📦

Audit-Verlauf

crud-with-spec-kit - 6 Audits

Audit-Version 6

Neueste Sicher

Jun 28, 2026, 03:50 AM

The five high-severity static weak-cryptography alerts are false positives caused by normal prose in SKILL.md, including words such as description, describing, desired, and codes. No evidence found of cryptographic code, command execution, network access, data exfiltration, or prompt-injection attempts.

1
Gescannte Dateien
192
Analysierte Zeilen
1
Review items
0
False positives ignored

Confirmed security concerns (1)

Niedrig
False Positive: Weak Cryptographic Algorithm Alerts
Static analysis reported weak cryptographic algorithm patterns at the listed prose-only lines. These lines describe CRUD workflow concepts and contain no cryptographic algorithm use, implementation code, imports, or executable commands.
The matched lines are documentation text only, and none contain crypto APIs or algorithm names used as code. Confidence is very low that these alerts represent a real security issue.
Geprüft von: codex

Audit-Version 5

Sicher

Jan 16, 2026, 03:44 PM

Pure documentation skill with no executable code. Static findings are false positives from the scanner misinterpreting documentation text as security patterns.

2
Gescannte Dateien
369
Analysierte Zeilen
0
Review items
0
False positives ignored
Keine Sicherheitsprobleme gefunden
Geprüft von: claude

Audit-Version 4

Sicher

Jan 16, 2026, 03:44 PM

Pure documentation skill with no executable code. Static findings are false positives from the scanner misinterpreting documentation text as security patterns.

2
Gescannte Dateien
369
Analysierte Zeilen
0
Review items
0
False positives ignored
Keine Sicherheitsprobleme gefunden
Geprüft von: claude

Audit-Version 3

Sicher

Jan 10, 2026, 09:48 AM

Pure documentation file containing only conceptual guidance. No executable code, scripts, network calls, or filesystem access detected. Safe for publication.

1
Gescannte Dateien
192
Analysierte Zeilen
0
Review items
0
False positives ignored
Keine Sicherheitsprobleme gefunden
Geprüft von: claude

Audit-Version 2

Sicher

Jan 10, 2026, 09:48 AM

Pure documentation file containing only conceptual guidance. No executable code, scripts, network calls, or filesystem access detected. Safe for publication.

1
Gescannte Dateien
192
Analysierte Zeilen
0
Review items
0
False positives ignored
Keine Sicherheitsprobleme gefunden
Geprüft von: claude

Audit-Version 1

Sicher

Jan 10, 2026, 09:48 AM

Pure documentation file containing only conceptual guidance. No executable code, scripts, network calls, or filesystem access detected. Safe for publication.

1
Gescannte Dateien
192
Analysierte Zeilen
0
Review items
0
False positives ignored
Keine Sicherheitsprobleme gefunden
Geprüft von: claude