Find Skills · Risk Assessment Edition
Paste the following prompt into your AI chat to install this skill:
Please follow the guide at https://skillhub.cn/install/skillhub.md to install @laoxi/zhaojineng.
About this skill
The Problem: Risk in Skill Discovery
When a user needs a skill for a task (like "automate weekly reports"), the challenge isn't finding options, but evaluating them. On platforms like SkillHub, the vast majority of tools lack transparency regarding their permission scope, privacy trajectory, and potential security risks. Installing an unverified skill can introduce backdoors, data leaks, or system instability.
Core Capability: Search, Assessment, and Decision Support
This skill (@laoxi/zhaojineng) provides a comprehensive workflow that deeply integrates skill discovery with independent security assessment. Its core is a built-in cli tool (built on the Python 3 standard library), functioning not as a mere search engine, but as a risk-filtered decision-support tool.
Key Steps & Capabilities:
- Intelligent Intent Parsing: Extracts the task, domain tag (mapped to a
category), and multiple keywords from user natural language, including synonyms, to improve search relevance. - Security-First Aggregated Search: The CLI tool queries the SkillHub public API and the assessment data from "Zhuangqiancha" (
zhuangqiancha.com) concurrently. It automatically deduplicates, cross-validates, and most critically, ranks results by security tier (🟢🟡🟠🔴⚪), prioritizing the visibility of risk. - Context-Aware Intent Matching: Further filters and ranks the initial CLI output based on
nameand purpose description to select the 3-5 most relevant matches. Supports flags like--safe-onlyto recommend only 🟢/🟡 tools, or--free-onlyfor tools requiring no API keys. - Transparent Risk Decision Path: Mandatory display of security tier and key risk signals with recommendations. For 🟠 (Caution) / 🔴 (High Risk) tools, it explicitly prompts users and requires a secondary confirmation via the
inspectcommand to view full evidence before installation. All assessments are based on public code and declarations.
Scope and Important Caveats
Applicable Scenarios:
- Quickly assessing the security of a batch of potential skill candidates.
- Situations requiring caution with third-party tools, where understanding permissions and privacy risks is a priority.
- Filtering based on specific task categories (e.g., office-efficiency) and security preferences (e.g., free-only or safe-only).
Important Caveats:
- Dependence on Public Data: Search and assessment rely entirely on the SkillHub public API and the independent evaluation database of Zhuangqiancha; no private data is involved.
- Assessment is Not a Guarantee: Security tiers (especially 🟢 "No Risk Found") are conclusions from a current public rule scan, not a manual audit or a guarantee of absolute safety. Terms like "No Risk Found" should be understood as "no known risk signals detected under current rules."
- Unindexed Tools (⚪) - Risk is User-Borne: For tools not indexed by Zhuangqiancha, the CLI clearly marks them as "No independent security assessment available." Their safety is entirely the user's judgment to bear.
- Text-Only Output: The skill is designed for interactive text guidance and does not generate or rely on any images or cards for result display, ensuring direct and clear information.
- Evidence-Based: For high-risk tools, specific evidence (e.g., suspicious code patterns or documented claims) from Zhuangqiancha must be shown. No excessive speculation is made without evidence.
Use Cases
- As a tech lead evaluating a new automation `skill` for the team, I need to quickly assess its permission scope, data exfiltration behavior, and author reputation to decide on approval.
- As an independent developer looking for a `GitHub` data processing tool, I want a platform that proactively reveals if the tool reads repo secrets or makes suspicious network connections.
- As a content creator, I need to filter for a free, image-processing `skill` on SkillHub, prioritizing tools whose privacy policies and known risk signals are transparently displayed.
- When provided with a `skill` link (e.g., from skillhub.cn), I need to immediately analyze its security tier and obtain key evidence to report the risk profile to my team.
Best For
- A tech lead or security engineer responsible for auditing and managing the procurement risks of third-party tools for their team.
- A developer who is highly sensitive to the privacy of their code and data, and wants to understand a tool's behavioral boundaries before using it.
- A freelancer or independent creator with a limited budget who needs to balance cost-effectiveness with avoiding malware and data breaches.
- A content platform reviewer who frequently handles user-submitted external tools or plugins and needs to perform rapid preliminary security screening.
Related Skills
Transforms LLMs into knowledge base maintainers to incrementally build and maintain a persistent, interlinked Markdown wiki.
A mindmap generation skill specialized in distilling complex information into structured knowledge frameworks for easy understanding and reuse.
BookBone distills books into operational thinking frameworks, extracting core mental models, methodologies, and concepts into structured knowledge tools.
A Python function for local academic paper retrieval engine, supporting multi-platform parallel search, export, and citation analysis, with built-in classic paper index.