If you find vskill useful, give it a star on GitHub→
vskill
LoginSkillsStudioSubmitPublishersTrustQueueDocsInsights
vskill

Securing the AI skills supply chain.

SkillsStudioPublishersTrustDocsQueueSubmitInsightsGitHubnpmSpecWeave

MIT License

<< Back to skill
── xiaoma-create-architecture — Security Report ────
Skillxiaoma-create-architecture
Publisherzqyl-xiaoma
Repositoryzqyl-xiaoma/xiaoma-cli-release →
OverallPASS

Scanned by vskill platform — 52 built-in patterns + 3 external SAST tools (semgrep, njsscan, trufflehog). Dependencies enriched with Socket.dev supply chain scores. Public Snyk and Socket.dev reports linked where available.

── Scanning Pipeline ───────────────────────────────
Tier 1: Pattern Scanner (52 checks)
PASS100/100
Tier 2: LLM Analysis
PENDING
── Tier 1 Detail ───────────────────────────────────
VerdictPASS
Score100/100
Patterns52
Findings0
── External Intelligence ───────────────────────────
npm Package@zeyue0329/xiaoma-cli
Socket.devunavailable
Socket.dev report →Snyk advisory →