سجل التدقيق
agy-worker - 8 عمليات التدقيق
مقارنة الإصدارات
التغييرات في القدرات والنتائج عبر الإصدارات المدقّقة، الأحدث أولاً.
| الإصدار | التاريخ | النتيجة | عناصر المراجعة | التغيير مقارنةً بالسابقة |
|---|---|---|---|---|
| v8 الأحدث | ٢٠ سبتمبر ٢٠٢٦، ٠٩:٠٨ م | 7 مؤكَّد | 50 | لا تغيير في القدرات |
| v7 | ١٩ سبتمبر ٢٠٢٦، ١٠:٤٧ ص | 3 مؤكَّد | 12 | لا تغيير في القدرات |
| v6 | ١٢ سبتمبر ٢٠٢٦، ٠٦:٢٦ م | لا توجد نتائج مؤكَّدة | 12 | لا تغيير في القدرات |
| v5 | ٦ سبتمبر ٢٠٢٦، ١٢:١١ م | 1 مؤكَّد | 4 | لا تغيير في القدرات |
| v4 | ٣١ أغسطس ٢٠٢٦، ١١:٢٤ ص | 1 مؤكَّد | 4 | لا تغيير في القدرات |
| v3 | ٣١ أغسطس ٢٠٢٦، ١١:٢٤ ص | 1 مؤكَّد | 4 | لا تغيير في القدرات |
| v2 | ٢٩ أغسطس ٢٠٢٦، ٠٧:٣٨ م | 1 مؤكَّد | 0 | لا تغيير في القدرات |
| v1 | ٢٩ أغسطس ٢٠٢٦، ١٠:٢٥ ص | 4 مؤكَّد | 4 | الأساس |
٢٠ سبتمبر ٢٠٢٦، ٠٩:٠٨ م
Most static matches are benign implementation, validation, documentation, schema, or control-character checks. Confirmed risks include provider and verifier execution, environment inheritance, keychain handling, settings access, and non-sandboxed provider authority. Static review was capped at 400/991 representative findings; omitted static matches are unconfirmed, so automatic publishing stays disabled until manual review.
مخاوف أمنية مؤكدة (7)
عناصر مراجعة القدرات (50)
هذه قدرات محلية حقيقية قد يُتوقع وجودها لهذه المهارة، لذا فهي تتطلب مراجعة ولكن لا تُحتسب كسلوك خبيث مؤكد.
عوامل الخطر
⚙️ الأوامر الخارجية (50)
🌐 الوصول إلى الشبكة (43)
📁 الوصول إلى نظام الملفات (50)
⚡ يحتوي على سكربتات (22)
🔑 متغيرات البيئة (15)
١٩ سبتمبر ٢٠٢٦، ١٠:٤٧ ص
The review confirmed intentional high-impact capabilities: external provider execution, repository-content transmission, verifier command execution, and limited private configuration access. Most static matches are false positives from defensive validation, documentation, compact schemas, or fixed local commands. Default session mode lacks host containment, and 589 lower-priority static matches remain outside the supplied adjudication set. Static review was capped at 400/989 representative findings; omitted static matches are unconfirmed, so automatic publishing stays disabled until manual review.
مخاوف أمنية مؤكدة (3)
عناصر مراجعة القدرات (12)
هذه قدرات محلية حقيقية قد يُتوقع وجودها لهذه المهارة، لذا فهي تتطلب مراجعة ولكن لا تُحتسب كسلوك خبيث مؤكد.
عوامل الخطر
⚙️ الأوامر الخارجية (50)
🌐 الوصول إلى الشبكة (43)
📁 الوصول إلى نظام الملفات (50)
⚡ يحتوي على سكربتات (22)
🔑 متغيرات البيئة (15)
١٢ سبتمبر ٢٠٢٦، ٠٦:٢٦ م
Most reviewed matches are false positives from documentation, schemas, validation literals, fixed Git commands, and type annotations. Confirmed risks are provider execution, approved verifier execution, legacy shell verification, selected environment forwarding, and opt-in access to Antigravity user settings. No prompt injection or exfiltration intent was found, but 565 capped static matches still require manual review before automatic publication. Static review was capped at 400/965 representative findings; omitted static matches are unconfirmed, so automatic publishing stays disabled until manual review.
عناصر مراجعة القدرات (12)
هذه قدرات محلية حقيقية قد يُتوقع وجودها لهذه المهارة، لذا فهي تتطلب مراجعة ولكن لا تُحتسب كسلوك خبيث مؤكد.
