هذا التقرير غير مترجم إلى اللغة المطلوبة. يتم عرض التقرير الإنجليزي الأساسي بدلاً منه.

تقييم أمني مُحدَّث بالإصدار

معرّف التقرير: SA-4646E067

6/28/2026, 1:15:03 PM

cloud-native تقييم أمني v7

تقرير شهادة أمان المهارة

سجل التدقيق
نموذج التدقيق: codex تقرير تاريخي
اسم المهارة
cloud-native
الإصدار
v7
المشرف
Azeem-2
التغطية
1 الملفات التي تم فحصها · 1,534 الأسطر التي تم تحليلها
إصدار السياسة
غير متاح

أعلى مستوى خطورة لنتيجة مؤكدة

مرتفع

تتطلب 3 اكتشافات أمنية مؤكدة اهتمامًا.

سياق التثبيت

الأدلة التاريخية

قد لا يصف هذا التقرير العنصر القابل للتثبيت حاليًا. افتح صفحة المهارة الحالية للحصول على إرشادات التثبيت.

افتح صفحة Skill الحالية

لا يحظر هذا التقرير البيان أو ملف ZIP ولا يصرح بهما.

The skill is not confirmed malicious and no prompt injection was found, but it includes high-risk operational examples. The remote shell installation pattern and shell-executed deployment hooks are confirmed; many weak-crypto, dynamic-import, and reconnaissance hits are false positives from Markdown fences, provider names, timestamps, and ordinary code examples.

موضع التقرير

تقرير تاريخي

افتح سجل التدقيق قبل استخدام هذا التقرير للتثبيت.

إقرار التدقيق

غير قابل للتصديق

الربط الثابت المطلوب غير مكتمل.

التحقق البشري

لم يتم التحقق منه

لم يتم تسجيل أي تحقق بشري لهذا التقرير.

التغطية

1 الملفات التي تم فحصها · 1,534 الأسطر التي تم تحليلها

6 عناصر معروضة للمراجعة

القيود

لا يدّعي هذا التقرير تنفيذًا في وقت التشغيل أو ضمن بيئة معزولة، ولا يثبت عدم وجود آثار جانبية.

سلسلة الأدلة

اتبع الأدلة من ربط المصدر إلى عقد التثبيت. تدعم الأدلة المتاحة التحقق؛ لكنها ليست ضمانًا للسلامة.

  1. المصدر

    الربط غير متاح

  2. العنصر البرمجي

    الهوية غير مكتملة

  3. التدقيق

    مكتمل

  4. عقد التثبيت

    افتح البيان للتحقق

    افتح البيان

القدرات المرصودة

تعني «تمت ملاحظته» أن هذا التقرير سجل أدلة داعمة. ولا يثبت عدم التسجيل أن القدرة غير موجودة.

يحتوي على سكربتات

قد ينفذ تعليمات برمجية مضمنة مع المهارة.

تمت ملاحظته في موضع دليل واحد 1

الوصول إلى الشبكة

قد يتصل بخدمات خارجية.

تمت ملاحظته في 3 مواضع أدلة

الوصول إلى نظام الملفات

قد يقرأ أو يكتب ملفات محلية.

تمت ملاحظته في 2 مواضع أدلة

متغيرات البيئة

قد يقرأ قيماً من بيئة العملية.

لم يتم تسجيله بواسطة هذا التدقيق

الأوامر الخارجية

قد يستدعي أوامر أو برامج خارج المهارة.

تمت ملاحظته في 5 مواضع أدلة

عناصر مراجعة القدرات (3)
متوسط
Generated Pulumi Code Uses Config Values Directly
The Pulumi generator writes Python source by interpolating resource names, property names, and values. Untrusted configuration could create invalid or unintended Python code.
The generator concatenates config-derived values into Python source before writing __main__.py. The risk is strong when configuration is untrusted, but the skill does not show an external input source.
منخفض
Infrastructure Files Written To Working Directory
The Terraform generator writes main.tf, variables.tf, and outputs.tf into the selected working directory. This is expected for IaC generation but can overwrite existing files if used carelessly.
The file writes are explicit and expected for the skill domain. The main concern is overwrite behavior, not malicious intent.
منخفض
External Manifest Dependency
The Argo CD initialization example applies a Kubernetes manifest directly from a GitHub URL. This is a supply-chain dependency but not evidence of exfiltration or malware.
The URL points to the Argo CD project manifest and is used by kubectl apply. It is a legitimate pattern with supply-chain risk if the remote content changes.

نتائج المخاطر

يتم فصل المخاوف الأمنية المؤكدة عن العناصر التي لا تزال بحاجة إلى مراجعة.

مخاوف أمنية مؤكدة (3)

RISK-001 مرتفع
Remote Shell Installation Pattern
The Flux installation example builds a command containing a remote install script URL and pipes it to bash through shell execution. This pattern can execute changed remote content with the privileges of the current user.
The code explicitly combines a remote install script with a pipe to bash and then calls the command with shell=True. This is a confirmed dangerous pattern, although it appears instructional rather than malicious.
RISK-002 مرتفع
Deployment Hooks Executed Through Bash
Deployment hook values from application configuration are passed to a shell wrapper. If hook content comes from an untrusted repository or user, it can execute arbitrary commands.
The hook string is read from app.hooks and executed with shell=True, then converted to bash -c. The injection risk depends on who controls hook configuration, but the execution behavior is clear.
RISK-003 متوسط
Auto-Approved Infrastructure Changes
Terraform and Pulumi examples apply or destroy infrastructure with automatic approval flags. This can cause destructive changes without a required human confirmation gate.
The commands use -auto-approve or --yes for apply and destroy operations. This is a real operational risk, but it is common in controlled CI pipelines.

أدلة الخبراء

هوية موضوع غير قابلة للتغيير، وبيانات تعريف الماسح الضوئي، والمطابقات المستبعدة، والأدلة على مستوى المصدر.

موضوع العنصر البرمجي

التزام Marketplace
غير متاح
تجزئة المحتوى
غير متاح
تجزئة الشجرة
غير متاح
مسار Skill
غير متاح
تجزئة حمولة التدقيق
غير متاح

البيانات الوصفية للتحليل

نموذج التدقيق: codex

حالة التحليل: مكتمل

النطاق محدود بالملفات والأسطر والأساليب والأدلة المسجلة. لا يُدّعى تنفيذ وقت التشغيل أو بيئة الاختبار المعزولة.

تم تجاهل الإيجابيات الكاذبة الثابتة (1)
منخفض
Static Analyzer False Positives
The dynamic import, weak cryptography, and system reconnaissance alerts are not confirmed threats in context. The cited locations are Markdown fences, relative imports, provider source names, timestamps, default Kubernetes service URLs, or normal loop variables.
Targeted review found no weak cryptographic algorithm use, dynamic runtime import, or reconnaissance behavior at these representative locations. The matches are caused by benign text or ordinary example code.

التحقق والتصدير

يربط البيان وملف القفل عناصر التثبيت بتجزئات تشفيرية. هذا الادعاء المتعلق بالسلامة منفصل عن التقييم الأمني.

إقرار التدقيق: not_attestable