首页 / Skills 目录 / 精选索引 / agentic-actions-auditor
trailofbits / skills

agentic-actions-auditor

Audits GitHub Actions workflows for security vulnerabilities in AI agent integrations including Claude Code Action, Gemini CLI, OpenAI Codex, and GitHub AI Inference. Detects attack vectors where attacker-controlled input reaches AI agents…

core - 许可证明确许可证 CC-BY-SA-4.0高风险6613 Stars更新 2026-08-14
  • B许可证传染性许可证,衍生作品需同协议开源
  • A维护最近 7 天内更新
  • D安全命中高危行为,需逐行审阅
仓库
trailofbits/skills
目录
plugins/agentic-actions-auditor/skills/agentic-actions-auditor
质量分
0.84
安全规则命中
1 项,使用前请阅读 SKILL.md

打开 Skill 目录 查看 SKILL.md 原文 在目录中搜索

安装到你的 Agent

命令默认装到 ~/.claude/skills/(Claude Code 全局目录)。Codex / Cursor 等其他 Agent 请换成它们各自的 skills 目录;只对当前项目生效时改成 .claude/skills/。运行前请先看一眼下面的安全体检。

只装 SKILL.md(最快)
mkdir -p ~/.claude/skills/agentic-actions-auditor && curl -fsSL https://raw.githubusercontent.com/trailofbits/skills/4db88ee79db0a68bbe049fe827e272ee2bc19510/plugins/agentic-actions-auditor/skills/agentic-actions-auditor/SKILL.md -o ~/.claude/skills/agentic-actions-auditor/SKILL.md
连同附件一起装(推荐)
git clone --depth 1 --filter=blob:none --sparse https://github.com/trailofbits/skills /tmp/agentic-actions-auditor-src && git -C /tmp/agentic-actions-auditor-src sparse-checkout set plugins/agentic-actions-auditor/skills/agentic-actions-auditor && cp -r /tmp/agentic-actions-auditor-src/plugins/agentic-actions-auditor/skills/agentic-actions-auditor ~/.claude/skills/agentic-actions-auditor

在本页阅读 SKILL.md

原文实时取自 GitHub(按提交哈希锁定的版本)。命中安全规则的行会被标红,并附中文解释。

安全体检报告

高风险 命中 1 条安全规则,许可证判定:传染性许可证。

  • 数据外发存在将本地数据发送到外部地址的行为。exfiltration

许可证:CC-BY-SA-4.0 · 衍生作品可能需要以相同许可证开源。

评估基于对公开 SKILL.md 的自动扫描,不替代人工审阅,也不构成法律建议。

本站只保存元数据与外链,不转存 SKILL.md 正文。引用或商用前请自行确认上游许可证与权限边界。数据快照来自公开仓库,可能滞后于上游。