عوامل الخطر
⚙️ الأوامر الخارجية (50)
📁 الوصول إلى نظام الملفات (50)
⚡ يحتوي على سكربتات (22)
🌐 الوصول إلى الشبكة (38)
🔑 متغيرات البيئة (15)
٦ سبتمبر ٢٠٢٦، ١٢:١١ م
All 400 presented static findings were adjudicated individually. Most matches are benign validation, documentation, schema, or bounded orchestration patterns, but account configuration access and legacy shell verification are confirmed risks. The skill also explicitly allows provider execution with normal filesystem and network authority in session mode, so operators must treat it as a delegation tool rather than a sandbox. Static review was capped at 400/962 representative findings; omitted static matches are unconfirmed, so automatic publishing stays disabled until manual review.
مخاوف أمنية مؤكدة (1)
عناصر مراجعة القدرات (4)
هذه قدرات محلية حقيقية قد يُتوقع وجودها لهذه المهارة، لذا فهي تتطلب مراجعة ولكن لا تُحتسب كسلوك خبيث مؤكد.
عوامل الخطر
⚙️ الأوامر الخارجية (50)
📁 الوصول إلى نظام الملفات (50)
⚡ يحتوي على سكربتات (22)
🌐 الوصول إلى الشبكة (37)
🔑 متغيرات البيئة (15)
٣١ أغسطس ٢٠٢٦، ١١:٢٤ ص
Of 400 static findings, 396 are lexical false positives from schema punctuation, defensive validation, documentation, or bounded local tooling. Confirmed risks are the external AGY launch, caller-selected verifier execution, and two legacy shell-verification paths. Default provider dispatch also creates a documented high-impact repository disclosure risk unless operators use a narrow approved scope. Static review was capped at 400/889 representative findings; omitted static matches are unconfirmed, so automatic publishing stays disabled until manual review.
مخاوف أمنية مؤكدة (1)
عناصر مراجعة القدرات (4)
هذه قدرات محلية حقيقية قد يُتوقع وجودها لهذه المهارة، لذا فهي تتطلب مراجعة ولكن لا تُحتسب كسلوك خبيث مؤكد.
عوامل الخطر
⚙️ الأوامر الخارجية (50)
📁 الوصول إلى نظام الملفات (50)
⚡ يحتوي على سكربتات (20)
🌐 الوصول إلى الشبكة (47)
🔑 متغيرات البيئة (14)
٣١ أغسطس ٢٠٢٦، ١١:٢٤ ص
Of 400 static findings, 396 are lexical false positives from schema punctuation, defensive validation, documentation, or bounded local tooling. Confirmed risks are the external AGY launch, caller-selected verifier execution, and two legacy shell-verification paths. Default provider dispatch also creates a documented high-impact repository disclosure risk unless operators use a narrow approved scope. Static review was capped at 400/889 representative findings; omitted static matches are unconfirmed, so automatic publishing stays disabled until manual review.
مخاوف أمنية مؤكدة (1)
عناصر مراجعة القدرات (4)
هذه قدرات محلية حقيقية قد يُتوقع وجودها لهذه المهارة، لذا فهي تتطلب مراجعة ولكن لا تُحتسب كسلوك خبيث مؤكد.
عوامل الخطر
⚙️ الأوامر الخارجية (50)
📁 الوصول إلى نظام الملفات (50)
⚡ يحتوي على سكربتات (20)
🌐 الوصول إلى الشبكة (47)
🔑 متغيرات البيئة (14)
٢٩ أغسطس ٢٠٢٦، ٠٧:٣٨ م
The 400 presented static matches are false positives caused by documentation syntax, compact JSON, defensive validation, and declared repository orchestration. One medium confidentiality risk remains: approved repository content is transmitted to the external agy provider, and 366 capped static matches still require manual review before automatic publication. Static review was capped at 400/766 representative findings; omitted static matches are unconfirmed, so automatic publishing stays disabled until manual review.
مخاوف أمنية مؤكدة (1)
عوامل الخطر
⚡ يحتوي على سكربتات (18)
⚙️ الأوامر الخارجية (50)
📁 الوصول إلى نظام الملفات (50)
🌐 الوصول إلى الشبكة (33)
٢٩ أغسطس ٢٠٢٦، ١٠:٢٥ ص
Most static matches are false positives caused by Markdown formatting, minified JSON Schemas, defensive control-character checks, and fixed argv subprocesses. Confirmed risks include external AGY dispatch, unrestricted driver-supplied Bash verification, and inherited environment exposure. The skill also embeds system-style persona prompts and intentionally transmits approved repository content to Google or Gemini services. Static review was capped at 400/724 representative findings; omitted static matches are unconfirmed, so automatic publishing stays disabled until manual review.
مخاوف أمنية مؤكدة (4)
عناصر مراجعة القدرات (4)
هذه قدرات محلية حقيقية قد يُتوقع وجودها لهذه المهارة، لذا فهي تتطلب مراجعة ولكن لا تُحتسب كسلوك خبيث مؤكد.