Audit-Verlauf
quality-reviewer - 6 Audits
Audit-Version 6
Neueste Mittleres RisikoJun 28, 2026, 10:15 AM
Static external-command and weak-cryptography alerts are mostly false positives from Markdown fences, inline code formatting, and words such as description. The skill is still medium risk because it grants wildcard tool access, asks the agent to inspect project files, and requires web research.
Probleme mit mittlerem Risiko (2)
Probleme mit niedrigem Risiko (3)
Risikofaktoren
⚙️ Externe Befehle (1)
📁 Dateisystemzugriff (1)
🌐 Netzwerkzugriff (2)
Erkannte Muster
Audit-Version 5
SicherJan 16, 2026, 04:02 PM
All 20 static findings are FALSE_POSITIVES. The scanner misclassified documentation syntax (markdown code blocks, backticks, URL fields) as executable code patterns. This is a pure prompt-based skill containing only markdown documentation. The 'ls' commands are example instructions, not executed code. No actual cryptographic algorithms, external commands, or network calls exist in this skill file.
Risikofaktoren
⚙️ Externe Befehle (8)
Audit-Version 4
SicherJan 16, 2026, 04:02 PM
All 20 static findings are FALSE_POSITIVES. The scanner misclassified documentation syntax (markdown code blocks, backticks, URL fields) as executable code patterns. This is a pure prompt-based skill containing only markdown documentation. The 'ls' commands are example instructions, not executed code. No actual cryptographic algorithms, external commands, or network calls exist in this skill file.
Risikofaktoren
⚙️ Externe Befehle (8)
Audit-Version 3
SicherJan 10, 2026, 10:22 AM
Prompt-based skill containing only markdown documentation for AI code review guidance. No executable code, scripts, or network calls. Operates as a system prompt instructing the AI to perform file reading and web research - appropriate for the stated purpose.
Audit-Version 2
SicherJan 10, 2026, 10:22 AM
Prompt-based skill containing only markdown documentation for AI code review guidance. No executable code, scripts, or network calls. Operates as a system prompt instructing the AI to perform file reading and web research - appropriate for the stated purpose.
Audit-Version 1
SicherJan 10, 2026, 10:22 AM
Prompt-based skill containing only markdown documentation for AI code review guidance. No executable code, scripts, or network calls. Operates as a system prompt instructing the AI to perform file reading and web research - appropriate for the stated purpose.