可信 — 风险评分 5/100
上次扫描:21 小时前 重新扫描
5 /100
NPM Package Scanner
Scan npm packages for risk, maintenance health, and upgrade concerns
The NPM Package Scanner is a legitimate security analysis tool that inspects npm dependencies for risks without any malicious behavior.
技能名称NPM Package Scanner
分析耗时18.0s
引擎pi
可以安装
No action needed. This skill is safe to use as documented.
资源类型声明权限推断权限状态证据
文件系统 READ READ ✓ 一致 Uses 'cat' and 'rg --files' to read manifests only
命令执行 WRITE READ ✓ 一致 Runs audit/read-only commands (npm ls, npm audit, bun audit)
网络访问 NONE NONE No network requests made

目录结构

1 文件 · 2.6 KB · 121 行
Markdown 1f · 121L
└─ 📝 SKILL.md Markdown 121L · 2.6 KB

安全亮点

✓ All tools explicitly declared in metadata.requires.bins
✓ No filesystem write operations performed
✓ No sensitive paths accessed (~/.ssh, ~/.aws, .env)
✓ No credential harvesting or exfiltration
✓ No remote script execution (curl|bash, wget|sh)
✓ No obfuscated or base64-encoded code
✓ Clear constraints: read-only analysis, no modifications
✓ Follows security tool legitimate-use patterns