sn-search-code
用于查找代码示例、开源项目、GitHub Issue、技术问答、开发者讨论、HuggingFace 模型/数据集/Space。
它会碰到什么
逐条看命中(3 条严重或高危)
- 严重
SKILL.md:10cred-pathsAPI key、token 与 cookie 统一建议写在仓库根目录 `.env`(参考 `.env.example`),并由 runtime 或用户在执行前加载为同名环境变量。脚本仍只从环境变量或显式 CLI 参数读取凭证;不要把真实密钥写入 skill payload、报告、日志或提交。
- 严重
SKILL.md:10cred-pathsAPI key、token 与 cookie 统一建议写在仓库根目录 `.env`(参考 `.env.example`),并由 runtime 或用户在执行前加载为同名环境变量。脚本仍只从环境变量或显式 CLI 参数读取凭证;不要把真实密钥写入 skill payload、报告、日志或提交。
- 高
scripts/search_utils.py:123cred-envreadreturn os.environ.get(env_var)
这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。
技能内容
sn-search-code - 开发者搜索
凭证配置
API key、token 与 cookie 统一建议写在仓库根目录 .env(参考 .env.example),并由 runtime 或用户在执行前加载为同名环境变量。脚本仍只从环境变量或显式 CLI 参数读取凭证;不要把真实密钥写入 skill payload、报告、日志或提交。
搜索 GitHub、Stack Overflow、Hacker News、HuggingFace 四个开发者核心平台。所有脚本无需 API 密钥 即可使用,但 GitHub --type code 搜索是例外(见下方说明)。
可用脚本
| 脚本 | 平台 | 用途 | API 密钥 |
|------|------|------|---------|
| github_search.py | GitHub | 仓库、代码、Issue 搜索 | code 类型必须;其他类型可选(提高限额) |
| stackoverflow_search.py | Stack Overflow | 技术问答搜索 | 无需 |
| hackernews_search.py | Hacker News | 技术新闻和讨论 | 无需 |
| huggingface_search.py | HuggingFace | 模型、数据集、Space 搜索 | 可选 HF_TOKEN(提高限额) |
依赖
首次运行或脚本提示缺库时,使用本技能的依赖清单安装到当前 Python 环境:
python3 -m pip install -r requirements.txt
不要在脚本内部自动安装依赖。若安装失败、网络不可用或包不可用,停止使用对应脚本并改用网页搜索,说明缺少依赖。
参数说明
github_search.py
python3 scripts/github_search.py <query> [选项]
| 参数 | 说明 | 默认值 |
|------|------|--------|
| query | 搜索关键词(必填) | — |
| --limit, -n | 返回结果数量 | 10 |
| --type, -t | 搜索类型:repositories, code, issues, repo, issue | repositories |
| --token | GitHub Token(也可通过 GITHUB_TOKEN 环境变量设置) | — |
> 注意:--type code 必须提供 token。
> GitHub API 对代码搜索接口强制要求认证,未提供 token 会返回 401。
> repositories 和 issues 类型无需 token,但有 token 可提高速率限制(未认证 10 次/分钟 → 认证 30 次/分钟)。
python3 scripts/github_search.py "machine learning framework" --type repositories --limit 5
python3 scripts/github_search.py "import asyncio" --type code --token ghp_xxx --limit 5
# 或通过环境变量:
GITHUB_TOKEN=ghp_xxx python3 scripts/github_search.py "import asyncio" --type code --limit 5
stackoverflow_search.py
python3 scripts/stackoverflow_search.py <query> [选项]
| 参数 | 说明 | 默认值 |
|------|------|--------|
| query | 搜索关键词(必填) | — |
| --limit, -n | 返回结果数量 | 10 |
| --sort | 排序方式:relevance, votes, creation, activity | relevance |
| --tagged | 按标签过滤,多个用分号分隔(如 python;asyncio) | — |
| --api-key | Stack Exchange API 密钥(也可通过 SO_API_KEY 环境变量设置,可选,提高限额) | — |
python3 scripts/stackoverflow_search.py "python async await" --limit 5
python3 scripts/stackoverflow_search.py "rust lifetime" --sort votes --tagged rust --limit 10
huggingface_search.py
python3 scripts/huggingface_search.py <query> [选项]
| 参数 | 说明 | 默认值 |
|------|------|--------|
| query | 搜索关键词(必填) | — |
| --limit, -n | 返回结果数量 | 10 |
| --type, -t | 搜索类型:models, datasets, spaces(及别名 model, dataset, space) | models |
| --token | HuggingFace Token(也可通过 HF_TOKEN 环境变量设置,可选,提高限额) | — |
python3 scripts/huggingface_search.py "bert" --type models --limit 5
python3 scripts/huggingface_search.py "text classification" --type datasets --limit 5
python3 scripts/huggingface_search.py "stable diffusion" --type spaces --limit 5
hackernews_search.py
python3 scripts/hackernews_search.py <query> [选项]
| 参数 | 说明 | 默认值 |
|------|------|--------|
| query | 搜索关键词(必填) | — |
| --limit, -n | 返回结果数量 | 10 |
| --sort | 排序方式:relevance, date | relevance |
| --tags | HN 标签过滤:story, comment, ask_hn, show_hn | — |
python3 scripts/hackernews_search.py "LLM agents" --limit 10
python3 scripts/hackernews_search.py "GPT-5" --sort date --tags story --limit 5
输出格式
所有脚本输出标准 JSON:
{
"success": true,
"query": "...",
"provider": "github|stackoverflow|hackernews",
"items": [
{"title": "...", "url": "...", "snippet": "...", ...}
],
"error": null
}想直接用这个技能?
本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。
它属于哪个仓库
同一个仓库里的其他技能
- large-file-parquet-analysis-and-highlight
- excel-conditional-comparison-and-large-file-processing
- excel-outlier-detection-and-highlighting
- large-file-conditional-formatting
- top-value-coloring
- numeric-extraction-and-distribution-analysis
- categorical-comparison-analysis
- group-by-analysis
- large-file-kpi-analysis
- pivot-table-cross-analysis
- time-series-and-categorical-analysis
- trend-analysis