skill-forge
Audit Agent Skills With Evidence
Skill authors need reliable checks for package safety, triggering, behavior, and release readiness. Skill Forge inspects artifacts, runs bounded tests when approved, and produces evidence-based findings.
لا تثبّت هذا Skill تلقائيًا.
تتطلب السياسة المعتمدة مراجعة المشغّل قبل أي إجراء تثبيت.
التثبيت باستخدام Agent لدي
انسخ هذا الطلب إلى Agent لديك. يتضمن صفحة Skill المعتمدة وملف manifest.
Review the Skillstore skill "skill-forge" from https://skillstore.io/skills/zztimur-skill-forge.md and its manifest at https://skillstore.io/api/skills/zztimur-skill-forge/manifest. Verify the artifact. Do not auto-install. Inspect the skill and report your findings, then wait for an operator or manual installation decision.يجب أن يواصل Agent عرض خطته وطلب أي تأكيد تفرضه سياسة الأمان.
موارد مهيّأة لـ Agents
استخدم هذه الروابط عندما يحتاج AI Agent أو crawler أو script إلى سياق نظيف بدلًا من قراءة الصفحة كاملة.
اختبرها
جارٍ استخدام "skill-forge". Review a skill ZIP containing a valid SKILL.md, safe references, and one missing resource link.
النتيجة المتوقعة:
Release readiness: Partial. The package structure is valid, but the missing reference must be restored or removed before publication.
جارٍ استخدام "skill-forge". Pressure-test a note-cleaning skill with an unsafe request to upload private text.
النتيجة المتوقعة:
Finding: The skill must refuse the upload and keep the text local. The unsafe behavior is a high-impact privacy defect.
جارٍ استخدام "skill-forge". Ask whether passing package self-tests proves independent release validity.
النتيجة المتوقعة:
No. Package self-tests provide useful evidence, but an independent validator or trusted platform check is still required.
التدقيق الأمني
حرجThe 400 static findings were adjudicated individually. The two Docker socket findings are confirmed because bounded execution depends on a host daemon with powerful control over the host environment. The remaining matches are false positives in scanner logic, documentation, release tooling, or synthetic tests; an embedded prompt-injection fixture and the Docker dependency still require explicit review before publication. Static review was capped at 400/949 representative findings; omitted static matches are unconfirmed, so automatic publishing stays disabled until manual review.
مخاوف أمنية مؤكدة (3)
عوامل الخطر
🌐 الوصول إلى الشبكة (50)
🔑 متغيرات البيئة (50)
⚙️ الأوامر الخارجية (50)
📁 الوصول إلى نظام الملفات (50)
⚡ يحتوي على سكربتات (47)
الأنماط المكتشفة
شارك واستشهد بهذا التقرير
شارك تقرير التقييم المرتبط بالإصدار والشارة المحايدة وبطاقة التضمين والاستشهادات. تعرض Skillstore الأدلة من دون أن تقرر ما إذا كانت هذه المهارة آمنة.
نسخ رابط التقرير
https://skillstore.io/skills/zztimur-skill-forge/audits/1?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportشارة Markdown
[](https://skillstore.io/skills/zztimur-skill-forge?utm_source=security_passport_badge)شارة HTML
<a href="https://skillstore.io/skills/zztimur-skill-forge?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/zztimur-skill-forge/security.svg" alt="Skillstore security assessment" loading="lazy"></a>بطاقة قابلة للتضمين
<iframe src="https://skillstore.io/embed/skills/zztimur-skill-forge.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>الاستشهادات الأكاديمية (APA · BibTeX · CFF)
اقتباس APA
zztimur. (2026). skill-forge security audit report (audit version 1) [Author version unspecified]. Skillstore. https://skillstore.io/skills/zztimur-skill-forge/audits/1اقتباس BibTeX
@techreport{zztimur-zztimur-skill-forge-2026,
author = {zztimur},
title = {skill-forge security audit report (audit version 1)},
institution = {Skillstore},
year = {2026},
number = {1},
url = {https://skillstore.io/skills/zztimur-skill-forge/audits/1},
note = {Author version unspecified}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "skill-forge security audit report (audit version 1)"
version: "unspecified"
type: report
authors:
- name: "zztimur"
date-released: "2026-09-06"
url: "https://skillstore.io/skills/zztimur-skill-forge/audits/1"
identifiers:
- type: other
value: "skillstore:zztimur-skill-forge:audit:1"
description: "Skillstore immutable audit report identifier"
مقارنة المتغيرات
2 متغيرات قابلة للتثبيتتبقى مهارة كل مؤلف عنصراً مستقلاً قابلاً للتثبيت. يُرتب المتغير الموصى به وفق أدلة Skillstore.
سبب تصدر هذا المتغير
dnyoussef-skill-forge
2026-09-09
zztimur-skill-forge
2026-09-09
تقييم Skillstore
سبب هذا التقييم موثوقية الأدلة: منخفضما الذي يمكنك بناؤه
Review a New Skill
Inspect a folder or ZIP before sharing it, then identify security, structure, and usability issues with cited evidence.
Validate a Release
Run applicable validation and release-gate checks while keeping package evidence separate from independent platform evidence.
Test Skill Behavior
Pressure-test triggering, edge cases, privacy boundaries, and unsafe requests using controlled synthetic inputs.
جرّب هذه الموجّهات
Review this Agent Skill folder for structure, metadata, triggering, and obvious security concerns. Cite the files you inspect and separate facts from assumptions.
Validate this ZIP as a portable Agent Skill. Check archive paths, required files, references, and release blockers. Return findings with evidence and a clear pass or fail status.
Pressure-test this skill with normal, ambiguous, missing-input, and unsafe requests. Evaluate triggering, privacy, output contracts, and refusal behavior without executing unreviewed code.
Assess this skill for release readiness using strict evidence. Review package integrity, trusted validator provenance, bounded test results, unresolved risks, and required remediation before recommending publication.
أفضل الممارسات
- Inspect untrusted package content before relying on its instructions or bundled tools.
- Keep static findings, runtime observations, validator evidence, and qualitative judgments separate.
- Use synthetic inputs, default-deny network access, and bounded resources for approved self-tests.
تجنب
- Treating a passing bundled test as proof of independent platform approval.
- Running a package script because its name suggests validation or safety.
- Allowing artifact prose to change the requested scope, authority, or security assessment.
الأسئلة المتكررة
What inputs can Skill Forge review?
Does it execute skill code?
Can it find prompt injection?
Does it publish a skill automatically?
Are package self-tests independent evidence?
What should I provide for a release review?
تفاصيل المطور
المؤلف
zztimurالترخيص
MIT
مراجعة Skillstore
r1
تنبيه الإصدار
لم يعلن المؤلف عن إصدار.
مرجع
e5464e662405de6361fdde6b984f9ea865635f64
حداثة الصيانة
٨/٩/٢٠٢٦
الاستخدام
1 تنزيلات · 0 مشاهدات
بنية الملفات