跳到主要内容
知仓学习社ZHICANG

codex-image-gallery

Start or reuse a self-contained local web gallery for browsing Codex-generated images. Use when the user asks to browse Codex generated images, open…

读凭据严重 0 · 高危 3daymade/claude-code-skills

它会碰到什么

扫了多少3 个文本文件,7 KB
它会碰到什么读凭据
命中总数5 处
命中统计严重 0 · 高 3 · 中 0 · 低 0
逐条看命中(3 条严重或高危)
  • scripts/server.mjs:9cred-envread
    const HOST = process.env.HOST || "127.0.0.1";
  • scripts/server.mjs:10cred-envread
    const DEFAULT_PORT = Number(process.env.PORT || process.argv[2] || 8765);
  • scripts/server.mjs:13cred-envread
    const IMAGE_ROOT = path.resolve(process.env.GALLERY_ROOT || path.join(os.homedir(), ".codex/generated_images"));

这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。

技能内容

Codex Image Gallery

Start a local browser gallery for Codex image outputs. This skill is self-contained: the server lives in scripts/server.mjs, and the UI template lives in assets/index.html.

Quick Start

Run commands from this skill directory, the directory containing this SKILL.md.

node scripts/server.mjs

The server prints the actual URL. It starts at http://127.0.0.1:8765/ and tries later ports if the default is occupied.

Workflow

  1. Check the default URL first:
   node -e 'fetch("http://127.0.0.1:8765/api/images").then(r => r.json()).then(j => console.log(j.rootPath, j.items.length)).catch(() => process.exit(1))'

If this succeeds, reuse the running server at http://127.0.0.1:8765/.

  1. If the API check fails, check for a running server process:
   pgrep -fl 'node .*server\.mjs' || true

When a process exists but the default URL fails, inspect its stdout or try likely later ports because the server auto-increments when a port is occupied.

  1. Verify any reused URL before reporting success:
   node -e 'fetch("http://127.0.0.1:8765/api/images").then(r => r.json()).then(j => console.log(j.rootPath, j.items.length))'

If the server chose another port, use that port.

  1. Start the server if none is running:
   node scripts/server.mjs

Keep the process running for the user and read stdout for the URL.

  1. Open the browser unless the user asks for URL-only:
   open http://127.0.0.1:8765/

Image Root

Default image root:

~/.codex/generated_images

Use a different folder with:

GALLERY_ROOT=/path/to/images node scripts/server.mjs

Validation

Before declaring the skill healthy after edits, run:

node --check scripts/server.mjs

Then start the server and verify:

  • GET /api/images returns JSON with rootPath and items
  • /images/<relative-path> returns image content for at least one listed item
  • The page loads from the bundled assets/index.html

Response

Report the URL, image root, whether the server was reused or newly started, and any verification failure. Keep the answer short.

想直接用这个技能?

本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。