扫描报告
10 /100
agent-Andri
Agent Andri — periodic status reporter writing to meeting-room file
A simple local status-reporting agent that periodically writes to a flat text file in a designated directory, with behavior fully aligned with its documentation.
可以安装
Skill is safe to use. The infinite while-loop in status_report.sh is a minor design concern for long-running sessions but does not constitute a security threat.
安全发现 2 项
| 严重性 | 安全发现 | 位置 |
|---|---|---|
| 低危 | Writes to hidden dot-directory under $HOME 敏感访问 | scripts/status_report.sh:9 |
| 低危 | Infinite loop without signal handling 敏感访问 | scripts/status_report.sh:12 |
| 资源类型 | 声明权限 | 推断权限 | 状态 | 证据 |
|---|---|---|---|---|
| 文件系统 | READ | WRITE | ✓ 一致 | SKILL.md declares writing to ~/.../to_leader.txt; scripts/status_report.sh line … |
目录结构
2 文件 · 983 B · 26 行 Shell 1f · 15L
Markdown 1f · 11L
├─
▾
scripts
│ └─
status_report.sh
Shell
└─
SKILL.md
Markdown
安全亮点
✓ All capabilities declared in SKILL.md are used exactly as documented
✓ No external network requests or data exfiltration
✓ No credential harvesting or environment variable exfiltration
✓ No obfuscation, base64 encoding, or suspicious code patterns
✓ No sensitive file paths (~/.ssh, ~/.aws, .env) accessed
✓ No remote script execution (curl|bash, wget|sh)
✓ No supply-chain risks — no dependencies declared or used
✓ Script uses set -euo pipefail for safe shell execution