سجل التدقيق
wecom-unified - 2 عمليات التدقيق
مقارنة الإصدارات
التغييرات في القدرات والنتائج عبر الإصدارات المدقّقة، الأحدث أولاً.
١٨ أغسطس ٢٠٢٦، ٠٨:٣٠ ص
Most static findings are false positives caused by multilingual documentation, Markdown code formatting, example URLs, and defensive file-handling code. The audit identified one material workflow risk: the skill can automatically install an unpinned global npm package without user confirmation. No prompt-injection language, credential exfiltration, or concealed executable payload was found in the reviewed evidence.
مخاوف أمنية مؤكدة (1)
عوامل الخطر
⚙️ الأوامر الخارجية (50)
📁 الوصول إلى نظام الملفات (8)
🌐 الوصول إلى الشبكة (10)
🔑 متغيرات البيئة (1)
١٨ أغسطس ٢٠٢٦، ٠٨:٣٠ ص
Most static findings are false positives caused by multilingual documentation, Markdown code formatting, example URLs, and defensive file-handling code. The audit identified one material workflow risk: the skill can automatically install an unpinned global npm package without user confirmation. No prompt-injection language, credential exfiltration, or concealed executable payload was found in the reviewed evidence.