سجل التدقيق
home-assistant-manager - 9 عمليات التدقيق
مقارنة الإصدارات
التغييرات في القدرات والنتائج عبر الإصدارات المدقّقة، الأحدث أولاً.
| الإصدار | التاريخ | النتيجة | عناصر المراجعة | التغيير مقارنةً بالسابقة |
|---|---|---|---|---|
| v9 الأحدث | ٩ يوليو ٢٠٢٦، ٠٤:٣١ م | 2 مؤكَّد | 33 | لا تغيير في القدرات |
| v8 | ٩ يوليو ٢٠٢٦، ٠٤:٣١ م | 2 مؤكَّد | 33 | لا تغيير في القدرات |
| v7 | ٥ يوليو ٢٠٢٦، ٠٦:١٢ م | 2 مؤكَّد | 33 | لا تغيير في القدرات |
| v6 | ٣٠ يونيو ٢٠٢٦، ٠٥:٥٠ ص | لا توجد نتائج مؤكَّدة | 4 | لا تغيير في القدرات |
| v5 | ١٧ يناير ٢٠٢٦، ٠٨:٠٦ ص | لا توجد نتائج مؤكَّدة | 0 | لا تغيير في القدرات |
| v4 | ١٧ يناير ٢٠٢٦، ٠٨:٠٦ ص | لا توجد نتائج مؤكَّدة | 0 | الوصول إلى الشبكةالوصول إلى نظام الملفاتمتغيرات البيئةالأوامر الخارجية |
| v3 | ٨ يناير ٢٠٢٦، ٠٢:٤٧ ص | لا توجد نتائج مؤكَّدة | 0 | لا تغيير في القدرات |
| v2 | ٨ يناير ٢٠٢٦، ٠٢:٤٧ ص | لا توجد نتائج مؤكَّدة | 0 | لا تغيير في القدرات |
| v1 | ٨ يناير ٢٠٢٦، ٠٢:٤٧ ص | لا توجد نتائج مؤكَّدة | 0 | الأساس |
٩ يوليو ٢٠٢٦، ٠٤:٣١ م
The skill is not malicious, but it intentionally guides privileged Home Assistant operations through SSH, hass-cli, git, and scp. Confirmed risks center on remote command execution, writing Home Assistant .storage files, persistent token setup, and commands that can affect real devices; many scanner hits were Markdown, template, or screenshot false positives. No prompt injection attempt was found in the reviewed files.
مخاوف أمنية مؤكدة (2)
عناصر مراجعة القدرات (33)
هذه قدرات محلية حقيقية قد يُتوقع وجودها لهذه المهارة، لذا فهي تتطلب مراجعة ولكن لا تُحتسب كسلوك خبيث مؤكد.
عوامل الخطر
🌐 الوصول إلى الشبكة (3)
📁 الوصول إلى نظام الملفات (8)
🔑 متغيرات البيئة (1)
⚙️ الأوامر الخارجية (88)
٩ يوليو ٢٠٢٦، ٠٤:٣١ م
The skill is not malicious, but it intentionally guides privileged Home Assistant operations through SSH, hass-cli, git, and scp. Confirmed risks center on remote command execution, writing Home Assistant .storage files, persistent token setup, and commands that can affect real devices; many scanner hits were Markdown, template, or screenshot false positives. No prompt injection attempt was found in the reviewed files.
مخاوف أمنية مؤكدة (2)
عناصر مراجعة القدرات (33)
هذه قدرات محلية حقيقية قد يُتوقع وجودها لهذه المهارة، لذا فهي تتطلب مراجعة ولكن لا تُحتسب كسلوك خبيث مؤكد.
عوامل الخطر
🌐 الوصول إلى الشبكة (3)
📁 الوصول إلى نظام الملفات (8)
🔑 متغيرات البيئة (1)
⚙️ الأوامر الخارجية (88)
٥ يوليو ٢٠٢٦، ٠٦:١٢ م
The package is a Markdown skill with a supporting dashboard image and no prompt injection text found in the reviewed files. Many static matches are Markdown formatting or documentation placeholders, but the skill intentionally guides agents through SSH, scp, git, hass-cli, and Home Assistant restart workflows. This should require explicit command review, scoped credentials, and careful handling of Home Assistant storage files.
