faq-collector — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited faq-collector (Agent Skill) and scored it 45/100 (orange). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 1 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 1 flagged
A base64 string of 128+ characters appears in a documentation file. Encoded prompt injection hides the hostile instruction in base64 — invisible to keyword filters — and relies on the agent's ability to decode it at runtime. There is no normal authoring reason to embed a multi-hundred-byte base64 blob in skill docs.
*.sig, SIGNATURES) outside the documentation.Every scanned point with the score it earned and what moved between them.
Aggregate score unchanged between these scans.
The primary manifest — the file an agent reads to learn what this artifact does.
收录标准: 通用性高、有明确方案、配置/操作类、非直觉问题。不收录: 纯个人环境问题、已有相同条目、未解决问题。
文件: <project_root>/.cherry-assistant/faq.md(目录不存在则 mkdir -p .cherry-assistant 创建)
条目格式(追加到末尾):
### Q: [通用化问题表述]
**A:** [简洁方案]
[分步骤操作]
- **关键词**: [逗号分隔]
- **相关文件/Issue**: [路径或#编号]
- **版本**: vX.X.X | **收录日期**: YYYY-MM-DD
---流程: 问题解决→判断收录标准→读FAQ查重→无重复则通用化后追加→有相似但更好则更新
搜索匹配: 用户提问时先读FAQ关键词匹配→命中直接给答案→未命中走正常诊断
与 Issue Reporter 协作: 先收录FAQ(记录方案)→如果是Bug再提Issue→FAQ记关联Issue编号
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.