πŸ“¦

agy-worker

v0.21.0 РСвизия содСрТимого r8 Высокий риск βš™οΈ Π’Π½Π΅ΡˆΠ½ΠΈΠ΅ ΠΊΠΎΠΌΠ°Π½Π΄Ρ‹πŸŒ Доступ ΠΊ ΡΠ΅Ρ‚ΠΈπŸ“ Доступ ΠΊ Ρ„Π°ΠΉΠ»ΠΎΠ²ΠΎΠΉ ΡΠΈΡΡ‚Π΅ΠΌΠ΅βš‘ Π‘ΠΎΠ΄Π΅Ρ€ΠΆΠΈΡ‚ ΡΠΊΡ€ΠΈΠΏΡ‚Ρ‹πŸ”‘ ΠŸΠ΅Ρ€Π΅ΠΌΠ΅Π½Π½Ρ‹Π΅ окруТСния

Delegate Repository Work Safely

Repository delegation can consume time and make verification inconsistent. This skill sends bounded work to agy, then keeps review, checks, repair, and acceptance with Codex.

ΠŸΠΎΠ΄Π΄Π΅Ρ€ΠΆΠΈΠ²Π°Π΅Ρ‚: Codex
⚠️ 38 ΠŸΠ»ΠΎΡ…ΠΎ

Π£ΡΡ‚Π°Π½ΠΎΠ²ΠΈΡ‚ΡŒ с ΠΏΠΎΠΌΠΎΡ‰ΡŒΡŽ ΠΌΠΎΠ΅Π³ΠΎ АгСнта

Π‘ΠΊΠΎΠΏΠΈΡ€ΡƒΠΉΡ‚Π΅ этот запрос Π² своСго АгСнта. Он содСрТит ΠΊΠ°Π½ΠΎΠ½ΠΈΡ‡Π΅ΡΠΊΡƒΡŽ страницу Skill ΠΈ манифСст.

Запрос Π°Π³Π΅Π½Ρ‚Π°
Review the Skillstore skill "agy-worker" from https://skillstore.io/skills/cagdasyurekli-agy-worker.md and its manifest at https://skillstore.io/api/skills/cagdasyurekli-agy-worker/manifest. Verify the artifact. Stop and obtain explicit user consent before installing or changing files.

Π’Π°Ρˆ АгСнт ΠΏΠΎ-ΠΏΡ€Π΅ΠΆΠ½Π΅ΠΌΡƒ Π΄ΠΎΠ»ΠΆΠ΅Π½ ΠΏΠΎΠΊΠ°Π·Π°Ρ‚ΡŒ ΠΏΠ»Π°Π½ ΠΈ Π·Π°ΠΏΡ€ΠΎΡΠΈΡ‚ΡŒ всС подтвСрТдСния, Ρ‚Ρ€Π΅Π±ΡƒΠ΅ΠΌΡ‹Π΅ ΠΏΠΎΠ»ΠΈΡ‚ΠΈΠΊΠΎΠΉ бСзопасности.

РСсурсы для AI-Π°Π³Π΅Π½Ρ‚ΠΎΠ²

Π˜ΡΠΏΠΎΠ»ΡŒΠ·ΡƒΠΉΡ‚Π΅ эти ссылки, ΠΊΠΎΠ³Π΄Π° AI-Π°Π³Π΅Π½Ρ‚Ρƒ, crawler ΠΈΠ»ΠΈ script Π½ΡƒΠΆΠ΅Π½ чистый контСкст вмСсто ΠΏΠΎΠ»Π½ΠΎΠΉ страницы.

ΠŸΡ€ΠΎΡ‚Π΅ΡΡ‚ΠΈΡ€ΠΎΠ²Π°Ρ‚ΡŒ

ИспользованиС «agy-worker». Explore the authentication flow and identify the files that handle token validation.

ΠžΠΆΠΈΠ΄Π°Π΅ΠΌΡ‹ΠΉ Ρ€Π΅Π·ΡƒΠ»ΡŒΡ‚Π°Ρ‚:

  • Mapped the authentication entry points and token validation path.
  • Listed evidence files and marked unverified assumptions for Codex review.

ИспользованиС «agy-worker». Add parser error-path tests under tests/parser and verify the change.

ΠžΠΆΠΈΠ΄Π°Π΅ΠΌΡ‹ΠΉ Ρ€Π΅Π·ΡƒΠ»ΡŒΡ‚Π°Ρ‚:

  • Implemented the focused tests within the approved path.
  • Ran the relevant test command and reported the final candidate status.

ИспользованиС «agy-worker». Audit the repository workflow and repair bounded failures.

ΠžΠΆΠΈΠ΄Π°Π΅ΠΌΡ‹ΠΉ Ρ€Π΅Π·ΡƒΠ»ΡŒΡ‚Π°Ρ‚:

Returned a structured project result with the candidate diff, verification evidence, remaining limits, and delivery recommendation.

