Fähigkeiten doc-writer Audit-Verlauf
📦

Audit-Verlauf

doc-writer - 6 Audits

Versionsvergleich

Änderungen an Fähigkeiten und Befunden über geprüfte Versionen hinweg, neueste zuerst.

VersionDatumErgebnisPrüfelementeÄnderung ggü. vorheriger
v6 Neueste4. Juli 2026, 13:29 Keine bestätigten Befunde0Keine Änderung der Fähigkeiten
v5 4. Juli 2026, 13:29 Keine bestätigten Befunde0Externe Befehle Dateisystemzugriff
v4 27. Juni 2026, 12:33 Keine bestätigten Befunde1Dateisystemzugriff Externe Befehle
v3 16. Jan. 2026, 12:09 Keine bestätigten Befunde0Keine Änderung der Fähigkeiten
v2 16. Jan. 2026, 12:09 Keine bestätigten Befunde0Externe Befehle
v1 10. Jan. 2026, 08:50 Keine bestätigten Befunde0Ausgangsbasis

4. Juli 2026, 13:29

The static findings are false positives caused by Markdown inline code around file paths and naming examples in SKILL.md. I found no prompt injection, data exfiltration intent, or unsafe command construction in the reviewed skill instructions.

1
Gescannte Dateien
26
Analysierte Zeilen
1
Prüfelemente
0
Falschmeldungen ignoriert
Geprüft von: codex

4. Juli 2026, 13:29

The static findings are false positives caused by Markdown inline code around file paths and naming examples in SKILL.md. I found no prompt injection, data exfiltration intent, or unsafe command construction in the reviewed skill instructions.

1
Gescannte Dateien
26
Analysierte Zeilen
1
Prüfelemente
0
Falschmeldungen ignoriert
Geprüft von: codex

27. Juni 2026, 12:33

The static analyzer reported shell execution and weak cryptography patterns, but the reviewed lines are Markdown code spans and prose, not executable code. The skill has a low residual risk because it instructs the assistant to read and write repository documentation files and optionally run configured validators.

1
Gescannte Dateien
26
Analysierte Zeilen
2
Prüfelemente
1
Falschmeldungen ignoriert
Elemente der Fähigkeitsprüfung (1)

Dies sind echte lokale Fähigkeiten, die für diese Fähigkeit erwartet werden können; daher müssen sie überprüft werden, werden jedoch nicht als bestätigtes bösartiges Verhalten gezählt.

Niedrig
Filesystem Documentation Changes
The skill asks the assistant to create or update Markdown files in repository documentation directories. This is expected behavior for a documentation skill, but users should review generated files before commit.
The instructions explicitly require generating or refreshing documentation files and saving them under documentation directories. This is a clear filesystem modification behavior, but it matches the declared purpose.
Statische falsch positive Treffer ignoriert (1)

Diese statischen Treffer wurden durch semantische Prüfung verworfen oder entsprachen reinen Schema-Tokens; daher werden sie aus Transparenzgründen angezeigt, beeinflussen jedoch nicht die Qualitätsbewertung.

Niedrig
Static Analyzer False Positives
The reported shell backtick and weak cryptography findings are not executable code. The flagged text consists of Markdown code spans, file names, directory names, and a plain description.
The reviewed file is a short Markdown instruction file with no Ruby, shell script, or cryptographic implementation. The flagged backticks are Markdown formatting, not command substitution.

Risikofaktoren

Geprüft von: codex

16. Jan. 2026, 12:09

This is a pure documentation skill with no executable code. The static analyzer flagged 20 false positives due to pattern matching on file paths and URL strings in markdown and JSON. No network calls, file system operations, external commands, or cryptographic operations exist in these files. Only plain text documentation and metadata.

2
Gescannte Dateien
206
Analysierte Zeilen
1
Prüfelemente
0
Falschmeldungen ignoriert
Geprüft von: claude

16. Jan. 2026, 12:09

This is a pure documentation skill with no executable code. The static analyzer flagged 20 false positives due to pattern matching on file paths and URL strings in markdown and JSON. No network calls, file system operations, external commands, or cryptographic operations exist in these files. Only plain text documentation and metadata.

2
Gescannte Dateien
206
Analysierte Zeilen
1
Prüfelemente
0
Falschmeldungen ignoriert
Geprüft von: claude

10. Jan. 2026, 08:50

Pure prompt-based skill containing only documentation guidelines. No executable code, no network calls, no file system access, no external commands. This is a configuration file that instructs an AI how to write documentation using repository templates and context.

1
Gescannte Dateien
26
Analysierte Zeilen
0
Prüfelemente
0
Falschmeldungen ignoriert
Für dieses abgeschlossene Audit wurden keine bestätigten Sicherheitsbefunde erfasst.
Geprüft von: claude