المهارات ad-account-auditor سجل التدقيق
📦

سجل التدقيق

ad-account-auditor - 10 عمليات التدقيق

مقارنة الإصدارات

التغييرات في القدرات والنتائج عبر الإصدارات المدقّقة، الأحدث أولاً.

الإصدارالتاريخالنتيجةعناصر المراجعةالتغيير مقارنةً بالسابقة
v10 الأحدث٢٦ يوليو ٢٠٢٦، ٠٩:٥١ ص لا توجد نتائج مؤكَّدة0لا تغيير في القدرات
v9 ٢٦ يوليو ٢٠٢٦، ٠٩:٥١ ص لا توجد نتائج مؤكَّدة0لا تغيير في القدرات
v8 ١٥ يوليو ٢٠٢٦، ٠٢:١٨ ص لا توجد نتائج مؤكَّدة0لا تغيير في القدرات
v7 ١٤ يوليو ٢٠٢٦، ١١:٢٠ م لا توجد نتائج مؤكَّدة0لا تغيير في القدرات
v6 ١٤ يوليو ٢٠٢٦، ١١:٢٠ م لا توجد نتائج مؤكَّدة0لا تغيير في القدرات
v5 ١٣ يوليو ٢٠٢٦، ١١:٢٦ ص 2 مؤكَّد0لا تغيير في القدرات
v4 ١٣ يوليو ٢٠٢٦، ١١:٢٦ ص 2 مؤكَّد0لا تغيير في القدرات
v3 ١٢ يوليو ٢٠٢٦، ١٠:٣٣ ص لا توجد نتائج مؤكَّدة0لا تغيير في القدرات
v2 ٦ يوليو ٢٠٢٦، ٠٢:٥٨ م 1 مؤكَّد1لا تغيير في القدرات
v1 ٤ يوليو ٢٠٢٦، ٠٣:٤٦ م لا توجد نتائج مؤكَّدة0الأساس

٢٦ يوليو ٢٠٢٦، ٠٩:٥١ ص

All 39 static findings are false positives caused by Markdown code formatting, static documentation links, metadata URLs, and fixed reference paths. The reviewed instructions limit the skill to assessment, require explicit authorization before persistence, and prohibit ad-account mutations without separate approval. No prompt injection, credential collection, data exfiltration, or arbitrary command execution evidence was found.

2
الملفات التي تم فحصها
350
الأسطر التي تم تحليلها
3
عناصر المراجعة
0
تم تجاهل الإيجابيات الكاذبة
دقّقه: claude

٢٦ يوليو ٢٠٢٦، ٠٩:٥١ ص

All 39 static findings are false positives caused by Markdown code formatting, static documentation links, metadata URLs, and fixed reference paths. The reviewed instructions limit the skill to assessment, require explicit authorization before persistence, and prohibit ad-account mutations without separate approval. No prompt injection, credential collection, data exfiltration, or arbitrary command execution evidence was found.

2
الملفات التي تم فحصها
350
الأسطر التي تم تحليلها
3
عناصر المراجعة
0
تم تجاهل الإيجابيات الكاذبة
دقّقه: claude

١٥ يوليو ٢٠٢٦، ٠٢:١٨ ص

All 38 static detections are false positives caused by Markdown formatting, fixed repository references, project metadata URLs, or a bounded Git root lookup. No prompt injection, untrusted command construction, data exfiltration, or user-controlled path traversal was found.

2
الملفات التي تم فحصها
348
الأسطر التي تم تحليلها
3
عناصر المراجعة
0
تم تجاهل الإيجابيات الكاذبة
دقّقه: codex

١٤ يوليو ٢٠٢٦، ١١:٢٠ م

All 38 static findings are false positives caused by Markdown code spans, fixed relative links, metadata URLs, and one hardcoded repository-root command. No user-controlled command execution, arbitrary path access, prompt injection, data exfiltration, or malicious intent was found.

2
الملفات التي تم فحصها
348
الأسطر التي تم تحليلها
3
عناصر المراجعة
0
تم تجاهل الإيجابيات الكاذبة
دقّقه: codex

١٤ يوليو ٢٠٢٦، ١١:٢٠ م

All 38 static findings are false positives caused by Markdown code spans, fixed relative links, metadata URLs, and one hardcoded repository-root command. No user-controlled command execution, arbitrary path access, prompt injection, data exfiltration, or malicious intent was found.

2
الملفات التي تم فحصها
348
الأسطر التي تم تحليلها
3
عناصر المراجعة
0
تم تجاهل الإيجابيات الكاذبة
دقّقه: codex

١٣ يوليو ٢٠٢٦، ١١:٢٦ ص

All 38 static findings are false positives based on their surrounding context. The skill contains no prompt injection, exfiltration, unsafe account mutation, or unauthorized persistence intent. Two low-severity concerns remain: unused network permission and missing data-minimization guidance for order or lead identifiers.