Аудит бСзопасности

Высокий риск

Most static matches are benign implementation, validation, documentation, schema, or control-character checks. Confirmed risks include provider and verifier execution, environment inheritance, keychain handling, settings access, and non-sandboxed provider authority. Static review was capped at 400/991 representative findings; omitted static matches are unconfirmed, so automatic publishing stays disabled until manual review.

92
ΠŸΡ€ΠΎΡΠΊΠ°Π½ΠΈΡ€ΠΎΠ²Π°Π½ΠΎ Ρ„Π°ΠΉΠ»ΠΎΠ²
39,230
ΠŸΡ€ΠΎΠ°Π½Π°Π»ΠΈΠ·ΠΈΡ€ΠΎΠ²Π°Π½ΠΎ строк
50
ΠŸΡƒΠ½ΠΊΡ‚Ρ‹ ΠΏΡ€ΠΎΠ²Π΅Ρ€ΠΊΠΈ
0
Π›ΠΎΠΆΠ½Ρ‹Π΅ срабатывания ΠΏΡ€ΠΎΠΈΠ³Π½ΠΎΡ€ΠΈΡ€ΠΎΠ²Π°Π½Ρ‹

ΠŸΠΎΠ΄Ρ‚Π²Π΅Ρ€ΠΆΠ΄Ρ‘Π½Π½Ρ‹Π΅ ΠΏΡ€ΠΎΠ±Π»Π΅ΠΌΡ‹ бСзопасности (7)

Высокий
Certificate/key files
keychain_path=prepared.keychain.path if prepared.keychain is not None else None,
The code binds a prepared keychain path or keychain preferences file, which is a sensitive-resource capability. It is used for native isolation, but compromise of the boundary could expose credential material.
Высокий
Certificate/key files
if prepared.keychain is None or prepared.keychain_preferences is None:
The code binds a prepared keychain path or keychain preferences file, which is a sensitive-resource capability. It is used for native isolation, but compromise of the boundary could expose credential material.
Высокий
Certificate/key files
if _bind_keychain(prepared.keychain.path) != prepared.keychain:
The code binds a prepared keychain path or keychain preferences file, which is a sensitive-resource capability. It is used for native isolation, but compromise of the boundary could expose credential material.
Высокий
Certificate/key files
prepared.keychain_preferences.path, modes={0o600}, limit=MAX_PROFILE_BYTES,
The code binds a prepared keychain path or keychain preferences file, which is a sensitive-resource capability. It is used for native isolation, but compromise of the boundary could expose credential material.
Высокий
Certificate/key files
) != prepared.keychain_preferences:
The code binds a prepared keychain path or keychain preferences file, which is a sensitive-resource capability. It is used for native isolation, but compromise of the boundary could expose credential material.
Высокий
Certificate/key files
prepared.keychain is not None or prepared.keychain_preferences is not None
The code binds a prepared keychain path or keychain preferences file, which is a sensitive-resource capability. It is used for native isolation, but compromise of the boundary could expose credential material.
Высокий
External Provider Transmission Without Host Isolation
The skill can transmit a whole disposable worktree to Google or Gemini, while default session mode retains normal user filesystem and network authority without host containment.
The documented workflow explicitly states both the external transmission boundary and the lack of sandbox or native containment in default session mode.
ΠŸΡƒΠ½ΠΊΡ‚Ρ‹ ΠΏΡ€ΠΎΠ²Π΅Ρ€ΠΊΠΈ возмоТностСй (50)

Π­Ρ‚ΠΎ Ρ€Π΅Π°Π»ΡŒΠ½Ρ‹Π΅ Π»ΠΎΠΊΠ°Π»ΡŒΠ½Ρ‹Π΅ возмоТности, ΠΊΠΎΡ‚ΠΎΡ€Ρ‹Π΅ ΠΌΠΎΠ³ΡƒΡ‚ ΠΎΠΆΠΈΠ΄Π°Ρ‚ΡŒΡΡ для этого Π½Π°Π²Ρ‹ΠΊΠ°, поэтому ΠΎΠ½ΠΈ Ρ‚Ρ€Π΅Π±ΡƒΡŽΡ‚ ΠΏΡ€ΠΎΠ²Π΅Ρ€ΠΊΠΈ, Π½ΠΎ Π½Π΅ ΡΡ‡ΠΈΡ‚Π°ΡŽΡ‚ΡΡ ΠΏΠΎΠ΄Ρ‚Π²Π΅Ρ€ΠΆΠ΄Ρ‘Π½Π½Ρ‹ΠΌ врСдоносным ΠΏΠΎΠ²Π΅Π΄Π΅Π½ΠΈΠ΅ΠΌ.

