هذا التقرير غير مترجم إلى اللغة المطلوبة. يتم عرض التقرير الإنجليزي الأساسي بدلاً منه.

تقييم أمني مُحدَّث بالإصدار

معرّف التقرير: SA-0DDFEFD1

6/28/2026, 10:17:49 PM

chronicle-assistant-guide تقييم أمني v6

تقرير شهادة أمان المهارة

سجل التدقيق
نموذج التدقيق: codex تقرير تاريخي
اسم المهارة
chronicle-assistant-guide
الإصدار
v6
المشرف
ChandlerHardy
التغطية
1 الملفات التي تم فحصها · 391 الأسطر التي تم تحليلها
إصدار السياسة
غير متاح

أعلى مستوى خطورة لنتيجة مؤكدة

متوسط

تتطلب 2 اكتشافات أمنية مؤكدة اهتمامًا.

سياق التثبيت

الأدلة التاريخية

قد لا يصف هذا التقرير العنصر القابل للتثبيت حاليًا. افتح صفحة المهارة الحالية للحصول على إرشادات التثبيت.

افتح صفحة Skill الحالية

لا يحظر هذا التقرير البيان أو ملف ZIP ولا يصرح بهما.

Static analysis flagged many Ruby backtick, sensitive file, and blocker patterns, but the reviewed file is Markdown guidance and examples. No malicious execution, prompt injection, network exfiltration, or credential theft was found. The remaining risk is that the guide encourages broad Chronicle history searches and local CLI use, which may expose local assistant history if not scoped.

موضع التقرير

تقرير تاريخي

افتح سجل التدقيق قبل استخدام هذا التقرير للتثبيت.

إقرار التدقيق

غير قابل للتصديق

الربط الثابت المطلوب غير مكتمل.

التحقق البشري

لم يتم التحقق منه

لم يتم تسجيل أي تحقق بشري لهذا التقرير.

التغطية

1 الملفات التي تم فحصها · 391 الأسطر التي تم تحليلها

2 عناصر معروضة للمراجعة

القيود

لا يدّعي هذا التقرير تنفيذًا في وقت التشغيل أو ضمن بيئة معزولة، ولا يثبت عدم وجود آثار جانبية.

سلسلة الأدلة

اتبع الأدلة من ربط المصدر إلى عقد التثبيت. تدعم الأدلة المتاحة التحقق؛ لكنها ليست ضمانًا للسلامة.

  1. المصدر

    الربط غير متاح

  2. العنصر البرمجي

    الهوية غير مكتملة

  3. التدقيق

    مكتمل

  4. عقد التثبيت

    افتح البيان للتحقق

    افتح البيان

القدرات المرصودة

تعني «تمت ملاحظته» أن هذا التقرير سجل أدلة داعمة. ولا يثبت عدم التسجيل أن القدرة غير موجودة.

يحتوي على سكربتات

قد ينفذ تعليمات برمجية مضمنة مع المهارة.

لم يتم تسجيله بواسطة هذا التدقيق

الوصول إلى الشبكة

قد يتصل بخدمات خارجية.

لم يتم تسجيله بواسطة هذا التدقيق

الوصول إلى نظام الملفات

قد يقرأ أو يكتب ملفات محلية.

تمت ملاحظته في 3 مواضع أدلة

متغيرات البيئة

قد يقرأ قيماً من بيئة العملية.

لم يتم تسجيله بواسطة هذا التدقيق

الأوامر الخارجية

قد يستدعي أوامر أو برامج خارج المهارة.

تمت ملاحظته في 12 مواضع أدلة

نتائج المخاطر

يتم فصل المخاوف الأمنية المؤكدة عن العناصر التي لا تزال بحاجة إلى مراجعة.

مخاوف أمنية مؤكدة (2)

RISK-001 متوسط
Broad Chronicle History Search May Expose Local Context
The guide tells assistants to search Chronicle before work and applies across all projects. This is useful, but searches may reveal prior sessions, summaries, or project history if users do not scope queries.
The file explicitly directs assistants to search Chronicle history and documents the local session database and transcript locations. The behavior is legitimate, but the privacy exposure is clear.
RISK-002 متوسط
Assistant-Directed Local CLI Commands
The skill includes many Chronicle CLI examples. The commands appear benign and related to the advertised purpose, but users should only run them in trusted environments.
The CLI commands are directly present and intended to be run by an assistant. They are Chronicle-specific examples, so the risk is operational rather than malicious.

أدلة الخبراء

هوية موضوع غير قابلة للتغيير، وبيانات تعريف الماسح الضوئي، والمطابقات المستبعدة، والأدلة على مستوى المصدر.

موضوع العنصر البرمجي

التزام Marketplace
غير متاح
تجزئة المحتوى
غير متاح
تجزئة الشجرة
غير متاح
مسار Skill
غير متاح
تجزئة حمولة التدقيق
غير متاح

البيانات الوصفية للتحليل

نموذج التدقيق: codex

حالة التحليل: مكتمل

النطاق محدود بالملفات والأسطر والأساليب والأدلة المسجلة. لا يُدّعى تنفيذ وقت التشغيل أو بيئة الاختبار المعزولة.

تم تجاهل الإيجابيات الكاذبة الثابتة (3)
منخفض
Markdown Backticks Misclassified as Ruby Execution
The static Ruby backtick findings are Markdown code spans and fenced examples. No Ruby code or command substitution syntax is present in the skill file.
The reviewed context shows Markdown examples, not executable Ruby. The file is a single SKILL.md document with no script file or runtime wrapper.
منخفض
Home Directory Paths Are Documentation
The hidden home directory paths describe Chronicle storage locations. They do not instruct the assistant to read or copy those files directly.
The paths appear under a current state reference section. There is no command that reads the database, transcripts, or configuration file directly.
منخفض
Sensitive and Blocker Patterns Are Textual False Positives
The Windows SAM, weak cryptography, and reconnaissance alerts are caused by ordinary prose or tool names. No evidence of credential theft, cryptographic misuse, or host reconnaissance was found.
The cited lines are descriptive text such as the skill description, an example saying SAME issue, a mistakes heading, and an MCP server note. No malicious semantic context is present.

التحقق والتصدير

يربط البيان وملف القفل عناصر التثبيت بتجزئات تشفيرية. هذا الادعاء المتعلق بالسلامة منفصل عن التقييم الأمني.

إقرار التدقيق: not_attestable