Skill Lint 與安全掃描工具鏈
Skill Lint 與安全掃描工具鏈
使用 SkillMD 的 CLI/MCP/lint engine 檢查格式與可疑能力。
SkillMD · 社群來源 · 安全
來源狀態
可用來源
這是第三方 Community Skill;2lus 收錄不代表已完整安全審計或保證安全。
資源類型
工具鏈
這是 CLI/MCP 工具鏈,不是 SKILL.md 套件。執行前請審查來源、相依套件與權限;掃描不保證安全。
與類似 Skill 有什麼不同?
- Skill 安全風險審查
SkillMD Security Linting 是可執行的掃描工具鏈;Skill Security 是審視第三方技能風險的流程,兩者都不保證安全。
來源描述的能力
這些是來源描述的可能操作,不代表 2lus 已授予權限或已測試。
尚未列出能力,請審查原始來源。
這個 Skill 是什麼?
這是實際工具鏈,與 Agent 引導的 Skill Security 人工審查流程不同;可產生結構化診斷,但不能保證 Skill 安全。
可以做什麼?何時適合使用?
- 發布前檢查 frontmatter。
- 在 CI 保存 SARIF 診斷。
- 比較新版本的 script/network 能力。
如何使用
- 先審查工具鏈來源和執行權限。
- 對獲准目錄進行 lint/scan,先不要使用 fix 或安裝功能。
- 檢閱每項 finding、誤報與未覆蓋行為,保留 JSON/SARIF 報告。
使用前你需要準備
- 待審查來源與權限
- 威脅假設及不能操作的範圍
你可以替換:
[scope]、[permissions]
環境與相依需求
- Node.js/npm 與 SkillMD CLI 或相應 MCP client;版本要求以所選套件 manifest 為準。
使用範例與 Prompt
以下是 2lus 撰寫的示範需求;請替換為你有權處理的檔案與專案,不代表已執行或保證結果。
入門
規劃發布前 SKILL.md lint 清單,涵蓋名稱、描述與 frontmatter,不安裝任何工具。
實務
使用已核准的 SkillMD 檢查指定目錄並產生 JSON 報告;只規劃命令,不使用 fix/add/publish。
進階
設計 CI 的 SARIF 審閱流程,區分 network_calls、executes_scripts 與 reads_secrets 的人工判斷,說明掃描無法涵蓋的執行時風險。
實用提醒
- 把格式錯誤、品質分數與安全發現分開判讀。
限制與注意事項
- 靜態掃描有誤報/漏報;零 finding 或高分均非安全證明。
安全注意事項
- CLI、scripts 與 MCP 都需審查來源和權限;不要自動安裝目標 Skill 或發布私人內容。
使用與設定
原始來源 ↗支援平台
未確認特定 Agent 相容性
來源與授權
來源查核日期(非安全認證): 2026-09-29
MIT
原始來源 ↗ 授權條款 ↗ 官方文件 ↗相關 Skills
使用第三方 Skill 前,請先檢查來源、權限與執行內容。安裝指令只供查看與複製,不會由 2lus 執行。
2lus AI Skills Library 提供 Skill 的整理與使用導覽。第三方 Skill 的內容、授權與可用性以原始來源為準。使用或安裝前,請自行確認其權限與執行內容。
Skill Lint & Security Scan
Use SkillMD’s CLI, MCP server and lint engine for format and capability diagnostics.
SkillMD · Community source · Security
Source status
Active source
This is a third-party community skill. Inclusion by 2lus is not a complete security audit or safety guarantee.
Resource type
Toolchain
This is a CLI/MCP toolchain, not a SKILL.md package. Review source, dependencies and permissions before execution; scans do not guarantee safety.
How is this different from similar skills?
- Skill Security
SkillMD Security Linting is an executable scanning toolchain; Skill Security is a third-party skill review workflow. Neither guarantees safety.
Documented capabilities
These are operations described upstream, not permissions granted or tested by 2lus.
Capabilities not declared here; review the original source.
What is this skill?
An executable toolchain rather than the agent-led Skill Security audit workflow. It produces structured findings, not proof that a skill is safe.
Use cases and when to use it
- Check frontmatter before publishing.
- Retain SARIF diagnostics in CI.
- Compare script/network capabilities across versions.
How to use it
- Review toolchain source and execution permissions.
- Plan lint/scan on an authorized directory without fix or installation actions.
- Review findings, false positives and blind spots; retain JSON/SARIF evidence.
What you need
- Source and permissions to review
- Threat assumptions and prohibited actions
You can replace:
[scope], [permissions]
Environment and dependencies
- Node.js/npm with the SkillMD CLI or a suitable MCP client; consult the selected package manifest for version requirements.
Usage and prompt examples
These example requests were written by 2lus. Substitute files and projects you may use; examples are not executed results or guarantees.
Beginner
Plan a pre-release SKILL.md checklist for names, descriptions and frontmatter without installing tools.
Practical
Plan commands for an approved SkillMD installation to inspect a directory and report JSON; do not use fix/add/publish.
Advanced
Design SARIF review in CI with human decisions for network_calls, executes_scripts and reads_secrets; document unobserved runtime risks.
Tips
- Separate format errors, quality scores and security findings.
Limitations
- Static scanning has false positives and negatives; zero findings or high scores do not prove safety.
Security notes
- Review CLI/scripts/MCP permissions; never auto-install a target skill or publish private content.
Usage and setup
Original source ↗Supported agents
Specific agent compatibility unknown
Sources and license
Source check date (not a safety certification): 2026-09-29
MIT
Original source ↗ License terms ↗ Documentation ↗Related skills
Before using a third-party skill, review its source, permissions and executable content. Commands are for viewing and copying only; 2lus does not execute them.
2lus AI Skills Library provides curated educational guides. Third-party content, licenses and availability are governed by their original sources. Review permissions and executable content before use or installation.