Высокий
Hidden file in home directory
p = os.path.expanduser("~/.gemini/antigravity-cli/settings.json")
The account-phase helper expands and reads the user settings file under ~/.gemini. This accesses provider configuration that may contain sensitive permissions or account settings.
Высокий
Process spawn
return spawn(job, "initial", resume=False, foreground=True)
The runtime launches provider, Git, or verification processes. This is required by the skill, but it creates a real command-execution boundary that must remain approval-bound.
Высокий
Process spawn
return spawn(job, "initial", resume=False, foreground=False)
The runtime launches provider, Git, or verification processes. This is required by the skill, but it creates a real command-execution boundary that must remain approval-bound.
Высокий
Process spawn
return spawn(
The runtime launches provider, Git, or verification processes. This is required by the skill, but it creates a real command-execution boundary that must remain approval-bound.
Высокий
Process spawn
return spawn(
The runtime launches provider, Git, or verification processes. This is required by the skill, but it creates a real command-execution boundary that must remain approval-bound.
Высокий
Python os.exec variants
os.execvpe(command[0], command, dict(os.environ))
The runtime launches provider, Git, or verification processes. This is required by the skill, but it creates a real command-execution boundary that must remain approval-bound.
Высокий
Python subprocess.Popen
process = subprocess.Popen(
The runtime launches provider, Git, or verification processes. This is required by the skill, but it creates a real command-execution boundary that must remain approval-bound.
Высокий
Python subprocess.Popen
process = subprocess.Popen(
The runtime launches provider, Git, or verification processes. This is required by the skill, but it creates a real command-execution boundary that must remain approval-bound.
Высокий
Python subprocess.Popen
child = subprocess.Popen(
The runtime launches provider, Git, or verification processes. This is required by the skill, but it creates a real command-execution boundary that must remain approval-bound.
Высокий
Python subprocess.Popen
process = subprocess.Popen(
The runtime launches provider, Git, or verification processes. This is required by the skill, but it creates a real command-execution boundary that must remain approval-bound.
Высокий
Python subprocess.Popen
process = subprocess.Popen(
The runtime launches provider, Git, or verification processes. This is required by the skill, but it creates a real command-execution boundary that must remain approval-bound.
Высокий
Python subprocess.Popen
controller_process = subprocess.Popen(
The runtime launches provider, Git, or verification processes. This is required by the skill, but it creates a real command-execution boundary that must remain approval-bound.
Высокий
Python subprocess.Popen
process = subprocess.Popen(argv, cwd=cwd, env=git_env(), stdin=subprocess.DEVNULL, stdout=subprocess
The runtime launches provider, Git, or verification processes. This is required by the skill, but it creates a real command-execution boundary that must remain approval-bound.
Высокий
Python subprocess.Popen
process = subprocess.Popen(
The runtime launches provider, Git, or verification processes. This is required by the skill, but it creates a real command-execution boundary that must remain approval-bound.
Высокий
Python subprocess.Popen
process = subprocess.Popen(
The runtime launches provider, Git, or verification processes. This is required by the skill, but it creates a real command-execution boundary that must remain approval-bound.
Высокий
Python subprocess.run
return subprocess.run(
The runtime launches provider, Git, or verification processes. This is required by the skill, but it creates a real command-execution boundary that must remain approval-bound.
Высокий
Python subprocess.run
subprocess.run(
The runtime launches provider, Git, or verification processes. This is required by the skill, but it creates a real command-execution boundary that must remain approval-bound.
Высокий
Python subprocess.run
subprocess.run(
The runtime launches provider, Git, or verification processes. This is required by the skill, but it creates a real command-execution boundary that must remain approval-bound.
Высокий
Python subprocess.run
provider_checked = subprocess.run(
The runtime launches provider, Git, or verification processes. This is required by the skill, but it creates a real command-execution boundary that must remain approval-bound.
Высокий
Python subprocess.run
canonical_checked = subprocess.run(
The runtime launches provider, Git, or verification processes. This is required by the skill, but it creates a real command-execution boundary that must remain approval-bound.
Высокий
Python subprocess.run
subprocess.run(
The runtime launches provider, Git, or verification processes. This is required by the skill, but it creates a real command-execution boundary that must remain approval-bound.
Высокий
Python subprocess.run
result = subprocess.run(command, cwd=cwd, env=git_env(), stdin=subprocess.DEVNULL, stdout=subprocess
The runtime launches provider, Git, or verification processes. This is required by the skill, but it creates a real command-execution boundary that must remain approval-bound.
Высокий
Python subprocess.run
completed = subprocess.run(
The runtime launches provider, Git, or verification processes. This is required by the skill, but it creates a real command-execution boundary that must remain approval-bound.
Высокий
Python subprocess.run
completed = subprocess.run(
The runtime launches provider, Git, or verification processes. This is required by the skill, but it creates a real command-execution boundary that must remain approval-bound.
Высокий
Python subprocess.run
proc = subprocess.run(
The runtime launches provider, Git, or verification processes. This is required by the skill, but it creates a real command-execution boundary that must remain approval-bound.
Высокий
Python subprocess.run
proc = subprocess.run(
