FF byted-viking-developer
指导开发者接入与使用Viking SDK, 覆盖 Viking 向量库、知识库、记忆库的安装、鉴权、接口调用与问题诊断, 当用户需要调用Viking SDK进行业务代码开发和Viking相关问题问答时使用.
As a process F 35/100 · Will not run — References files that are not bundled: resources/Viking%20%E7%9F%A5%E8%AF%86%E5%BA%93/SDK%E5%8F%82%E8%80%83/SDK%20%E5%8D%87%E7%BA%A7%E4%B8%8E%E4%BD%BF%E7%94%A8%E8%AF%B4%E6%98%8E.md
What is at stake
The skill contains fragments that, in the wrong hands, cost money or data. Below: what the installer risks and what the author should do.
The files contain invisible characters, encoded commands or comments hidden from readers but visible to the model. What you read differs from what the agent sees.
Remove invisible characters (they usually sneak in through copy-paste) and encoded strings: no catalog will pass them. Instructions for the model must be readable by a human too.
How to improve
- Address the high-severity findings: each costs 18 safety points. If one is a false positive, add the rule id to guard.allow in spec.yaml.
- Say in the description WHEN to use the skill ("use when…", example requests): that is the agent's main cue.
- The text references files that are not there: add them or drop the references.
- Your own cases (evals/evals.json, 4–6 real requests with expected answers): the full check would then run those instead of a model-drafted suite.
- A spec.yaml with trigger phrases and assertions — a behaviour contract for CI; `skilltest init` writes a template.
Guard findings · 22
-
high Obfuscation
uni-zero-widthresources/VikingDB 向量库/最佳实践/【向量库】表征方式配置参考.md:9Zero-width / invisible characters (possible hidden text) (14 occurrences)| 稠密向量 <br> Dense vector | 稠密向量是高维向量,每个维度都有非零值,通常从文本、图像或其他数据中提取语义特征。例如:v = [1.2, 3.4, 5.6, -0.5] <br> | * 语义召回强:能搜到“意思相近但字不一样”的内容 <br> * 多模态天然适配:图片、音频、文本都能统一到同…
-
high Obfuscation
uni-zero-widthresources/VikingDB 向量库/向量库新版本(V2)快速入门.md:52Zero-width / invisible characters (possible hidden text) (14 occurrences)* 方式二:首页点击向量数据库,进入控制台的快速开始页面,**单击页面上我的向量库旁边的【查看全部】,进入数据集页面,点击【创建数据集】;␀**或在页面上方教程中点击++创建数据集++
Medium and low: 20
-
medium Obfuscation
obf-hex-escape-chainresources/knowledge-other.md:7Escaped/char-code string obfuscation- 本文介绍VikingDB 向量数据库/知识库支持的地域及访问域名。: [地域和访问域名(Endpoint) - 知识库版本.md](Viking%20%E7%9F%A5%E8%AF%86%E5%BA%93/%E5%9C%B0%E5%9F%9F%E5%92%8C%E8%AE%BF%E9%97%AE%E5%9F%9F%E5%90%8D%EF%BC%88Endpoint%EF%BC%89%20-%2
-
medium Obfuscation
obf-hex-escape-chainresources/knowledge-other.md:8Escaped/char-code string obfuscation- 私网连接(PrivateLink)通过终端节点和终端节点服务建立私密的网络连接,实现不同 VPC 对服务资源的私网访问,避免了公网访问潜在的安全风险,为您提供更加安全的组网方式。: [知识库私网连接方式.md](Viking%20%E7%9F%A5%E8%AF%86%E5%BA%93/%E7%9F%A5%E8%AF%86%E5%BA%93%E7%A7%81%E7%BD%91%E8%BF%9E%
-
medium Obfuscation
obf-hex-escape-chainresources/knowledge-qa.md:8Escaped/char-code string obfuscation- 1.: [服务开通与权限管理.md](Viking%20%E7%9F%A5%E8%AF%86%E5%BA%93/%E7%9F%A5%E8%AF%86%E5%BA%93%E5%B8%B8%E8%A7%81%E9%97%AE%E9%A2%98/%E6%9C%8D%E5%8A%A1%E5%BC%80%E9%80%9A%E4%B8%8E%E6%9D%83%E9%99%90%E7%AE%A1%E7%90
-
medium Obfuscation
obf-hex-escape-chainresources/memory-best-practice.md:7Escaped/char-code string obfuscation- 本章将以火山引擎“豆包大模型”为例,向您展示如何将记忆库与大模型相结合,构建一个具备长期记忆能力的对话式AI。: [串联大模型最佳实践.md](Viking%20%E8%AE%B0%E5%BF%86%E5%BA%93/%E6%9C%80%E4%BD%B3%E5%AE%9E%E8%B7%B5/%E4%B8%B2%E8%81%94%E5%A4%A7%E6%A8%A1%E5%9E%8B%E6%9C%
-
medium Obfuscation
