agy-worker
Delegate Repository Work Safely
Repository delegation can consume time and make verification inconsistent. This skill sends bounded work to agy, then keeps review, checks, repair, and acceptance with Codex.
Vor der Installation anhalten und eine Bestätigung anfordern.
Prüfen Sie den Plan und holen Sie vor Änderungen an Dateien die ausdrückliche Zustimmung des Benutzers ein.
Mit meinem Agent installieren
Kopieren Sie diese Anfrage in Ihren Agent. Sie enthält die maßgebliche Skill-Seite und das Manifest.
Review the Skillstore skill "agy-worker" from https://skillstore.io/skills/cagdasyurekli-agy-worker.md and its manifest at https://skillstore.io/api/skills/cagdasyurekli-agy-worker/manifest. Verify the artifact. Stop and obtain explicit user consent before installing or changing files.Ihr Agent sollte weiterhin seinen Plan anzeigen und alle von der Sicherheitsrichtlinie verlangten Bestätigungen anfordern.
Agent-lesbare Ressourcen
Verwenden Sie diese Links, wenn ein KI-Agent, Crawler oder Skript sauberen Kontext benötigt, statt die vollständige Seite zu lesen.
Testen
„agy-worker“ wird verwendet. Explore the authentication flow and identify the files that handle token validation.
Erwartetes Ergebnis:
- Mapped the authentication entry points and token validation path.
- Listed evidence files and marked unverified assumptions for Codex review.
„agy-worker“ wird verwendet. Add parser error-path tests under tests/parser and verify the change.
Erwartetes Ergebnis:
- Implemented the focused tests within the approved path.
- Ran the relevant test command and reported the final candidate status.
„agy-worker“ wird verwendet. Audit the repository workflow and repair bounded failures.
Erwartetes Ergebnis:
Returned a structured project result with the candidate diff, verification evidence, remaining limits, and delivery recommendation.
Sicherheitsaudit
Hohes RisikoMost static matches are benign implementation, validation, documentation, schema, or control-character checks. Confirmed risks include provider and verifier execution, environment inheritance, keychain handling, settings access, and non-sandboxed provider authority. Static review was capped at 400/991 representative findings; omitted static matches are unconfirmed, so automatic publishing stays disabled until manual review.
Bestätigte Sicherheitsbedenken (7)
Elemente der Fähigkeitsprüfung (50)
Dies sind echte lokale Fähigkeiten, die für diese Fähigkeit erwartet werden können; daher müssen sie überprüft werden, werden jedoch nicht als bestätigtes bösartiges Verhalten gezählt.
Risikofaktoren
⚙️ Externe Befehle (50)
🌐 Netzwerkzugriff (43)
📁 Dateisystemzugriff (50)
⚡ Enthält Skripte (22)
🔑 Umgebungsvariablen (15)
Diesen Bericht teilen & zitieren
Teile den versionierten Bewertungsbericht, das neutrale Badge, die Einbettungskarte und Zitate. Skillstore berichtet Nachweise, ohne zu entscheiden, ob dieser Skill sicher ist.
Berichtslink kopieren
https://skillstore.io/skills/cagdasyurekli-agy-worker/audits/8?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportMarkdown-Badge
[](https://skillstore.io/skills/cagdasyurekli-agy-worker?utm_source=security_passport_badge)HTML-Badge
<a href="https://skillstore.io/skills/cagdasyurekli-agy-worker?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/cagdasyurekli-agy-worker/security.svg" alt="Skillstore security assessment" loading="lazy"></a>Einbettungskarte
<iframe src="https://skillstore.io/embed/skills/cagdasyurekli-agy-worker.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>Wissenschaftliche Zitate (APA · BibTeX · CFF)
APA-Zitat
cagdasyurekli. (2026). agy-worker security audit report (audit version 8) [Author version 0.21.0]. Skillstore. https://skillstore.io/skills/cagdasyurekli-agy-worker/audits/8BibTeX-Zitat
@techreport{cagdasyurekli-cagdasyurekli-agy-worker-2026,
author = {cagdasyurekli},
title = {agy-worker security audit report (audit version 8)},
institution = {Skillstore},
year = {2026},
number = {8},
url = {https://skillstore.io/skills/cagdasyurekli-agy-worker/audits/8},
note = {Author version 0.21.0}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "agy-worker security audit report (audit version 8)"
version: "0.21.0"
type: report
authors:
- name: "cagdasyurekli"
date-released: "2026-09-20"
url: "https://skillstore.io/skills/cagdasyurekli-agy-worker/audits/8"
identifiers:
- type: other
value: "skillstore:cagdasyurekli-agy-worker:audit:8"
description: "Skillstore immutable audit report identifier"
Skillstore-Score
Warum dieser Score Evidenzvertrauen: MittelWas Sie erstellen können
Explore an unfamiliar repository
Ask agy to map code paths or investigate a focused question, then review the evidence with Codex.