2
الملفات التي تم فحصها
348
الأسطر التي تم تحليلها
5
عناصر المراجعة
0
تم تجاهل الإيجابيات الكاذبة

مخاوف أمنية مؤكدة (2)

منخفض
Unnecessary Network Permission
The skill grants WebFetch although the workflow relies on exported data and local immutable references, increasing network capability without a defined use.
The frontmatter explicitly allows WebFetch, while the workflow defines no required remote request and warns against fetching mutable sources.
منخفض
Sensitive Identifier Handling Is Underspecified
The skill requests deduplicated order or lead IDs from commerce, analytics, or CRM exports without requiring hashing, redaction, or field minimization.
The requested evidence explicitly includes order and lead IDs, but the reviewed instructions provide no privacy handling requirements.
دقّقه: codex

١٣ يوليو ٢٠٢٦، ١١:٢٦ ص

جميع النتائج الثابتة البالغ عددها 38 هي إيجابيات كاذبة استنادًا إلى سياقها المحيط. لا تحتوي المهارة على حقن مطالبات أو استخلاص بيانات أو تعديل غير آمن للحسابات أو نية استمرارية غير مصرّح بها. تبقى مشكلتان منخفضتا الخطورة: إذن شبكة غير مستخدم وإرشادات مفقودة لتقليل البيانات لمعرّفات الطلبات أو العملاء المحتملين.

2
الملفات التي تم فحصها
348
الأسطر التي تم تحليلها
5
عناصر المراجعة
0
تم تجاهل الإيجابيات الكاذبة

مخاوف أمنية مؤكدة (2)

منخفض
إذن شبكة غير ضروري
تمنح المهارة WebFetch رغم أن سير العمل يعتمد على بيانات مُصدّرة ومراجع محلية غير قابلة للتغيير، مما يزيد من قدرة الشبكة دون استخدام محدد.
تسمح البيانات الوصفية الأمامية صراحةً بـ WebFetch، بينما لا يحدد سير العمل أي طلب بعيد مطلوب ويحذر من جلب المصادر القابلة للتغيير.
منخفض
معالجة المعرّفات الحساسة غير محددة بشكل كافٍ
تطلب المهارة معرّفات طلبات أو عملاء محتملين بعد إزالة التكرار من صادرات التجارة أو التحليلات أو CRM دون اشتراط التجزئة أو التنقيح أو تقليل الحقول.
تتضمن الأدلة المطلوبة صراحةً معرّفات الطلبات والعملاء المحتملين، لكن التعليمات المُراجَعة لا توفر أي متطلبات لمعالجة الخصوصية.
دقّقه: codex

١٢ يوليو ٢٠٢٦، ١٠:٣٣ ص

النتائج الساكنة هي إيجابيات كاذبة ناجمة عن تنسيق Markdown، وروابط عناوين URL للبيانات الوصفية، وروابط الوثائق الثابتة، وبحث مستودع مضمّن في الشيفرة. لم يُعثر على تنفيذ أوامر يتحكم به المستخدم، أو حقن مطالبات، أو تسريب بيانات، أو تعديل غير مصرح به للحسابات.

2
الملفات التي تم فحصها
347
الأسطر التي تم تحليلها
3
عناصر المراجعة
0
تم تجاهل الإيجابيات الكاذبة
دقّقه: codex

٦ يوليو ٢٠٢٦، ٠٢:٥٨ م

Most static findings are Markdown formatting, repository-relative links, or marketing audit language rather than executable shell commands, arbitrary path traversal, or system reconnaissance. One network finding is confirmed because the skill can fetch mutable reference instructions from GitHub at runtime, and one semantic privacy finding covers persistent memory writes for account audit results.

1
الملفات التي تم فحصها
176
الأسطر التي تم تحليلها
5
عناصر المراجعة
0
تم تجاهل الإيجابيات الكاذبة

مخاوف أمنية مؤكدة (1)

متوسط
Persistent Storage of Sensitive Ad Account Audit Results
The skill instructs agents to save audit artifacts and promote vetoes to memory files. These records can contain account, conversion, spend, or order information.
Lines 58-59 and 163 explicitly require persistent memory writes for audit artifacts, vetoes, and verdicts. The data sources include exported ad and ecommerce records, so sensitive business data may be retained.
عناصر مراجعة القدرات (1)

هذه قدرات محلية حقيقية قد يُتوقع وجودها لهذه المهارة، لذا فهي تتطلب مراجعة ولكن لا تُحتسب كسلوك خبيث مؤكد.

متوسط
Hardcoded URL
*Standalone install fallback*: if that relative path does not exist, this skill was installed standa
This line tells the agent to fetch missing runbook or reference files from raw.githubusercontent.com on the main branch. That mutable external dependency can alter behavior after review, even though it is limited to the author repo.
دقّقه: codex

٤ يوليو ٢٠٢٦، ٠٣:٤٦ م

All 63 static findings were adjudicated as false positives. The flagged backticks are Markdown formatting, the relative paths are fixed repository documentation links, and the URLs point to the public GitHub project or reference fallback. No prompt injection, data exfiltration intent, arbitrary command execution, or unsafe filesystem behavior was found in SKILL.md.

1
الملفات التي تم فحصها
176
الأسطر التي تم تحليلها
3
عناصر المراجعة
0
تم تجاهل الإيجابيات الكاذبة
دقّقه: codex