سجل التدقيق
chronicle-assistant-guide - 8 عمليات التدقيق
مقارنة الإصدارات
التغييرات في القدرات والنتائج عبر الإصدارات المدقّقة، الأحدث أولاً.
| الإصدار | التاريخ | النتيجة | عناصر المراجعة | التغيير مقارنةً بالسابقة |
|---|---|---|---|---|
| v8 الأحدث | ٥ يوليو ٢٠٢٦، ٠٧:٠٢ ص | 1 مؤكَّد | 0 | لا تغيير في القدرات |
| v7 | ٥ يوليو ٢٠٢٦، ٠٧:٠٢ ص | 1 مؤكَّد | 0 | لا تغيير في القدرات |
| v6 | ٢٨ يونيو ٢٠٢٦، ١٠:١٧ م | 2 مؤكَّد | 0 | لا تغيير في القدرات |
| v5 | ١٦ يناير ٢٠٢٦، ٠٩:٢٨ م | لا توجد نتائج مؤكَّدة | 0 | لا تغيير في القدرات |
| v4 | ١٦ يناير ٢٠٢٦، ٠٩:٢٨ م | لا توجد نتائج مؤكَّدة | 0 | الوصول إلى نظام الملفاتالأوامر الخارجية |
| v3 | ١٠ يناير ٢٠٢٦، ١٢:٠٥ م | لا توجد نتائج مؤكَّدة | 0 | لا تغيير في القدرات |
| v2 | ١٠ يناير ٢٠٢٦، ١٢:٠٥ م | لا توجد نتائج مؤكَّدة | 0 | لا تغيير في القدرات |
| v1 | ١٠ يناير ٢٠٢٦، ١٢:٠٥ م | لا توجد نتائج مؤكَّدة | 0 | الأساس |
٥ يوليو ٢٠٢٦، ٠٧:٠٢ ص
The static command findings are false positives from Markdown inline code, code fences, and Chronicle CLI examples. The hidden-file and SQLite findings are documentation of Chronicle storage paths, not direct file access. A semantic privacy issue remains because the guide encourages broad Chronicle searches across all projects without requiring scoping or consent.
مخاوف أمنية مؤكدة (1)
عوامل الخطر
⚙️ الأوامر الخارجية (55)
📁 الوصول إلى نظام الملفات (6)
٥ يوليو ٢٠٢٦، ٠٧:٠٢ ص
The static command findings are false positives from Markdown inline code, code fences, and Chronicle CLI examples. The hidden-file and SQLite findings are documentation of Chronicle storage paths, not direct file access. A semantic privacy issue remains because the guide encourages broad Chronicle searches across all projects without requiring scoping or consent.
مخاوف أمنية مؤكدة (1)
عوامل الخطر
⚙️ الأوامر الخارجية (55)
📁 الوصول إلى نظام الملفات (6)
٢٨ يونيو ٢٠٢٦، ١٠:١٧ م
Static analysis flagged many Ruby backtick, sensitive file, and blocker patterns, but the reviewed file is Markdown guidance and examples. No malicious execution, prompt injection, network exfiltration, or credential theft was found. The remaining risk is that the guide encourages broad Chronicle history searches and local CLI use, which may expose local assistant history if not scoped.
مخاوف أمنية مؤكدة (2)
تم تجاهل الإيجابيات الكاذبة الثابتة (3)
تم تجاهل هذه المطابقات الثابتة بواسطة المراجعة الدلالية أو لأنها طابقت رموزًا خاصة بالمخطط فقط، لذا تُعرض للشفافية لكنها لا تؤثر في درجة الجودة.
عوامل الخطر
⚙️ الأوامر الخارجية (12)
📁 الوصول إلى نظام الملفات (3)
١٦ يناير ٢٠٢٦، ٠٩:٢٨ م
Pure documentation skill containing only markdown guidance. No executable code, file access, network calls, or command execution capabilities. All 90 static findings are false positives triggered by pattern-matching on documentation text.
عوامل الخطر
📁 الوصول إلى نظام الملفات (6)
⚙️ الأوامر الخارجية (56)
١٦ يناير ٢٠٢٦، ٠٩:٢٨ م
Pure documentation skill containing only markdown guidance. No executable code, file access, network calls, or command execution capabilities. All 90 static findings are false positives triggered by pattern-matching on documentation text.
عوامل الخطر
📁 الوصول إلى نظام الملفات (6)
⚙️ الأوامر الخارجية (56)
١٠ يناير ٢٠٢٦، ١٢:٠٥ م
Pure documentation skill with no executable code. Contains only markdown guidance for using Chronicle session tracking. No file access, network calls, or command execution capabilities.
١٠ يناير ٢٠٢٦، ١٢:٠٥ م
Pure documentation skill with no executable code. Contains only markdown guidance for using Chronicle session tracking. No file access, network calls, or command execution capabilities.
١٠ يناير ٢٠٢٦، ١٢:٠٥ م
Pure documentation skill with no executable code. Contains only markdown guidance for using Chronicle session tracking. No file access, network calls, or command execution capabilities.