treg
Access Live Data and Connected APIs with treg
Agents often lack credentials for live data and external APIs. treg searches priced endpoints and calls approved services through one authenticated interface.
Не устанавливайте этот Skill автоматически.
Каноническая политика требует проверки оператором перед любым действием по установке.
Установить с помощью моего Агента
Скопируйте этот запрос в своего Агента. Он содержит каноническую страницу Skill и манифест.
Review the Skillstore skill "treg" from https://skillstore.io/skills/superdesigndev-treg.md and its manifest at https://skillstore.io/api/skills/superdesigndev-treg/manifest. Verify the artifact. Do not auto-install. Inspect the skill and report your findings, then wait for an operator or manual installation decision.Ваш Агент по-прежнему должен показать план и запросить все подтверждения, требуемые политикой безопасности.
Ресурсы для AI-агентов
Используйте эти ссылки, когда AI-агенту, crawler или script нужен чистый контекст вместо полной страницы.
Протестировать
Использование «treg». Find a provider for subreddit posts, but do not spend any balance.
Ожидаемый результат:
I found matching endpoints and compared their required inputs, observed reliability, speed, and price. No endpoint was called.
Использование «treg». Prepare a company enrichment request and use the least expensive reliable provider.
Ожидаемый результат:
The selected provider accepts the company domain you have and has stronger observed reliability. The listed call price requires your confirmation.
Использование «treg». Create a plan for a limited CI agent that can read Stripe balances.
Ожидаемый результат:
Use a dedicated agent identity, allow only the Stripe tool, grant read-only access, set a daily cap, and review the audit log.
Аудит безопасности
КритичноThe audit confirms remote pipe-to-shell installation, credential collection, hidden configuration access, and broad authenticated command execution. Many backtick and URL matches are documentation-only false positives, but the confirmed critical and high-risk workflows require strong user consent and verification.
Подтверждённые проблемы безопасности (6)
Пункты проверки возможностей (34)
Это реальные локальные возможности, которые могут ожидаться для этого навыка, поэтому они требуют проверки, но не считаются подтверждённым вредоносным поведением.
Факторы риска
⚙️ Внешние команды (50)
🌐 Доступ к сети (11)
📁 Доступ к файловой системе (5)
🔑 Переменные окружения (2)
Обнаруженные паттерны
Поделиться и цитировать этот отчет
Делитесь версионным отчетом об оценке, нейтральным значком, встраиваемой карточкой и цитатами. Skillstore публикует доказательства, не решая, безопасен ли этот Skill.
Копировать ссылку на отчёт
https://skillstore.io/skills/superdesigndev-treg/audits/1?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportЗначок Markdown
[](https://skillstore.io/skills/superdesigndev-treg?utm_source=security_passport_badge)Значок HTML
<a href="https://skillstore.io/skills/superdesigndev-treg?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/superdesigndev-treg/security.svg" alt="Skillstore security assessment" loading="lazy"></a>Встраиваемая карточка
<iframe src="https://skillstore.io/embed/skills/superdesigndev-treg.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>Академические ссылки (APA · BibTeX · CFF)
Цитата APA
superdesigndev. (2026). treg security audit report (audit version 1) [Author version 0.11.0]. Skillstore. https://skillstore.io/skills/superdesigndev-treg/audits/1Цитата BibTeX
@techreport{superdesigndev-superdesigndev-treg-2026,
author = {superdesigndev},
title = {treg security audit report (audit version 1)},
institution = {Skillstore},
year = {2026},
number = {1},
url = {https://skillstore.io/skills/superdesigndev-treg/audits/1},
note = {Author version 0.11.0}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "treg security audit report (audit version 1)"
version: "0.11.0"
type: report
authors:
- name: "superdesigndev"
date-released: "2026-08-14"
url: "https://skillstore.io/skills/superdesigndev-treg/audits/1"
identifiers:
- type: other
value: "skillstore:superdesigndev-treg:audit:1"
description: "Skillstore immutable audit report identifier"
Оценка Skillstore
Почему такая оценка Достоверность доказательств: СреднийЧто вы можете построить
Research live market data
Find and compare endpoints for rankings, backlinks, trends, advertising, or company enrichment before making approved calls.
Connect internal API accounts
Register an existing service credential and let authorized teammates call the API without receiving the raw secret.
Automate scoped agent tasks
Create a limited agent identity, allow selected tools, set daily caps, and review its call history.
Попробуйте эти промпты
Search treg for an endpoint that provides [data type]. Show required inputs, price, and reliability. Do not call it yet.
Compare treg providers for [task] using my available inputs. Rank them by compatibility, reliability, price, and recent success.
Prepare a treg call for [endpoint] with [inputs]. State the exact price and request confirmation before spending any balance.
Plan a treg integration for [service]. Use minimal scopes, read-only access, explicit tool allowlists, daily caps, and item-level secret consent.
Лучшие практики
- Review endpoint inputs, observed reliability, price, and recent success before calling.
- Confirm every paid or state-changing action with the user immediately before execution.
- Use dedicated identities, minimal scopes, tool allowlists, daily caps, and audit logs.
Избегать
- Do not pipe a remote installer into a shell without verification.
- Do not grant blanket approval for every treg command.
- Do not scan or upload credentials without an exact preview and item-level consent.
Часто задаваемые вопросы
What does treg provide?
Does every call cost money?
Can treg access existing team APIs?
Does treg handle secrets?
Can treg change connected accounts?
What should users verify before installation?
Сведения для разработчиков
Автор
superdesigndevЛицензия
MIT
Версия автора
v0.11.0
Ревизия Skillstore
r1
Репозиторий
https://github.com/superdesigndev/treg/tree/bc0c6111d1f25f802b3675a5d8ecf7267650bd9b/skills/tregСсылка
8d471fa6bb01c43c43d332bf9105df157c067391
Актуальность поддержки
15.08.2026
Использование
0 загрузок · 0 просмотров
Структура файлов
📄 SKILL.md