هذا التقرير غير مترجم إلى اللغة المطلوبة. يتم عرض التقرير الإنجليزي الأساسي بدلاً منه.

تقييم أمني مُحدَّث بالإصدار

معرّف التقرير: SA-E96D1BA6

1/30/2026, 3:04:02 AM

game-test-case-generator تقييم أمني v2

تقرير شهادة أمان المهارة

سجل التدقيق
نموذج التدقيق: claude تقرير تاريخي
اسم المهارة
game-test-case-generator
الإصدار
v2
المشرف
snake-mustang
التغطية
11 الملفات التي تم فحصها · 1,983 الأسطر التي تم تحليلها
إصدار السياسة
غير متاح

ملخص الاكتشاف المؤكد

لا توجد نتائج أمنية مؤكدة

لم يسجل التدقيق المكتمل أي نتائج أمنية مؤكدة. لا يُعد هذا دليلاً على أن المهارة ليس لها آثار جانبية.

سياق التثبيت

الأدلة التاريخية

قد لا يصف هذا التقرير العنصر القابل للتثبيت حاليًا. افتح صفحة المهارة الحالية للحصول على إرشادات التثبيت.

افتح صفحة Skill الحالية

لا يحظر هذا التقرير البيان أو ملف ZIP ولا يصرح بهما.

Security review confirms all static findings are false positives. The 48 external_command detections are markdown documentation examples, not code execution. Network references are standard documentation links. Filesystem access is limited to local format conversion utilities. The skill is safe for marketplace publication.

موضع التقرير

تقرير تاريخي

افتح سجل التدقيق قبل استخدام هذا التقرير للتثبيت.

إقرار التدقيق

غير قابل للتصديق

الربط الثابت المطلوب غير مكتمل.

التحقق البشري

لم يتم التحقق منه

لم يتم تسجيل أي تحقق بشري لهذا التقرير.

التغطية

11 الملفات التي تم فحصها · 1,983 الأسطر التي تم تحليلها

0 عناصر معروضة للمراجعة

القيود

لا يدّعي هذا التقرير تنفيذًا في وقت التشغيل أو ضمن بيئة معزولة، ولا يثبت عدم وجود آثار جانبية.

سلسلة الأدلة

اتبع الأدلة من ربط المصدر إلى عقد التثبيت. تدعم الأدلة المتاحة التحقق؛ لكنها ليست ضمانًا للسلامة.

  1. المصدر

    الربط غير متاح

  2. العنصر البرمجي

    الهوية غير مكتملة

  3. التدقيق

    مكتمل

  4. عقد التثبيت

    افتح البيان للتحقق

    افتح البيان

القدرات المرصودة

تعني «تمت ملاحظته» أن هذا التقرير سجل أدلة داعمة. ولا يثبت عدم التسجيل أن القدرة غير موجودة.

يحتوي على سكربتات

قد ينفذ تعليمات برمجية مضمنة مع المهارة.

لم يتم تسجيله بواسطة هذا التدقيق

الوصول إلى الشبكة

قد يتصل بخدمات خارجية.

تمت ملاحظته في 4 مواضع أدلة

الوصول إلى نظام الملفات

قد يقرأ أو يكتب ملفات محلية.

تمت ملاحظته في 3 مواضع أدلة

متغيرات البيئة

قد يقرأ قيماً من بيئة العملية.

لم يتم تسجيله بواسطة هذا التدقيق

الأوامر الخارجية

قد يستدعي أوامر أو برامج خارج المهارة.

تمت ملاحظته في 48 مواضع أدلة

نتائج المخاطر

يتم فصل المخاوف الأمنية المؤكدة عن العناصر التي لا تزال بحاجة إلى مراجعة.

لم تُسجّل نتائج أمنية مؤكدة لهذا التدقيق المكتمل.

أدلة الخبراء

هوية موضوع غير قابلة للتغيير، وبيانات تعريف الماسح الضوئي، والمطابقات المستبعدة، والأدلة على مستوى المصدر.

موضوع العنصر البرمجي

التزام Marketplace
غير متاح
تجزئة المحتوى
غير متاح
تجزئة الشجرة
غير متاح
مسار Skill
غير متاح
تجزئة حمولة التدقيق
غير متاح

البيانات الوصفية للتحليل

نموذج التدقيق: claude

حالة التحليل: مكتمل

النطاق محدود بالملفات والأسطر والأساليب والأدلة المسجلة. لا يُدّعى تنفيذ وقت التشغيل أو بيئة الاختبار المعزولة.

تم تجاهل الإيجابيات الكاذبة الثابتة (6)
حرج
Prompt Injection Attempt Detected
Critical heuristic flagged dangerous combination of code execution, network, and credential access. Evaluation: This is a false positive. The skill contains documentation showing command examples (markdown code blocks) and documentation links. No actual code execution, network requests, or credential access occurs. The skill is a test case generator with no runtime network or credential functionality.
All 48 external_command detections are markdown documentation examples showing command syntax. Network detections are standard documentation URLs. Filesystem access is limited to local file read/write for format conversion.
متوسط
Ruby/Shell Backtick Execution Documentation
Pattern detected at multiple locations in README.md and SKILL.md. These are markdown documentation examples showing command syntax for format conversion scripts, not actual code execution.
Backticks in markdown denote code formatting for documentation, not shell execution. Commands like `python scripts/convert_to_excel.py` are example usage instructions.
متوسط
Hidden File Access Reference
Documentation references to ~/.cursor/skills/ directory. This is standard cursor skill installation documentation, not hidden file exploitation.
The ~/.cursor/skills/ path is the standard installation location for Cursor editor skills, documented for user installation purposes.
منخفض
Hardcoded URLs in Documentation
URLs detected in README.md for badges and documentation links. These are standard markdown image and link references.
URLs are license badges and documentation links. No sensitive data transmission occurs.
منخفض
System Reconnaissance in Test Documents
Example test documents contain test scenarios for network disconnection and system states. These are legitimate test cases, not reconnaissance.
Test documents describing scenarios like network disconnection are standard test case content for testing game behavior under abnormal conditions.
منخفض
High File Entropy
Markdown files show elevated entropy scores (6.25-7.33 bits). This is normal for files containing Chinese Unicode text and mixed content.
Chinese Unicode characters and mixed content naturally increase file entropy. Files are standard markdown documentation.

التحقق والتصدير

يربط البيان وملف القفل عناصر التثبيت بتجزئات تشفيرية. هذا الادعاء المتعلق بالسلامة منفصل عن التقييم الأمني.

إقرار التدقيق: not_attestable