監査履歴
agentic-structure - 10 監査
バージョン比較
監査済みバージョン間の機能と検出結果の変化(新しい順)。
| バージョン | 日付 | 結果 | レビュー項目 | 前バージョンとの変化 |
|---|---|---|---|---|
| v10 最新 | 9. Juli 2026, 01:06 | 確認された検出結果なし | 0 | 機能の変化なし |
| v9 | 9. Juli 2026, 01:06 | 確認された検出結果なし | 0 | 機能の変化なし |
| v8 | 6. Juli 2026, 02:48 | 確認された検出結果なし | 0 | 機能の変化なし |
| v7 | 6. Juli 2026, 02:48 | 確認された検出結果なし | 0 | ファイルシステムへのアクセスネットワークアクセス |
| v6 | 28. Juni 2026, 13:12 | 確認された検出結果なし | 2 | ファイルシステムへのアクセスネットワークアクセス 外部コマンド |
| v5 | 16. Jan. 2026, 17:20 | 確認された検出結果なし | 0 | 機能の変化なし |
| v4 | 16. Jan. 2026, 17:20 | 確認された検出結果なし | 0 | 外部コマンド |
| v3 | 10. Jan. 2026, 10:55 | 確認された検出結果なし | 0 | 機能の変化なし |
| v2 | 10. Jan. 2026, 10:55 | 確認された検出結果なし | 0 | 機能の変化なし |
| v1 | 10. Jan. 2026, 10:55 | 確認された検出結果なし | 0 | 基準 |
9. Juli 2026, 01:06
All static findings are false positives caused by benign guideline language and defensive security examples. The skill is a documentation-only programming framework with read-only allowed tools and no evidence of prompt injection, data exfiltration intent, command execution, or unsafe network behavior.
9. Juli 2026, 01:06
All static findings are false positives caused by benign guideline language and defensive security examples. The skill is a documentation-only programming framework with read-only allowed tools and no evidence of prompt injection, data exfiltration intent, command execution, or unsafe network behavior.
6. Juli 2026, 02:48
All static findings are false positives caused by security and development guideline prose. The files provide defensive coding, collaboration, secret-handling, hashing, and error-handling guidance; I found no malicious intent, prompt injection, executable payloads, or data-exfiltration behavior.
静的解析の誤検知を無視 (1)
これらの静的マッチはセマンティックレビューで却下されたか、スキーマのみのトークンに一致したため、透明性のために表示されていますが、品質スコアには影響しません。
6. Juli 2026, 02:48
All static findings are false positives caused by security and development guideline prose. The files provide defensive coding, collaboration, secret-handling, hashing, and error-handling guidance; I found no malicious intent, prompt injection, executable payloads, or data-exfiltration behavior.
静的解析の誤検知を無視 (1)
これらの静的マッチはセマンティックレビューで却下されたか、スキーマのみのトークンに一致したため、透明性のために表示されていますが、品質スコアには影響しません。
28. Juni 2026, 13:12
Static analysis reported many critical and high patterns, but review found them to be documentation false positives, mostly Markdown backticks, security terminology, and examples that warn against unsafe practices. No prompt injection, credential access, malware behavior, or command execution intent was found. The remaining low risk is that the knowledge protocol describes creating reference files and using web fetches for documentation.
機能レビュー項目 (2)
これらは、このスキルに期待される可能性のある実際のローカル機能であるため、レビューが必要ですが、確認済みの悪意ある動作としてはカウントされません。
静的解析の誤検知を無視 (2)
これらの静的マッチはセマンティックレビューで却下されたか、スキーマのみのトークンに一致したため、透明性のために表示されていますが、品質スコアには影響しません。
リスク要因
📁 ファイルシステムへのアクセス (4)
16. Jan. 2026, 17:20
Pure documentation skill containing only markdown guidelines. No executable code, no network operations, no command execution. The skill specifies allowed-tools: Read, Grep, Glob only. All 142 static findings are FALSE POSITIVES caused by the scanner detecting security terminology in documentation (e.g., 'Do not use MD5' flagged as 'weak crypto').
リスク要因
⚙️ 外部コマンド (36)
16. Jan. 2026, 17:20
Pure documentation skill containing only markdown guidelines. No executable code, no network operations, no command execution. The skill specifies allowed-tools: Read, Grep, Glob only. All 142 static findings are FALSE POSITIVES caused by the scanner detecting security terminology in documentation (e.g., 'Do not use MD5' flagged as 'weak crypto').
リスク要因
⚙️ 外部コマンド (36)
10. Jan. 2026, 10:55
Pure prompt-based skill containing only markdown documentation files. No executable code, network operations, filesystem access, or command execution. The skill provides development guidelines for AI coding assistants.
10. Jan. 2026, 10:55
Pure prompt-based skill containing only markdown documentation files. No executable code, network operations, filesystem access, or command execution. The skill provides development guidelines for AI coding assistants.
10. Jan. 2026, 10:55
Pure prompt-based skill containing only markdown documentation files. No executable code, network operations, filesystem access, or command execution. The skill provides development guidelines for AI coding assistants.