مخاوف أمنية مؤكدة (2)
عناصر مراجعة القدرات (33)
هذه قدرات محلية حقيقية قد يُتوقع وجودها لهذه المهارة، لذا فهي تتطلب مراجعة ولكن لا تُحتسب كسلوك خبيث مؤكد.
عوامل الخطر
🌐 الوصول إلى الشبكة (3)
📁 الوصول إلى نظام الملفات (8)
🔑 متغيرات البيئة (1)
⚙️ الأوامر الخارجية (88)
٣٠ يونيو ٢٠٢٦، ٠٥:٥٠ ص
Static analysis reported many high-risk patterns, but review found no executable source code or prompt-injection attempt. Most command findings are Markdown examples, while the skill still legitimately directs SSH, scp, hass-cli, token, and Home Assistant storage workflows that can change a live instance.
عناصر مراجعة القدرات (4)
هذه قدرات محلية حقيقية قد يُتوقع وجودها لهذه المهارة، لذا فهي تتطلب مراجعة ولكن لا تُحتسب كسلوك خبيث مؤكد.
تم تجاهل الإيجابيات الكاذبة الثابتة (1)
تم تجاهل هذه المطابقات الثابتة بواسطة المراجعة الدلالية أو لأنها طابقت رموزًا خاصة بالمخطط فقط، لذا تُعرض للشفافية لكنها لا تؤثر في درجة الجودة.
عوامل الخطر
⚙️ الأوامر الخارجية (5)
🌐 الوصول إلى الشبكة (4)
📁 الوصول إلى نظام الملفات (4)
🔑 متغيرات البيئة (4)
الأنماط المكتشفة
١٧ يناير ٢٠٢٦، ٠٨:٠٦ ص
This is a pure prompt-based skill containing only documentation (SKILL.md, README.md) with example commands and configuration patterns. No executable code, scripts, or direct system access is performed by the skill itself. The static analyzer flagged markdown code fences as 'backtick execution' and documentation links as 'hardcoded URLs' - all false positives from documentation pattern matching. The skill provides Claude with expert knowledge about Home Assistant management workflows.
عوامل الخطر
🌐 الوصول إلى الشبكة (1)
📁 الوصول إلى نظام الملفات (1)
🔑 متغيرات البيئة (1)
⚙️ الأوامر الخارجية (1)
١٧ يناير ٢٠٢٦، ٠٨:٠٦ ص
This is a pure prompt-based skill containing only documentation (SKILL.md, README.md) with example commands and configuration patterns. No executable code, scripts, or direct system access is performed by the skill itself. The static analyzer flagged markdown code fences as 'backtick execution' and documentation links as 'hardcoded URLs' - all false positives from documentation pattern matching. The skill provides Claude with expert knowledge about Home Assistant management workflows.
عوامل الخطر
🌐 الوصول إلى الشبكة (1)
📁 الوصول إلى نظام الملفات (1)
🔑 متغيرات البيئة (1)
⚙️ الأوامر الخارجية (1)
٨ يناير ٢٠٢٦، ٠٢:٤٧ ص
This is a pure prompt-based skill containing only documentation and guidance. No executable code, scripts, network calls, or file system access is performed by the skill itself. The skill provides Claude with expert knowledge about Home Assistant management workflows.
٨ يناير ٢٠٢٦، ٠٢:٤٧ ص
This is a pure prompt-based skill containing only documentation and guidance. No executable code, scripts, network calls, or file system access is performed by the skill itself. The skill provides Claude with expert knowledge about Home Assistant management workflows.
٨ يناير ٢٠٢٦، ٠٢:٤٧ ص
This is a pure prompt-based skill containing only documentation and guidance. No executable code, scripts, network calls, or file system access is performed by the skill itself. The skill provides Claude with expert knowledge about Home Assistant management workflows.