The runtime launches provider, Git, or verification processes. This is required by the skill, but it creates a real command-execution boundary that must remain approval-bound.
Высокий
Python subprocess.run
proc = subprocess.run(
The runtime launches provider, Git, or verification processes. This is required by the skill, but it creates a real command-execution boundary that must remain approval-bound.
Высокий
Python subprocess.run
proc = subprocess.run(
The runtime launches provider, Git, or verification processes. This is required by the skill, but it creates a real command-execution boundary that must remain approval-bound.
Высокий
Python subprocess.run
return subprocess.run(
The runtime launches provider, Git, or verification processes. This is required by the skill, but it creates a real command-execution boundary that must remain approval-bound.
Высокий
Python subprocess.run
proc = subprocess.run(
The runtime launches provider, Git, or verification processes. This is required by the skill, but it creates a real command-execution boundary that must remain approval-bound.
Высокий
Python subprocess.run
proc = subprocess.run(verify_cmd, check=False)
The runtime launches provider, Git, or verification processes. This is required by the skill, but it creates a real command-execution boundary that must remain approval-bound.
Высокий
Python subprocess.run
fin_proc = subprocess.run(
The runtime launches provider, Git, or verification processes. This is required by the skill, but it creates a real command-execution boundary that must remain approval-bound.
Π‘Ρ€Π΅Π΄Π½ΠΈΠΉ
Hidden file access
p = os.path.expanduser("~/.gemini/antigravity-cli/settings.json")
The account-phase helper expands and reads the user settings file under ~/.gemini. This accesses provider configuration that may contain sensitive permissions or account settings.
Π‘Ρ€Π΅Π΄Π½ΠΈΠΉ
Unix shell invocation
/bin/bash -c "${verify_specs[$i]}"
The verifier invokes a shell or defines a shell supervisor. Shell execution can run arbitrary commands, so this is a real execution boundary even with the documented controls.
Π‘Ρ€Π΅Π΄Π½ΠΈΠΉ
Unix shell invocation
/bin/bash -c "${verify_specs[$i]}"
The verifier invokes a shell or defines a shell supervisor. Shell execution can run arbitrary commands, so this is a real execution boundary even with the documented controls.
Π‘Ρ€Π΅Π΄Π½ΠΈΠΉ
Unix shell invocation
SCRIPT_SHELLS = frozenset({"/bin/bash", "/bin/sh"})
The verifier invokes a shell or defines a shell supervisor. Shell execution can run arbitrary commands, so this is a real execution boundary even with the documented controls.
Π‘Ρ€Π΅Π΄Π½ΠΈΠΉ
Unix shell invocation
"/bin/sh", "-c", supervisor, "bounded-git-supervisor",
The verifier invokes a shell or defines a shell supervisor. Shell execution can run arbitrary commands, so this is a real execution boundary even with the documented controls.
Π‘Ρ€Π΅Π΄Π½ΠΈΠΉ
Unix shell invocation
"/bin/bash",
The verifier invokes a shell or defines a shell supervisor. Shell execution can run arbitrary commands, so this is a real execution boundary even with the documented controls.
Низкий
Python environment access
environment = os.environ.copy()
The code reads or copies the process environment for child execution. Environment variables can contain credentials, so filtering must remain complete and approval-bound.
Низкий
Python environment access
if name in os.environ:
The code reads or copies the process environment for child execution. Environment variables can contain credentials, so filtering must remain complete and approval-bound.
Низкий
Python environment access
(os.fsencode(name), b"\0", os.fsencode(os.environ[name]), b"\0")
The code reads or copies the process environment for child execution. Environment variables can contain credentials, so filtering must remain complete and approval-bound.
Низкий
Python environment access
os.execvpe(command[0], command, dict(os.environ))
The code reads or copies the process environment for child execution. Environment variables can contain credentials, so filtering must remain complete and approval-bound.
Низкий
Python environment access
environment = os.environ.copy()
The code reads or copies the process environment for child execution. Environment variables can contain credentials, so filtering must remain complete and approval-bound.
Низкий
Python environment access
environment = {name: os.environ[name] for name in allowed if name in os.environ}
The code reads or copies the process environment for child execution. Environment variables can contain credentials, so filtering must remain complete and approval-bound.
Низкий
Python environment access
configured = os.environ.get("XDG_STATE_HOME")
The code reads or copies the process environment for child execution. Environment variables can contain credentials, so filtering must remain complete and approval-bound.
Низкий
Python environment access
home_text = os.environ.get("HOME")
The code reads or copies the process environment for child execution. Environment variables can contain credentials, so filtering must remain complete and approval-bound.
Низкий
Python environment access
environment = dict(os.environ)
The code reads or copies the process environment for child execution. Environment variables can contain credentials, so filtering must remain complete and approval-bound.
Низкий
Python environment access
env = dict(os.environ)
The code reads or copies the process environment for child execution. Environment variables can contain credentials, so filtering must remain complete and approval-bound.
Низкий
Python environment access
os.environ.get("AGY_WORKER_LOG_DIR") or (state_path.parent / "logs")
The code reads or copies the process environment for child execution. Environment variables can contain credentials, so filtering must remain complete and approval-bound.
Низкий
Python environment access
os.environ.get("AGY_WORKER_LOG_DIR") or (SCRIPTS.parent / "logs")
The code reads or copies the process environment for child execution. Environment variables can contain credentials, so filtering must remain complete and approval-bound.

