扫描报告
5 /100
nephesh-studio
完整智能团队协作架构,10个专业岗位分工协作,CEO全程调度,通过文件知识库持续成长。处理大型复杂任务,隔离执行不打扰,稳定交付高质量结果。
Nephesh Studio is a purely documentation-driven AI team collaboration skill with no executable code, all declared capabilities being filesystem operations for project management and subagent spawning for workflow coordination.
可以安装
Approve for use. The skill is a legitimate workflow orchestration system with well-documented markdown files and no executable scripts.
安全发现 3 项
| 严重性 | 安全发现 | 位置 |
|---|---|---|
| 低危 | Documentation-only skill | SKILL.md:1 |
| 提示 | Cron command reference in documentation | SKILL.md:85 |
| 提示 | Subagent spawning is clearly declared | SKILL.md:143 |
| 资源类型 | 声明权限 | 推断权限 | 状态 | 证据 |
|---|---|---|---|---|
| 文件系统 | WRITE | WRITE | ✓ 一致 | SKILL.md declares project directory creation and file writing |
| 技能调用 | WRITE | WRITE | ✓ 一致 | SKILL.md: subagent spawning with run/cleanup/delete parameters |
| 命令执行 | NONE | NONE | — | No shell execution in code; cron command is documentation only |
| 网络访问 | NONE | NONE | — | No network requests made by the skill itself |
| 环境变量 | NONE | NONE | — | No environment variable access patterns found |
| 剪贴板 | NONE | NONE | — | No clipboard access patterns found |
| 浏览器 | NONE | NONE | — | No browser automation patterns found |
| 数据库 | NONE | NONE | — | No direct database access patterns found |
目录结构
29 文件 · 119.5 KB · 3011 行 Markdown 29f · 3011L
├─
▾
hr
│ ├─
performance.md
Markdown
│ └─
README.md
Markdown
├─
▾
learning
│ ├─
ceo.md
Markdown
│ ├─
content-editor.md
Markdown
│ ├─
data-analyst.md
Markdown
│ ├─
data-collector.md
Markdown
│ ├─
hr-manager.md
Markdown
│ ├─
project-manager.md
Markdown
│ ├─
qa-auditor.md
Markdown
│ ├─
senior-backend.md
Markdown
│ ├─
senior-frontend.md
Markdown
│ └─
task-planner.md
Markdown
├─
▾
projects
│ └─
README.md
Markdown
├─
▾
roles
│ ├─
ceo.md
Markdown
│ ├─
content-editor.md
Markdown
│ ├─
data-analyst.md
Markdown
│ ├─
data-collector.md
Markdown
│ ├─
hr-manager.md
Markdown
│ ├─
project-manager.md
Markdown
│ ├─
qa-auditor.md
Markdown
│ ├─
senior-backend.md
Markdown
│ ├─
senior-frontend.md
Markdown
│ └─
task-planner.md
Markdown
├─
AGENCY.md
Markdown
├─
daily-checklist.md
Markdown
├─
RULES.md
Markdown
├─
SKILL.md
Markdown
├─
TEAM-ROSTER.md
Markdown
└─
workflow.md
Markdown
安全亮点
✓ All 29 files are markdown documentation - no executable code or scripts
✓ All capabilities (filesystem writes, subagent spawning) are clearly declared in SKILL.md
✓ No network exfiltration or credential harvesting patterns detected
✓ No shell execution, base64 encoding, or eval() patterns found
✓ No access to sensitive paths (~/.ssh, ~/.aws, .env) detected
✓ Clear workflow documentation with no hidden instructions
✓ Well-structured team collaboration system focused on legitimate project management