AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified MIT Self-run

Source Audit

skill-metalaihq-trip-event-curator-source-audit · by metalaihq

Run the pre-output guard over any deliverable in this plugin, now with a source-permission gate: verify ToS/robots verdicts for every source actually used (Luma/Meetup/RA usable per 2026-07-08 measurement, Eventbrite API prohibited, Devpost direct fetching prohibited per its explicit anthropic-ai disallow — substitutions must be stated), plus source-tag coverage on every claim, travel-window inte…

No reviews yet
0 installs
0 views
view→install

Install

$ agentstack add skill-metalaihq-trip-event-curator-source-audit

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-metalaihq-trip-event-curator-source-audit)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
1mo ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Source Audit? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

Source Audit (출력 전 가드 — 소스 권한·출처·PII·시크릿·라벨 전수 검사)

산출물이 세션을 떠나기 전의 마지막 게이트. v1 source-audit(체크리스트·DOI 오탐 수정)를 승계하고, v2에서 소스 ToS/robots 실측 게이트가 추가됐다 — 이 플러그인은 남의 데이터를 긁어 재배포하는 물건이 아니라, 허용된 공개 소스를 출처와 함께 인용하는 물건이다. 검사는 전수이거나 무효다.

Workflow

  1. 대상 확정 (0단계)context/curator-context.md 확인 + 검사 대상 산출물(발굴 목록·여정·브리프·HTML)을 특정한다.
  2. 소스 권한 게이트 (v2 신설) — 산출물이 실제 사용한 소스 목록을 추출하고 판정표(curator-context의 ToS/robots 실측표 + 각 스카우트 sources.md)와 대조한다:
  • 사용 가능 판정 소스인가? (Luma·RA·e-flux·Meetup 공개 페이지 등 — 2026-07-08 실측)
  • 금지 소스 사용 흔적 0건: Eventbrite API(v0.2 라이선스 실측)·Devpost 직접 수집(anthropic-ai UA 명시 차단)·Strava. 발견 보조로 쓴 경우 공식 교차·대체 명기가 있는지.
  • 판정표에 없는 새 소스 → robots/ToS 실측 후 표에 추가 기록했는지. 미실측 소스는 위반.
  1. 체크리스트 전수 실행 — 항목당 판정(통과/위반)+위반 위치:
  • ① 출처 태그 커버리지: 수치·날짜·상태·실명 주장 전수에 [출처|날짜] 또는 신호 ID.
  • ② 여행 윈도우 교집합: 채택 이벤트 전건이 윈도우와 교집합 — 안 겹치는 것이 본 목록에 섞여 있으면 위반 (인접 참고 버킷은 통과).
  • ③ 이중 시간축·캡처 시점: 전 카드 freshness(기준일)+entry_status(캡처일). ended가 진행중으로 나간 곳 0건 ($edition-check 판정 대조).
  • ④ 여행가치 판정 기록: 채택 이벤트에 4축 판정, drop 로그 존재. 관공서 API 단독 소싱 0건.
  • ⑤ 가격·재고 정직성: 표기 그대로가 아닌 숫자 0건, null+갭 처리는 통과.
  • ⑥ PII 0: 이메일·전화 0건 — 전화 패턴 검사 전 URL·DOI·arXiv 토큰 제거 (v0.2 오탐 교훈).
  • ⑦ 시크릿 0: 키·토큰·비밀번호 패턴 0건.
  • ⑧ 라벨 무결성: 인과 단정 0건, 추정치 전건 estimate 라벨+각주, (기억 기반—재검증 필요) 문장이 하한 카운트에 미포함.
  1. 판정·조치 — 전 항목 통과 → "통과"+항목별 검사 건수. 위반 → 위반 목록+수정 지시, 통과 보고 금지. 수정은 원 스킬이 하고 재검사한다 (작성·검증 분리).

산출물 스키마

| # | 항목 | 판정 | 검사 건수 | 위반 위치·내용 | 수정 지시 | |---|---|---|---|---|---|

  • 사용 소스 목록·권한 판정표 + 최종 판정 (통과 / 위반 N건 — 재검사 필요).

하한

  • 소스 권한 게이트 + 체크리스트 8항목 전수 실행 + 항목별 판정·검사 건수 기록. 부분 실행 후 통과 보고 금지. 위반이 하나라도 있으면 최종 판정은 통과가 될 수 없다.

증거 규칙

상세 기준·하한표: [evidence-rules.md](../traveler-profile/references/evidence-rules.md)

  1. 모든 신호·주장에 [출처명 | 날짜 | 수치 또는 원문 인용] 태그. 출처 없는 신호 기재 금지.
  2. 웹서치가 1차, assets/snapshot/은 2차 — 모든 상태는 "캡처 시점 기준" 명시.
  3. 여행 윈도우 교집합·이중 시간축·종료 회기 오인 금지 — 이 스킬이 최종 대조자다.
  4. 여행가치 게이트 기록 검사 — 관공서 API 단독 소싱은 위반이다.
  5. 소스 ToS/robots 실측 준수 — 미실측 소스 사용은 위반, 대체·명기 여부를 검사한다. 하한 미달 시 통과 보고 금지.

원칙

  • 감사는 산출물이 아니라 여행자를 지킨다 — 끝난 전시 하나, 틀린 마감일 하나가 여행 하루를 날린다.
  • 소스 권한은 성능이 아니라 원칙이다 — 명시적으로 거부한 사이트(Devpost의 anthropic-ai 차단)는 기술적으로 가능해도 존중한다.
  • 검사 건수를 기록하라 — "위반 0건"과 "검사 안 함"은 다른 문장이다.
  • 이 스킬은 고치지 않는다 — 위반과 수정 지시까지가 소관, 수정은 원 스킬이 (작성과 검증의 분리).

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.