Π€Π°ΠΊΡ‚ΠΎΡ€Ρ‹ риска

βš™οΈ Π’Π½Π΅ΡˆΠ½ΠΈΠ΅ ΠΊΠΎΠΌΠ°Π½Π΄Ρ‹ (50)
README.md:56 references/PROJECT_LIFECYCLE_AND_VERIFICATION.md:71 references/PROJECT_LIFECYCLE_AND_VERIFICATION.md:80 references/PROJECT_LIFECYCLE_AND_VERIFICATION.md:81 references/PROJECT_LIFECYCLE_AND_VERIFICATION.md:82 references/PROJECT_LIFECYCLE_AND_VERIFICATION.md:252 references/PROJECT_LIFECYCLE_AND_VERIFICATION.md:253 references/PROJECT_LIFECYCLE_AND_VERIFICATION.md:287 references/PROJECT_LIFECYCLE_AND_VERIFICATION.md:288-290 runtime/agy-worker.sh:14 runtime/agy-worker.sh:15 runtime/agy-worker.sh:1262 runtime/agy-worker.sh:1263 runtime/agy-worker.sh:1300 runtime/agy-worker.sh:25 runtime/agy-worker.sh:30 runtime/agy-worker.sh:237 runtime/agy-worker.sh:464 runtime/agy-worker.sh:473-475 runtime/agy-worker.sh:497 runtime/agy-worker.sh:498 runtime/agy-worker.sh:499 runtime/agy-worker.sh:603 runtime/agy-worker.sh:604 runtime/agy-worker.sh:649 runtime/agy-worker.sh:650 runtime/agy-worker.sh:651 runtime/agy-worker.sh:652 runtime/agy-worker.sh:663 runtime/agy-worker.sh:685 runtime/agy-worker.sh:690 runtime/agy-worker.sh:692 runtime/agy-worker.sh:696 runtime/agy-worker.sh:720-725 runtime/agy-worker.sh:901-906 runtime/agy-worker.sh:980 runtime/agy-worker.sh:1009-1011 runtime/agy-worker.sh:1043-1054 runtime/agy-worker.sh:1225 runtime/agy-worker.sh:1226 runtime/agy-worker.sh:1306 runtime/agy-worker.sh:15-1262 runtime/benchmark.sh:5 runtime/codex-usage-report.sh:5 runtime/delegation-policy.sh:5 runtime/doctor.sh:21 runtime/doctor.sh:32 runtime/doctor.sh:37-38 runtime/doctor.sh:85-86 runtime/doctor.sh:146-147
🌐 Доступ ΠΊ сСти (43)
references/PROJECT_LIFECYCLE_AND_VERIFICATION.md:25 runtime/compat/agy-version-manifest.json:20 runtime/compat/agy-version-manifest.json:64 runtime/compat/agy-version-manifest.json:111 runtime/compat/agy-version-manifest.json:163 runtime/compat/agy-version-manifest.json:212 runtime/compat/agy-version-manifest.json:257 runtime/compat/agy-version-manifest.json:277 runtime/compat/agy-version-manifest.json:303 runtime/compat/agy-version-manifest.json:347 runtime/compat/model-effort-matrix.schema.json:2 runtime/compat/model-effort-matrix.schema.json:3 runtime/compat/version-manifest.schema.json:2 runtime/schemas/benchmark-plan.schema.json:1 runtime/schemas/benchmark-result.schema.json:1 runtime/schemas/delegation-policy.schema.json:2 runtime/schemas/evidence-receipt.schema.json:2 runtime/schemas/job-state.schema.json:2 runtime/schemas/model-evidence-campaign-advisory-preview.schema.json:2 runtime/schemas/model-evidence-campaign-advisory-summary.schema.json:2 runtime/schemas/model-evidence-campaign-aggregate-preview.schema.json:2 runtime/schemas/model-evidence-campaign-aggregate.schema.json:2 runtime/schemas/model-evidence-campaign-evaluation.schema.json:2 runtime/schemas/model-evidence-campaign-plan.schema.json:2 runtime/schemas/model-evidence-campaign-record.schema.json:2 runtime/schemas/model-evidence-campaign-record.schema.json:156 runtime/schemas/model-intelligence-advisory.schema.json:2 runtime/schemas/model-intelligence-evidence.schema.json:2 runtime/schemas/model-intelligence-evidence.schema.json:85 runtime/schemas/model-recommendation.schema.json:2 runtime/schemas/model-selection.schema.json:2 runtime/schemas/swebench-workflow-study-advisory.schema.json:1 runtime/schemas/swebench-workflow-study-report.schema.json:1 runtime/schemas/worker-result.provider.schema.json:2 runtime/schemas/worker-result.schema.json:2 runtime/schemas/workflow-state.schema.json:2 runtime/scripts/codex_usage_report.py:726 runtime/scripts/compatibility.py:245 runtime/scripts/compatibility.py:246 runtime/scripts/feedback-triage.py:31 runtime/scripts/model_evidence_campaign.py:28 runtime/scripts/model_intelligence.py:26 SKILL.md:36
πŸ“ Доступ ΠΊ Ρ„Π°ΠΉΠ»ΠΎΠ²ΠΎΠΉ систСмС (50)
⚑ Π‘ΠΎΠ΄Π΅Ρ€ΠΆΠΈΡ‚ скрипты (22)
πŸ”‘ ΠŸΠ΅Ρ€Π΅ΠΌΠ΅Π½Π½Ρ‹Π΅ окруТСния (15)
ΠŸΠΎΠ΄Π΅Π»ΠΈΡ‚ΡŒΡΡ ΠΈ Ρ†ΠΈΡ‚ΠΈΡ€ΠΎΠ²Π°Ρ‚ΡŒ этот ΠΎΡ‚Ρ‡Π΅Ρ‚

