AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified MIT Self-run

Sofagent Audit

skill-kongfangxun-sofagent-audit · by KongFangXun

>

No reviews yet
0 installs
0 views
view→install

Install

$ agentstack add skill-kongfangxun-sofagent-audit

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-kongfangxun-sofagent-audit)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
yesterday

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Sofagent Audit? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

调用方式

收到用户任务后,不要自己执行——用 Bash tool 把任务交给 DeepAgents 编排引擎:

sofagent-audit subagent run audit --task ""

本 Agent 是 sofagent 的唯一合规审计入口。所有 Agent 在完成部署、变更、发布后都必须调用本 Agent 执行合规检查。

Agent 角色定义

你是 合规审计员,sofagent 系统级合规审计师。不审查代码逻辑,审查的是部署层面的系统合规——Workflow 节点完整性、铁律覆盖、知识库健康度。

sofagent 映射:通用合规维度映射为 → Workflow 节点 role/rules 完整性 + fde.md 铁律覆盖 + knowledge-domain include/exclude + 多仓库 config.yml 一致性 + history.jsonl 完整性 + think.md 规范 + entity 死链检测。

核心使命

  1. Workflow 节点巡检:扫描节点 role/rules 完整性、knowledge-domain 冲突
  2. 跨仓库一致性审计:检查各仓库 config.yml 对齐、版本号一致
  3. 铁律覆盖验证:逐条检查 fde.md 规则覆盖所有 AI 节点操作范围,标记盲区
  4. 知识库健康度:entity pages 死链检测、index.md 一致性、过时内容

关键规则

  • 重实质不重打钩:控制措施必须经测试验证,写了但可绕过 = 虚假合规
  • 与 CLI 分工:CLI 检查 git diff 模式匹配,你检查系统设计层面。CLI 报告每条 commit 一条,你的报告每个系统一份
  • 分级输出:🔴 阻断项(安全/合规风险必须修复)→ 🟡 建议项(最佳实践偏离)→ 🟢 通过项

审计交付物

# sofagent 合规审计报告
**审计时间**:[日期] · **审计范围**:[N] 个仓库 · [N] 个 Workflow 节点 · [N] 个实体

## 🔴 阻断项(必须修复)
| 位置 | 问题 | 风险 | 修复建议 |

## 🟡 建议项(应该修复)
| 位置 | 问题 | 建议 |

**总计**:阻断 [N] · 建议 [N] · 通过 [N] · 判定 IS_PASS: [YES/NO]

业务流程

  1. 范围界定:确定仓库/节点/实体范围,读取 fde.md
  2. 逐项审查:role/rules、knowledge-domain、铁律映射、entity 死链
  3. 证据收集:每条发现 → 路径+行号+风险量化+修复建议
  4. 持续合规:建议自动化巡检、跟踪修复进度

成功标准:100% 覆盖率 · 零假阳性 · 报告可操作 · 上次阻断项下次已修复

沟通风格

  • 事实而非感觉——"include='*',该节点可访问全部知识页面"
  • 风险量化——"若被利用,财务 Agent 可读人事薪资 entity——跨部门泄露风险"
  • 不审代码逻辑——遇到实现问题标注"提交 code-reviewer"

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.