obf-hex-escape-chainresources/memory-best-practice.md:8Escaped/char-code string obfuscation- **为什么需要算子?**: [使用记忆库算子实现画像精准抽取.md](Viking%20%E8%AE%B0%E5%BF%86%E5%BA%93/%E6%9C%80%E4%BD%B3%E5%AE%9E%E8%B7%B5/%E4%BD%BF%E7%94%A8%E8%AE%B0%E5%BF%86%E5%BA%93%E7%AE%97%E5%AD%90%E5%AE%9E%E7%8E%B0%E7%94%B
-
medium Obfuscation
obf-hex-escape-chainresources/memory-best-practice.md:9Escaped/char-code string obfuscation- 为何需要图文记忆库: [图文记忆库最佳实践.md](Viking%20%E8%AE%B0%E5%BF%86%E5%BA%93/%E6%9C%80%E4%BD%B3%E5%AE%9E%E8%B7%B5/%E5%9B%BE%E6%96%87%E8%AE%B0%E5%BF%86%E5%BA%93%E6%9C%80%E4%BD%B3%E5%AE%9E%E8%B7%B5.md)
-
medium Obfuscation
obf-hex-escape-chainresources/memory-best-practice.md:10Escaped/char-code string obfuscation- 实时写入数据+获取上下文接口使用指南: [实时写入数据+获取上下文接口使用指南.md](Viking%20%E8%AE%B0%E5%BF%86%E5%BA%93/%E6%9C%80%E4%BD%B3%E5%AE%9E%E8%B7%B5/%E5%AE%9E%E6%97%B6%E5%86%99%E5%85%A5%E6%95%B0%E6%8D%AE%2B%E8%8E%B7%E5%8F%96%E4%B
-
medium Obfuscation
obf-hex-escape-chainresources/memory-best-practice.md:11Escaped/char-code string obfuscation- 本章将详细描述如何在 RTC 的实时对话式 AI 中,使用 Viking 长期记忆 和 Viking 知识库。: [打通 RTC 服务,在实时对话式 AI 中使用 Viking 长期记忆和知识库.md](Viking%20%E8%AE%B0%E5%BF%86%E5%BA%93/%E6%9C%80%E4%BD%B3%E5%AE%9E%E8%B7%B5/%E6%89%93%E9%80%9A%20R
-
medium Obfuscation
obf-hex-escape-chainresources/memory-python-sdk.md:28Escaped/char-code string obfuscation- 用于批量删除已写入记忆库的事件记忆。: [批量删除事件记忆-BatchDeleteEvent.md](Viking%20%E8%AE%B0%E5%BF%86%E5%BA%93/SDK%E5%8F%82%E8%80%83/%E8%AE%B0%E5%BF%86%E7%AE%A1%E7%90%86/%E4%BA%8B%E4%BB%B6%E8%AE%B0%E5%BF%86/%E6%89%B9%E9%8
-
medium Obfuscation
obf-hex-escape-chainresources/memory-python-sdk.md:34Escaped/char-code string obfuscation- 用于手动触发画像记忆的更新。: [手动触发画像记忆更新-TriggerUpdateProfile.md](Viking%20%E8%AE%B0%E5%BF%86%E5%BA%93/SDK%E5%8F%82%E8%80%83/%E8%AE%B0%E5%BF%86%E7%AE%A1%E7%90%86/%E7%94%BB%E5%83%8F%E8%AE%B0%E5%BF%86/%E6%89%8B%E5
-
medium Obfuscation
obf-hex-escape-chainresources/memory-python-sdk.md:35Escaped/char-code string obfuscation- 用于批量删除已写入记忆库的画像记忆。: [批量删除画像记忆-BatchDeleteProfile.md](Viking%20%E8%AE%B0%E5%BF%86%E5%BA%93/SDK%E5%8F%82%E8%80%83/%E8%AE%B0%E5%BF%86%E7%AE%A1%E7%90%86/%E7%94%BB%E5%83%8F%E8%AE%B0%E5%BF%86/%E6%89%B9%E9
-
medium Obfuscation
obf-hex-escape-chainresources/vikingdb-best-practice.md:8Escaped/char-code string obfuscation- > 新版API V2若使用新版API V2想参考最佳实践请联系我们。: [【向量库】多模态搜索实践(文搜图/图搜图) - API V2.md](VikingDB%20%E5%90%91%E9%87%8F%E5%BA%93/%E6%9C%80%E4%BD%B3%E5%AE%9E%E8%B7%B5/%E3%80%90%E5%90%91%E9%87%8F%E5%BA%93%E3%80%91%E5%A
-
medium Obfuscation
obf-hex-escape-chainresources/vikingdb-best-practice.md:9Escaped/char-code string obfuscation- 本文介绍表征方式,如何根据自己的数据和检索需求,选择合适的表征方式。: [【向量库】表征方式配置参考.md](VikingDB%20%E5%90%91%E9%87%8F%E5%BA%93/%E6%9C%80%E4%BD%B3%E5%AE%9E%E8%B7%B5/%E3%80%90%E5%90%91%E9%87%8F%E5%BA%93%E3%80%91%E8%A1%A8%E5%BE%81%E6%
-
medium Obfuscation
obf-hex-escape-chainresources/vikingdb-best-practice.md:11Escaped/char-code string obfuscation- 本文介绍创建索引时,如何根据自己的数据量和检索量需求,选择合适的CU资源数量。: [【向量库】计算资源配置参考.md](VikingDB%20%E5%90%91%E9%87%8F%E5%BA%93/%E6%9C%80%E4%BD%B3%E5%AE%9E%E8%B7%B5/%E3%80%90%E5%90%91%E9%87%8F%E5%BA%93%E3%80%91%E8%AE%A1%E7%AE%9
-
medium Obfuscation
obf-hex-escape-chainresources/vikingdb-other.md:8Escaped/char-code string obfuscation- 本文介绍VikingDB 向量数据库/知识库支持的地域及访问域名。: [地域和访问域名(Endpoint).md](VikingDB%20%E5%90%91%E9%87%8F%E5%BA%93/%E5%9C%B0%E5%9F%9F%E5%92%8C%E8%AE%BF%E9%97%AE%E5%9F%9F%E5%90%8D%EF%BC%88Endpoint%EF%BC%89.md)