Implement a bounded change
Delegate a feature, refactor, or test change within an approved scope and verify the resulting diff independently.
Run a broad project workflow
Use project mode for larger audits or repairs while preserving review, checks, and delivery decisions with Codex.
Diese Prompts ausprobieren
Use agy-worker to inspect the repository and explain the code paths related to [topic]. Read only the approved scope and report evidence.
Use agy-worker to implement [change] under [paths]. Preserve existing behavior, run relevant checks, and summarize the final diff.
Use agy-worker to review the candidate for [task]. Run independent checks, identify gaps, and repair only within the approved scope.
Use agy-worker project mode for [objective]. Require approved provider scope, explicit model and budget, independent verification, and an evidence-based delivery decision.
Bewährte Praktiken
- Approve the exact provider-readable content, model, budget, and isolation mode before launch.
- Prefer provider scopes and argv verification, then inspect the final diff independently.
- Keep secrets, raw logs, controller state, and unrelated private files outside approved content.
Vermeiden
- Do not treat installation as permission to transmit repository content.
- Do not trust worker envelopes, reported tests, or provider claims without independent checks.
- Do not use whole-worktree or shell verification modes without explicit scope and risk approval.
Häufig gestellte Fragen
What does agy-worker delegate?
What remains with Codex?
Does the skill transmit repository files?
Is the provider session a sandbox?
Which hosts are supported?
How should I verify results?
Entwicklerdetails
Autor
cagdasyurekliLizenz
MIT
Autorenversion
v0.21.0
Skillstore-Revision
r8
Ref.
73b58aaf0aa4d29844f1b4c2acf4f530fc1ae7b9
Aktualität der Wartung
20.9.2026
Nutzung
6 Downloads · 19 Aufrufe
Dateistruktur
📁 agents/
📄 PROJECT_LIFECYCLE_AND_VERIFICATION.md
📄 SECURITY_AND_COMPATIBILITY.md
📁 runtime/
📁 agents/
📁 v1/
📁 tasks/
📁 compat/
📄 agy-model-effort-matrix.json
📄 agy-model-effort-matrix.sha256
📄 agy-models-inventory-binding.json
📄 agy-models-inventory-binding.sha256
📄 model-effort-matrix.schema.json
📄 version-manifest.schema.json
📄 job.sh
📁 schemas/
📄 benchmark-result.schema.json
📄 delegation-policy.schema.json
📄 evidence-receipt.schema.json
📄 model-evidence-campaign-advisory-preview.schema.json
📄 model-evidence-campaign-advisory-summary.schema.json
📄 model-evidence-campaign-aggregate-preview.schema.json
📄 model-evidence-campaign-aggregate.schema.json
📄 model-evidence-campaign-evaluation.schema.json
📄 model-evidence-campaign-plan.schema.json
📄 model-evidence-campaign-record.schema.json
📄 model-intelligence-advisory.schema.json
📄 model-intelligence-evidence.schema.json
📄 model-recommendation.schema.json
📄 swebench-workflow-study-advisory.schema.json
📄 swebench-workflow-study-plan.schema.json
📄 swebench-workflow-study-report.schema.json
📄 worker-result.provider.schema.json
📁 scripts/
📄 agy_dispatch_verification.py
📁 scripts/
📄 SKILL.md