可信 — 风险评分 5/100
上次扫描:20 小时前 重新扫描
5 /100
hello
没有任何实际意义的skill,用于测试
A minimal test skill containing only SKILL.md with no executable code, scripts, or dependencies — body content is internal development notes with no malicious behavior.
技能名称hello
分析耗时17.5s
引擎pi
可以安装
No action needed. The skill is purely informational and safe to use.

安全发现 1 项

严重性 安全发现 位置
低危
SKILL.md body contains unrelated development notes 文档欺骗
The SKILL.md frontmatter declares 'hello' as a test skill with no practical purpose, but the body contains internal development notes about Phabricator bootstrapping, Microsoft OAuth, and database redesign. This is a content mismatch, though in this case the 'deception' is clearly benign (it is a test/placeholder skill).
name: hello
description: 没有任何实际意义的skill,用于测试
→ If this is intended as a real skill, clean up SKILL.md to remove internal notes. If it is truly a test placeholder, this finding can be ignored.
SKILL.md:1

目录结构

1 文件 · 2.0 KB · 24 行
Markdown 1f · 24L
└─ 📝 SKILL.md Markdown 24L · 2.0 KB

安全亮点

✓ No executable scripts or code files present
✓ No dependencies or package files
✓ No credential access or environment variable reading
✓ No network requests or external communications
✓ No obfuscated code or base64 payloads
✓ No filesystem write operations
✓ No shell or command execution