Π”Π΅Π»ΠΈΡ‚Π΅ΡΡŒ вСрсионным ΠΎΡ‚Ρ‡Π΅Ρ‚ΠΎΠΌ ΠΎΠ± ΠΎΡ†Π΅Π½ΠΊΠ΅, Π½Π΅ΠΉΡ‚Ρ€Π°Π»ΡŒΠ½Ρ‹ΠΌ Π·Π½Π°Ρ‡ΠΊΠΎΠΌ, встраиваСмой ΠΊΠ°Ρ€Ρ‚ΠΎΡ‡ΠΊΠΎΠΉ ΠΈ Ρ†ΠΈΡ‚Π°Ρ‚Π°ΠΌΠΈ. Skillstore ΠΏΡƒΠ±Π»ΠΈΠΊΡƒΠ΅Ρ‚ Π΄ΠΎΠΊΠ°Π·Π°Ρ‚Π΅Π»ΡŒΡΡ‚Π²Π°, Π½Π΅ Ρ€Π΅ΡˆΠ°Ρ, бСзопасСн Π»ΠΈ этот Skill.

ΠžΡ‚ΠΊΡ€Ρ‹Ρ‚ΡŒ вСрсионный ΠΎΡ‚Ρ‡Π΅Ρ‚
ΠžΡ†Π΅Π½ΠΊΠ° бСзопасности

ΠšΠΎΠΏΠΈΡ€ΠΎΠ²Π°Ρ‚ΡŒ ссылку Π½Π° ΠΎΡ‚Ρ‡Ρ‘Ρ‚

https://skillstore.io/skills/cagdasyurekli-agy-worker/audits/8?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report

Π—Π½Π°Ρ‡ΠΎΠΊ Markdown

[![Skillstore security assessment](https://skillstore.io/badges/skills/cagdasyurekli-agy-worker/security.svg)](https://skillstore.io/skills/cagdasyurekli-agy-worker?utm_source=security_passport_badge)

Π—Π½Π°Ρ‡ΠΎΠΊ HTML

<a href="https://skillstore.io/skills/cagdasyurekli-agy-worker?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/cagdasyurekli-agy-worker/security.svg" alt="Skillstore security assessment" loading="lazy"></a>

ВстраиваСмая ΠΊΠ°Ρ€Ρ‚ΠΎΡ‡ΠΊΠ°

<iframe src="https://skillstore.io/embed/skills/cagdasyurekli-agy-worker.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>
АкадСмичСскиС ссылки (APA Β· BibTeX Β· CFF)

Π¦ΠΈΡ‚Π°Ρ‚Π° APA

cagdasyurekli. (2026). agy-worker security audit report (audit version 8) [Author version 0.21.0]. Skillstore. https://skillstore.io/skills/cagdasyurekli-agy-worker/audits/8

Π¦ΠΈΡ‚Π°Ρ‚Π° BibTeX

@techreport{cagdasyurekli-cagdasyurekli-agy-worker-2026, author = {cagdasyurekli}, title = {agy-worker security audit report (audit version 8)}, institution = {Skillstore}, year = {2026}, number = {8}, url = {https://skillstore.io/skills/cagdasyurekli-agy-worker/audits/8}, note = {Author version 0.21.0} }

