📦

Audit-Verlauf

coding-standards - 5 Audits

Versionsvergleich

Änderungen an Fähigkeiten und Befunden über geprüfte Versionen hinweg, neueste zuerst.

VersionDatumErgebnisPrüfelementeÄnderung ggü. vorheriger
v5 Neueste20. Juli 2026, 17:15 Keine bestätigten Befunde0Externe Befehle
v4 27. Juni 2026, 16:35 Keine bestätigten Befunde0 Externe Befehle
v3 16. Jan. 2026, 11:58 Keine bestätigten Befunde0Keine Änderung der Fähigkeiten
v2 16. Jan. 2026, 11:58 Keine bestätigten Befunde0Externe Befehle
v1 10. Jan. 2026, 09:08 Keine bestätigten Befunde0Ausgangsbasis

27. Juni 2026, 16:35

Static analysis reported many external command and weak cryptography patterns, but review found they are false positives from Markdown code fences, inline TypeScript identifiers, and ordinary example text. No executable scripts, network calls, credential access, prompt injection, or malicious intent were found in SKILL.md. The skill is safe to publish as documentation-only coding guidance.

1
Gescannte Dateien
436
Analysierte Zeilen
0
Prüfelemente
3
Falschmeldungen ignoriert
Statische falsch positive Treffer ignoriert (3)

Diese statischen Treffer wurden durch semantische Prüfung verworfen oder entsprachen reinen Schema-Tokens; daher werden sie aus Transparenzgründen angezeigt, beeinflussen jedoch nicht die Qualitätsbewertung.

Niedrig
False positive external command detections
The external command detections occur inside Markdown code fences and inline TypeScript examples, such as component structure, hooks, imports, and commit-message formatting. They are documentation examples and are not executed by the skill.
The reviewed locations are Markdown examples and headings, not runnable skill code. No shell invocation, dynamic execution, or instruction to run commands is present.
Niedrig
False positive weak cryptography detections
The weak cryptography detections are caused by unrelated text fragments in the description and TypeScript examples. No cryptographic API, hash function, encryption routine, or password handling logic appears in the skill.
The flagged lines contain prose or ordinary test/example code, not crypto usage. There is no evidence of MD5, SHA1, DES, or similar weak algorithms being used.
Niedrig
False positive reconnaissance detections
The reconnaissance detections map to TypeScript sample code and documentation text, including array find examples and error handling examples. They do not gather system information or inspect a host environment.
The reviewed content is static coding guidance with no operating system commands or environment inspection. No evidence of host reconnaissance was found.
Für dieses abgeschlossene Audit wurden keine bestätigten Sicherheitsbefunde erfasst.
Geprüft von: codex

16. Jan. 2026, 11:58

This skill contains only markdown documentation with TypeScript code examples. All 91 static findings are false positives: hash strings triggered C2/crypto keywords, mathematical formulas were misidentified as cryptographic code, and TypeScript patterns were flagged as system reconnaissance. No executable code, network calls, file system access, or environment variable usage exists.

2
Gescannte Dateien
614
Analysierte Zeilen
1
Prüfelemente
0
Falschmeldungen ignoriert
Geprüft von: claude

16. Jan. 2026, 11:58

This skill contains only markdown documentation with TypeScript code examples. All 91 static findings are false positives: hash strings triggered C2/crypto keywords, mathematical formulas were misidentified as cryptographic code, and TypeScript patterns were flagged as system reconnaissance. No executable code, network calls, file system access, or environment variable usage exists.

2
Gescannte Dateien
614
Analysierte Zeilen
1
Prüfelemente
0
Falschmeldungen ignoriert
Geprüft von: claude

10. Jan. 2026, 09:08

This skill contains only documentation in markdown format. No executable code, scripts, network calls, filesystem access, or environment variable access. Pure reference documentation for coding standards.

1
Gescannte Dateien
436
Analysierte Zeilen
0
Prüfelemente
0
Falschmeldungen ignoriert
Für dieses abgeschlossene Audit wurden keine bestätigten Sicherheitsbefunde erfasst.
Geprüft von: claude