跳到主要内容
知仓学习社ZHICANG

dual-axis-skill-reviewer

Review skills in any project using a dual-axis method: (1) deterministic code-based checks (structure, scripts, tests, execution safety) and (2) LLM…

读凭据执行命令严重 0 · 高危 6tradermonty/claude-trading-skills

它会碰到什么

扫了多少7 个文本文件,81 KB
它会碰到什么读凭据执行命令
命中总数6 处
命中统计严重 0 · 高 6 · 中 0 · 低 0
逐条看命中(6 条严重或高危)
  • scripts/run_dual_axis_review.py:313cred-envread
    env["UV_CACHE_DIR"] = str(project_root / ".uv-cache")
  • scripts/run_dual_axis_review.py:316exec-spawn
    proc = subprocess.run(
  • scripts/run_dual_axis_review.py:329exec-spawn
    proc = subprocess.run(
  • scripts/tests/test_run_dual_axis_review.py:691exec-spawn
    proc = subprocess.run(
  • scripts/tests/test_run_dual_axis_review.py:739exec-spawn
    proc = subprocess.run(
  • scripts/tests/test_run_dual_axis_review.py:808cred-envread
    'import os\napi_key = os.environ.get("FMP_API_KEY")\nprint(api_key)\n',

这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。

技能内容

Dual Axis Skill Reviewer

Run the dual-axis reviewer script and save reports to reports/.

The script supports:

  • Random or fixed skill selection
  • Auto-axis scoring with optional test execution
  • LLM prompt generation
  • LLM JSON review merge with weighted final score
  • Cross-project review via --project-root
  • Non-scoring display of skills-index.yaml production verification declarations

When to Use

  • Need reproducible scoring for one skill in skills/*/SKILL.md.
  • Need improvement items when final score is below 90.
  • Need both deterministic checks and qualitative LLM code/content review.
  • Need to review skills in a different project from the command line.

Prerequisites

  • Python 3.9+
  • uv (recommended — auto-resolves pyyaml dependency via inline metadata)
  • For tests: uv sync --extra dev or equivalent in the target project
  • For LLM-axis merge: JSON file that follows the LLM review schema (see Resources)

Workflow

Determine the correct script path based on your context:

  • Same project: skills/dual-axis-skill-reviewer/scripts/run_dual_axis_review.py
  • Global install: ~/.claude/skills/dual-axis-skill-reviewer/scripts/run_dual_axis_review.py

The examples below use REVIEWER as a placeholder. Set it once:

# If reviewing from the same project:
REVIEWER=skills/dual-axis-skill-reviewer/scripts/run_dual_axis_review.py

# If reviewing another project (global install):
REVIEWER=~/.claude/skills/dual-axis-skill-reviewer/scripts/run_dual_axis_review.py

Step 1: Run Auto Axis + Generate LLM Prompt

uv run "$REVIEWER" \
  --project-root . \
  --emit-llm-prompt \
  --output-dir reports/

When reviewing a different project, point --project-root to it:

uv run "$REVIEWER" \
  --project-root /path/to/other/project \
  --emit-llm-prompt \
  --output-dir reports/

Step 2: Run LLM Review

  • Use the generated prompt file in reports/skill_review_prompt_<skill>_<timestamp>.md.
  • Ask the LLM to return strict JSON output.
  • When running inside Claude Code, let Claude act as orchestrator: read the generated prompt, produce the LLM review JSON, and save it for the merge step.

Step 3: Merge Auto + LLM Axes

uv run "$REVIEWER" \
  --project-root . \
  --skill <skill-name> \
  --llm-review-json <path-to-llm-review.json> \
  --auto-weight 0.5 \
  --llm-weight 0.5 \
  --output-dir reports/

Step 4: Optional Controls

  • Fix selection for reproducibility: --skill <name> or --seed <int>
  • Review all skills at once: --all
  • Skip tests for quick triage: --skip-tests
  • Change report location: --output-dir <dir>
  • Increase --auto-weight for stricter deterministic gating.
  • Increase --llm-weight when qualitative/code-review depth is prioritized.

Output

  • reports/skill_review_<skill>_<timestamp>.json
  • reports/skill_review_<skill>_<timestamp>.md
  • reports/skill_review_prompt_<skill>_<timestamp>.md (when --emit-llm-prompt is enabled)

When the target project has a skills-index.yaml entry with a complete verification block, JSON

and Markdown reports also show its declared axes, not_verified gaps, non-applicable axes, and

all_applicable_axes_passed. This section is informational only. It is excluded from auto/LLM/final

scores and does not replace a live high-severity issue check.

Installation (Global)

To use this skill from any project, symlink it into ~/.claude/skills/:

ln -sfn /path/to/claude-trading-skills/skills/dual-axis-skill-reviewer \
  ~/.claude/skills/dual-axis-skill-reviewer

After this, Claude Code will discover the skill in all projects, and the script is accessible at ~/.claude/skills/dual-axis-skill-reviewer/scripts/run_dual_axis_review.py.

Resources

  • Auto axis scores metadata, workflow coverage, execution safety, artifact presence, and test health.
  • Auto axis detects knowledge_only skills and adjusts script/test expectations to avoid unfair penalties.
  • LLM axis scores deep content quality (correctness, risk, missing logic, maintainability).
  • Final score is weighted average.
  • If final score is below 90, improvement items are required and listed in the markdown report.
  • Script: skills/dual-axis-skill-reviewer/scripts/run_dual_axis_review.py
  • LLM schema: references/llm_review_schema.md
  • Rubric detail: references/scoring_rubric.md

想直接用这个技能?

本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。