CITATION.cff

cff-version: 1.2.0 message: "If you use this Skill, cite its author and this versioned security audit report." title: "agy-worker security audit report (audit version 8)" version: "0.21.0" type: report authors: - name: "cagdasyurekli" date-released: "2026-09-20" url: "https://skillstore.io/skills/cagdasyurekli-agy-worker/audits/8" identifiers: - type: other value: "skillstore:cagdasyurekli-agy-worker:audit:8" description: "Skillstore immutable audit report identifier"

ΠžΡ†Π΅Π½ΠΊΠ° Skillstore

ΠŸΠΎΡ‡Π΅ΠΌΡƒ такая ΠΎΡ†Π΅Π½ΠΊΠ° Π”ΠΎΡΡ‚ΠΎΠ²Π΅Ρ€Π½ΠΎΡΡ‚ΡŒ Π΄ΠΎΠΊΠ°Π·Π°Ρ‚Π΅Π»ΡŒΡΡ‚Π²: Π‘Ρ€Π΅Π΄Π½ΠΈΠΉ
82
АрхитСктура
100
Π‘ΠΎΠΏΡ€ΠΎΠ²ΠΎΠΆΠ΄Π°Π΅ΠΌΠΎΡΡ‚ΡŒ
87
ΠšΠΎΠ½Ρ‚Π΅Π½Ρ‚
67
БообщСство
91
БоотвСтствиС спСцификации

Π§Ρ‚ΠΎ Π²Ρ‹ ΠΌΠΎΠΆΠ΅Ρ‚Π΅ ΠΏΠΎΡΡ‚Ρ€ΠΎΠΈΡ‚ΡŒ

Explore an unfamiliar repository

Ask agy to map code paths or investigate a focused question, then review the evidence with Codex.

Implement a bounded change

Delegate a feature, refactor, or test change within an approved scope and verify the resulting diff independently.

Run a broad project workflow

Use project mode for larger audits or repairs while preserving review, checks, and delivery decisions with Codex.

ΠŸΠΎΠΏΡ€ΠΎΠ±ΡƒΠΉΡ‚Π΅ эти ΠΏΡ€ΠΎΠΌΠΏΡ‚Ρ‹

Start a repository exploration
Use agy-worker to inspect the repository and explain the code paths related to [topic]. Read only the approved scope and report evidence.
Implement a focused task
Use agy-worker to implement [change] under [paths]. Preserve existing behavior, run relevant checks, and summarize the final diff.
Verify a delegated change
Use agy-worker to review the candidate for [task]. Run independent checks, identify gaps, and repair only within the approved scope.
Run a controlled project workflow
Use agy-worker project mode for [objective]. Require approved provider scope, explicit model and budget, independent verification, and an evidence-based delivery decision.

Π›ΡƒΡ‡ΡˆΠΈΠ΅ ΠΏΡ€Π°ΠΊΡ‚ΠΈΠΊΠΈ

  • Approve the exact provider-readable content, model, budget, and isolation mode before launch.
  • Prefer provider scopes and argv verification, then inspect the final diff independently.
  • Keep secrets, raw logs, controller state, and unrelated private files outside approved content.

Π˜Π·Π±Π΅Π³Π°Ρ‚ΡŒ

  • Do not treat installation as permission to transmit repository content.
  • Do not trust worker envelopes, reported tests, or provider claims without independent checks.
  • Do not use whole-worktree or shell verification modes without explicit scope and risk approval.

Часто Π·Π°Π΄Π°Π²Π°Π΅ΠΌΡ‹Π΅ вопросы

What does agy-worker delegate?
It delegates repository exploration, implementation, testing, and bounded repair to Google Antigravity CLI.
What remains with Codex?
Codex retains scope decisions, diff review, independent verification, repair decisions, and final acceptance.
Does the skill transmit repository files?
It can transmit approved scoped files or an explicitly approved whole worktree to the external provider.
Is the provider session a sandbox?
No. Default session mode retains normal user filesystem and network authority without native host containment.
Which hosts are supported?
The package supports OpenAI Codex CLI hosts with Bash, Python 3, Git, and agy available.
How should I verify results?
Inspect the actual diff and run driver-owned checks in an isolated verification copy before delivery.

