技能 检查

安全 社区
解读按原文结构重写,命令、链接、术语均保留;右侧可核对作者原始 SKILL.md

原文结构

  • Installation:Ensure skill-check is available before running checks: No install (recommended for one-off or agent use): npx skill-check — uses npm to run the latest version; requires Node.js and network on first run. Global install (curl): curl -fsSL…
  • Commands reference:npx skill-check check [path] — run validation (+ optional security scan). Default path is . npx skill-check check [path] --no-security-scan — lint only, skip security scan npx skill-check check [path] --format json — machine-readable output with quality scores
  • Interpreting results:error — spec or rule violation; should be fixed. warn — recommendation; may be acceptable depending on context. suggestion — every diagnostic includes an actionable suggestion text.

适用与边界

  • When to use:User asks to validate, lint, or check skill files User provides a local path (e.g. ~/.cursor/skills, ./skills, or a repo root) User provides a GitHub repo URL and wants skills in that repo validated
  • Local validation:Run skill-check against the given path: Quick lint only: npx skill-check check <path> --no-security-scan --format json Full check (includes security scan): npx skill-check check <path> --format json
  • GitHub repo validation:Clone the repo shallowly into a temp directory, e.g. git clone --depth 1 <url> /tmp/skill-check-<short-hash> (or use a system temp path). Run npx skill-check check /tmp/skill-check-<hash> (with --format json if you will parse results).

原文中的明确线索

  • 要点:「No install (recommended for one-off or agent use)」、「Global install (curl)」、「Homebrew」、「error」、「warn」、「suggestion」、「quality score」、「duplicates」
  • 文件与命令npx skill-check— installs a globalbrew tap thedaviddias/skill-check https://github.com/thedaviddias/skill-checkbrew install skill-checknpx skill-check rules~/.cursor/skills./skillsnpx skill-check check <path> --no-security-scan --format json

流狐整理:以上内容来自当前 SKILL.md 的章节与原词;未补写作者没有声明的工具、兼容性或能力。

流狐档案 作者与许可取自来源;运行、权限和网络为流狐检测或估算
流狐分类
安全
作者声明 Agent
未找到明确声明;不据此推断已兼容或已测试
静态检查
83 / 100 · 启发式扫描,不代表运行安全
作者 / 版本 / 许可
@thedaviddias · 未声明 license
流狐 Token 估算
低消耗
流狐接入估算
即装即用
是否需要外部 API Key
未发现要求
检测到的系统要求
macOS · Linux · Windows
底层运行要求
Node.js
检测到的文件与系统行为
  • 只读
  • 允许写入 / 修改
检测到的网络行为
允许外网请求
安装命令数
无(仅作为资料)

档案由构建时根据 SKILL.md 与安装命令自动衍生,可能与作者实际意图存在差异。

需要注意: 未限定 allowed-tools,默认拥有全部工具权限。;检出高风险片段:pipe_curl_to_shell

输出预览 skill-check.preview
# Interpreting results

- **error** — spec or rule violation; should be fixed.
- **warn** — recommendation; may be acceptable depending on context.
- **suggestion** — every diagnostic includes an actionable suggestion text.
- **quality score** — 0-100 per skill, weighted across frontmatter (30%), description (30%), body (20%), links (10%), file (10%).
- **duplicates** — `duplicates.name` / `duplicates.description` warnings when multiple skills share the same name or description.
- Exit code 0 means no errors; non-zero means validation failed or security scan found issues.

讨论

基于 GitHub Discussions。登录 GitHub 即可参与讨论、点赞、订阅更新。