Skill Lint 與安全掃描工具鏈

Skill Lint 與安全掃描工具鏈

使用 SkillMD 的 CLI/MCP/lint engine 檢查格式與可疑能力。

SkillMD · 社群來源 · 安全

來源狀態

可用來源

這是第三方 Community Skill;2lus 收錄不代表已完整安全審計或保證安全。

資源類型

工具鏈

這是 CLI/MCP 工具鏈,不是 SKILL.md 套件。執行前請審查來源、相依套件與權限;掃描不保證安全。

與類似 Skill 有什麼不同?

  • Skill 安全風險審查

    SkillMD Security Linting 是可執行的掃描工具鏈;Skill Security 是審視第三方技能風險的流程,兩者都不保證安全。

來源描述的能力

這些是來源描述的可能操作,不代表 2lus 已授予權限或已測試。

尚未列出能力,請審查原始來源。

這個 Skill 是什麼?

這是實際工具鏈,與 Agent 引導的 Skill Security 人工審查流程不同;可產生結構化診斷,但不能保證 Skill 安全。

可以做什麼?何時適合使用?

  • 發布前檢查 frontmatter。
  • 在 CI 保存 SARIF 診斷。
  • 比較新版本的 script/network 能力。

如何使用

  1. 先審查工具鏈來源和執行權限。
  2. 對獲准目錄進行 lint/scan,先不要使用 fix 或安裝功能。
  3. 檢閱每項 finding、誤報與未覆蓋行為,保留 JSON/SARIF 報告。

使用前你需要準備

  • 待審查來源與權限
  • 威脅假設及不能操作的範圍

你可以替換:

[scope]、[permissions]

環境與相依需求

  • Node.js/npm 與 SkillMD CLI 或相應 MCP client;版本要求以所選套件 manifest 為準。

使用範例與 Prompt

以下是 2lus 撰寫的示範需求;請替換為你有權處理的檔案與專案,不代表已執行或保證結果。

入門

規劃發布前 SKILL.md lint 清單,涵蓋名稱、描述與 frontmatter,不安裝任何工具。

實務

使用已核准的 SkillMD 檢查指定目錄並產生 JSON 報告;只規劃命令,不使用 fix/add/publish。

進階

設計 CI 的 SARIF 審閱流程,區分 network_calls、executes_scripts 與 reads_secrets 的人工判斷,說明掃描無法涵蓋的執行時風險。

實用提醒

  • 把格式錯誤、品質分數與安全發現分開判讀。

限制與注意事項

  • 靜態掃描有誤報/漏報;零 finding 或高分均非安全證明。

安全注意事項

  • CLI、scripts 與 MCP 都需審查來源和權限;不要自動安裝目標 Skill 或發布私人內容。

使用與設定

原始來源 ↗

支援平台

未確認特定 Agent 相容性

來源與授權

來源查核日期(非安全認證): 2026-09-29

MIT

原始來源 ↗ 授權條款 ↗ 官方文件 ↗

相關 Skills

使用第三方 Skill 前,請先檢查來源、權限與執行內容。安裝指令只供查看與複製,不會由 2lus 執行。

2lus AI Skills Library 提供 Skill 的整理與使用導覽。第三方 Skill 的內容、授權與可用性以原始來源為準。使用或安裝前,請自行確認其權限與執行內容。

Skill Lint & Security Scan

Use SkillMD’s CLI, MCP server and lint engine for format and capability diagnostics.

SkillMD · Community source · Security

Source status

Active source

This is a third-party community skill. Inclusion by 2lus is not a complete security audit or safety guarantee.

Resource type

Toolchain

This is a CLI/MCP toolchain, not a SKILL.md package. Review source, dependencies and permissions before execution; scans do not guarantee safety.

How is this different from similar skills?

  • Skill Security

    SkillMD Security Linting is an executable scanning toolchain; Skill Security is a third-party skill review workflow. Neither guarantees safety.

Documented capabilities

These are operations described upstream, not permissions granted or tested by 2lus.

Capabilities not declared here; review the original source.

What is this skill?

An executable toolchain rather than the agent-led Skill Security audit workflow. It produces structured findings, not proof that a skill is safe.

Use cases and when to use it

  • Check frontmatter before publishing.
  • Retain SARIF diagnostics in CI.
  • Compare script/network capabilities across versions.

How to use it

  1. Review toolchain source and execution permissions.
  2. Plan lint/scan on an authorized directory without fix or installation actions.
  3. Review findings, false positives and blind spots; retain JSON/SARIF evidence.

What you need

  • Source and permissions to review
  • Threat assumptions and prohibited actions

You can replace:

[scope], [permissions]

Environment and dependencies

  • Node.js/npm with the SkillMD CLI or a suitable MCP client; consult the selected package manifest for version requirements.

Usage and prompt examples

These example requests were written by 2lus. Substitute files and projects you may use; examples are not executed results or guarantees.

Beginner

Plan a pre-release SKILL.md checklist for names, descriptions and frontmatter without installing tools.

Practical

Plan commands for an approved SkillMD installation to inspect a directory and report JSON; do not use fix/add/publish.

Advanced

Design SARIF review in CI with human decisions for network_calls, executes_scripts and reads_secrets; document unobserved runtime risks.

Tips

  • Separate format errors, quality scores and security findings.

Limitations

  • Static scanning has false positives and negatives; zero findings or high scores do not prove safety.

Security notes

  • Review CLI/scripts/MCP permissions; never auto-install a target skill or publish private content.

Usage and setup

Original source ↗

Supported agents

Specific agent compatibility unknown

Sources and license

Source check date (not a safety certification): 2026-09-29

MIT

Original source ↗ License terms ↗ Documentation ↗

Related skills

Before using a third-party skill, review its source, permissions and executable content. Commands are for viewing and copying only; 2lus does not execute them.

2lus AI Skills Library provides curated educational guides. Third-party content, licenses and availability are governed by their original sources. Review permissions and executable content before use or installation.