mangou-ai-motion-comics — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited mangou-ai-motion-comics (Agent Skill) and scored it 96/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 1 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 1 flagged
A bulleted imperative like {match} tells the agent to never reveal, disclose, or mention something to the user. Used adversarially it can instruct the agent to hide its tool calls or lie about what it did — stripping the transparency a user relies on to trust the agent.
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Mangou 用 YAML 管理资产和分镜,用 CLI 执行生成与回填,适合把 AI 漫剧流程收敛成可审计、可批量执行的项目目录。
asset_defs/*.yaml、storyboards/*.yamltasks.jsonl 或 YAML 回填状态按这个顺序执行:
Mangou checklist
- [ ] 确认技能已安装
- [ ] 优先通过 vercel-labs/skills 安装技能入口
- [ ] 轻量安装态不包含 Bun runtime,不要直接假设 `src/main.ts` 已存在
- [ ] 需要 CLI 时,优先运行 `node bootstrap-runtime.mjs`
- [ ] 需要本地只读页面时,再安装独立 dashboard 包
- [ ] 检索工作区记忆:开始任务前检查 `workspace/.mangou/memories/`
- [ ] 先读项目目录规范,再改 YAML
- [ ] 生成后只信任 tasks.jsonl 和 YAML latest 回填
- [ ] 失败时先读 error,再修正参数或 prompt
- [ ] 沉淀经验:任务完成后,询问用户是否总结记忆库node bootstrap-runtime.mjsknowledge/;如果技能根目录还没有 src/main.ts,先安装 runtime,再执行 Bun 命令。provider;tasks.image.provider 和 tasks.video.provider 都必须在 YAML 里显式写出。tasks.jsonl 为唯一真相源,YAML latest 是投影缓存。storyboard split 只依赖 meta.grid / --grid,不要靠 prompt 文本推断宫格。error、latest、tasks.jsonl 末尾记录,再决定是否重试。workspace/.mangou/memories/),如有冲突以时间较近的记录为准。默认推荐:
bltaievolink~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.