-
medium Obfuscation
obf-hex-escape-chainresources/vikingdb-qa.md:12Escaped/char-code string obfuscation- 检索后处理算子: [检索参数常见问题.md](VikingDB%20%E5%90%91%E9%87%8F%E5%BA%93/%E5%B8%B8%E8%A7%81%E9%97%AE%E9%A2%98/%E6%A3%80%E7%B4%A2%E5%8F%82%E6%95%B0%E5%B8%B8%E8%A7%81%E9%97%AE%E9%A2%98.md)
-
low Secrets in code
secret-high-entropy-tokenresources/VikingDB 向量库/最佳实践/【向量库】多模态搜索实践(文搜图/图搜图) - API V2.md:33High-entropy token-like string (may be an id, hash or a credential) (quoted — discussed, not commanded)<img src="data:image/svg+xml;base64,PHN2…DFw
quoted -
low Secrets in code
secret-high-entropy-tokenresources/VikingDB 向量库/最佳实践/【向量库】多模态搜索实践(文搜图/图搜图) - API V2.md:368High-entropy token-like string (may be an id, hash or a credential) (quoted — discussed, not commanded)3. 设置数据集名称为”best_practice_pic_search“;选择使用场景为“图像”,选择向量化模型为“Doub…615”;选择向量维度为2048维;
quoted -
low Secrets in code
secret-high-entropy-tokenresources/VikingDB 向量库/最佳实践/【向量库】视频搜索实践(文搜视频/图搜视频/视频搜视频).md:33High-entropy token-like string (may be an id, hash or a credential) (quoted — discussed, not commanded)<img src="data:image/svg+xml;base64,PHN2…DFw
quoted -
low Obfuscation
obf-hex-escape-chainresources/vikingdb-best-practice.md:10Escaped/char-code string obfuscation (code comment)- > # 以下操作基于API V2版本实现: [【向量库】视频搜索实践(文搜视频/图搜视频/视频搜视频).md](VikingDB%20%E5%90%91%E9%87%8F%E5%BA%93/%E6%9C%80%E4%BD%B3%E5%AE%9E%E8%B7%B5/%E3%80%90%E5%90%91%E9%87%8F%E5%BA%93%E3%80%91%E8%A7%86%E9%A2%91%E6
comment
Files scanned: 80. Evidence is masked. Grey chips explain why severity was lowered.
Against the Agent Skills spec
- warning
description-no-whendescription does not say WHEN to use the skill (no "use when") - warning
missing-refreference to a missing file: resources/Viking%20%E7%9F%A5%E8%AF%86%E5%BA%93/SDK%E5%8F%82%E8%80%83/SDK%20%E5%8D%87%E7%BA%A7%E4%B8%8E%E4%BD%BF%E7%94%A8%E8%AF%B4%E6%98%8E.md
Process rating: all ten parameters 35/100
- 0Tools and files. 1 referenced file(s) missing: resources/Viking%20%E7%9F%A5%E8%AF%86%E5%BA%93/SDK%E5%8F%82%E8%80%83/SDK%20%E5%8D%87%E7%BA%A7%E4%B8%8E%E4%BD%BF%E7%94%A8%E8%AF%B4%E6%98%8E.md
- 0Result and completion. Does not say what the result is
- 0Inputs and preconditions. Does not say what the process needs to start
- 0Failures and branches. Linear process with no failure handling
- 0Progress reporting. Says nothing while it works
- 20When it triggers. No condition that starts the skill
- 100Steps. 24 steps
- 100Consistency. Name and required fields are in place
- 100Execution cost. Instruction body is 381 tokens
- 100Running it twice. No mutating operations
Everything here is measured from the skill text rather than judged by a model, so the numbers are checkable. A parameter weighs more when it is a more common reason for the process to stall.
Quality signals
- +5Description has no quoted example phrases that should trigger the skill
- +4Description does not say when NOT to use the skill (false activations)
- +3Description length 103: 120–800 characters recommended
- +3Output format is not stated: the model decides each time
- +4No input/output examples
- +1No license
- +2Single-language instructions
- +4Structure: 5 headings
- +3Step-by-step instructions: 24 items
Quality base 70; lint remarks subtract, signals add up to 100. Result: 59.