Token导航 LogoToken导航TokenDH.com
研究检索external-servicegithub未标认证来源可访问许可证需确认审计通过

automation-audit-ops自动化审计操作

Agent Skill

用于辅助安全审计、权限检查、凭据风险、认证流程和常见漏洞排查。它适合让 Agent 梳理敏感配置、检查依赖风险、分析鉴权逻辑或生成安全复核清单。使用时不能把工具输出直接当最终结论,涉及密钥、令牌、用户数据或生产系统时,应先确认最小权限、脱敏方式和操作边界。

总安装

29,376

周安装

1,193

GitHub Stars

170,297

下载量

9,504
CodexClaudeCursorGemini CLI

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

unknown

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:automation-audit-ops(自动化审计操作)
来源仓库:https://github.com/affaan-m/everything-claude-code
仓库路径:skills/automation-audit-ops
安装命令:
npx skills add https://github.com/affaan-m/everything-claude-code --skill automation-audit-ops
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 npx skills 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

skills.shnpx skills
npx skills add https://github.com/affaan-m/everything-claude-code --skill automation-audit-ops

简介

automation-audit-ops 辅助安全审计与运维检查,梳理敏感配置、依赖风险和鉴权逻辑,生成可操作的复核清单。

  • 适用于生产环境的安全审查、凭据管理和漏洞排查,强调证据驱动的建议而非直接结论。
  • 通过 npx skills add 命令从指定 GitHub 仓库安装,需配合其他 ECC-native 技能完成完整审计流程。
  • 涉及密钥、令牌或用户数据时,应先确认最小权限与脱敏方式,避免直接操作生产系统。
  • 适用宿主包括 Codex、Claude、Cursor、Gemini CLI,接入前应确认版本、权限和运行环境要求。

SKILL.md

Automation Audit Ops

Use this when the user asks what automations are live, which jobs are broken, where overlap exists, or what tooling and connectors are actually doing useful work right now.

This is an audit-first operator skill. The job is to produce an evidence-backed inventory and a keep / merge / cut / fix-next recommendation set before rewriting anything.

Skill Stack

Pull these ECC-native skills into the workflow when relevant:

  • workspace-surface-audit for connector, MCP, hook, and app inventory
  • knowledge-ops when the audit needs to reconcile live repo truth with durable context
  • github-ops when the answer depends on CI, scheduled workflows, issues, or PR automation
  • ecc-tools-cost-audit when the real problem is webhook fanout, queued jobs, or billing burn in the sibling app repo
  • research-ops when local inventory must be compared against current platform support or public docs
  • verification-loop for proving post-fix state instead of relying on assumed recovery

When to Use

  • user asks "what automations do I have", "what is live", "what is broken", or "what overlaps"
  • the task spans cron jobs, GitHub Actions, local hooks, MCP servers, connectors, wrappers, or app integrations
  • the user wants to know what was ported from another agent system and what still needs to be rebuilt inside ECC
  • the workspace has accumulated multiple ways to do the same thing and the user wants one canonical lane

Guardrails

  • start read-only unless the user explicitly asked for fixes
  • separate:

- configured - authenticated - recently verified - stale or broken - missing entirely

  • do not claim a tool is live just because a skill or config references it
  • do not merge or delete overlapping surfaces until the evidence table exists

Workflow

1. Inventory the real surface

Read the current live surface before theorizing:

  • repo hooks and local hook scripts
  • GitHub Actions and scheduled workflows
  • MCP configs and enabled servers
  • connector- or app-backed integrations
  • wrapper scripts and repo-specific automation entrypoints

Group them by surface:

  • local runtime
  • repo CI / automation
  • connected external systems
  • messaging / notifications
  • billing / customer operations
  • research / monitoring

2. Classify each item by live state

For every surfaced automation, mark:

  • configured
  • authenticated
  • recently verified
  • stale or broken
  • missing

Then classify the problem type:

  • active breakage
  • auth outage
  • stale status
  • overlap or redundancy
  • missing capability

3. Trace the proof path

Back every important claim with a concrete source:

  • file path
  • workflow run
  • hook log
  • config entry
  • recent command output
  • exact failure signature

If the current state is ambiguous, say so directly instead of pretending the audit is complete.

4. End with keep / merge / cut / fix-next

For each overlapping or suspect surface, return one call:

  • keep
  • merge
  • cut
  • fix next

The value is in collapsing noisy automation into one canonical ECC lane, not in preserving every historical path.

Output Format

CURRENT SURFACE
- automation
- source
- live state
- proof

FINDINGS
- active breakage
- overlap
- stale status
- missing capability

RECOMMENDATION
- keep
- merge
- cut
- fix next

NEXT ECC MOVE
- exact skill / hook / workflow / app lane to strengthen

Pitfalls

  • do not answer from memory when the live inventory can be read
  • do not treat "present in config" as "working"
  • do not fix lower-value redundancy before naming the broken high-signal path
  • do not widen the task into a repo rewrite if the user asked for inventory first

Verification

  • important claims cite a live proof path
  • each surfaced automation is labeled with a clear live-state category
  • the final recommendation distinguishes keep / merge / cut / fix-next

适合场景

01

用户想查找某类 Agent Skill 时

02

需要根据任务场景推荐可安装能力包时

03

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

Codex

37.07%
按下载量换算3,523

Claude

27.21%
按下载量换算2,586

Cursor

17.27%
按下载量换算1,641

Gemini CLI

9.01%
按下载量换算856

安全审计

Gen Agent Trust Hub

通过

Socket

通过

Snyk

通过

权限和风险

external-service

该 Skill 可能调用第三方服务、云服务或外部模型 API,使用前需要确认账号、额度、数据发送范围和服务条款。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills