Audit-Verlauf
markdown - 6 Audits
Versionsvergleich
Änderungen an Fähigkeiten und Befunden über geprüfte Versionen hinweg, neueste zuerst.
| Version | Datum | Ergebnis | Prüfelemente | Änderung ggü. vorheriger |
|---|---|---|---|---|
| v6 Neueste | 4. Juli 2026, 17:36 | Keine bestätigten Befunde | 0 | Keine Änderung der Fähigkeiten |
| v5 | 4. Juli 2026, 17:36 | Keine bestätigten Befunde | 0 | Netzwerkzugriff Dateisystemzugriff |
| v4 | 27. Juni 2026, 16:22 | 1 bestätigt | 0 | Dateisystemzugriff Netzwerkzugriff |
| v3 | 16. Jan. 2026, 14:47 | Keine bestätigten Befunde | 0 | Keine Änderung der Fähigkeiten |
| v2 | 16. Jan. 2026, 14:47 | Keine bestätigten Befunde | 0 | NetzwerkzugriffExterne Befehle |
| v1 | 10. Jan. 2026, 09:05 | Keine bestätigten Befunde | 0 | Ausgangsbasis |
4. Juli 2026, 17:36
The static analyzer matched Markdown fences and inline code as Ruby backtick execution. Review found documented markdownlint-cli2 usage and a public documentation URL, with no prompt injection, data exfiltration, or arbitrary command construction in SKILL.md.
Risikofaktoren
⚙️ Externe Befehle (37)
🌐 Netzwerkzugriff (1)
4. Juli 2026, 17:36
The static analyzer matched Markdown fences and inline code as Ruby backtick execution. Review found documented markdownlint-cli2 usage and a public documentation URL, with no prompt injection, data exfiltration, or arbitrary command construction in SKILL.md.
Risikofaktoren
⚙️ Externe Befehle (37)
🌐 Netzwerkzugriff (1)
27. Juni 2026, 16:22
Static command findings are mostly false positives from Markdown code fences, not Ruby backtick execution. The skill still directs agents to run markdownlint-cli2 and shell file operations on documents, so publication is reasonable with a warning. No prompt injection, malicious network behavior, or cryptographic code was found.
Bestätigte Sicherheitsbedenken (1)
Statische falsch positive Treffer ignoriert (3)
Diese statischen Treffer wurden durch semantische Prüfung verworfen oder entsprachen reinen Schema-Tokens; daher werden sie aus Transparenzgründen angezeigt, beeinflussen jedoch nicht die Qualitätsbewertung.
Risikofaktoren
⚙️ Externe Befehle (4)
📁 Dateisystemzugriff (4)
Erkannte Muster
16. Jan. 2026, 14:47
This is a documentation-only skill with no executable code. All flagged patterns are false positives from markdown documentation content. The skill provides instructions for using markdownlint-cli2, a legitimate open-source tool. No security concerns identified.
Risikofaktoren
🌐 Netzwerkzugriff (1)
⚙️ Externe Befehle (39)
16. Jan. 2026, 14:47
This is a documentation-only skill with no executable code. All flagged patterns are false positives from markdown documentation content. The skill provides instructions for using markdownlint-cli2, a legitimate open-source tool. No security concerns identified.
Risikofaktoren
🌐 Netzwerkzugriff (1)
⚙️ Externe Befehle (39)
10. Jan. 2026, 09:05
This is a prompt-based documentation skill with no executable code. The skill provides guidelines for using markdownlint-cli2, a legitimate open-source markdown linting tool. No concerning patterns detected.