سجل التدقيق
codeconscious-identity - 8 عمليات التدقيق
مقارنة الإصدارات
التغييرات في القدرات والنتائج عبر الإصدارات المدقّقة، الأحدث أولاً.
| الإصدار | التاريخ | النتيجة | عناصر المراجعة | التغيير مقارنةً بالسابقة |
|---|---|---|---|---|
| v8 الأحدث | ٦ يوليو ٢٠٢٦، ١٢:٤٤ م | 3 مؤكَّد | 13 | لا تغيير في القدرات |
| v7 | ٦ يوليو ٢٠٢٦، ١٢:٤٤ م | 3 مؤكَّد | 13 | لا تغيير في القدرات |
| v6 | ٢٩ يونيو ٢٠٢٦، ٠٩:٤٣ م | لا توجد نتائج مؤكَّدة | 6 | لا تغيير في القدرات |
| v5 | ١٧ يناير ٢٠٢٦، ٠٤:٣٤ ص | لا توجد نتائج مؤكَّدة | 0 | لا تغيير في القدرات |
| v4 | ١٧ يناير ٢٠٢٦، ٠٤:٣٤ ص | لا توجد نتائج مؤكَّدة | 0 | الأوامر الخارجيةالوصول إلى الشبكةالوصول إلى نظام الملفات |
| v3 | ١٠ يناير ٢٠٢٦، ٠٢:٣٧ م | لا توجد نتائج مؤكَّدة | 0 | لا تغيير في القدرات |
| v2 | ١٠ يناير ٢٠٢٦، ٠٢:٣٧ م | لا توجد نتائج مؤكَّدة | 0 | لا تغيير في القدرات |
| v1 | ١٠ يناير ٢٠٢٦، ٠٢:٣٧ م | لا توجد نتائج مؤكَّدة | 0 | الأساس |
٦ يوليو ٢٠٢٦، ١٢:٤٤ م
Most high-entropy and backtick findings are false positives caused by Markdown, Chinese text, and code-formatted paths. I confirmed risks around parent-directory memory commands, predictable /tmp files, and a documented subprocess.run(shell=True) executor. I also found semantic risks from persona override wording and persistent memory collection.
مخاوف أمنية مؤكدة (3)
عناصر مراجعة القدرات (13)
هذه قدرات محلية حقيقية قد يُتوقع وجودها لهذه المهارة، لذا فهي تتطلب مراجعة ولكن لا تُحتسب كسلوك خبيث مؤكد.
عوامل الخطر
📁 الوصول إلى نظام الملفات (14)
⚙️ الأوامر الخارجية (38)
🌐 الوصول إلى الشبكة (2)
٦ يوليو ٢٠٢٦، ١٢:٤٤ م
Most high-entropy and backtick findings are false positives caused by Markdown, Chinese text, and code-formatted paths. I confirmed risks around parent-directory memory commands, predictable /tmp files, and a documented subprocess.run(shell=True) executor. I also found semantic risks from persona override wording and persistent memory collection.
مخاوف أمنية مؤكدة (3)
عناصر مراجعة القدرات (13)
هذه قدرات محلية حقيقية قد يُتوقع وجودها لهذه المهارة، لذا فهي تتطلب مراجعة ولكن لا تُحتسب كسلوك خبيث مؤكد.
عوامل الخطر
📁 الوصول إلى نظام الملفات (14)
⚙️ الأوامر الخارجية (38)
🌐 الوصول إلى الشبكة (2)
٢٩ يونيو ٢٠٢٦، ٠٩:٤٣ م
AI review confirmed that most static command detections are Markdown command examples or inline command names, not hidden executable payloads. The skill still contains high-risk guidance: a copied task executor runs task-provided shell commands with shell=True and writes user-provided paths, while the docs encourage broad filesystem exploration and adjacent memory access. No prompt injection attempt or credential exfiltration was found, so this is high risk but not a confirmed malicious block.
عناصر مراجعة القدرات (6)
هذه قدرات محلية حقيقية قد يُتوقع وجودها لهذه المهارة، لذا فهي تتطلب مراجعة ولكن لا تُحتسب كسلوك خبيث مؤكد.
تم تجاهل الإيجابيات الكاذبة الثابتة (2)
تم تجاهل هذه المطابقات الثابتة بواسطة المراجعة الدلالية أو لأنها طابقت رموزًا خاصة بالمخطط فقط، لذا تُعرض للشفافية لكنها لا تؤثر في درجة الجودة.
عوامل الخطر
⚙️ الأوامر الخارجية (5)
📁 الوصول إلى نظام الملفات (5)
🌐 الوصول إلى الشبكة (3)
الأنماط المكتشفة
١٧ يناير ٢٠٢٦، ٠٤:٣٤ ص
Pure documentation skill containing only markdown files defining AI command behaviors. All 651 static findings are FALSE POSITIVES because: (1) files are markdown documentation, not executable code; (2) bash command examples in docs are not vulnerabilities; (3) SHA-256 hash fields are secure, not weak algorithms; (4) path examples in docs are not path traversal; (5) documentation links are legitimate. No actual code execution, network calls, filesystem access, or credential handling exists.
عوامل الخطر
⚙️ الأوامر الخارجية (553)
🌐 الوصول إلى الشبكة (3)
١٧ يناير ٢٠٢٦، ٠٤:٣٤ ص
Pure documentation skill containing only markdown files defining AI command behaviors. All 651 static findings are FALSE POSITIVES because: (1) files are markdown documentation, not executable code; (2) bash command examples in docs are not vulnerabilities; (3) SHA-256 hash fields are secure, not weak algorithms; (4) path examples in docs are not path traversal; (5) documentation links are legitimate. No actual code execution, network calls, filesystem access, or credential handling exists.
عوامل الخطر
⚙️ الأوامر الخارجية (553)
🌐 الوصول إلى الشبكة (3)
١٠ يناير ٢٠٢٦، ٠٢:٣٧ م
Pure documentation skill containing only markdown files that define AI command behaviors. No executable code, network calls, filesystem access, or external command execution. All files are declarative documentation describing system identity and command specifications.
١٠ يناير ٢٠٢٦، ٠٢:٣٧ م
Pure documentation skill containing only markdown files that define AI command behaviors. No executable code, network calls, filesystem access, or external command execution. All files are declarative documentation describing system identity and command specifications.
١٠ يناير ٢٠٢٦، ٠٢:٣٧ م
Pure documentation skill containing only markdown files that define AI command behaviors. No executable code, network calls, filesystem access, or external command execution. All files are declarative documentation describing system identity and command specifications.