هذا التقرير غير مترجم إلى اللغة المطلوبة. يتم عرض التقرير الإنجليزي الأساسي بدلاً منه.

تقييم أمني مُحدَّث بالإصدار

معرّف التقرير: SA-2719F9B2

6/28/2026, 4:35:48 PM

managing-task-lifecycle تقييم أمني v6

تقرير شهادة أمان المهارة

سجل التدقيق
نموذج التدقيق: codex تقرير تاريخي
اسم المهارة
managing-task-lifecycle
الإصدار
v6
المشرف
BPSAI
التغطية
5 الملفات التي تم فحصها · 1,287 الأسطر التي تم تحليلها
إصدار السياسة
غير متاح

ملخص الاكتشاف المؤكد

لا توجد نتائج أمنية مؤكدة

لم يسجل التدقيق المكتمل أي نتائج أمنية مؤكدة. لا يُعد هذا دليلاً على أن المهارة ليس لها آثار جانبية.

سياق التثبيت

الأدلة التاريخية

قد لا يصف هذا التقرير العنصر القابل للتثبيت حاليًا. افتح صفحة المهارة الحالية للحصول على إرشادات التثبيت.

افتح صفحة Skill الحالية

لا يحظر هذا التقرير البيان أو ملف ZIP ولا يصرح بهما.

Static analysis produced many command, network, filesystem, and credential indicators, but most are Markdown command examples or environment variable documentation. The confirmed risk is legitimate workflow automation: the helper script runs fixed local commands, and the skill instructs agents to use PairCoder, Trello, GitHub, git, test, and lint commands. No prompt injection, obfuscation, credential exfiltration, or malicious intent was found.

موضع التقرير

تقرير تاريخي

افتح سجل التدقيق قبل استخدام هذا التقرير للتثبيت.

إقرار التدقيق

غير قابل للتصديق

الربط الثابت المطلوب غير مكتمل.

التحقق البشري

لم يتم التحقق منه

لم يتم تسجيل أي تحقق بشري لهذا التقرير.

التغطية

5 الملفات التي تم فحصها · 1,287 الأسطر التي تم تحليلها

4 عناصر معروضة للمراجعة

القيود

لا يدّعي هذا التقرير تنفيذًا في وقت التشغيل أو ضمن بيئة معزولة، ولا يثبت عدم وجود آثار جانبية.

سلسلة الأدلة

اتبع الأدلة من ربط المصدر إلى عقد التثبيت. تدعم الأدلة المتاحة التحقق؛ لكنها ليست ضمانًا للسلامة.

  1. المصدر

    الربط غير متاح

  2. العنصر البرمجي

    الهوية غير مكتملة

  3. التدقيق

    مكتمل

  4. عقد التثبيت

    افتح البيان للتحقق

    افتح البيان

القدرات المرصودة

تعني «تمت ملاحظته» أن هذا التقرير سجل أدلة داعمة. ولا يثبت عدم التسجيل أن القدرة غير موجودة.

يحتوي على سكربتات

قد ينفذ تعليمات برمجية مضمنة مع المهارة.

تمت ملاحظته في 2 مواضع أدلة

الوصول إلى الشبكة

قد يتصل بخدمات خارجية.

تمت ملاحظته في 3 مواضع أدلة

الوصول إلى نظام الملفات

قد يقرأ أو يكتب ملفات محلية.

تمت ملاحظته في 4 مواضع أدلة

متغيرات البيئة

قد يقرأ قيماً من بيئة العملية.

تمت ملاحظته في موضع دليل واحد 1

الأوامر الخارجية

قد يستدعي أوامر أو برامج خارج المهارة.

تمت ملاحظته في 6 مواضع أدلة

عناصر مراجعة القدرات (4)
متوسط
Helper Script Runs Local Project Commands
TRUE POSITIVE. The completion helper invokes subprocess.run for pytest, ruff, and git status. The commands are fixed, but tests and lint checks can execute project-controlled code.
Direct subprocess usage is present with hardcoded command arrays. Confidence is high for command execution, but lower for abuse because no shell string or user-controlled command is used.
متوسط
Lifecycle Commands Can Modify Task And Trello State
TRUE POSITIVE. The skill instructs agents to run PairCoder task and ttask commands that can update local task files, trigger hooks, and move Trello cards.
The documented behavior clearly changes workflow state and may call remote Trello services. It appears intended and transparent, not covert or malicious.
متوسط
Full CLI Reference Includes Broad Operational Commands
TRUE POSITIVE. The reference lists install, migration, webhook, git, GitHub, Trello, and MCP commands. These can affect files, repositories, or remote services if executed.
The commands are documentation examples rather than automatic execution. They still expand the operational scope agents may follow when using this skill.
منخفض
Environment Variable Names Are Credential Documentation
NEEDS REVIEW. The reference lists Trello, GitHub, and Toggl token variable names, but no code in this skill reads or exports them.
The credential names are real operational inputs for the PairCoder CLI, but this skill only documents them. Human review should confirm marketplace warnings cover token handling.

نتائج المخاطر

يتم فصل المخاوف الأمنية المؤكدة عن العناصر التي لا تزال بحاجة إلى مراجعة.

لم تُسجّل نتائج أمنية مؤكدة لهذا التدقيق المكتمل.

أدلة الخبراء

هوية موضوع غير قابلة للتغيير، وبيانات تعريف الماسح الضوئي، والمطابقات المستبعدة، والأدلة على مستوى المصدر.

موضوع العنصر البرمجي

التزام Marketplace
غير متاح
تجزئة المحتوى
غير متاح
تجزئة الشجرة
غير متاح
مسار Skill
غير متاح
تجزئة حمولة التدقيق
غير متاح

البيانات الوصفية للتحليل

نموذج التدقيق: codex

حالة التحليل: مكتمل

النطاق محدود بالملفات والأسطر والأساليب والأدلة المسجلة. لا يُدّعى تنفيذ وقت التشغيل أو بيئة الاختبار المعزولة.

تم تجاهل الإيجابيات الكاذبة الثابتة (3)
منخفض
Markdown Backticks Misclassified As Ruby Shell Execution
FALSE POSITIVE. Most external command alerts are inline Markdown code spans or fenced shell examples documenting PairCoder commands, not Ruby backtick execution.
The cited files are Markdown and the surrounding context is command documentation. No Ruby code or shell interpolation was found at these locations.
منخفض
Hardcoded URL Alerts Are Documentation Examples
FALSE POSITIVE. The URL findings are placeholder repository, pull request, or Trello links in documentation. No code sends data to these URLs.
The locations show example values used in reference tables or command snippets. I did not find code performing network requests to those URLs.
منخفض
Path Traversal And Weak Crypto Labels Are Documentation Artifacts
FALSE POSITIVE. The path traversal alert points to a Markdown relative link, and weak cryptography alerts point to words or extensions in documentation.
The cited contexts do not contain hashing or cryptographic operations. The relative path is a documentation link, not a file access operation.

التحقق والتصدير

يربط البيان وملف القفل عناصر التثبيت بتجزئات تشفيرية. هذا الادعاء المتعلق بالسلامة منفصل عن التقييم الأمني.

إقرار التدقيق: not_attestable