地可解释扫描 SKILL.md/脚本/配置中的破坏性命令、隐藏外联、读取密钥、混淆、提示注入与持久化,CLI 加 36 个 fixture 与 GitHub Actions,输出审计报告与
查看原仓库英文描述
Static, local, explainable pre-install security audit for Agent Skills. Scans SKILL.md/scripts/config for destructive commands, hidden network calls, secret reads, obfuscation, prompt injection, persistence. CLI + 36 fixtures + GitHub Actions.
agent-skillsai-securityclaude-codecodexdsh-pluginprompt-injectionsupply-chain-security
基础信息核对
自动核对
中文简介
自动核对
安装命令
自动核对
分类
自动核对
项目活跃度
数据覆盖 60% · 有限数据 · 数据截至 2026-08-19
53/100
最近代码活动
24/35
1 次提交 · 最近推送 20 天前
Issue 响应
N/A
0 个样本 · 暂不计分
PR 协作
N/A
0 个样本 · 暂不计分
贡献持续性
3/10
1 位近 90 天活跃贡献者
版本交付
5/5
最近发布 20 天前
社区关注度
0/10
0 Stars · 0 Forks
安装
该项目不以标准 DSH 插件形式分发(克隆到各宿主 skills 目录的 Skill 安全审计工具,面向多宿主而非 DSH 分发,判 external。)。安装与使用方式请查看原仓库。