repo-compliance-audit
1
总安装量
1
周安装量
#53919
全站排名
安装命令
npx skills add https://github.com/okwinds/miscellany --skill repo-compliance-audit
Agent 安装分布
amp
1
trae
1
trae-cn
1
opencode
1
codex
1
Skill 文档
Repo Compliance Audit
æ¬ skill æä¾ä¸ä¸ªä¸¤é¶æ®µå·¥ä½æµï¼å å®¡è®¡åºæ¥åï¼åç±äººç±»å¾ééè¦æ´æ¹çæ¡ç®ï¼æåæ§è¡éæ©æ§æ´æ¹ãæ ¸å¿ç®æ æ¯âåè§å®¡æ¥å¯åè¯âåâæ´æ¹æå°åãé»è®¤ä¸æ¹ä¸å¡é»è¾âã
工使µï¼Audit â 人类å¾é â Remediationï¼
1) Auditï¼åªè¯»å®¡è®¡ï¼é»è®¤ä¸æ¹ä»åºï¼
å¨ç®æ ä»åºæ ¹ç®å½è¿è¡ï¼æç¨ --repo æå®ï¼ï¼
python3 scripts/audit_repo.py --repo . --out /tmp/repo-compliance-audit
è¾åºï¼
report.mdï¼äººç±»å¯è¯»å®¡è®¡æ¥åï¼ç»è®ºæè¦ãé£é©å级ãè¯æ®ãæ´æ¹æ¸ åï¼findings.jsonï¼æºå¨å¯è¯»åç°å表ï¼å å«finding.idãè¯æ®ä¸å»ºè®®ä¿®å¤ï¼
CI / é¨ç¦ç¨æ³ï¼å¯éï¼ï¼
python3 scripts/audit_repo.py --repo . --out /tmp/repo-compliance-audit --fail-on high
æ¨èé¨ç¦çç¥ï¼é¢åâæ§è¡è¿ç¨å¯¹é½ AGENTS.mdâï¼
- æå°é¨ç¦ï¼æ¨èé»è®¤ï¼ï¼ç¨
--fail-on highï¼ä¸»è¦æ¦æªï¼- è§åæä»¶å®æ´æ§é«é£é©ï¼
AGENTS_MD_DELETED/AGENTS_MD_MODIFIED - è¿ç¨è¯æ®é«é£é©ï¼
AGENTS_EXECUTION_TEST_EVIDENCE_MISSING - ææ¾å®å
¨é£é©ï¼
POSSIBLE_SECRET_FOUND
- è§åæä»¶å®æ´æ§é«é£é©ï¼
- ä¸¥æ ¼é¨ç¦ï¼æéå¯ç¨ï¼ï¼ç¨
--fail-on mediumï¼ä¼é¢å¤æ¦æªï¼- Spec-first è¯æ®ç¼ºå¤±ç±»ï¼ä¾å¦
SPEC_ENTRYPOINT_MISSINGãAGENTS_EXECUTION_SPEC_FIRST_EVIDENCE_MISSINGï¼ - worklog è¿ç¨è¯æ®ç¼ºå¤±ç±»ï¼ä¾å¦
AGENTS_EXECUTION_WORKLOG_EVIDENCE_MISSINGï¼
- Spec-first è¯æ®ç¼ºå¤±ç±»ï¼ä¾å¦
è¾åºè±æï¼å ±äº«æ¥åæ¶å»ºè®®å¼å¯ï¼ï¼
# ä»
è±æ report.mdï¼ä¿ç findings.json ä¾ç³»ç»ç¼æ/æ´æ¹ä½¿ç¨ï¼
python3 scripts/audit_repo.py --repo . --out /tmp/repo-compliance-audit --redact report
# report.md + findings.json åè±æï¼å¯¹å¤å
±äº«ï¼
python3 scripts/audit_repo.py --repo . --out /tmp/repo-compliance-audit --redact all
é使³é²/åªå£°ï¼å¯éï¼ï¼
python3 scripts/audit_repo.py --repo . --out /tmp/repo-compliance-audit --no-git-meta
python3 scripts/audit_repo.py --repo . --out /tmp/repo-compliance-audit --no-secret-scan
2) 人类å¾éè¦æ´æ¹çæ¡ç®
ä» report.md æ findings.json ééæ© finding.idï¼ç¨éå·åéæåå
¥æä»¶ã
3) Remediationï¼éæ©æ§æ´æ¹ï¼é»è®¤åªè· safe-to-autofixï¼
python3 scripts/remediate_repo.py \
--repo . \
--findings /tmp/repo-compliance-audit/findings.json \
--select DOCS_INDEX_MISSING,ENV_EXAMPLE_MISSING
约æï¼
- é»è®¤ä»
æ§è¡
safe_to_autofix=trueçä¿®å¤é¡¹ - é»è®¤ä¸è¦çå·²ææä»¶ï¼é¤éæ¾å¼
--overwriteï¼ - é»è®¤ä¸æ¹ä¸å¡é»è¾ï¼åªåâåè§éª¨æ¶/è¯æ®/ä»åºå«çâ类修å¤ï¼
è¾åºå¦ä½è¢«ç³»ç»ä½¿ç¨ï¼å¼ºç»æ vs çæå ¼å®¹ï¼
- æ§å¶é¢å¼ºç»æï¼
findings.jsonç¨äºç³»ç»çº§äº¤äºï¼å¯ç¼æãå¯å®¡è®¡ãå¯åé¨ç¦ï¼ã - 对人类çæå好ï¼
report.md以å¯è¯»æ§ä¼å ï¼ä¸å¼ºå¶ç»æå JSONã - é¿å
æ¯ä¸ªèç¹é½å¼ºå¶ç»æåï¼ä»
å¨âé¨ç¦/èç¹ç¡®å®éè¦æºå¨å¯è¯»å¤æâæ¶å¯ç¨
--fail-onæåªå¯¹æäº finding å gateã - è§åæä»¶å®æ´æ§ä¼å
ï¼å¦æä½ å
³æ³¨ç¼ç æºè½ä½çè§å被âå é¤/篡æ¹âï¼å¯ä»¥éç¹å
³æ³¨å®¡è®¡è¾åºä¸ç
AGENTS_MD_DELETED/AGENTS_MD_MODIFIED/AGENTS_MD_UNTRACKEDï¼åºäº git åè¯ï¼è¥é git ä»åºåä» è½æç¤ºï¼ã
èµæº
skills/repo-compliance-audit/scripts/audit_repo.pyï¼å®¡è®¡å ¥å£skills/repo-compliance-audit/scripts/remediate_repo.pyï¼æ´æ¹å ¥å£ï¼æfinding.idéæ©æ§æ§è¡ï¼skills/repo-compliance-audit/references/finding-catalog.mdï¼finding ID ç®å½ï¼æ©å±/对é½å£å¾ç¨ï¼