{
  "markdown": "# 🛡️ Skills-Security-Check\n\nA hybrid AI-powered security auditing tool for scanning skill directories and generating visual security dashboards.\n\n一款結合 AI 智慧分析的混合式安全審查工具，用於掃描技能目錄並生成視覺化安全儀表板。\n\n![License](https://img.shields.io/badge/license-MIT-blue.svg)\n![Python](https://img.shields.io/badge/python-3.8+-green.svg)\n\n## 📸 Dashboard Preview | 儀表板預覽\n\n![Dashboard Preview](assets/dashboard-preview.png)\n\n## 📖 Overview | 概述\n\n**Skills-Security-Check** is a security scanning tool designed for AI Agent skill repositories. It combines:\n\n**Skills-Security-Check** 是一款專為 AI Agent 技能倉庫設計的安全掃描工具，結合了：\n\n1. **Static Analysis | 靜態分析** - Regex-based pattern matching to identify potential risks | 使用正則表達式匹配潛在風險\n2. **AI Intelligence | AI 智慧分析** - Leverages AI agents to analyze findings and reduce false positives | 利用 AI 代理分析發現並減少誤報\n3. **Visual Dashboard | 視覺化儀表板** - Generates a beautiful, interactive HTML dashboard | 生成精美的互動式 HTML 儀表板\n\n### What It Detects | 偵測項目\n\n| Category | 類別 | Examples | 範例 |\n|----------|------|----------|------|\n| 🔑 **Sensitive Operations** | 敏感操作 | API keys, credentials, environment variables | API 金鑰、憑證、環境變數 |\n| 🌐 **Network Activity** | 網路活動 | External URLs, IP addresses, API endpoints | 外部連結、IP 位址、API 端點 |\n| 🎭 **Obfuscation Signals** | 混淆跡象 | Base64 encoding, eval(), dynamic imports | Base64 編碼、eval()、動態載入 |\n| 📦 **Package Installs** | 套件安裝 | npm, pip, apt, brew, yarn, pnpm, gem, go | npm, pip, apt, brew 等安裝指令 |\n| ⚠️ **High-Risk Patterns** | 高風險模式 | Shell execution, download-and-execute | Shell 執行、下載並執行 |\n\n---\n\n## 🚀 Quick Start | 快速開始\n\n### Prerequisites | 前置需求\n- Python 3.8+\n- No external dependencies required (uses standard library only)\n- 無需外部依賴（僅使用 Python 標準函式庫）\n\n### Installation | 安裝\n\n```bash\n# Clone the repository | 複製專案\ngit clone https://github.com/YOUR_USERNAME/Skills-Security-Check.git\n\n# Navigate to the skill directory | 進入技能目錄\ncd Skills-Security-Check\n```\n\n### Usage | 使用方式\n\n```bash\n# Scan a directory of skills | 掃描技能目錄\npython3 scripts/scan_skills.py --root /path/to/your/skills\n\n# The dashboard will auto-open in your browser\n# 儀表板將自動在瀏覽器中開啟\n```\n\n### Output Structure | 輸出結構\n\n```\nreports/YYYYMMDD_HHMMSS/\n├── index.html          # Interactive dashboard | 互動式儀表板\n├── data.json           # Raw scan data | 原始掃描資料\n└── prompts/            # AI audit prompts | AI 審查提示詞\n    ├── skill1_audit_prompt.txt\n    └── skill2_audit_prompt.txt\n```\n\n---\n\n## 🤖 AI-Powered Workflow | AI 驅動工作流程\n\nThis skill is designed to work with AI agents. The recommended workflow:\n\n此技能專為 AI 代理設計，建議的工作流程如下：\n\n1. **Run Scanner | 執行掃描** → Generates raw findings and audit prompts | 生成原始發現與審查提示詞\n2. **AI Analysis | AI 分析** → Agent reads prompts and creates `audit.json` for each skill | 代理讀取提示詞並為每個技能建立 `audit.json`\n3. **Integrate & Present | 整合呈現** → Re-run scanner to merge AI insights into final report | 重新執行掃描器以合併 AI 洞察至最終報告\n\nSee [SKILL.md](SKILL.md) for detailed agent instructions.\n\n詳細的代理指示請參閱 [SKILL.md](SKILL.md)。\n\n---\n\n## 📊 Dashboard Features | 儀表板功能\n\n- **Executive Summary | 總覽摘要** - Overall security score and top risks at a glance | 一目了然的安全評分與高風險項目\n- **Risk Filtering | 風險篩選** - Filter by High/Medium/Low risk levels | 依高/中/低風險等級篩選\n- **Detailed Views | 詳細檢視** - Click any skill to see full breakdown | 點擊任何技能查看完整分析\n- **AI Insights Card | AI 洞察卡片** - Displays AI-generated analysis when available | 顯示 AI 生成的分析結果\n- **Responsive Design | 響應式設計** - Works on desktop and tablet | 支援桌面與平板裝置\n\n---\n\n## 🔧 Configuration | 設定\n\n### Command Line Arguments | 命令列參數\n\n| Argument | 參數 | Description | 說明 | Default | 預設值 |\n|----------|------|-------------|------|---------|--------|\n| `--root` | | Root directory containing skills to scan | 包含待掃描技能的根目錄 | Current directory | 當前目錄 |\n| `--out` | | Custom output path for HTML report | 自訂 HTML 報告輸出路徑 | Auto-generated | 自動生成 |\n\n---\n\n## 📁 Project Structure | 專案結構\n\n```\nSkills-Security-Check/\n├── SKILL.md                    # AI agent instructions | AI 代理指示\n├── README.md                   # This file | 本檔案\n├── scripts/\n│   └── scan_skills.py          # Main scanner script | 主掃描腳本\n├── assets/\n│   └── dashboard_template.html # Dashboard HTML template | 儀表板 HTML 模板\n└── reports/                    # Generated reports | 生成的報告 (gitignored)\n```\n\n---\n\n## 🤝 Contributing | 貢獻\n\nContributions are welcome! Please feel free to submit a Pull Request.\n\n歡迎貢獻！請隨時提交 Pull Request。\n\n---\n\n## 👤 Author | 作者\n\n**Prompt Case**\n\n[![Threads](https://img.shields.io/badge/Threads-@prompt__case-000000?style=flat&logo=threads)](https://www.threads.com/@prompt_case)\n[![Patreon](https://img.shields.io/badge/Patreon-Support-FF424D?style=flat&logo=patreon)](https://www.patreon.com/MattTrendsPromptEngineering)\n\n- 🧵 Threads: [@prompt_case](https://www.threads.com/@prompt_case)\n- 💖 Patreon: [MattTrendsPromptEngineering](https://www.patreon.com/MattTrendsPromptEngineering)\n\n---\n\n## 📄 License | 授權\n\nThis project is licensed under the MIT License.\n\n本專案採用 MIT 授權條款。\n\n## 🙏 Acknowledgments | 致謝\n\nBuilt with ❤️ for the AI Agent ecosystem.\n\n為 AI Agent 生態系統用心打造 ❤️\n",
  "bytes": 5001,
  "sha": "52219b10ea222dea4fa60c8bce626e1d1e4cbca6c390b785b6c0a31439e10de5",
  "repo_slug": "toolsai/skills-security-check",
  "fonte": "repo",
  "truncated": false,
  "api": "https://api.agentalog.com/api/listings/skl_toolsai_skills_security_check_skills_sec_d49e4275/readme"
}