БвСдСния для Ρ€Π°Π·Ρ€Π°Π±ΠΎΡ‚Ρ‡ΠΈΠΊΠΎΠ²

Автор

cagdasyurekli

ЛицСнзия

MIT

ВСрсия Π°Π²Ρ‚ΠΎΡ€Π°

v0.21.0

РСвизия Skillstore

r8

Бсылка

73b58aaf0aa4d29844f1b4c2acf4f530fc1ae7b9

ΠΠΊΡ‚ΡƒΠ°Π»ΡŒΠ½ΠΎΡΡ‚ΡŒ ΠΏΠΎΠ΄Π΄Π΅Ρ€ΠΆΠΊΠΈ

20.09.2026

ИспользованиС

6 Π·Π°Π³Ρ€ΡƒΠ·ΠΎΠΊ Β· 18 просмотров

Π‘Ρ‚Ρ€ΡƒΠΊΡ‚ΡƒΡ€Π° Ρ„Π°ΠΉΠ»ΠΎΠ²

πŸ“ agents/

πŸ“„ openai.yaml

πŸ“„ README.md

πŸ“ references/

πŸ“„ PROJECT_LIFECYCLE_AND_VERIFICATION.md

πŸ“„ SECURITY_AND_COMPATIBILITY.md

πŸ“„ TROUBLESHOOTING.md

πŸ“ runtime/

πŸ“ agents/

πŸ“„ bulk-test-writer.md

πŸ“„ diff-reviewer.md

πŸ“„ repo-inventory.md

πŸ“„ agy-worker.sh

πŸ“„ benchmark.sh

πŸ“ benchmarks/

πŸ“ v1/

πŸ“„ manifest.json

πŸ“„ portable-source.json

πŸ“ tasks/

πŸ“ exact-edit/

πŸ“„ candidate.txt

πŸ“„ envelope.json

πŸ“„ initial.txt

πŸ“ variants/

πŸ“„ bulk.json

πŸ“„ codex-usage-report.sh

πŸ“ compat/

πŸ“„ agy-last-reviewed.txt

πŸ“„ agy-model-effort-matrix.json

πŸ“„ agy-model-effort-matrix.sha256

πŸ“„ agy-models-inventory-binding.json

πŸ“„ agy-models-inventory-binding.sha256

πŸ“„ agy-upstream-head.txt

πŸ“„ agy-verified-version.txt

πŸ“„ agy-version-manifest.json

πŸ“„ agy-version-manifest.sha256

πŸ“„ model-effort-matrix.schema.json

πŸ“ model-intelligence/

πŸ“„ dataset.v1.json

πŸ“„ version-manifest.schema.json

πŸ“„ delegation-policy.sh

πŸ“„ doctor.sh

πŸ“„ evidence-report.sh

πŸ“„ feedback-triage.sh

πŸ“„ ground-truth.sh

πŸ“„ job.sh

πŸ“„ model-evidence-campaign.sh

πŸ“„ model-intelligence.sh

πŸ“„ model-recommendation.sh

πŸ“„ model-selection.sh

πŸ“„ qa-gate.sh

πŸ“ schemas/

πŸ“„ benchmark-plan.schema.json

πŸ“„ benchmark-result.schema.json

πŸ“„ delegation-policy.schema.json

πŸ“„ evidence-receipt.schema.json

πŸ“„ job-state.schema.json

πŸ“„ model-evidence-campaign-advisory-preview.schema.json

πŸ“„ model-evidence-campaign-advisory-summary.schema.json

πŸ“„ model-evidence-campaign-aggregate-preview.schema.json

πŸ“„ model-evidence-campaign-aggregate.schema.json

πŸ“„ model-evidence-campaign-evaluation.schema.json

πŸ“„ model-evidence-campaign-plan.schema.json

πŸ“„ model-evidence-campaign-record.schema.json

πŸ“„ model-intelligence-advisory.schema.json

πŸ“„ model-intelligence-evidence.schema.json

πŸ“„ model-recommendation.schema.json

πŸ“„ model-selection.schema.json

πŸ“„ swebench-workflow-study-advisory.schema.json

πŸ“„ swebench-workflow-study-plan.schema.json

πŸ“„ swebench-workflow-study-report.schema.json

πŸ“„ worker-result.provider.schema.json

πŸ“„ worker-result.schema.json

πŸ“„ workflow-state.schema.json

πŸ“ scripts/

πŸ“„ agy_dispatch_containment.py

πŸ“„ agy_dispatch_verification.py

πŸ“„ agy_dispatch_worktree.py

πŸ“„ agy_dispatch.py

πŸ“„ benchmark.py

πŸ“„ candidate_state.py

πŸ“„ codex_usage_report.py

πŸ“„ compatibility.py

πŸ“„ delegation_policy.py

πŸ“„ doctor-metadata.py

πŸ“„ evidence_receipt.py

πŸ“„ evidence_report.py

πŸ“„ feedback-triage.py

πŸ“„ job_lifecycle.py

πŸ“„ legacy_dispatch_state.py

πŸ“„ model_evidence_campaign.py

πŸ“„ model_intelligence.py

πŸ“„ model_selection.py

πŸ“„ model-recommendation.py

πŸ“„ recommendation_record.py

πŸ“„ swebench_workflow_study.py

πŸ“„ transmission_preview.py

πŸ“„ validate-envelope.py

πŸ“„ version_manifest_engine.py

πŸ“„ workflow.py

πŸ“„ swebench-workflow-study.sh

πŸ“„ verify-job.sh

πŸ“„ workflow.sh

πŸ“ scripts/

πŸ“„ resolve-pipeline.sh

πŸ“„ SKILL.md