هذا التقرير غير مترجم إلى اللغة المطلوبة. يتم عرض التقرير الإنجليزي الأساسي بدلاً منه.

تقييم أمني مُحدَّث بالإصدار

معرّف التقرير: SA-45D27453

6/29/2026, 11:48:54 PM

ghe-changelog تقييم أمني v6

تقرير شهادة أمان المهارة

سجل التدقيق
نموذج التدقيق: codex تقرير تاريخي
اسم المهارة
ghe-changelog
الإصدار
v6
المشرف
Emasoft
التغطية
1 الملفات التي تم فحصها · 352 الأسطر التي تم تحليلها
إصدار السياسة
غير متاح

أعلى مستوى خطورة لنتيجة مؤكدة

حرج

تتطلب 4 اكتشافات أمنية مؤكدة اهتمامًا.

سياق التثبيت

الأدلة التاريخية

قد لا يصف هذا التقرير العنصر القابل للتثبيت حاليًا. افتح صفحة المهارة الحالية للحصول على إرشادات التثبيت.

افتح صفحة Skill الحالية

لا يحظر هذا التقرير البيان أو ملف ZIP ولا يصرح بهما.

Static external-command findings are mostly legitimate shell examples for changelog automation, but they still execute git, sed, gh, and file mutation commands if followed. The static weak-cryptography matches appear to be false positives from changelog and markdown text. Publication should be blocked because the skill includes prompt-injection style instructions that demand verbatim obedience to user specifications with no exceptions.

موضع التقرير

تقرير تاريخي

افتح سجل التدقيق قبل استخدام هذا التقرير للتثبيت.

إقرار التدقيق

غير قابل للتصديق

الربط الثابت المطلوب غير مكتمل.

التحقق البشري

لم يتم التحقق منه

لم يتم تسجيل أي تحقق بشري لهذا التقرير.

التغطية

1 الملفات التي تم فحصها · 352 الأسطر التي تم تحليلها

4 عناصر معروضة للمراجعة

القيود

لا يدّعي هذا التقرير تنفيذًا في وقت التشغيل أو ضمن بيئة معزولة، ولا يثبت عدم وجود آثار جانبية.

سلسلة الأدلة

اتبع الأدلة من ربط المصدر إلى عقد التثبيت. تدعم الأدلة المتاحة التحقق؛ لكنها ليست ضمانًا للسلامة.

  1. المصدر

    الربط غير متاح

  2. العنصر البرمجي

    الهوية غير مكتملة

  3. التدقيق

    مكتمل

  4. عقد التثبيت

    افتح البيان للتحقق

    افتح البيان

القدرات المرصودة

تعني «تمت ملاحظته» أن هذا التقرير سجل أدلة داعمة. ولا يثبت عدم التسجيل أن القدرة غير موجودة.

يحتوي على سكربتات

قد ينفذ تعليمات برمجية مضمنة مع المهارة.

لم يتم تسجيله بواسطة هذا التدقيق

الوصول إلى الشبكة

قد يتصل بخدمات خارجية.

لم يتم تسجيله بواسطة هذا التدقيق

الوصول إلى نظام الملفات

قد يقرأ أو يكتب ملفات محلية.

تمت ملاحظته في 3 مواضع أدلة

متغيرات البيئة

قد يقرأ قيماً من بيئة العملية.

لم يتم تسجيله بواسطة هذا التدقيق

الأوامر الخارجية

قد يستدعي أوامر أو برامج خارج المهارة.

تمت ملاحظته في 7 مواضع أدلة

نتائج المخاطر

يتم فصل المخاوف الأمنية المؤكدة عن العناصر التي لا تزال بحاجة إلى مراجعة.

مخاوف أمنية مؤكدة (4)

RISK-001 حرج
Prompt Injection Attempt Detected
The skill tells the agent that user specifications are absolute, must be followed verbatim, and admit no exceptions. This can override higher-priority safety and marketplace review instructions when the skill is loaded.
The text explicitly creates an absolute instruction hierarchy around user requests. That semantic context confirms a prompt-injection risk rather than a benign changelog instruction.
RISK-002 مرتفع
Permission to Modify Assistant Configuration
The skill permits writes to ~/.claude for plugin and settings fixes. A marketplace skill should not broadly authorize changes to hidden assistant configuration because that can create persistence or alter future agent behavior.
The hidden home-directory path is explicit and the stated purpose is settings modification. No malicious payload is shown, but the capability is sensitive.
RISK-003 متوسط
Shell-Based Changelog Automation Examples
The skill includes shell snippets that run git, grep, sed, cp, and date commands, then modify CHANGELOG.md. These commands match the skill purpose, but they can overwrite files or process untrusted repository content if copied and executed without review.
The command execution and file mutation are directly visible, but they are presented as changelog tooling. The risk is operational misuse rather than confirmed malicious behavior.
RISK-004 متوسط
External GitHub CLI Data Used in Changelog Output
The skill fetches an issue title with gh and appends it to CHANGELOG.md. Issue titles are external content and could inject misleading markdown into release notes if not reviewed.
The gh command and append operations are explicit. The risk depends on repository issue permissions and review practices, so confidence is high but not absolute.

أدلة الخبراء

هوية موضوع غير قابلة للتغيير، وبيانات تعريف الماسح الضوئي، والمطابقات المستبعدة، والأدلة على مستوى المصدر.

موضوع العنصر البرمجي

التزام Marketplace
غير متاح
تجزئة المحتوى
غير متاح
تجزئة الشجرة
غير متاح
مسار Skill
غير متاح
تجزئة حمولة التدقيق
غير متاح

البيانات الوصفية للتحليل

نموذج التدقيق: codex

حالة التحليل: مكتمل

النطاق محدود بالملفات والأسطر والأساليب والأدلة المسجلة. لا يُدّعى تنفيذ وقت التشغيل أو بيئة الاختبار المعزولة.

تم تجاهل الإيجابيات الكاذبة الثابتة (2)
منخفض
Static Weak-Cryptography Alerts Are False Positives
The weak-cryptography alerts do not correspond to hashing, encryption, or credential handling logic in the reviewed skill. They appear to match ordinary changelog, markdown, and git-related text.
No cryptographic API, weak digest use, or security-sensitive hashing operation appears at the cited locations. The cited lines are descriptive text or configuration examples.
منخفض
Device-File Alerts Are Benign Stderr Redirections
The scanner flagged standard device-file access, but the cited examples use stderr redirection to suppress command errors. This is common shell behavior, though it can hide useful diagnostics.
The cited patterns are 2>/dev/null redirections in shell examples, not reads or writes to sensitive device files. The only concern is reduced visibility into failures.

التحقق والتصدير

يربط البيان وملف القفل عناصر التثبيت بتجزئات تشفيرية. هذا الادعاء المتعلق بالسلامة منفصل عن التقييم الأمني.

إقرار التدقيق: not_attestable