已安装 Skills 的安全审计工具。用于批量审计 Skills 的安全性,包括命令执行、网络访问、文件访问、数据泄露、依赖风险、提示词越权和触发条件检查。适用于用户提供 Skills 列表和文件内容时进行安全扫描、护栏审查、提示词越权审查或强化建议。
- Initial release of skill-security-audit, a tool for batch auditing the security of installed Skills. - Supports detection of command execution, network access, file/system access, data leakage, dependency risks, prompt injection, and trigger condition issues. - Provides structured security reports per Skill with severity ratings, risk evidence, and remediation suggestions. - Includes auditing matrix and severity definitions to standardize risk evaluation. - Output includes both detailed reports and an overall summary highlighting top risks and remediation priorities.