Fähigkeiten markdown Audit-Verlauf
📦

Audit-Verlauf

markdown - 6 Audits

Versionsvergleich

Änderungen an Fähigkeiten und Befunden über geprüfte Versionen hinweg, neueste zuerst.

VersionDatumErgebnisPrüfelementeÄnderung ggü. vorheriger
v6 Neueste4. Juli 2026, 17:36 Keine bestätigten Befunde0Keine Änderung der Fähigkeiten
v5 4. Juli 2026, 17:36 Keine bestätigten Befunde0Netzwerkzugriff Dateisystemzugriff
v4 27. Juni 2026, 16:22 1 bestätigt0Dateisystemzugriff Netzwerkzugriff
v3 16. Jan. 2026, 14:47 Keine bestätigten Befunde0Keine Änderung der Fähigkeiten
v2 16. Jan. 2026, 14:47 Keine bestätigten Befunde0NetzwerkzugriffExterne Befehle
v1 10. Jan. 2026, 09:05 Keine bestätigten Befunde0Ausgangsbasis

27. Juni 2026, 16:22

Static command findings are mostly false positives from Markdown code fences, not Ruby backtick execution. The skill still directs agents to run markdownlint-cli2 and shell file operations on documents, so publication is reasonable with a warning. No prompt injection, malicious network behavior, or cryptographic code was found.

1
Gescannte Dateien
269
Analysierte Zeilen
3
Prüfelemente
3
Falschmeldungen ignoriert

Bestätigte Sicherheitsbedenken (1)

Mittel
External Command and File Modification Guidance
The skill instructs agents to run markdownlint-cli2, copy files, list files, and write a markdownlint configuration. This is legitimate for Markdown linting, but it can modify user documents or project configuration if paths are not scoped carefully.
The commands are clearly documented and intended for linting workflows. Risk is moderate because they can alter files, but no malicious command or exfiltration behavior is present.
Statische falsch positive Treffer ignoriert (3)

Diese statischen Treffer wurden durch semantische Prüfung verworfen oder entsprachen reinen Schema-Tokens; daher werden sie aus Transparenzgründen angezeigt, beeinflussen jedoch nicht die Qualitätsbewertung.

Niedrig
Markdown Code Fences Misclassified as Ruby Backticks
The static external command detections are triggered by Markdown fenced examples. The file contains documentation and command examples, not Ruby backtick execution code.
The referenced lines are Markdown fences and examples in SKILL.md. No Ruby source file or executable backtick expression is present.
Niedrig
Documentation Link Misclassified as Network Access
The hardcoded URL points to markdownlint rule documentation. The skill does not instruct agents to fetch, upload, or transmit data to that URL.
The only URL appears in a documentation reference line. There is no network command, request API, or data transfer instruction nearby.
Niedrig
Weak Cryptography Finding Is Not Supported
The static high-risk cryptography finding points to the YAML description area. No cryptographic algorithm, hashing operation, or security-sensitive primitive appears there.
The cited lines only describe Markdown linting. I found no evidence of MD5, SHA1, encryption, signing, or password handling in the skill file.

Erkannte Muster

External Command and File Modification Guidance
Geprüft von: codex

10. Jan. 2026, 09:05

This is a prompt-based documentation skill with no executable code. The skill provides guidelines for using markdownlint-cli2, a legitimate open-source markdown linting tool. No concerning patterns detected.

1
Gescannte Dateien
269
Analysierte Zeilen
0
Prüfelemente
0
Falschmeldungen ignoriert
Für dieses abgeschlossene Audit wurden keine bestätigten Sicherheitsbefunde erfasst.
Geprüft von: claude